Skip to content

Instantly share code, notes, and snippets.

@lbr77
lbr77 / README.md
Created April 28, 2024 13:39
SpirigGame App1e_Tree's Big Duck Writeup

出题碎碎念

嗯...题面没有骗人。

首先就是确实那天App1e_Tree打穿了全场。

然后空虚和寂寞嘛...这个大家可以去问问他(?。

确实也是在天津街头闲逛的时候拍到的东西。

@lbr77
lbr77 / README.md
Last active April 28, 2024 13:43
SpiritGame sqlshark writeup exp and server.

出题碎碎念:

想法来自群友的调侃:那是不是搞一个sqlmap risk3 level5然后抓包就能出题了?

嗯于是这道题出题时候的参数就是:python sqlmap.py -u "http://localhost:8080/login?usr=LiBr&pwd=11d188aa7daf1c0ef4744d33888fd0da" --risk 3 --level 5 --thread 8 --dump -T table

出题人wp:

导出所有有用包之用python处理可以看到有效信息:

@lbr77
lbr77 / README.md
Last active April 27, 2024 04:39
Enjoy the Game!

想必做到这一步的你应该看得出来504b是什么东西了吧?

有没有想起comment里说的密码是什么?

@lbr77
lbr77 / config1.json
Created March 18, 2024 06:39
DubheCTF authorized mess & unauthorized less v2ray config
{
"log": {
"loglevel":"debug"
},
"inbounds": [
{
"protocol": "dokodemo-door",
"port": 50005,
"settings": {
"address": "172.20.0.2",
@lbr77
lbr77 / README.md
Last active February 17, 2024 16:25
HashExtensionExploit

PyMd5 from https://github.com/Utkarsh87/md5-hashing/blob/master/md5.py

Usage:

from hash_ext_exp import HashExtensionExploit
import hashlib
key = b"test"
old_msg = b"1234555"
old_hash = hashlib.md5(key+old_msg).hexdigest()
nhash,nmsg = HashExtensionExploit(old_msg,old_hash,len(key),b"1234").run();
@lbr77
lbr77 / solve.py
Last active December 31, 2023 14:11
Game
import base64 as b64
def bintotext(ress, count=7):
res = ""
for i in range(0, len(ress), count):
res += chr(int(ress[i : i + count], 2))
return res
git config --global https.proxy http://127.0.0.1:1080
git config --global https.proxy https://127.0.0.1:1080
git config --global --unset http.proxy
git config --global --unset https.proxy
npm config delete proxy
@lbr77
lbr77 / install.sh
Created August 10, 2022 14:29
Scripts for Synology DS120j or similar machines to install docker
#!/usr/bin/env bash
# Description: Install docker-aarch64 for ds120j
# System Required: Synology
# Author: lbr77
# some scrpts from github.com/P3TERX
#
# MIT License
#
@lbr77
lbr77 / index.js
Created May 29, 2021 07:01
基于CF-Workers的站点PV统计
addEventListener("fetch", (event) => {
event.respondWith(
handleRequest(event)
);
});
async function handleRequest(event){
const url = new URL(event.request.url);
const method = event.request.method;
if(method === "GET"){
let record = await JSON.parse(await KV.get("RECORD"))
@lbr77
lbr77 / index.js
Created May 22, 2021 10:53
CDN开源
addEventListener("fetch", event => {
event.respondWith(handleRequest(event))
})
const BUCKET_NAME = "lbr77/CDN@main"
const BUCKET_URL = `http://cdn.jsdelivr.net/gh/${BUCKET_NAME}`
async function serveAsset(event) {
const url = new URL(event.request.url)
const cache = caches.default