Featured image of post Nssctf Easyssrf Wp

Nssctf Easyssrf Wp

字数: 171

题目说是 ssrf。SSRF(Server-Side Request Forgery) 是服务端请求伪造。可以利用它来访问内部或外部资源。

本题获取网络快照,用 curl 获取网站。

试试 127.0.0.1/flag:

但是用 127.0.0.1/fl4g 直接就:

试了下 http://0/fl4g
快照就是该网站

再试试看 file://fl4g 出现提示:

我们跳到 ha1x1ux1u.php
提供源码:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
<?php

highlight_file(__FILE__);
error_reporting(0);

$file = $_GET["file"];
if (stristr($file, "file")){
  die("你败了.");
}

//flag in /flag
echo file_get_contents($file);

直接 GET 给 file 传参 /flag

参考资料

  1. ctfwiki ssrf