Topic at I spring and Autumn CTF training camp
Look at the source code, found tips:
Open user.php, page blank, refer to the big guy's blog to know there may be a User.php.bak backup file, download the file can get the user name list
Take the burp blasting:
None of the 700 supposedly were born in 1999? Take 1998 and try again ..... It's cold again ... I've been trying until 1990, and finally there's a big guy who's been in this year.
Account Lixiuyun, password lixiuyun1990
Enter into a blank personal center
Delete the comment in Firefox viewer, then upload an image and try
After the file name is added. PHP return cannot appear PHP, then take PHT instead
Here by the way PHP aliases: PhP2, PhP3, PhP4, PHP5, Phps, PHT, phtm, phtml
Access view.php, look at the interface may be a file read
Tips for filtering flag, take flflagag and try it.
"Baidu Cup" CTF competition September _123 (file backup, explosion, upload)