当前位置:网站首页>百度杯”CTF比赛 2017 二月场,Web:爆破-2
百度杯”CTF比赛 2017 二月场,Web:爆破-2
2022-07-05 13:00:00 【Part 02】
题目内容:
flag不在变量中。
<?php
include "flag.php";
$a = @$_REQUEST['hello'];
eval( "var_dump($a);");
show_source(__FILE__);?hello=file('flag.php')

file 命令直接可以读出来
file_get_contents 也行,但在源码里

边栏推荐
- DataPipeline双料入选中国信通院2022数智化图谱、数据库发展报告
- RHCSA8
- Detailed explanation of navigation component of openharmony application development
- 爱可生SQLe审核工具顺利完成信通院‘SQL质量管理平台分级能力’评测
- Solve Unicode decodeerror: 'GBK' codec can't decode byte 0xa2 in position 107
- go 数组与切片
- 155. 最小栈
- How to protect user privacy without password authentication?
- Why is your next computer a computer? Explore different remote operations
- 【Hot100】33. 搜索旋转排序数组
猜你喜欢

How can non-technical departments participate in Devops?

精彩速递|腾讯云数据库6月刊

Association modeling method in SAP segw transaction code

Natural language processing series (I) introduction overview

Simple page request and parsing cases

uni-app开发语音识别app,讲究的就是简单快速。

Android本地Sqlite数据库的备份和还原

无密码身份验证如何保障用户隐私安全?

RHCSA9
![leetcode:221. Maximum square [essence of DP state transition]](/img/ea/158e8659657984794c52a0449e0ee5.png)
leetcode:221. Maximum square [essence of DP state transition]
随机推荐
JXL notes
RHCSA4
My colleague didn't understand selenium for half a month, so I figured it out for him in half an hour! Easily showed a wave of operations of climbing Taobao [easy to understand]
RHCSA10
Simple page request and parsing cases
Developers, is cloud native database the future?
Sorry, we can't open xxxxx Docx, because there is a problem with the content (repackaging problem)
MySQL splits strings for conditional queries
潘多拉 IOT 开发板学习(HAL 库)—— 实验7 窗口看门狗实验(学习笔记)
Le rapport de recherche sur l'analyse matricielle de la Force des fournisseurs de RPA dans le secteur bancaire chinois en 2022 a été officiellement lancé.
Why is your next computer a computer? Explore different remote operations
How to choose note taking software? Comparison and evaluation of notion, flowus and WOLAI
逆波兰表达式
Alibaba cloud SLB load balancing product basic concept and purchase process
先写API文档还是先写代码?
The Research Report "2022 RPA supplier strength matrix analysis of China's banking industry" was officially launched
SAP UI5 FlexibleColumnLayout 控件介绍
CF:A. The Third Three Number Problem【关于我是位运算垃圾这个事情】
Android本地Sqlite数据库的备份和还原
Principle and configuration of RSTP protocol