from flask import Flask, request, render_template_string,current_app
app = Flask(__name__)
@app.route('/') defhello_world():# put application's code here person = 'knave' if request.args.get('name'): person = request.args.get('name') template = '<h1>Hi, %s.</h1>' % person return render_template_string(template)
from flask import Flask, request, render_template_string,current_app
app = Flask(__name__)
@app.route('/') defhello_world():# put application's code here person = 'knave' blacklist='{'#彻底杜绝ssti if request.args.get('name'): person = request.args.get('name') if blacklist in person:#关键字检测 return"fxxk hacker" template = '<h1>Hi, %s.</h1>' % person return render_template_string(template) @app.route('/shell') deftest(): return"123"