当前位置:网站首页>Supporting title of the book from 0 to 1: ctfer's growth road (Zhou Geng)
Supporting title of the book from 0 to 1: ctfer's growth road (Zhou Geng)
2022-07-06 06:52:00 【Borrow ZJ article [de]bvxie】
Here is the custom directory title
Common collection
Release prompt :
Use dirbuster Tool for web directory scanning ,⼯ Yes kali⾃ belt ,
cd /usr/share/dirbuster
java -jar DirBuster-1.0-RC1.jar
use URL Fuzz, You can specify a directory , Specify scan admin All the files under the directory ,dir Represents every line of the dictionary
/admin/{dir}.php This is blasting admin All under directory php file
perhaps
Or is it dirsearch course ,
forehead , The environment was also checked ,,, Didn't sweep it out , Try to do it yourself
/robots.txt
Get a hint , Visit available :flag1:n1book{info_1
/index.php~
Get a hint , Visit available :flag2:s_v3ry_im
.index.php.swp
You'll get a file
I read this question wp, The software still doesn't understand , Try again in a few days .
Careless Xiao Li
Git test , Use GitHack The script tests it , course !kali It has its own Git、Python2 and Python3. Switch to virtual machine … Mainly in the second half of the day GitHack, Failed all the time !
We found the reason !!! Not solve , Looking around for information, I found another tool scrabble Can replace it , Tutorial links !
Open terminal in folder ,
./scrabble + website ls
see
cat + file
SQL Inject -1
Find the injection point ,
边栏推荐
- The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
- Erreur de type résolue avec succès: type de données « catégorie» non sous - jacente
- 【每日一题】729. 我的日程安排表 I
- kubernetes集群搭建Zabbix监控平台
- 女生学软件测试难不难 入门门槛低,学起来还是比较简单的
- How much is the price for the seal of the certificate
- 攻防世界 MISC中reverseMe简述
- ML之shap:基于adult人口普查收入二分类预测数据集(预测年收入是否超过50k)利用Shap值对XGBoost模型实现可解释性案例之详细攻略
- Classification des verbes reconstruits grammaticalement - - English Rabbit Learning notes (2)
- UDP攻击是什么意思?UDP攻击防范措施
猜你喜欢
Phishing & filename inversion & Office remote template
ML之shap:基于adult人口普查收入二分类预测数据集(预测年收入是否超过50k)利用Shap值对XGBoost模型实现可解释性案例之详细攻略
18.多级页表与快表
When my colleague went to the bathroom, I helped my product sister easily complete the BI data product and got a milk tea reward
How to reconstruct the class explosion caused by m*n strategies?
Leetcode - 152 product maximum subarray
【软件测试进阶第1步】自动化测试基础知识
Apache DolphinScheduler源码分析(超详细)
顶测分享:想转行,这些问题一定要考虑清楚!
同事上了个厕所,我帮产品妹子轻松完成BI数据产品顺便得到奶茶奖励
随机推荐
MySQL high frequency interview 20 questions, necessary (important)
librosa音频处理教程
万丈高楼平地起,每个API皆根基
Biomedical localization translation services
Brief introduction to the curriculum differences of colleges and universities at different levels of machine human major -ros1/ros2-
同事上了个厕所,我帮产品妹子轻松完成BI数据产品顺便得到奶茶奖励
How effective is the Chinese-English translation of international economic and trade contracts
自动化测试环境配置
Map of mL: Based on the adult census income two classification prediction data set (whether the predicted annual income exceeds 50K), use the map value to realize the interpretable case of xgboost mod
AttributeError: Can‘t get attribute ‘SPPF‘ on <module ‘models. common‘ from ‘/home/yolov5/models/comm
Biomedical English contract translation, characteristics of Vocabulary Translation
Office doc add in - Online CS
机器学习植物叶片识别
In English translation of papers, how to do a good translation?
How much is the price for the seal of the certificate
How to do a good job in financial literature translation?
[ 英语 ] 语法重塑 之 动词分类 —— 英语兔学习笔记(2)
Leetcode daily question (1997. first day where you have been in all the rooms)
PCL实现选框裁剪点云
成功解决AttributeError: Can only use .cat accessor with a ‘category‘ dtype