HMAC Forgery
Hashing
🔴 Qiyin
500 ball
0 ta yechim
Length Extension hujumi - MD5 va SHA1 ga qarshi:
HMAC-MD5(secret || "admin=false") bilasiz
secret uzunligi = 10 bayt
"admin=true" uchun HMAC yasang.
(Kontseptual: NULL{length_extension_attack})
🚩 Flag topshirish
Flag topshirish uchun
tizimga kiring
yoki
ro'yxatdan o'ting.