当前位置:网站首页>ctf [RoarCTF 2019]easy_ calc
ctf [RoarCTF 2019]easy_ calc
2022-06-26 04:16:00 【eliforsharon】
I've learned something new, so record it
First, it's easy to find calc.php, however url Of get But I can't input characters , After the query, it is found that PHP String parsing features of .
utilize PHP String parsing features of
utilize PHP String parsing features of Bypass
This article is very detailed , And the subject of waf Only numbers are allowed , The input string... Is not allowed , use num=%20 Can bypass La .
Then you can go through chr To bypass .
View directory
var_dump(scandir(chr(47)));
see flagg
var_dump(file_get_contents(chr(47).chr(102).chr(49).chr(97).chr(103).chr(103)));
utilize HTTP Smuggling bypass
Vulnerability related articles
According to the vulnerability of inconsistent data received at the front and back end , I don't quite understand QAQ
边栏推荐
- Quanergy welcomes Lori sundberg as chief human resources officer
- 六、项目实战---识别猫和狗
- MapReduce execution principle record
- Spark - 一文搞懂 parquet
- Matplotlib multi line chart, dot scatter chart
- [QT] resource file import
- Parse JSON interface and insert it into the database in batch
- Threejs专用天空盒素材,五种天空盒素材免费下载
- The open software of win10 system is too small. How to make it larger (effective through personal test)
- WPF value conversion
猜你喜欢
Unity mobile game performance optimization spectrum CPU time-consuming optimization divided by engine modules
【QT】资源文件导入
线程同步之读写锁
【QT】对话框dialog
Judge the same value of two sets 𞓜 different values
【掘金运营套路揭露】真心被掘金的套路....
[Qunhui] no port access (reverse proxy + intranet penetration)
Clickhouse stand alone installation
How to use EEPROM in 51 Single Chip Microcomputer?
线程同步之条件变量
随机推荐
China air compressor manufacturing market demand analysis and investment prospect research report 2022-2028
WPF 值转换
What should I do if I don't understand the precious metal indicators
Webrtc series - 7-ice supplement of network transmission preference and priority
Capture packets (Wireshark)
Getting started with flask
Analysis report on development trend and market demand of global and Chinese molecular diagnostics industry from 2022 to 2028
Nailing open platform - applet development practice (nailing applet server side)
bubble sort
[Qunhui] command line acme SH automatically apply for domain name certificate
Zeromq from getting started to mastering
解析JSON接口并批量插入到数据库中
在出海获客这件事上,数字广告投放之外,广告主还能怎么玩儿?
捕获数据包(Wireshark)
[从零开始学习FPGA编程-45]:视野篇 - 集成电路助力数字化时代高质量发展-2-市场预测
Wechat applet is bound to a dynamic array to implement a custom radio box (after clicking the button, disable the button and enable other buttons)
Threejs专用天空盒素材,五种天空盒素材免费下载
使用Jsoup提取接口中的图片
What should I do if the 51 SCM board cannot find the device in keil
Analysis report on the development trend and operation status of China's environmental monitoring instrument industry from 2022 to 2028