For the complete documentation index, see llms.txt. This page is also available as Markdown.

SUCTF 2019

Web

pythonnginx

้€š่ฟ‡ๆŸฅ็œ‹ๆบไปฃ็ ๅฏไปฅๅ‘็Žฐไปฅไธ‹ๅ†…ๅฎนใ€‚

@app.route('/getUrl', methods=['GET', 'POST'])
def getUrl():
    url = request.args.get("url") # ่ฎพ url=https://xxx.com/index.php
    host = parse.urlparse(url).hostname # xxx.com
    if host == 'suctf.cc':
        return "ๆˆ‘ๆ‰Œ your problem? 111"
    parts = list(urlsplit(url)) # ['https', 'xxx.com', '/index.php', '', '']
    host = parts[1] # xxx.com
    if host == 'suctf.cc':
        return "ๆˆ‘ๆ‰Œ your problem? 222 " + host
    newhost = []
    for h in host.split('.'):
        newhost.append(h.encode('idna').decode('utf-8'))
    parts[1] = '.'.join(newhost)
    #ๅŽปๆމ url ไธญ็š„็ฉบๆ ผ
    finalUrl = urlunsplit(parts).split(' ')[0]
    host = parse.urlparse(finalUrl).hostname
    if host == 'suctf.cc':
        return urllib.request.urlopen(finalUrl).read()
    else:
        return "ๆˆ‘ๆ‰Œ your problem? 333"
    </code>
#    <!-- Dont worry about the suctf.cc. Go on! -->
#    <!-- Do you know the nginx? -->

ๆœฌ้ข˜้œ€่ฆ็ป•่ฟ‡็ฌฌไธ€ๅฑ‚ๅ’Œ็ฌฌไบŒๅฑ‚็š„ๅŸŸๅๅˆคๆ–ญ๏ผŒๅนถไธ”ๅœจ็ปๅކไธ€ๆฌก idna ็ผ–็ ๅŽ็š„็ฌฌไธ‰ๅฑ‚ไธญๅˆ่ฆ็ฌฆๅˆ host ๅไธบ suctf.cc ๏ผŒidna ็š„ไพ‹ๅญๅฆ‚ไธ‹ใ€‚

ๅ› ๆญคๅฏไปฅ้€š่ฟ‡็‰ˆๆƒ็ฌฆๅทๆฅ็ป•่ฟ‡็ฌฌไธ€ๅฑ‚ๅ’Œ็ฌฌไบŒๅฑ‚็š„็ป•่ฟ‡ๅนถไธ”ๅˆ็ฌฆๅˆ host ๅไธบ suctf.cc ใ€‚ๅˆๅ› ไธบ้ข˜็›ฎไธญๅŒ…ๅซๆ็คบ Do you know the nginx ๆ•…้œ€่ฆไปŽ nginx ็š„็›ธๅ…ณๆ–‡ไปถไธญๆฅๆ‰พ flag ๏ผŒๆœ€ๅŽๅฏไปฅๅœจ /usr/local/nginx/conf/nginx.conf ไธญๆ‰พๅˆฐ็›ธๅ…ณไฟกๆฏ๏ผŒPayload ไปฅๅŠๅ›žๆ˜พๅฆ‚ไธ‹ๆ‰€็คบใ€‚

้€š่ฟ‡ๆž„้€ ไปฅไธ‹ Payload ๅณๅฏๅพ—ๅˆฐ flag ใ€‚

Last updated