Skip to content

Commit ecb946d

Browse files
committed
tpctf2025: add some details
1 parent ec2467e commit ecb946d

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

source/_posts/tpctf2025/whereIsRop.md

+7
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,13 @@ gdbserver 127.0.0.1:1337 login.cgi "$@"
8181

8282
![confusion](/assets/tpctf2025/cmdConfusion.png)
8383

84+
{% folding purple::更多细节 %}
85+
压缩包中还有一些html和js文件,阅读后可以发现,如果在网页端尝试登录,会首先将密码使用
86+
`gen_enc`加密,再提交登录/注册请求。然而,这并不是强制的。由于没有提供注册接口,
87+
数据库又是空的,因此我们需要先手动发送http请求来注册。注册成功后如果登录,由于不存在
88+
`manager.cgi`,因此会显示404。
89+
{% endfolding %}
90+
8491
## EXPLOIT
8592

8693
```python

0 commit comments

Comments
 (0)