# [CH] Trending Cats ###### tags:`Writeup` `Web` `Chinese` > [name=FlyDragon] ## Step.1 在新分頁中開啟圖片可以發現每個貓貓都有四位數編號 ![](https://hackmd.io/_uploads/SyVSiy2P3.png) ## Step.2 已知沒有編號 1 的貓咪,利用這點撰寫程式 ```py= import requests NotFound = requests.get(f"http://lotuxctf.com:20003/1.jpg").text found = [] for i in range(6000, 7000): print(i) response = requests.get(f"http://lotuxctf.com:20003/{i}.jpg").text if(response != NotFound): print(f"found at {i}") found.append(i) print(found) ``` 可以找到編號 6166 的 `spin cat` ![](https://hackmd.io/_uploads/BJ_t6JnP2.png) ## Step.3 根據其他頁面的命名規則推測會有 `spin.php` ![](https://hackmd.io/_uploads/r1jGA12vn.png) ## Step.4 點擊按鈕發現會送出 `cat=aGFwcHk%3D` base64 decode `aGFwcHk%3D --> happy` base64 encode `spin --> c3Bpbg==` --> `spin.php?cat=c3Bpbg==` 得到 flag ![](https://hackmd.io/_uploads/Sy3PklhD3.png) {%hackmd M1bgOPoiQbmM0JRHWaYA1g %}