当前位置:网站首页>Ctfshow web entry information collection
Ctfshow web entry information collection
2022-07-05 14:58:00 【Cwxh0125】
Catalog
web3
You can see it by grabbing the bag directly flag
web4

Try to access robots.txt

web5
Topic tips phps Source code leakage

download phps Open the source file
web6

According to the tip flag Put it in
Check the source code after downloading .
After submitting, it is found that there is something wrong Try to visit url/fl000g.txt obtain flag
web7

First, learn about version control
During code development , You often need to modify the source code many times , In this way, multiple versions of the same code are generated , In the development process, it is usually necessary to manage these multiple versions of code , So that it can be done when necessary Code rollback 、 Comparison between multiple versions 、 Multi person collaborative development 、 Code branch 、 Branch merging Wait for the operation .
Such demand exists in large numbers , As software becomes more and more complex 、 More and more code 、 More and more developers are involved , Version management is becoming more and more difficult , At this point, professional software is needed to manage the version , This process is called version control , The software that realizes version control is called version control software .
Common distributed version control software :Git
Common centralized version control software :CVS、SVN
visit url/.git

web8
Same as web7

web9
According to the prompt, we know that there is abnormal shutdown vim yes Linux A compiler in a system Abnormal shutdown will leave .swp file

web10
According to the tips, you can only examine this question cookie


Use burp Conduct url decode

web11
According to the prompt Domain name resolution

web12

Log in and you will see flag

web13
According to the prompts, find the user manual at the bottom of the page The second page is shown in the figure below
Follow the prompts to visit url/system1103/login.php
The login interface will appear Log in and get flag
web14

visit url/editor
See that you can upload files The first reaction is to try to upload the Trojan horse Then I found that I didn't have upload permission
In the upload space, in var/html/nothinghere Found in the fl000g.txt

visit url/nothinghere/fl000g.txt You can get flag

web15
The website page can see the administrator's QQ

Try to add You can get the location information And the secret protection problem is the city Log in after resetting the password You can get it. flag


web16
First, let's look at the probe
php Probes are used to probe space 、 Server health and PHP For information , The probe can view the hard disk resources of the server in real time 、 Memory footprint 、 network card Traffic 、 System load 、 Server time and other information

stay phpinfo Mid search flag You can find

web17
*.sql File is mysql Backup files exported from the database ;
Direct access url/backup.sql
Open to get flag
web18
On the surface, it looks like a simple game

But after me “ Gaowan ” After trying, I found it impossible And there is not even an integral page It means there is another way

see js file You can find the ciphertext 
16 Hexadecimal decryption 
visit url/110.php You can get flag
web19


Check the source code of the page according to the prompt
Get the user name and password But the error will appear after input 
utilize burp post Pass parameters to bypass the front-end encryption
web20



Find it after downloading flag.
complete
边栏推荐
- be careful! Software supply chain security challenges continue to escalate
- webRTC SDP mslabel lable
- MongDB学习笔记
- 漫画:优秀的程序员具备哪些属性?
- 729. My schedule I: "simulation" & "line segment tree (dynamic open point) &" block + bit operation (bucket Division) "
- Total amount analysis accounting method and potential method - allocation analysis
- 30岁汇源,要换新主人了
- 想进阿里必须啃透的12道MySQL面试题
- Interview shock 62: what are the precautions for group by?
- I collect multiple Oracle tables at the same time. After collecting for a while, I will report that Oracle's OGA memory is exceeded. Have you encountered it?
猜你喜欢

【数组和进阶指针经典笔试题12道】这些题,满足你对数组和指针的所有幻想,come on !

Interview shock 62: what are the precautions for group by?

1330:【例8.3】最少步数

Crud of MySQL

Behind the ultra clear image quality of NBA Live Broadcast: an in-depth interpretation of Alibaba cloud video cloud "narrowband HD 2.0" technology

MongDB学习笔记

有一个强大又好看的,赛过Typora,阿里开发的语雀编辑器

leetcode:881. 救生艇

Run faster with go: use golang to serve machine learning

超级哇塞的快排,你值得学会!
随机推荐
Photoshop plug-in - action related concepts - actions in non loaded execution action files - PS plug-in development
Un week - end heureux
APR protocol and defense
GPS original coordinates to Baidu map coordinates (pure C code)
【招聘岗位】基础设施软件开发人员
maxcompute有没有能查询 表当前存储容量的大小(kb) 的sql?
12 MySQL interview questions that you must chew through to enter Alibaba
STM32+BH1750光敏传感器获取光照强度
GPS原始坐标转百度地图坐标(纯C代码)
webRTC SDP mslabel lable
实现一个博客系统----使用模板引擎技术
NBA赛事直播超清画质背后:阿里云视频云「窄带高清2.0」技术深度解读
IPv6与IPv4的区别 网信办等三部推进IPv6规模部署
基于TI DRV10970驱动直流无刷电机
通过npm 或者 yarn安装依赖时 报错 出现乱码解决方式
Reconnaissance des caractères easycr
Type declaration of all DOM elements in TS
手写promise与async await
有一个强大又好看的,赛过Typora,阿里开发的语雀编辑器
Does maxcompute have SQL that can query the current storage capacity (KB) of the table?

