Offensive and defensive world web articles writeup

1. Insert picture description here
Open the scene found
Insert picture description here
our first view the page source code
found Insert picture description here
after inquiry, cyberpeace network security means, namely to understand, this is the Flag
2. Insert picture description here
first understand what is robots protocol
found just add the url in robots.txt protocol to see robots
Insert picture description here
I found Insert picture description here
that I thought f1ag_1s_h3re.php was a flag, but I submitted an error and thought of the characteristics of the robots protocol. After putting f1ag_1s_h3re.php in the url, I found flag Insert picture description here
3.

Insert picture description here
First understand a point of knowledge.
If there are backup files on the website, common backup file extensions are: ".git", ".svn", ".swp", ".~", ".bak", ".bash_history", ". "bkf" Try to enter the common file backup extensions in sequence after the URL.
After adding a suffix to the url in turn, no flag or file can be obtained.
But there is index.php in the page, try to enter it into the url, and then enter the above suffix in turn, and finally find

Insert picture description here
Then
open it with notepad++ and find the flag

Insert picture description here
4.
Insert picture description here
Open the scene, capture the package, find the following picture,
Insert picture description here
Insert picture description here
perform the picture operation, and find the flag
Insert picture description here

Insert picture description here

Insert picture description here
Insert picture description here
Delete the disabled
Insert picture description here
button and press it, and you get the flag
6. Insert picture description here
Insert picture description here
Try some simple password usernames. I
Insert picture description here
found that the username is admin. Here I thought of the blasting password, but in the process of checking burp, I found it by accident

Insert picture description here
Get the flag directly

Guess you like

Origin blog.csdn.net/qq_51954912/article/details/113882224