当前位置:网站首页>Xctf attack and defense world web master advanced area php2
Xctf attack and defense world web master advanced area php2
2022-07-28 03:34:00 【l8947943】
0x01. Enter the environment , View content
Pictured , Prompt whether the authentication is successful 
Use dirsearch Make a sweep , Found to have index.php You can visit 
0x02. Problem analysis
0x02_1. Source audit
Try http://61.147.171.105:53836/index.php, Still prompt whether the authentication is successful , The title says PHP2, Guess if index.phps.
Access link :http://61.147.171.105:53836/index.phps, To present php Source code , Pictured :
Code audit :
- Direct in id by admin Echo directly not allowed
- When it comes to url Encoding admin, The function can echo Access granted Other results
- It should be noted that , The browser can directly decode the results after one encoding
therefore , The idea of the post audit topic is to make admin Carry out secondary coding .
0x02_2. Solve the problem
Use burpsuite Encoding , Pictured :
Carry out secondary coding , Got admin The secondary code of is :%25%36%31%25%36%34%25%36%64%25%36%39%25%36%65
Bring it to url Input in :http://61.147.171.105:53836/index.php?id=%25%36%31%25%36%34%25%36%64%25%36%39%25%36%65, The results are shown in the figure :
The final answer is :cyberpeace{a42c178d69b50f367135a2b6e0c90ecb}
边栏推荐
- VMware virtual machine network settings
- How to make the Internet access the intranet IP (used by esp8266 web pages)
- How to use JDBC to operate database
- 动态规划——474. 一和零
- Methods of SQL server backup database
- 203. Remove linked list elements
- How to reinstall win11 system with one click
- Volvo: what on earth does the deep-rooted "sense of security" rely on?
- Shell:资源监控脚本和高负载报警
- golang 获取循环嵌套结构的tag
猜你喜欢

MySQL事务的ACID特性及并发问题实例分析
![[5g NR] RRC reject analysis](/img/51/fc39804b39a9014be3130c09e5444c.png)
[5g NR] RRC reject analysis

Airiot Q & A issue 6 | how to use the secondary development engine?

Unity backpack system

Billions of asset addresses are blacklisted? How to use the tether address freezing function?

叶子识别 颜色的特征提取 缺陷检测等

Asemi rectifier bridge gbpc5010, gbpc5010 parameters, gbpc5010 size

每周推荐短视频:如何正确理解“精益”这个词?

Volvo: what on earth does the deep-rooted "sense of security" rely on?

Shell: resource monitoring script and high load alarm
随机推荐
Digital economy has become the biggest attraction
什么是Tor?Tor浏览器更新有什么用?
响应式高端网站模板源码图库素材资源下载平台源码
Unity simply implements the dialog function
Container related concepts
整合SSM实现增删改查搜索
[R language] environment specifies to delete RM function
Acid characteristics of MySQL transactions and example analysis of concurrency problems
一键重装win7系统详细教程
GNU General Public License v2.0 GNU General Public License
redis源码分析(谁说C语言就不能分析了?)
ASEMI整流桥GBPC3510在直流有刷电机中的妙用
每日练习------实现双色球的彩票功能。规则:从36个红球中随机选择不重复的6个数,从15个篮球中随机选择1个组成一注彩票。可以选择买多注。
golang gorm查询任意字段的组装方法
C # set TextBox control not editable
What if the word selection box of win11 input method is missing?
C WinForm development: how to add pictures to project resources
203. Remove linked list elements
STM32 RT thread virtual file system mount operation
8000字讲透OBSA原理与应用实践