[BJDCTF2020]EasySearch
打开环境,是个登录框:随便输入后弹窗显示错误:SQL注入也没有什么发现,那就用dirsearch扫描一下,发现了index.php.swp,访问得到源码:<?php ob_start(); function get_hash(){ $chars = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789!@#$%^&*()+-'; $random = $chars[mt_rand(0,..