当前位置:网站首页>攻防世界WEB练习区(weak_auth、simple_php、xff_referer)
攻防世界WEB练习区(weak_auth、simple_php、xff_referer)
2022-07-24 02:36:00 【不知名白帽】
目录
weak_auth
题目介绍

题目思路
访问靶场

一般这种的都是弱口令登录
比如账号为admin
密码为123456、admin、root等
也可以用BP进行爆破
利用burpsuite爆破密码
登录自己猜测的密码admin/admin截取流量包

上传到intruder

选择cluster bomb对账号和密码进行爆破

设置payload


开始爆破

爆破成功

找到flag
cyberpeace{dad2b6ebac23fe80a9dc79eb0c9e5b63}
simple_php
题目介绍

题目思路
访问靶场

PHP内容理解
a=0且a不为空;所以a=0a
b>1234且不为纯数字;所以b=1235aa

找到flag
Cyberpeace{647E37C7627CC3E4019EC69324F66C7C}
xff_referer
题目介绍

题目思路
访问靶场

伪造XFF

返回referer
伪造feferer

找到flag
cyberpeace{e8b2f1bc317d06993ab6349580f5eda6}
边栏推荐
- Essential skills for programmers -- breakpoint debugging (idea version)
- Emmet syntax summary
- Discussion on sending redundant API requests for Spartacus UI transfer state of SAP e-commerce cloud
- Reading notes: self cultivation of programmers - Chapter 3
- Sharing a case of controller restart caused by a CIFS bug in NetApp Fas series
- IBM: realize the quantum advantage of fault tolerance by 2030
- Understand the timing of loading classes into the JVM
- Brief introduction of tfw6524 perfectly replacing imported pt6524 chip
- 关于 SAP Fiori 应用的离线使用
- Digital transformation behind the reshaping growth of catering chain stores
猜你喜欢

508. 出现次数最多的子树元素和-哈希表法纯c实现

22 -- range and of binary search tree

数据湖(十五):Spark与Iceberg整合写操作
![[C language] preprocessing details](/img/c3/861165ce20c135f4feedee1f112261.png)
[C language] preprocessing details

Leetcode 70 climbing stairs, 199 right view of binary tree, 232 realizing queue with stack, 143 rearranging linked list

Network protocol details: UDP

"Why should we do IVX?"—— Interview with IVX CEO Meng Zhiping to understand IVX corporate culture

Research on XMPP service (I)

Doodle Icons - 一组免费商用的涂鸦风格图标库,可爱轻快又独特

Leetcode exercise -- two questions about the nearest common ancestor of binary trees
随机推荐
Vscade connects to the server. The password is correct, but it has been unable to connect
Leetcode 203. remove linked list elements (2022.07.22)
程序员必备技能----断点调试(IDEA版)
Composition API (in setup) watch usage details
Unity TimeLine使用教程
Reading notes: self cultivation of programmers - Chapter 3
Understand the transport layer protocol - tcp/udp
How to judge null for different types of fields, sets, lists / sets / maps, and objects
Understand the low code implementation of microservices
Summary of problems encountered in the development process in July
Leetcode exercise -- two questions about the nearest common ancestor of binary trees
Resumption: a deck of cards (54), three people fighting the landlord, what is the probability that the big and small kings are in the same family
[diary of supplementary questions] [2022 Niuke summer school 1] d-mocha and railgun
Go basic notes_ 5_ Array slice
Audio processing based on time-frequency diagram matlab
【补题日记】[2022牛客暑期多校1]I-Chiitoitsu
Uie: unified model of information extraction
I'm a novice. I heard that there is a breakeven financial product in opening an account. What is it?
Doodle Icons - 一组免费商用的涂鸦风格图标库,可爱轻快又独特
QT display Chinese garbled code