# web1

F12 查看源代码

ctfshow{003df495-852d-4326-9f57-aee33ebdbb5a}

image-20250402224023049

# web2

image-20250402224539067

题解一

ctrl + u 查看网页源代码 / 在 URL 前加上 view-source:

image-20250402224707389

题解二

刷新的同时按 F12 查看源代码

image-20250406205446977

# web3

抓包

Flag: ctfshow{a2f4a406-c69c-4135-bb09-197a2230b537}

image-20250406203240665
image-20250406202851164

# web4

访问 url/robots.txt ,根据提示 访问 url/flagishere.txt

ctfshow{d1fc90c5-0c02-4457-a8fd-446ddf5f6c3f}
image-20250406203833372
image-20250406203847247

# web5

phps 泄露,访问 url/index.php

image-20250406204721617

# web6

访问 url/www.zip ,然后访问 url/fl000g.txt

image-20250406210448625
image-20250406210436670

# web7

访问 url/.git

image-20250406211902205

# web8

访问 url/.svn

image-20250406213018884

# web9

访问 url/index.php.swp

image-20250406213659612

# web10

F12 查看 cookies 或者 抓包

URL 解码

image-20250406215028988
image-20250406215252742
image-20250406215009170

# web11

域名查询

域名解析查询 | DNS 查询

阿里云



# web12

访问 url/robots.txt 接着访问 url/admin

账号: admin 密码: 372619038 (帮助热线号码)

ctfshow{e4ded847-4db4-4295-b998-1ac949c90089}

image-20250406230955467
image-20250406230856053
image-20250406231153154

# web13

拉到最下面, document 下载,查看用户名和密码,访问 靶机/system1103/login.php

ctfshow{16b63f10-2d6f-41fe-affc-9b4588184d47}

image-20250406231933953
image-20250406231950964
image-20250406231858102

# web14

访问 url/editor 在图片上传处可以查看整个目录 找到 flag 的位置

nothinghereeditor 在同一目录下

ctfshow{efea91c6-f966-4022-adc4-3f3b87fa8170}

image-20250406234839218
image-20250406234743967

# web15

访问 url/admin 查询 QQ 得知现居陕西西安,回答密保问题获得重置密码

ctfshow{af4c6156-aac0-4702-b47c-0d44d354d067}

image-20250407002355266
image-20250407002445091

# web16

访问 url/tz.php , 找到 PHPINFO ,查看 php 信息

ctfshow{1191cce9-d664-40fa-81cc-c0bb07fe2f1c}

image-20250407135131371
image-20250407135041938
image-20250407135131371

# web17

访问 url/backup.sql

ctfshow{2b4eda41-3d14-4ee7-adf1-c78bb5e867d3}

image-20250407135741167

# web18

Flappy_js.js 看到提示信息,访问 url/110.php

ctfshow{a48fcacb-d9f4-4e3e-8e20-6f2215fe7cf5}

image-20250409120021668
image-20250409120037458
image-20250409120053482

# web19

源代码有账号密码,post 得到 ctfshow {5d6760a0-d647-4cd7-bed1-076c68fc072c}

image-20250409120921147

# web20

访问 url /db/db.mdb

image-20250409121741141