<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>青少年CTF论坛 - Web</title>
    <link>https://bbs.qsnctf.com/forum-web-1.html</link>
    <description>Latest 20 threads of Web</description>
    <copyright>Copyright(C) 青少年CTF论坛</copyright>
    <generator>Discuz! Board by Comsenz Inc.</generator>
    <lastBuildDate>Sat, 08 Aug 2026 04:59:26 +0000</lastBuildDate>
    <ttl>60</ttl>
    <image>
      <url>https://bbs.qsnctf.com/static/image/common/logo_88_31.gif</url>
      <title>青少年CTF论坛</title>
      <link>https://bbs.qsnctf.com/</link>
    </image>
    <item>
      <title>CatShell，猫猫你太狠了</title>
      <link>https://bbs.qsnctf.com/thread-964-1-1.html</link>
      <description><![CDATA[实在没思路了，三天啊，脑子已经被猫猫榨干了

有没有大佬可以提供一下解题思路嘞？求求了]]></description>
      <category>Web</category>
      <author>QiRan</author>
      <pubDate>Fri, 30 May 2025 08:06:15 +0000</pubDate>
    </item>
    <item>
      <title>入门需要怎么做？</title>
      <link>https://bbs.qsnctf.com/thread-454-1-1.html</link>
      <description><![CDATA[新人小白，极限6天学习然后上战场，请问如何入门，学习最基础的]]></description>
      <category>Web</category>
      <author>郑好耶耶耶</author>
      <pubDate>Sat, 09 Dec 2023 16:32:44 +0000</pubDate>
    </item>
    <item>
      <title>sqlmap连接不到目标RUL</title>
      <link>https://bbs.qsnctf.com/thread-432-1-1.html</link>
      <description><![CDATA[小白求问，s]]></description>
      <category>Web</category>
      <author>suiyuan</author>
      <pubDate>Thu, 16 Nov 2023 08:04:45 +0000</pubDate>
    </item>
    <item>
      <title>PHP特性05</title>
      <link>https://bbs.qsnctf.com/thread-377-1-1.html</link>
      <description><![CDATA[太菜了，搞好久


使用HackBar载入地址
按提示加入
file.php?k%20e%20y=123%0a

%20绕过下划线
%0a将字符串扩充长度不影响数值比较
加入post值
command=system(ls);highlight_file(next(array_reverse(scandir(dirname(__FILE__)))));
为了绕过文件名的点直接背过气去， ...]]></description>
      <category>Web</category>
      <author>wepcool</author>
      <pubDate>Mon, 25 Sep 2023 01:47:22 +0000</pubDate>
    </item>
    <item>
      <title>signin--WP</title>
      <link>https://bbs.qsnctf.com/thread-129-1-1.html</link>
      <description><![CDATA[[xmd]# signin

```php]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Fri, 17 Mar 2023 15:01:01 +0000</pubDate>
    </item>
    <item>
      <title>include01-02 --WP</title>
      <link>https://bbs.qsnctf.com/thread-128-1-1.html</link>
      <description><![CDATA[[xmd]# include01

```php
 

你能否获取Flag?
hello 你能否获取Flag?
hello
```

打开题目发现是个文件包含的题目

我们使用伪协议来读取flag，可以打开phpinfo()来得到flag，也可以使用查看文件来得到flag。

![](./data/attachment/forum/202303/17/225039ic525el2bc ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Fri, 17 Mar 2023 14:51:30 +0000</pubDate>
    </item>
    <item>
      <title>eval--WP</title>
      <link>https://bbs.qsnctf.com/thread-127-1-1.html</link>
      <description><![CDATA[[xmd]# eval

打开题目

