当前位置:网站首页>I include of spring and Autumn
I include of spring and Autumn
2022-07-05 15:11:00 【Golden silk】
Open the connection , The title prompt is a File Inclusion Vulnerability
First try to visit flag.php, What also have no

Continue to look at flag Is it in the front directory , utilize include structure payload
url?path=../flag.php

Try another layer of directory , Nothing at all
So I have to change my mind
Come to the original page , Find out
allow_url_include = ON

It's time to take advantage of PHP flow input La
structure payload
url?path=php://input
Re pass post The ginseng
<?php echo system('ls');?>
Check all the files in the current file directory ,
system Function is to execute system commands
ls yes Linux System commands
Because I'm hot hackbar I don't know why it can't pass POST Pass no = Parameters of
So I used it fiddler The ginseng , It can also be used. burpsuite

ls -a yes Linux The order of , Follow ls almost
ls command - Linux Complete tutorial of commands (yiibai.com)
Click on execute
View the returned packets

Only found dle345aae.php This document can , Check this file again
Reuse file streams php://input, Again, this time it's used fiddler
Pass on POST, use Linux in cat The order of
cat command - Linux Complete tutorial of commands (yiibai.com)

Check the returned data again

Get flag
Of course we know flag Name of file , You can also use another method to view flag
utilize PHP flow filter
?path=php://filter/convert.base64-encode/resource= file a
It means that base64 View the file in the form of encoding a
structure payload
url?path=php://filter/convert.base64-encode/resource=dle345aae.php

The obtained code is base64 Decoding can see flag 了
边栏推荐
- Can I pass the PMP Exam in 20 days?
- Ten billion massage machine blue ocean, difficult to be a giant
- Run faster with go: use golang to serve machine learning
- Crud of MySQL
- Go learning ----- relevant knowledge of JWT
- No one consults when doing research and does not communicate with students. UNC assistant professor has a two-year history of teaching struggle
- GPS original coordinates to Baidu map coordinates (pure C code)
- maxcompute有没有能查询 表当前存储容量的大小(kb) 的sql?
- 我想咨询一下,mysql一个事务对于多张表的更新,怎么保证数据一致性的?
- Behind the ultra clear image quality of NBA Live Broadcast: an in-depth interpretation of Alibaba cloud video cloud "narrowband HD 2.0" technology
猜你喜欢

【jvm】运算指令

百亿按摩仪蓝海,难出巨头

Huawei Hubble incarnation hard technology IPO harvester

30岁汇源,要换新主人了

Ctfshow web entry explosion

No one consults when doing research and does not communicate with students. UNC assistant professor has a two-year history of teaching struggle

How to paste the contents copied by the computer into mobaxterm? How to copy and paste

市值蒸发超百亿美元,“全球IoT云平台第一股”赴港求生

Bugku's steganography

基于TI DRV10970驱动直流无刷电机
随机推荐
危机重重下的企业发展,数字化转型到底是不是企业未来救星
The difference between abstract classes and interfaces in PHP (PHP interview theory question)
我这边同时采集多个oracle表,采集一会以后,会报oracle的oga内存超出,大家有没有遇到的?
Reasons and solutions for redis cache penetration and cache avalanche
Where is the operation of convertible bond renewal? Is it safer and more reliable to open an account
sql server char nchar varchar和nvarchar的区别
Microframe technology won the "cloud tripod Award" at the global Cloud Computing Conference!
长列表优化虚拟滚动
SQL Server learning notes
华为哈勃化身硬科技IPO收割机
Crud de MySQL
一键更改多个文件名字
Ctfshow web entry information collection
DVWA range clearance tutorial
Anaconda uses China University of science and technology source
Visual task scheduling & drag and drop | scalph data integration based on Apache seatunnel
Redis' transaction mechanism
Easyocr character recognition
JMeter performance test: serveragent resource monitoring
Un week - end heureux