当前位置:网站首页>Bugku login1
Bugku login1
2022-07-26 15:58:00 【白塔河冲浪手】
进入环境是一个web管理系统

开始一顿试,目录爆破,万能密码,弱口令,sql注入都没用
提示:约束攻击
随便注册一个用户登陆回显不是管理员不能看flag
那意思就是让我们登录管理员就能看flag了
注册admin用户提示admin已存在,则利用约束攻击
注册用户名admin ,密码随便
直接登录admin,用上面注册的密码登录

边栏推荐
- parker泵PV140R1K1T1PMMC
- 初识OpenGL (3)片段着色器(Fragment Shader)
- Build resume editor based on Nocode
- Promise, async await and the solution of cross domain problems -- the principle of proxy server
- 小哥自创AI防拖延系统,一玩手机就被“闪瞎” | Reddit高热
- 马斯克被曝绿了谷歌创始人:导致挚友二婚破裂,曾下跪求原谅
- Jmeter快速上手之接口测试
- 13年资深开发者分享一年学习Rust经历:从必备书目到代码练习一网打尽
- 换把人体工学椅,缓解久坐写代码的老腰吧~
- Understanding weight sharing in convolutional neural networks
猜你喜欢
.net get injection object manually

German EMG e-anji thruster ed301/6 HS

Sklearn clustering clustering

Vs2019debug mode too laggy can't enter the breakpoint

单例模式

小哥自创AI防拖延系统,一玩手机就被“闪瞎” | Reddit高热

Musk was exposed to be the founder of Google: he broke up his best friend's second marriage and knelt down to beg for forgiveness

换把人体工学椅,缓解久坐写代码的老腰吧~
“卡片笔记法”在思源的具体实践案例

我们被一个 kong 的性能 bug 折腾了一个通宵
随机推荐
Bucher gear pump qx81-400r301
数智转型,管理先行|JNPF全力打造“全生命周期管理”平台
御神楽的学习记录之SoC FPGA的第一个工程-Hello World
Clojure 运行原理之字节码生成篇
Is it safe for Guoyuan futures to open an account online? What is the account opening process?
VS2019Debug模式太卡进不去断点
A coal mine in Yangquan, Shanxi Province, suffered a safety accident that killed one person and was ordered to stop production for rectification
A comprehensive review of image enhancement technology in deep learning
bucher齿轮泵QX81-400R301
一文详解 Redis 中 BigKey、HotKey 的发现与处理
Google Earth Engine——MERRA-2 M2T1NXAER:1980-2022年气溶胶逐日数据集
Coo format of adjacency matrix
C# 给Word每一页设置不同文字水印
终于有人把红蓝对抗讲明白了
PS + PL heterogeneous multicore case development manual for Ti C6000 tms320c6678 DSP + zynq-7045 (3)
Daily1:SVM
Research and application of the whole configuration of large humanoid robot
13 years of senior developers share a year of learning rust experience: from the necessary bibliography to code practice
Can the parameterized view get SQL with different rows according to the characteristics of the incoming parameters? For example, here I want to use the column in the transmission parameter @field
This article explains in detail the discovery and processing of bigkey and hotkey in redis