Git Product home page Git Product logo

wonderkun / ctf_web Goto Github PK

View Code? Open in Web Editor NEW
672.0 33.0 201.0 26.55 MB

a project aim to collect CTF web practices .

Home Page: https://wonderkun.github.io/CTF_web/

License: MIT License

PHP 44.40% CSS 25.54% JavaScript 22.78% HTML 4.38% Python 1.51% Shell 0.07% XSLT 0.12% Mako 0.01% Dockerfile 0.20% Hack 0.09% Batchfile 0.01% Smarty 0.41% PLpgSQL 0.48% Makefile 0.01%
ctf ctf-web web-challenges score practise

ctf_web's Introduction

CTF-web

              _                                    _               ____ _____ _____                 _        
__      _____| | ___ ___  _ __ ___   ___          | |_ ___        / ___|_   _|  ___|  __      _____| |__     
\ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \         | __/ _ \      | |     | | | |_ ____\ \ /\ / / _ \ '_ \    
 \ V  V /  __/ | (_| (_) | | | | | |  __/         | || (_) |     | |___  | | |  _|_____\ V  V /  __/ |_) |   
  \_/\_/ \___|_|\___\___/|_| |_| |_|\___|          \__\___/       \____| |_| |_|        \_/\_/ \___|_.__/   

Backers on Open Collective Sponsors on Open Collective Build Status

Hello, everyone! I'am wonderkun.

I am intersted in web scurity and absorbed in web challenges of CTFS. Hence,I made this repo for the purpose of collecting some interesting web practises

and some ideas with expansions. I will provide with source codes downloaded from CTF or written by myself , writeups in detail and exps.

Aiming at giving some conveniences for beginers to start CTF and improving my personal ability , I spend a lot of time on doing this.

If you find some errors or want to give some advice, do not hesitate to contact me at follows ways :

Recommend to you an another repo which is better than this one . My-CTF-Web-Challenges

Thank you for the other contibuters:

Hope you will love it and if you think it is of value, please star it . Thank you !!!

Naming Rules :

A majority of the practises is named as webXXX-YY.

  • XXX represents the score of this subject. Obviously,the higher the score, the harder the subject.

  • YY represents the numbering of the subject,for instance , web100-2 is the second subject of the 100 points.

Other Naming Rules

  • sql_inject is the practises of sql inject collection

  • exec Arbitrary command execution.

  • NSq\og This is a CTF runed by CloverSec in Xian,Shanxi province.

  • shiyanba Those subject are collected from shiyanba,which is a good place to learn CTF.

  • php4fun Php4fun.

  • uncategorized Some uncategorized subjects.

Welcome to contribute to it.

Contributors

This project exists thanks to all the people who contribute. [Contribute].

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]

ctf_web's People

Contributors

ckc9759 avatar monkeywithacupcake avatar mozhu1024 avatar wangyihang avatar wonderkun avatar yichinzhu avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

ctf_web's Issues

请问一下400-4的问题

请问一下 执行语句http://127.0.0.1:5555/index.php?file=phar://Up10aDs/y9c8v9ow3s6ans5o8oy5u3qnsdnckeva.png/1里的1是自己构造的吗?里面的内容是什么呢?如何通过这个语句找到F1AgIsH3r3G00d.php呢?😭😭

web100-4的问题

你好,在web100-4Index.php里面,$KEY='ISecer:www.isecer.com';这句话应该在unserialize($cookie) === "$KEY"前面吧。

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.