> For the complete documentation index, see [llms.txt](https://gitbook-88.gitbook.io/ctf-writeup/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gitbook-88.gitbook.io/ctf-writeup/2020/2020-gkctf/lao-ba-xiao-chao-shi-er.md).

# 老八小超市儿

shopxo模板

默认密码admin/shopox登录后台

在网站管理 -> 主题管理 -> 主题安装 -> 更多主题下载里面下载一个主题

<figure><img src="https://1298837596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUlxElCQcjylbSFsJycU3%2Fuploads%2FHCutv6ZKYaXd7CJRajL2%2Fimage-22-1.png?alt=media&amp;token=94fcbee1-bf00-4a03-8050-a6ac04d71e3f" alt=""><figcaption></figcaption></figure>

下载下来之后，在 default/**static** 里面放一句话木马，重新上传。

上传后再用那牛逼的蚁剑，使用payload：

```
url/public/static/index/default/shell.php
```

<figure><img src="https://1298837596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUlxElCQcjylbSFsJycU3%2Fuploads%2Ft999oW2F9NsU7I4oqlzr%2Fimage-27-1.png?alt=media&amp;token=84019922-8221-4b93-b496-a9c466df4ea5" alt=""><figcaption></figcaption></figure>

可以看到假flag，提示日期，查看auto.sh文件

<figure><img src="https://1298837596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUlxElCQcjylbSFsJycU3%2Fuploads%2FfPom6CTQUjcQV5Deggwo%2Fimage-29-1.png?alt=media&amp;token=9d3532f4-cbdb-4674-9851-f75a3ef33207" alt=""><figcaption></figcaption></figure>

查看写文件

<figure><img src="https://1298837596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUlxElCQcjylbSFsJycU3%2Fuploads%2Foqyz58J4URWFLZlUg7TH%2Fimage-30-1.png?alt=media&amp;token=8c76a570-56b1-41e0-be2f-d426d6407be7" alt=""><figcaption></figcaption></figure>

该文件可以任意写，把flag写到hint即可。
