当前位置:网站首页>Ctfshow web entry information collection
Ctfshow web entry information collection
2022-07-05 14:58:00 【Cwxh0125】
Catalog
web3
You can see it by grabbing the bag directly flag
web4

Try to access robots.txt

web5
Topic tips phps Source code leakage

download phps Open the source file
web6

According to the tip flag Put it in
Check the source code after downloading .
After submitting, it is found that there is something wrong Try to visit url/fl000g.txt obtain flag
web7

First, learn about version control
During code development , You often need to modify the source code many times , In this way, multiple versions of the same code are generated , In the development process, it is usually necessary to manage these multiple versions of code , So that it can be done when necessary Code rollback 、 Comparison between multiple versions 、 Multi person collaborative development 、 Code branch 、 Branch merging Wait for the operation .
Such demand exists in large numbers , As software becomes more and more complex 、 More and more code 、 More and more developers are involved , Version management is becoming more and more difficult , At this point, professional software is needed to manage the version , This process is called version control , The software that realizes version control is called version control software .
Common distributed version control software :Git
Common centralized version control software :CVS、SVN
visit url/.git

web8
Same as web7

web9
According to the prompt, we know that there is abnormal shutdown vim yes Linux A compiler in a system Abnormal shutdown will leave .swp file

web10
According to the tips, you can only examine this question cookie


Use burp Conduct url decode

web11
According to the prompt Domain name resolution

web12

Log in and you will see flag

web13
According to the prompts, find the user manual at the bottom of the page The second page is shown in the figure below
Follow the prompts to visit url/system1103/login.php
The login interface will appear Log in and get flag
web14

visit url/editor
See that you can upload files The first reaction is to try to upload the Trojan horse Then I found that I didn't have upload permission
In the upload space, in var/html/nothinghere Found in the fl000g.txt

visit url/nothinghere/fl000g.txt You can get flag

web15
The website page can see the administrator's QQ

Try to add You can get the location information And the secret protection problem is the city Log in after resetting the password You can get it. flag


web16
First, let's look at the probe
php Probes are used to probe space 、 Server health and PHP For information , The probe can view the hard disk resources of the server in real time 、 Memory footprint 、 network card Traffic 、 System load 、 Server time and other information

stay phpinfo Mid search flag You can find

web17
*.sql File is mysql Backup files exported from the database ;
Direct access url/backup.sql
Open to get flag
web18
On the surface, it looks like a simple game

But after me “ Gaowan ” After trying, I found it impossible And there is not even an integral page It means there is another way

see js file You can find the ciphertext 
16 Hexadecimal decryption 
visit url/110.php You can get flag
web19


Check the source code of the page according to the prompt
Get the user name and password But the error will appear after input 
utilize burp post Pass parameters to bypass the front-end encryption
web20



Find it after downloading flag.
complete
边栏推荐
- How to paste the contents copied by the computer into mobaxterm? How to copy and paste
- Leetcode: Shortest Word Distance II
- 百亿按摩仪蓝海,难出巨头
- Photoshop插件-动作相关概念-ActionList-ActionDescriptor-ActionList-动作执行加载调用删除-PS插件开发
- 面试突击62:group by 有哪些注意事项?
- 【华为机试真题详解】字符统计及重排
- Interpretation of Apache linkage parameters in computing middleware
- Crud de MySQL
- JMeter performance test: serveragent resource monitoring
- Brief introduction of machine learning framework
猜你喜欢

Run faster with go: use golang to serve machine learning

Crud de MySQL

Fr exercise topic --- comprehensive question

Security analysis of Web Architecture

Interpretation of Apache linkage parameters in computing middleware

qt creater断点调试程序详解

【数组和进阶指针经典笔试题12道】这些题,满足你对数组和指针的所有幻想,come on !

社区团购撤城“后遗症”

【jvm】运算指令

Fr exercise topic - simple question
随机推荐
[recruitment position] Software Engineer (full stack) - public safety direction
市值蒸发超百亿美元,“全球IoT云平台第一股”赴港求生
729. My schedule I: "simulation" & "line segment tree (dynamic open point) &" block + bit operation (bucket Division) "
maxcompute有没有能查询 表当前存储容量的大小(kb) 的sql?
Interview shock 62: what are the precautions for group by?
How to open an account of qiniu securities? Is it safe to open an account?
Shanghai under layoffs
用 Go 跑的更快:使用 Golang 为机器学习服务
Interpretation of Apache linkage parameters in computing middleware
I collect multiple Oracle tables at the same time. After collecting for a while, I will report that Oracle's OGA memory is exceeded. Have you encountered it?
easyOCR 字符識別
Cartoon: what are the attributes of a good programmer?
Using tensorboard to visualize the training process in pytoch
[detailed explanation of Huawei machine test] happy weekend
Ecotone technology has passed ISO27001 and iso21434 safety management system certification
Dark horse programmer - software testing -10 stage 2-linux and database -44-57 why learn database, description of database classification relational database, description of Navicat operation data, de
【jvm】运算指令
GPS original coordinates to Baidu map coordinates (pure C code)
亿咖通科技通过ISO27001与ISO21434安全管理体系认证
Differences between IPv6 and IPv4 three departments including the office of network information technology promote IPv6 scale deployment

