当前位置:网站首页>xxe of CTF
xxe of CTF
2022-08-02 04:01:00 【SevenCold】
xxe vulnerability means that we can inject external entities. When external entities are allowed to be referenced, by constructing malicious content, it can lead to reading arbitrary files, executing system commands, detecting intranet ports, and attacking intranet websites.
Two writeups
Question 1:
bp packet capture
Then you can perform xml injection
This is two xxe, let's try first and secondSpecies (because the source code does not mark which file the flag is in)
Then enter the intranet
However, if you can't get in, you can only find a surviving host.
Direct Violent Search
Question 2:
Follow the idea of the question above
But noFind the flag....
Finally, I can only find it in the file, but the title does not indicate which file the specific flag is in, so I can only try the /flag file
It turned out to be
边栏推荐
- 14. JS Statements and Comments, Variables and Data Types
- hackmyvm: controller walkthrough
- hackmyvm-bunny预排
- [mikehaertl/php-shellcommand] A library for invoking external command operations
- IO stream, encoding table, character stream, character buffer stream
- (6) 学生信息管理系统设计
- hackmyvm: may walkthrough
- hackmyvm: juggling walkthrough
- 16.JS事件, 字符串和运算符
- [symfony/mailer]一个优雅易用的发送邮件类库
猜你喜欢
12.什么是JS
Shuriken: 1 vulnhub walkthrough
Phonebook
Offensive and defensive world - novice MISC area 1-12
CSRF(跨站请求伪造)
(2) 顺序结构、对象的布尔值、选择结构、循环结构、列表、字典、元组、集合
CTF入门之php文件包含
hackmyvm-random walkthrough
[sebastian/diff] A historical change extension library for comparing two texts
What are the killer super powerful frameworks or libraries or applications for PHP?
随机推荐
Basic use of v-on, parameter passing, modifiers
13.JS输出内容和语法
What are the PHP framework?
Introduction to PHP (self-study notes)
PHP Foundation March Press Announcement Released
TCP communications program
[symfony/mailer]一个优雅易用的发送邮件类库
vim编辑模式
hackmyvm: juggling walkthrough
(3)Thinkphp6数据库
1.初识PHP
IP access control: teach you how to implement an IP firewall with PHP
命令执行漏洞
hackmyvm: again walkthrough
(1) introduction to Thinkphp6, installation view, template rendering, variable assignment
CTF之xxe
PHP有哪些杀手级超厉害框架或库或应用?
Solve the problem of Zlibrary stuck/can't find the domain name/reached the limit, the latest address of Zlibrary
(7) 浅学 “爬虫” 过程 (概念+练习)
[campo/random-user-agent] Randomly fake your User-Agent