当前位置:网站首页>[极客大挑战 2019]Havefun1
[极客大挑战 2019]Havefun1
2022-04-23 06:32:00 【隔壁Cc】
题目靶机链接
http://60076ab2-e535-445f-ac1b-6ea24e101699.node4.buuoj.cn:81
首先点击靶机 进去发现是一个猫咪(晃动尾巴发现还能动,目测像只乖巧的狗狗尾巴一摇一摇的,好了这不重要)
其次点击F12打开开发者模式发现有一串PHP代码,代码的意思为:以GET的方式传入cat,直接输出cat值,如果cat的值=dog 则输出 'Syc{cat_cat_cat_cat}'。
<!--
$cat=$_GET['cat'];
echo $cat;
if($cat=='dog'){
echo 'Syc{cat_cat_cat_cat}';
}
-->
代码意思理解清楚了就方便做题了,试一下输入 ?cat=dog flag就出来了
结束
版权声明
本文为[隔壁Cc]所创,转载请带上原文链接,感谢
https://blog.csdn.net/WINDY_PACE/article/details/121686876
边栏推荐
- Internal network security attack and defense: a practical guide to penetration testing (IV): Authority improvement analysis and defense
- Essays (updated from time to time)
- Intranet penetration series: ICMP of Intranet tunnel_ Tran
- A series of articles, a summary of common vulnerabilities of Web penetration (continuously updated)
- CTF attack and defense world brush questions 51-
- linux下mysql数据库备份与恢复(全量+增量)
- Alibaba sentinel学习QA
- The displayed amount of ABAP ALV is inconsistent with the exported amount
- 云计算技能大赛 -- openstack私有云环境 第二部分
- Houdini terrain and fluid solution (simulated debris flow)
猜你喜欢
DVWA靶场练习
BUUCTF MISC刷题
C # control the camera, rotate and drag the observation script (similar to scenes observation mode)
Unity C single case mode learning review notes
STO With Billing 跨公司库存转储退货
Towords Open World Object Detection
FUEL: Fast UAV Exploration using Incremental Frontier Structure and Hierarchical Planning
Simplify exporting to SVG data files and all images in SVG folder
C problem of marking the position of polygons surrounded by multiple rectangles
《内网安全攻防:渗透测试实战指南》读书笔记(八):权限维持分析及防御
随机推荐
C read INI file and write data to INI file
Shapley Explanation Networks
Intranet penetration series: dns2tcp of Intranet tunnel
一文了解系列,对web渗透的常见漏洞总结(持续更新)
Search and replacement of C text file (WinForm)
Teach-Repeat-Replan: A Complete and Robust System for Aggressive Flight in Complex Environments
When using flash, the code ends automatically without an error, the connection cannot be maintained, and the URL cannot be accessed.
Buuctf misc brush questions
Enterprise wechat login free jump self built application
Houdini>刚体, 刚体破碎RBD
内网渗透系列:内网隧道之pingtunnel
C problem of marking the position of polygons surrounded by multiple rectangles
Research on software security based on NLP (I)
云计算技能大赛 -- openstack私有云环境 第二部分
Using lambda expression to solve the problem of C file name sorting (whether it is 100 or 11)
Post of experience in preparation for guarantee and research -- the 18th (2021) Central South planning department promoted the exemption to Zhejiang University Institute of Technology
內網滲透系列:內網隧道之icmpsh
Simplify exporting to SVG data files and all images in SVG folder
[NLP notes] preliminary study on CRF principle
第七章 资产减值