ISCTF2025-web部分复现 2025-12-12 16:26 | 252 | 1 | 未分类 1311 字 | 20 分钟 Author:endowment 感觉很考验代码审计这一块😘 难过的bottle 给了源码,可恶的黑名单:会被压缩文件内容进行渲染,是bottle框架,然后有过滤这么多字符,这边用全角字符搭配八进制绕过(python是可以解析全角字符的,确实牛!) PythonBLACKLIST = ["b","c","d","e","h","i","j"…