HTB之Weather App

本文详细介绍了在Hack The Box (HTB) 的Weather App挑战中,如何通过信息收集、理解应用程序工作原理,发现SSRF漏洞和SQL注入点,并最终构造Payload进行攻击的全过程。重点讨论了利用SSRF攻击和SQL注入漏洞注册admin用户并获取flag的策略。
摘要由CSDN通过智能技术生成

HTB之Weather App

0x01 挑战说明
CHALLENGE DESCRIPTION
A pit of eternal darkness, a mindless journey of abeyance, this feels like a never-ending dream. I think I'm hallucinating with the memories of my past life, it's a reflection of how thought I would have turned out if I had tried enough. A weatherman, I said! Someone my community would look up to, someone who is to be respected. I guess this is my way of telling you that I've been waiting for someone to come and save me. This weather application is notorious for trapping the souls of ambitious weathermen like me. Please defeat the evil bruxa that's operating this website and set me free! 🧙‍♀️
0x02 收集信息

打开页面,没有找到什么可利用的信息。

在这里插入图片描述

下载所需的文件,里面有此天气程序的源代码和一个docker容器

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值