当前位置:网站首页>I include of spring and Autumn
I include of spring and Autumn
2022-07-05 15:11:00 【Golden silk】
Open the connection , The title prompt is a File Inclusion Vulnerability
First try to visit flag.php, What also have no
Continue to look at flag Is it in the front directory , utilize include structure payload
url?path=../flag.php
Try another layer of directory , Nothing at all
So I have to change my mind
Come to the original page , Find out
allow_url_include = ON
It's time to take advantage of PHP flow input La
structure payload
url?path=php://input
Re pass post The ginseng
<?php echo system('ls');?>
Check all the files in the current file directory ,
system Function is to execute system commands
ls yes Linux System commands
Because I'm hot hackbar I don't know why it can't pass POST Pass no = Parameters of
So I used it fiddler The ginseng , It can also be used. burpsuite
ls -a yes Linux The order of , Follow ls almost
ls command - Linux Complete tutorial of commands (yiibai.com)
Click on execute
View the returned packets
Only found dle345aae.php This document can , Check this file again
Reuse file streams php://input, Again, this time it's used fiddler
Pass on POST, use Linux in cat The order of
cat command - Linux Complete tutorial of commands (yiibai.com)
Check the returned data again
Get flag
Of course we know flag Name of file , You can also use another method to view flag
utilize PHP flow filter
?path=php://filter/convert.base64-encode/resource= file a
It means that base64 View the file in the form of encoding a
structure payload
url?path=php://filter/convert.base64-encode/resource=dle345aae.php
The obtained code is base64 Decoding can see flag 了
边栏推荐
- Photoshop插件-动作相关概念-ActionList-ActionDescriptor-ActionList-动作执行加载调用删除-PS插件开发
- 【华为机试真题详解】欢乐的周末
- Magic methods and usage in PHP (PHP interview theory questions)
- Mongdb learning notes
- Go learning ----- relevant knowledge of JWT
- Redis distributed lock principle and its implementation with PHP (1)
- [12 classic written questions of array and advanced pointer] these questions meet all your illusions about array and pointer, come on!
- 裁员下的上海
- IPv6与IPv4的区别 网信办等三部推进IPv6规模部署
- 计算中间件 Apache Linkis参数解读
猜你喜欢
Fr exercise topic --- comprehensive question
[JVM] operation instruction
Aike AI frontier promotion (7.5)
危机重重下的企业发展,数字化转型到底是不是企业未来救星
Interpretation of Apache linkage parameters in computing middleware
Bugku's steganography
Au - delà du PARM! La maîtrise de l'Université de Pékin propose diverse pour actualiser complètement le classement du raisonnement du NLP
Photoshop插件-动作相关概念-ActionList-ActionDescriptor-ActionList-动作执行加载调用删除-PS插件开发
Microframe technology won the "cloud tripod Award" at the global Cloud Computing Conference!
Ten billion massage machine blue ocean, difficult to be a giant
随机推荐
两个BI开发,3000多张报表?如何做的到?
Jmeter性能测试:ServerAgent资源监控
easyOCR 字符識別
IPv6与IPv4的区别 网信办等三部推进IPv6规模部署
机器学习框架简述
华为哈勃化身硬科技IPO收割机
Huiyuan, 30, is going to have a new owner
MySQL----函数
CPU design practice - Chapter 4 practical task 2 using blocking technology to solve conflicts caused by related problems
MongDB学习笔记
JMeter performance test: serveragent resource monitoring
漫画:程序员不是修电脑的!
Mongdb learning notes
SQL Server learning notes
How can I quickly check whether there is an error after FreeSurfer runs Recon all—— Core command tail redirection
729. My schedule I: "simulation" & "line segment tree (dynamic open point) &" block + bit operation (bucket Division) "
Install and configure Jenkins
Leetcode: Shortest Word Distance II
Two Bi development, more than 3000 reports? How to do it?
[recruitment position] infrastructure software developer