baby_web

在创建场景之后打开网页,发现hello world

G85B7o8CQmxFHkAAJkAAJkAAJkAAJkAAJkAAJLDGB+UIanWQHPcVsD4b5wNi6gekcMnKlwDB7thcqgyHTJOTEXOJvFh6eBEiABEiABEiABEiABEhgWRJIX+zei5tBwwolstDKFJBMBt2cAMP08MJlCXGei0rvZZPv9ef7uft1MPwP1gVmZUTu9kwAAAAASUVORK5CYII=

方法一:使用bp

地址默认是1.php,我们要把它改成index.php(题干提醒访问初始页面)但是直接修改会跳回原来的1.php所以我们需要进行抓包 ,检查为什么会跳转?

跳转是因为在默认访问index.php时响应为302

所以在使用bp抓包后我们将请求处改成index.php

gAAIgAAIgAAIgECMCUCMiTFwNAcCIAACIAACcUYAYkycDQjMAQEQAAEQAAEQSHwCEGMSf4zRQxAAARAAARAIRABiDO4PEAABEAABEAABEIgxAYgxMQaO5kAABEAABEAgzgj8Pz4OZPqi4W7aAAAAAElFTkSuQmCC

我们可以在响应处直接发现flag

方法二:使用开发者工具(点击f12)

打开hackbar,点开网络功能,重新加载,显示当前地址的网络记录,可以在右边看响应头和请求头。

我们直接在地址处将1.php修改成index.php,可以发现网络功能处已经出现访问记录,然后我们可以在右侧的响应区发现flag

OKUvQ5sAAAAASUVORK5CYII=

方法三:python脚本编写

import requests

url = "http://61.147.171.105:58804/1.php"

response = requests.get(url, allow_redirects=False)

if 'FLAG' in response.headers and 'flag{' in response.headers['FLAG']:

    flag_stare = response.headers['FLAG'].index('flag{')

    flag_end = response.headers['FLAG'].index('}', flag_stare) + 1 

    flag = response.headers['FLAG'][flag_stare:flag_end]

    print("存在flag" + flag)

else:

    print("未找到flag")

mUuD9Ll+5h9vkH8lOUi9hJ9xlsC8zs3w0flYJmygInaDkfzX6L3otmAPCALX2i9QwREQAREQAREoEIgpQJEd4AIiIAIiIAIiIAIiIAIiEASBCRAkqCuY4qACIiACIiACIiACIhASglIgKT0wmvZIiACIiACIiACIiACIpAEAQmQJKjrmCIgAiIgAiIgAiIgAiKQUgISICm98Fq2CIiACIiACIiACIiACCRBQAIkCeo6pgiIgAiIgAiIgAiIgAiklIAESEovvJYtAiIgAiIgAiIgAiIgAkkQkABJgrqOKQIiIAIiIAIiIAIiIAIpJSABktILr2WLgAiIgAiIgAiIgAiIQBIEJECSoK5jioAIiIAIiIAIiIAIiEBKCUiApPTCa9kiIAIiIAIiIAIiIAIikAQBCZAkqOuYIiACIiACIiACIiACIpBSAhIgKb3wWrYIiIAIiIAIiIAIiIAIJEFAAiQJ6jqmCIiACIiACIiACIiACKSUgARISi+8li0CIiACIiACIiACIiACSRCQAEmCuo4pAiIgAiIgAiIgAiIgAiklIAGS0guvZYuACIiACIiACIiACIhAEgQkQJKgrmOKgAiIgAiIgAiIgAiIQEoJSICk9MJr2SIgAiIgAiIgAiIgAiKQBAEJkCSo65giIAIiIAIiIAIiIAIikFICEiApvfBatgiIgAiIgAiIgAiIgAgkQUACJAnqOqYIiIAIiIAIiIAIiIAIpJSABEhKL7yWLQIiIAIiIAIiIAIiIAJJEJAASYK6jikCIiACIiACIiACIiACKSUgAZLSC69li4AIiIAIiIAIiIAIiEASBCRAkqCuY4qACIiACIiACIiACIhASglIgKT0wmvZIiACIiACIiACIiACIpAEAQmQJKjrmCIgAiIgAiIgAiIgAiKQUgISICm98Fq2CIiACIiACIiACIiACCRBQAIkCeo6pgiIgAiIgAiIgAiIgAiklIAESEovvJYtAiIgAiIgAiIgAiIgAkkQkABJgrqOKQIiIAIiIAIiIAIiIAIpJSABktILr2WLgAiIgAiIgAiIgAiIQBIEJECSoK5jioAIiIAIiIAIiIAIiEBKCUiApPTCa9kiIAIiIAIiIAIiIAIikAQBCZAkqOuYIiACIiACIiACIiACIpBSAhIgKb3wWrYIiIAIiIAIiIAIiIAIJEFAAiQJ6jqmCIiACIiACIiACIiACKSUgARISi+8li0CIiACIiACIiACIiACSRCQAEmCuo4pAiIgAiIgAiIgAiIgAiklIAGS0guvZYuACIiACIiACIiACIhAEgQkQJKgrmOKgAiIgAiIgAiIgAiIQEoJSICk9MJr2SIgAiIgAiIgAiIgAiKQBAEJkCSo65giIAIiIAIiIAIiIAIikFICEiApvfBatgiIgAiIgAiIgAiIgAgkQUACJAnqOqYIiIAIiIAIiIAIiIAIpJSABEhKL7yWLQIiIAIiIAIiIAIiIAJJEJAASYK6jikCIiACIiACIiACIiACKSUgAZLSC69li4AIiIAIiIAIiIAIiEASBCRAkqCuY4qACIiACIiACIiACIhASglIgKT0wmvZIiACIiACIiACIiACIpAEAQmQJKjrmCIgAiIgAiIgAiIgAiKQUgISICm98Fq2CIiACIiACIiACIiACCRB4H8BCFXtFQiixHoAAAAASUVORK5CYII=

运行之后得到结果flag

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值