当前位置:网站首页>Ctfshow web entry information collection
Ctfshow web entry information collection
2022-07-05 14:58:00 【Cwxh0125】
Catalog
web3
You can see it by grabbing the bag directly flag
web4
Try to access robots.txt
web5
Topic tips phps Source code leakage
download phps Open the source file
web6
According to the tip flag Put it in
Check the source code after downloading .
After submitting, it is found that there is something wrong Try to visit url/fl000g.txt obtain flag
web7
First, learn about version control
During code development , You often need to modify the source code many times , In this way, multiple versions of the same code are generated , In the development process, it is usually necessary to manage these multiple versions of code , So that it can be done when necessary Code rollback 、 Comparison between multiple versions 、 Multi person collaborative development 、 Code branch 、 Branch merging Wait for the operation .
Such demand exists in large numbers , As software becomes more and more complex 、 More and more code 、 More and more developers are involved , Version management is becoming more and more difficult , At this point, professional software is needed to manage the version , This process is called version control , The software that realizes version control is called version control software .
Common distributed version control software :Git
Common centralized version control software :CVS、SVN
visit url/.git
web8
Same as web7
web9
According to the prompt, we know that there is abnormal shutdown vim yes Linux A compiler in a system Abnormal shutdown will leave .swp file
web10
According to the tips, you can only examine this question cookie
Use burp Conduct url decode
web11
According to the prompt Domain name resolution
web12
Log in and you will see flag
web13
According to the prompts, find the user manual at the bottom of the page The second page is shown in the figure below
Follow the prompts to visit url/system1103/login.php
The login interface will appear Log in and get flag
web14
visit url/editor
See that you can upload files The first reaction is to try to upload the Trojan horse Then I found that I didn't have upload permission
In the upload space, in var/html/nothinghere Found in the fl000g.txt
visit url/nothinghere/fl000g.txt You can get flag
web15
The website page can see the administrator's QQ
Try to add You can get the location information And the secret protection problem is the city Log in after resetting the password You can get it. flag
web16
First, let's look at the probe
php Probes are used to probe space 、 Server health and PHP For information , The probe can view the hard disk resources of the server in real time 、 Memory footprint 、 network card Traffic 、 System load 、 Server time and other information
stay phpinfo Mid search flag You can find
web17
*.sql File is mysql Backup files exported from the database ;
Direct access url/backup.sql
Open to get flag
web18
On the surface, it looks like a simple game
But after me “ Gaowan ” After trying, I found it impossible And there is not even an integral page It means there is another way
see js file You can find the ciphertext
16 Hexadecimal decryption
visit url/110.php You can get flag
web19
Check the source code of the page according to the prompt
Get the user name and password But the error will appear after input
utilize burp post Pass parameters to bypass the front-end encryption web20
Find it after downloading flag.
complete
边栏推荐
- Niuke: intercepting missiles
- 浅谈Dataset和Dataloader在加载数据时如何调用到__getitem__()函数
- Two Bi development, more than 3000 reports? How to do it?
- qt creater断点调试程序详解
- 可视化任务编排&拖拉拽 | Scaleph 基于 Apache SeaTunnel的数据集成
- Change multiple file names with one click
- STM32+BH1750光敏传感器获取光照强度
- MySQL----函数
- Type declaration of all DOM elements in TS
- [12 classic written questions of array and advanced pointer] these questions meet all your illusions about array and pointer, come on!
猜你喜欢
Section - left closed right open
CODING DevSecOps 助力金融企业跑出数字加速度
【华为机试真题详解】字符统计及重排
APR protocol and defense
NBA赛事直播超清画质背后:阿里云视频云「窄带高清2.0」技术深度解读
Interpretation of Apache linkage parameters in computing middleware
微帧科技荣获全球云计算大会“云鼎奖”!
Machine learning notes - gray wolf optimization
Dark horse programmer - software testing -10 stage 2-linux and database -44-57 why learn database, description of database classification relational database, description of Navicat operation data, de
1330:【例8.3】最少步数
随机推荐
anaconda使用中科大源
Pointer operation - C language
Un week - end heureux
CPU设计实战-第四章实践任务二用阻塞技术解决相关引发的冲突
【数组和进阶指针经典笔试题12道】这些题,满足你对数组和指针的所有幻想,come on !
CPU design practice - Chapter 4 practical task 2 using blocking technology to solve conflicts caused by related problems
Reconnaissance des caractères easycr
开挖财上的证券账户可以吗?安全吗?
CPU design related notes
Structure - C language
Mysql---- function
JS bright blind your eyes date selector
There is a powerful and good-looking language bird editor, which is better than typora and developed by Alibaba
通过npm 或者 yarn安装依赖时 报错 出现乱码解决方式
【招聘岗位】基础设施软件开发人员
一键更改多个文件名字
CPU设计实战-第四章实践任务三用前递技术解决相关引发的冲突
TS所有dom元素的类型声明
Differences between IPv6 and IPv4 three departments including the office of network information technology promote IPv6 scale deployment
FR练习题目---简单题