当前位置:网站首页>[ACTF2020 Freshman Competition]Exec 1
[ACTF2020 Freshman Competition]Exec 1
2022-07-29 21:25:00 【Borrow zj article [de]BvxiE】
ping命令
如何在cmd里面ping命令
指令:racert 网址
pinga website and ping -t A URL comes out of the difference,The former is only displayed4组数据.
ipconfig /allDisplay your computer configuration
WiresharkA little bit of use,查找时(过滤)
ping时:ip.addr ==网址 and icmp
directly on the web page:
http and ip.addr == 网址
ip.addr ==网址 and tcp
27个常用的 Linux 命令!ls会列举出当前工作目录的内容(文件或文件夹)
[ACTF2020 新生赛]Exec 1
养成习惯!Just grab a bag!This question does not use tools,whole principle!
127.0.0.1;ls

127.0.0.1;ls /,列出根目录下的文件
127.0.0.1;cat /flag,cat进行读取
or available from below127.0.0.1;cat ../../../flag
是看wp的,Sort out the knowledge points
1.127.0.0.1;cat index.php,Find the information inside


isset ()A function is used to determine if a variable is set and not null;换句话说,only if the variable is notnull时才返回true.
2.目录遍历
简单了解一下目录遍历!127.0.0.1;ls ../
127.0.0.1;ls ../../
127.0.0.1;ls ../../../和127.0.0.1;ls ../../../../效果一样,So in general as long as there are enough sets!
命令注入
Just to find out this time命令注入符号!
Excerpt from the previous link!
可参考文章:https://blog.csdn.net/m0_47745762/article/details/118932465?ops_request_misc=%257B%2522request%255Fid%2522%253A%2522165848802716782248535320%2522%252C%2522scm%2522%253A%252220140713.130102334…%2522%257D&request_id=165848802716782248535320&biz_id=0&utm_medium=distribute.pc_search_result.none-task-blog-2allsobaiduend~default-1-118932465-null-null.142v33experiment_2_v1,185v2control&utm_term=actf2020%20%E6%96%B0%E7%94%9F%E8%B5%9B%5Dexec%2019&spm=1018.2226.3001.4187
及文章:https://blog.csdn.net/wangyuxiang946/article/details/120995294?ops_request_misc=%257B%2522request%255Fid%2522%253A%2522165848802716782248535320%2522%252C%2522scm%2522%253A%252220140713.130102334…%2522%257D&request_id=165848802716782248535320&biz_id=0&utm_medium=distribute.pc_search_result.none-task-blog-2allsobaiduend~default-2-120995294-null-null.142v33experiment_2_v1,185v2control&utm_term=actf2020%20%E6%96%B0%E7%94%9F%E8%B5%9B%5Dexec%2019&spm=1018.2226.3001.4187
边栏推荐
- 分布式限流 redission RRateLimiter 的使用及原理
- A dish hold up valuations billions of mt. Pickled fish, can move beyond the edge food safety?
- JMeter usage tutorial (2)
- mysql 获取字段注释 和获取表字段
- RNA的化学修饰原理|Gal-PEG-siRNA|siRNA-S-S-DSPE|siRNA-s-s-PEG|cholesterol-siRNA
- internship:利用easypoi将excel表数据导入导出
- VR直播营销需求增加,数据模块为我们铺路
- Agile Organization | The path for enterprises to overcome the impact of the digital wave
- :style中颜色使用函数动态获取赋值
- Permutations of a small feat: cantor
猜你喜欢

JMeter tutorial (a)

诺氟沙星-DNA复合物|半乳糖化脂质体-聚阳离子-DNA复合物|注意事项

LOG4J 学习

MySQL数据查询 - 简单查询

一 JS中Promise用法、二闭包的概念与用法、三对象创建的四种方式与区区别、四 如何声明一个类

五个供应商销售谈判策略的识别以及应对它们的方法

SAG1-MIC8复合DNA基因疫苗|新型脂质-HAP-DNA复合体|实验要求

Thesis writing strategy | how to write an academic research paper

这半年我做交易链路自动化回归的那些事儿...

Data visualization ---- web page displays temperature and humidity
随机推荐
LeetCode 0593. 有效的正方形
JMeter usage tutorial (2)
【593. 有效的正方形】
240. Searching 2D Matrix II
Oracle问题: ORA-01882: 未找到时区
小学弟问:程序员的工作是不是每天都是敲一天的代码呢?
打破原则!MongoDB 引入 SQL?
The younger brother asked: Is the work of a programmer a day’s work of code?
如何优雅的自定义 ThreadPoolExecutor 线程池
优惠券系统设计思想
聚丙烯微孔膜的等离子体改性及DNA|有机自由基改性DNA-阳离子脂质复合体的应用
Kotlin - Coroutine Scope CoroutineScope, Coroutine Builder CoroutineBuilder, Coroutine Scope Function CoroutineScope Functiom
诺氟沙星-DNA复合物|半乳糖化脂质体-聚阳离子-DNA复合物|注意事项
怎么实现您的个人知识库?
Data visualization ---- web page displays temperature and humidity
VR直播营销需求增加,数据模块为我们铺路
LeetCode 593 有效的正方形[数学] HERODING的LeetCode之路
分布式限流 redission RRateLimiter 的使用及原理
Huawei laptop keyboard locked (how does the laptop keyboard light up)
LOG4J 学习