漏洞原理 题目知识点讲的详细:
王叹之
https://www.cnblogs.com/wangtanzhi/p/12239918.html
web
[HCTF 2018]WarmUp
※※※※
全解:https://www.jianshu.com/p/1c2998973197
PHP 代码审计
phpmyadmin 4.8.1任意文件包含
[强网杯 2019]随便注
※※※※
比赛web题全解:https://www.jianshu.com/p/db6e2576b674
fuzz一下,过滤规则得出,然后
show tables =>得表名
show columns from table_name =>
[护网杯 2018]easy_tornado
※※※※
模板注入,服务端模板注入攻击 (SSTI),Tornado是python写web的应用框架;
http://www.creatapd.com/2018%E6%8A%A4%E7%BD%91%E6%9D%AFwriteup/
https://www.anquanke.com/post/id/161849?from=groupmessage#h2-1
[SUCTF 2019]EasySQL1
https://www.jianshu.com/p/5644f7c39c68
https://blog.csdn.net/qq_43619533/article