```php
 
```

直接使用get请求

![](./data/attachment/forum/202303/17/224947vvlc1fccv08005l5.png)

/?cmd=system(\'ls /\');

发现flag

查看flag

![](./data/attachment/forum/202303/17/224953jj93wro339zjy3r2.png)

/?cmd=system(\'c]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Fri, 17 Mar 2023 14:49:56 +0000</pubDate>
    </item>
    <item>
      <title>登陆试试-WP</title>
      <link>https://bbs.qsnctf.com/thread-126-1-1.html</link>
      <description><![CDATA[[xmd]# 登陆试试

我们看下题目描述

题目描述：**Syclover**用户忘了他的密码，咋办哦,依稀记得密码为**6位数字,以774开头**，这次我们来爆爆他的密码，让他再也不犯相同的错了

![](./data/attachment/forum/202303/17/222820v4dtlev29243e6rv.png)

打开题目发现是个 ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Fri, 17 Mar 2023 14:28:47 +0000</pubDate>
    </item>
    <item>
      <title>nics_easyweb--WP</title>
      <link>https://bbs.qsnctf.com/thread-107-1-1.html</link>
      <description><![CDATA[[xmd]# nics_easyweb

首先打开题目发现是phpinfo();

![QQ截图20230111195122.png](https://s2.loli.net/2023/01/11/gwRkZFloLdDs7NB.png)

搜索flag发现确实有但是提交是错误的

![QQ截图20230111202101.png](https://s2.loli.net/2023/01/11/7MyWuUfQiwHZkCT.png)

! ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:47:51 +0000</pubDate>
    </item>
    <item>
      <title>骑士cms01--WP</title>
      <link>https://bbs.qsnctf.com/thread-105-1-1.html</link>
      <description><![CDATA[[xmd]#骑士cms01


打开划到最底下发现是74cms
 ![](./data/attachment/forum/202303/13/004230ummapn75pv5l231m.png)
百度一下很多getshell的办法选一个
http: //127.0.0.1/index.php?m=Admin
访问后台发现需要登陆，尝试使用admin 123456发现错误然后在尝试admin ；ad ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:42:58 +0000</pubDate>
    </item>
    <item>
      <title>帝国cms01-03 --WP</title>
      <link>https://bbs.qsnctf.com/thread-103-1-1.html</link>
      <description><![CDATA[[xmd]
#1.]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:38:53 +0000</pubDate>
    </item>
    <item>
      <title>Flask1 -WP</title>
      <link>https://bbs.qsnctf.com/thread-102-1-1.html</link>
      <description><![CDATA[[xmd]#Flask1

 ![](./data/attachment/forum/202303/13/003231ylw81uf1naww1u5k.png)
根据题目发现是flask
 ![](./data/attachment/forum/202303/13/003237ttlyvl5zoggomdgh.png)
有返回，直接上tplmap
![](./data/attachment/forum/202303/13/003256uf3syy5t0v604vvh. ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:33:12 +0000</pubDate>
    </item>
    <item>
      <title>Checkme1-8 WP</title>
      <link>https://bbs.qsnctf.com/thread-101-1-1.html</link>
      <description><![CDATA[[xmd]#Checkme1-8 WP
##Checkme01
 ![](./data/attachment/forum/202303/13/002050wem23jrhzjruaaz2.png)
$keys = base64_decode(urldecode($keys));
需要先将qsnctf字符进行base64编码才能使$keys==\&quot;qsnctf\&quot;判断成立。
 ![](./data/attachment/forum/202303/13/002226y ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:30:52 +0000</pubDate>
    </item>
    <item>
      <title>q1jun的小秘密</title>
      <link>https://bbs.qsnctf.com/thread-99-1-1.html</link>
      <description><![CDATA[[xmd]# q1jun的小秘密

首先打开题目发现是ssh

![image.png](https://s2.loli.net/2023/01/12/VFAPXBWoEtC2glf.png)

直接使用ssh连接

```bash
ssh q1jun@challenge.qsnctf.com -p 10573
```

连接上以后查看目录下有什么文件，发现有个hint.txt直接打开

```bash
[q1 ...]]></description>
      <category>Web</category>
      <author>虾虾一米六</author>
      <pubDate>Sun, 12 Mar 2023 16:15:13 +0000</pubDate>
    </item>
    <item>
      <title>青少年CTF平台---sqli-labs</title>
      <link>https://bbs.qsnctf.com/thread-69-1-1.html</link>
      <description><![CDATA[[xmd]![](https://img-blog.csdnimg.cn/b3a606939ad148828b39895607d7eb29.png)
##题目:sqli-labs

#考点sql注入

打开题目

先查找字段数(id=1\' order by 3 --+)

到4的时候会返回错误信息
![](https://img-blog.csdnimg.cn/029befeec2c14094aeba9bbe2b8009ff.png)
发 ...]]></description>
      <category>Web</category>
      <author>鲤鱼</author>
      <pubDate>Wed, 08 Mar 2023 15:02:14 +0000</pubDate>
    </item>
    <item>
      <title>Web-Easy flag在哪里？（题目解析）</title>
      <link>https://bbs.qsnctf.com/thread-55-1-1.html</link>
      <description><![CDATA[打开容器，在页面源代码中找到flag！]]></description>
      <category>Web</category>
      <author>w147865932</author>
      <pubDate>Sat, 04 Mar 2023 13:33:29 +0000</pubDate>
    </item>
  </channel>
</rss>