当前位置:网站首页>Bugku's Eval

Bugku's Eval

2022-07-05 15:11:00 Golden silk

Open the connection

The title looks familiar , It's similar to the question I wrote before

i Spring and autumn blasting -1_l2872253606 The blog of -CSDN Blog

i Spring and autumn blasting -2_l2872253606 The blog of -CSDN Blog

The above article is more detailed than the following

utilize eval function , First, check the global variables

structure payload

url?hello=$GLOBALS

good heavens , I didn't find any flag, And was ridiculed

explain flag Is not a variable , It should be in flag.php It's annotated

structure Payload

url?hello=);highlight_file('flag.php');var_dump(

Get flag

Since it's in the document , It can also be done in another way , Utilization function

structure Payload

url?hello=file('flag.php')

Get the same flag

原网站

版权声明
本文为[Golden silk]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/02/202202140518211052.html