본문 바로가기

Web Security/webhacking.kr

[Webhacking.kr] old-17


This problem is in webhacking.kr.
URL: https://webhacking.kr/challenge/js-4//

If you enter the URL, you can see the below photo.


First, View Source

<title>Challenge 17</title>
<body bgcolor=black>
<font color=red size=10></font>
<form name=login>
<input type=passwd name=pw><input type=button onclick=sub() value="check">
function sub(){ if(login.pw.value==unlock){ location.href="?"+unlock/10; } else{ alert("Wrong"); } }

you can do it like this to get the value of "unlock".




If you enter the value on the input tag, you can solve the problem.


'Web Security > webhacking.kr' 카테고리의 다른 글

[Webhacking.kr] old-20  (0) 2021.08.01
[Webhacking.kr] old-18  (0) 2021.08.01
[Webhacking.kr] old-16  (0) 2021.08.01
[Webhacking.kr] old-14  (0) 2021.08.01
[Webhacking.kr] old-13  (0) 2021.08.01