当前位置:网站首页>Bugku login1

Bugku login1

2022-07-26 16:10:00 Baita River surfer

Entering the environment is a web Management system

  Start a trial , Catalog explosion , Universal password , Weak password ,sql Injection is useless

Tips : Constraint attack

The login echo of any registered user is not something that administrators cannot see flag

That means that we can log in to the administrator to see flag 了

register admin User tips admin Already exists , Then use constraints to attack

Register user name admin                  , The code is random

Direct login admin, Log in with the password registered above

 

原网站

版权声明
本文为[Baita River surfer]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/207/202207261557516673.html