Natas 5-6 change cookie

how to solve:

Username: natas5
password: iX6IOfmpN7AYOQGPwtn3fXpbaJVJcHfq
URL: http://natas5.natas.labs.overthewire.org

You are notloggedin. This is a bit of a conundrum, obviously we are logged in, but we are not logged in, why is this?

Here we have to talk about the characteristics of the http protocol, http protocol is a stateless protocol, each time the transfer of data will be disconnected, so how can we verify the identity of it, then rely on the cookie, the cookie is assigned by the server to the browser, the cookie stores the status of the session and the identity of the information, and then each http request, will take the cookie information to the server. Each http request will bring the cookie information to the server, and the server will make different responses according to the cookie information.

source code here:

Well, question is solved, what about the knoweldge? I know nothing about cookie before except it is ‘bad’. I need to know more about why it’s ‘bad’.

It was already 2:00 today, I will go deeper tomorrow.

Published by endecoder

MY shitting learning experience

Leave a comment