flag from indexed db : U2FsdGVkX19wWL7itIL7TZcLTP/e1ulrZolI9AHTA8OBGOCodbZKdOxPF41rGV9C+X7PZPt9ISJKQMpTl+Fwew==
{"code":"CryptoJS.AES.decrypt(CIPHERTEXT, KEY).toString(CryptoJS.enc.Utf8)"} ( kita dapetin dari session ) kita asumsi bahwa flagnya nanti memakai function ini tinggal cari secretnya
secret ada di session lgsg aja
CryptoJS.AES.decrypt('U2FsdGVkX19wWL7itIL7TZcLTP/e1ulrZolI9AHTA8OBGOCodbZKdOxPF41rGV9C+X7PZPt9ISJKQMpTl+Fwew==','secret key is very secure').toString(CryptoJS.enc.Utf8)
flag : TBTL{th15_1S_n0t_53CUR3_5T0r4G3}
Talk to you
lfi on the page , first we use ../flag.txt and the site said the flag in database.sqlite so we change the parameter and we get the flag