@app.route('/',methods=['POST']) defindex(): username = request.form.get('username') password = request.form.get('password') session["username"] = username session["password"] = password Evil = evil() if request.data: iffilter(str(request.data)): return"NO POLLUTED!!!YOU NEED TO GO HOME TO SLEEP~" else: merge(json.loads(request.data), Evil) return"MYBE YOU SHOULD GO /ADMIN TO SEE WHAT HAPPENED" return render_template("index.html")
@app.route('/admin',methods=['POST', 'GET']) deftemplates(): username = session.get("username", None) password = session.get("password", None) if username and password: if username == "adminer"and password == app.secret_key: return render_template("important.html", flag=open("/flag", "rt").read()) else: return"Unauthorized" else: returnf'Hello, This is the POLLUTED page.'
if __name__ == '__main__': app.run(host='0.0.0.0',debug=True, port=80)