当前位置:网站首页>[GKCTF 2021]easycms
[GKCTF 2021]easycms
2022-08-05 22:21:00 【New Reading of the Classic of Tea.】
[GKCTF 2021]easycms
Solution 1:
Have a hint to check it before opening

But the login page does not appear when I click the login in the upper right corner of the page
Look at the masters who can scan admin.php with Yujian, but mine can't scan it, add admin.php to the url to find the login page
![]()
The prompt tells us that the password is a five-digit weak password, and the account number is admin. The password is 12345
Find Design--Theme--Custom

Then edit the header

Type select php source code

Try to grab the flag directly, , but the savedWhen there is a problem, permission is required (this file name is different for everyone)

Begin to bypass permissions below: find design--component--material library

Feel free to upload a txt file

Refresh the page after uploading successfully, then edit what we uploaded and change the name to ../../../../../system/tmp/mpor (the last mpor is different for everyone), then save

In this way, the permissions have been bypassed. At this time, go back to design--theme--custom--page header editing--type selection as php source code, and grab the flag again 
The upload is successful at this point
Return to the homepage of the website to find the flag

Solution 2:
After entering the page, find Design--Theme--Custom

After clicking in, there is an export theme in the upper right corner

Click to enter and fill in the content at will, and save after filling out

At this point, he will pop up the download interface, click download, and then find the file in the download management, right-click there is a copy download link 
Found a bunch of base encrypted strings behind the download link, decrypt it and take a look

It should be the path, try to find the flag directly, /flag is encrypted with base64 to L2ZsYWc=

Then replace the path content in the link directly with L2ZsYWc=, go directly to visit
![]()
And then a file will pop up, download and open it with Notepad to find the flag

边栏推荐
猜你喜欢
随机推荐
从升职不加薪到取消外包员工餐厅福利,腾讯又开启了降本增效!
关于求直线交点的问题。
如何优雅的消除系统重复代码
[OMV] Xiaomi camera cannot get the network storage of OMV6 installed on Debian 11 is unknown
Day11: binary tree -- - > full ~, ~, heap completely
Analytics Redefined - EventBridge Real-Time Event Analytics Platform Released
印刷行业APS解决方案
ROS环境搭建过程
MySQL简介
nodejs(三)模块化,exports对象,npm与包的分类和结构,模块分类,模块作用域,exports对象,dependencies与devDepndencies节点,nrm,i5ting_toc
登录注册(无封装)flask
有关CRT密码反编译问题
中国石油大学(北京)-《 油层物理》第一阶段在线作业
nodejs(一)fs模块(操作文件的模块),path路径模块,路径拼接path.join,抵消两层路径的写法,浏览器中的js
LeetCode 每日一题——623. 在二叉树中增加一行
Centos7源码编译安装postgresql 11.7
[ssh] Solve the problem that the debian 11 system crt cannot ssh login
APS在印刷行业的应用前景和应用效益
redis宕机导致数据丢失的重大生产事故总结
解读APS及其效益









