import requests for i in range(1,1000): payload="http://node4.anna.nssctf.cn:28150/shop?page=%d"%(i) res=requests.get(payload) if"lv6.png"in res.content.decode('utf-8'): print(i) break
import tornado.web from sshop.base import BaseHandler import pickle import urllib
classAdminHandler(BaseHandler): @tornado.web.authenticated defget(self, *args, **kwargs): ifself.current_user == "admin": returnself.render('form.html', res='This is Black Technology!', member=0) else: returnself.render('no_ass.html')
@tornado.web.authenticated defpost(self, *args, **kwargs): try: become = self.get_argument('become') p = pickle.loads(urllib.unquote(become)) returnself.render('form.html', res=p, member=1) except: returnself.render('form.html', res='This is Black Technology!', member=0) 关键句是 p = pickle.loads(urllib.unquote(become)