From 22cfa3027e437958243f4c98dc564e9259dececb Mon Sep 17 00:00:00 2001 From: thomashaw Date: Tue, 9 May 2017 15:24:46 +0100 Subject: [PATCH] removing special chars from b64 flag generator + changed qr code link --- modules/generators/flag/flag_base64/secgen_local/local.rb | 6 +++++- modules/generators/image/qr_code/secgen_metadata.xml | 2 +- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/modules/generators/flag/flag_base64/secgen_local/local.rb b/modules/generators/flag/flag_base64/secgen_local/local.rb index bd273a113..9de54fc08 100644 --- a/modules/generators/flag/flag_base64/secgen_local/local.rb +++ b/modules/generators/flag/flag_base64/secgen_local/local.rb @@ -8,7 +8,11 @@ class Base64FlagGenerator < StringGenerator def generate require 'securerandom' - self.outputs << "flag{#{SecureRandom.base64}}" + flag = SecureRandom.base64 + flag.tr!('/','', ) + flag.tr!('+', '' ) + flag.tr!('=', '') + self.outputs << "flag{#{flag}}" end end diff --git a/modules/generators/image/qr_code/secgen_metadata.xml b/modules/generators/image/qr_code/secgen_metadata.xml index 89c0e6564..4874bdaac 100644 --- a/modules/generators/image/qr_code/secgen_metadata.xml +++ b/modules/generators/image/qr_code/secgen_metadata.xml @@ -17,7 +17,7 @@ https://github.com/whomwah/rqrcode - Use a QR reader mobile app or online decoder e.g. http://blog.qr4.nl/Online-QR-Code_decoder.aspx + Use a QR reader mobile app or online decoder e.g. https://online-barcode-reader.inliteresearch.com/ strings_to_leak