【Attack and Defense World】Study Notes【CTF】

Web type
1. Web baby_web
Note (knowledge points): sql injection, SSRF, php deserialization
Example: web-facebook

Solution: index.php redirects. Click F12 in the Firefox browser, click the network, and see the message header.
insert image description here

2. Ics-06
topic description: The cloud platform report center collected the data of the basic service of device management, but the data was deleted, and only one place left traces of intruders.
answer:
insert image description here

Knowledge point: the use of Burp toolkit.

3. Easyupload
topic description: In the eyes of a qualified hacker, all upload points are backdoors left by developers.
answer:
insert image description here

Knowledge points: file upload questions; burp packet capture; Chinese Ant Sword
4. Inget
topic description: None

answer:insert image description here

insert image description here

Knowledge point: It is known from the title that this is injected based on the GET request of the WEB page. Guess this is a SQL injection problem.
5. Web_php_include
Title description: None
insert image description here

Solution: Add this string at the back
insert image description here

6. simple_php
topic description: Xiao Ning heard that php is the best language, so she wrote a few lines of php code after simple learning.insert image description here

Solution: Look at the code and know that the condition of flag is a==0 and if a is true, b>1234.

Guess you like

Origin blog.csdn.net/weixin_43485035/article/details/127238301