当前位置:网站首页>[wp]ctfshow-web入门信息搜集
[wp]ctfshow-web入门信息搜集
2022-07-25 19:27:00 【_小飒】
开了ctfshow的web入门开始刷题
web1
F12
web2
先打开F12,再复制容器网址
官方wp:view-source:
web3
burp抓包
web4-6 略
需要设置延时扫
web7
/.git/
web8
/.svn/
web9
/index.php.swp
web10-11 略
web12

web13
题干:技术文档里面不要出现敏感信息,部署到生产环境后及时修改默认密码
Web14
编译器漏洞,听闻过以前这种漏洞很多
查看源文件" <img src="editor/upload/banner-app.png" alt="App">"
存在这样一个路径访问/editor/
插入文件——文件空间里找到flag
web15
按照提示完成的
访问/admin页面 发现有一个忘记密码操作,需要输入地址 在主页面下面看到QQ邮箱,通过QQ号查询邮箱,是西安的 修改密码成功,用户名 admin 登录成功获得flag
web16
php探针-phpinfo
web17
扫目录获得
backup.sql
web18
if(score>100)
{
var result=window.confirm("\u4f60\u8d62\u4e86\uff0c\u53bb\u5e7a\u5e7a\u96f6\u70b9\u76ae\u7231\u5403\u76ae\u770b\u770b");
}
得到110.php
web19
查看源码
web20
扫描后台,下载到数据库。打开即可
flag{ctfshow_old_database}
边栏推荐
- Nezha d1-h test microbench
- 鸿蒙-大喵计算画板-视频
- Alibaba cloud free SSL certificate application detailed process
- Modelsim and quartus jointly simulate PLL FIFO and other IP cores
- 高并发下如何保证数据库和缓存双写一致性?
- Telnet installation and telnet (correct password) cannot log in!
- [Detr for 3D object detection] detr3d: 3D object detection from multi view images via 3D-to-2D queries
- TypeError: ‘str‘ object is not callable的错误原因
- Introduction of this course (Introduction to machine learning)
- An idea of solving div adapting to screen
猜你喜欢
![[hdlbits questions] Verilog language (3) modules: hierarchy section](/img/35/ccdbb55aa0aff7e9dec2bf9e64c4e2.png)
[hdlbits questions] Verilog language (3) modules: hierarchy section

JS 基本类型 引用类型 深/浅克隆复制

阿里云免费SSL证书申请详细流程
![[server data recovery] a data recovery case of a brand ProLiant server raid paralysis, database file loss, and database file backup damage](/img/89/92ace2f76beefd258d00d26cd921c9.png)
[server data recovery] a data recovery case of a brand ProLiant server raid paralysis, database file loss, and database file backup damage

小程序毕设作品之微信校园维修报修小程序毕业设计成品(1)开发概要
![[reading notes] deep learning Chapter 1: Introduction](/img/b3/58f71b032cd8f04ecf95d48281a41a.png)
[reading notes] deep learning Chapter 1: Introduction

高并发下如何保证数据库和缓存双写一致性?

网上商城系统MySql数据库设计项目实战

How to analyze qiime2 after obtaining picrust2 results

Wechat campus maintenance and repair applet graduation design finished product of applet completion work (4) opening report
随机推荐
How to change the chords after the tune of the song is changed
telnet安装以及telnet(密码正确)无法登录!
小程序毕设作品之微信校园维修报修小程序毕业设计成品(5)任务书
蓝桥杯基础练习——矩阵的回形取数(C语言)
Scala foundation [set 01]
小程序毕设作品之微信校园维修报修小程序毕业设计成品(1)开发概要
NPM semantic version control, solution console prop being mutated: "placement" error
Openresty Lua resty mlcache multi-level cache
【DETR用于3D目标检测】DETR3D: 3D Object Detection from Multi-view Images via 3D-to-2D Queries
Juzhi cloud computing opens a new era to the "proprietary cloud" of Youfu network
英诚医院内部网络规划与设计
Solve the problem that the win10 account has no administrator rights
Wechat campus maintenance and repair applet graduation design finished product (7) Interim inspection report
[record of question brushing] 21. Merge two ordered linked lists
授权无线通信标准
Introduction of this course (Introduction to machine learning)
SDL text display
【阅读笔记】《深度学习》第一章:引言
Hongke shares | how to solve blackmail software security vulnerabilities
GBASE 8s UDR内存管理_01_mi_alloc