当前位置:网站首页>攻防世界WEB练习区(backup、cookie、disabled_button)
攻防世界WEB练习区(backup、cookie、disabled_button)
2022-07-24 02:36:00 【不知名白帽】
目录
backup
题目介绍

题目思路
访问靶场

常见备份文件后缀名
“.bak”
“.git”
“.svn”
“.swp”
“.~”
“.bash_history”
“.bkf”
访问index.php.bak
会下载index.php.bak文件

找到flag
Cyberpeace{855A1C4B3401294CB6604CCC98BDE334}
cookie
题目介绍

题目思路
访问靶场

F12查看网络寻找cookie

访问cookie.php页面
根据提示查看http响应

找到flag
cyberpeace{9485fb1968e7c4cc0f170ac0feb51804}
disabled_button
题目介绍

题目思路
访问靶场

F12常看网页源代码

修改网页源代码
删除disabled

发现flag按钮能够点击
点击flag按钮

发现flag
cyberpeace{1fd982589c3c5568ef56a354ba18bdda}
边栏推荐
- Beansearcher receives array parameters and logical deletion
- Mysql database, grouping function
- 云原生讲解【扩展篇】
- JpaRepository扩展接口
- 程序员必备技能----断点调试(IDEA版)
- [untitled]
- 我国科学家在高安全量子密钥分发网络方面取得新进展
- Mysql数据库,分组函数篇
- Wonderful! The description of meituan Octo distributed service management system is too clear
- Crop leaf disease identification system
猜你喜欢

Jina AI and datawhale jointly launched a learning project!

Unity timeline tutorial

C language actual combat guessing game

营员招募|心怀世界的AI青年们,联合国需要你为可持续发展助力!

【知识图谱】实践篇——基于医疗知识图谱的问答系统实践(Part2):图谱数据准备与导入

关于 SAP 电商云 Spartacus UI Transfer State 冗余 API 请求发送的讨论
![[untitled]](/img/57/a3104833cb5fcc05916075f3bfdaf3.png)
[untitled]
![[untitled]](/img/57/916e26018ddfa5ee1ef752fbbc3a4a.png)
[untitled]

关于缺少编程基础的朋友想转行 ABAP 开发岗提出的一些咨询问题和解答

Understand the low code implementation of microservices
随机推荐
This article shows you how to use SQL to process weekly report data
Digital transformation behind the reshaping growth of catering chain stores
【补题日记】[2022牛客暑期多校1]C-Grab the Seat
Leetcode 70 climbing stairs, 199 right view of binary tree, 232 realizing queue with stack, 143 rearranging linked list
[jailhouse article] virtualization over multiprocessor system on chip an enabling paradigm for
Reading notes: self cultivation of programmers - Chapter 3
Jina AI and datawhale jointly launched a learning project!
Leetcode 203. remove linked list elements (2022.07.22)
Understand the low code implementation of microservices
利用宝塔面板计划任务执行自动推送网址到百度收录
Detailed vector
Redis data type concept
Jparepository extension interface
The solution of using non root user management in secure stand-alone database under general machine environment
Pyg uses messagepassing to build GCN to realize node classification
[datasets] - downloading some datasets of flyingthings3d optical flow
【补题日记】[2022杭电暑期多校1]B-Dragon slayer
“我们为什么要做 iVX ? ” ——访 iVX CEO 孟智平 了解 iVX 企业文化
[diary of supplementary questions] [2022 Niuke summer school 1] d-mocha and railgun
Summary of problems encountered in the development process in July