這兩場都有稍微參加一下,但不是每一題都有看,這篇純粹做個筆記而已,稍微記一下解法,不會太詳細。
老樣子,筆記一下關鍵字:
- GraphQL batch query + alias
- Python os.path.join 絕對路徑
- Svg XSS, foreignObject
- WebRTC CSP bypass
- Status code xsleak
- DNS rebinding
- nmap command injection
- ruby rack 上傳檔案暫存
- buildConstraintViolationWithTemplate EL injection
- request smuggling
- document.baseURI
- 200/404 status code xsleak