[极客大挑战 2019]Http
检查源码,发现Secret.php
进入Secret.php
It doesn't come from 'https://www.Sycsecret.com'提示
burp抓包修改Referer
Referer: https://www.Sycsecret.com
提示Please use "Syclover" brows
修改UA
User-Agent: Syclover
提示No!!! you can only read this locally!!!
修改XFF
X-Forwarded-For: 127.0.0.1
得到flag