当前位置:网站首页>百度杯”CTF比赛 2017 二月场,Web:爆破-2
百度杯”CTF比赛 2017 二月场,Web:爆破-2
2022-07-05 13:00:00 【Part 02】
题目内容:
flag不在变量中。
<?php
include "flag.php";
$a = @$_REQUEST['hello'];
eval( "var_dump($a);");
show_source(__FILE__);?hello=file('flag.php')

file 命令直接可以读出来
file_get_contents 也行,但在源码里

边栏推荐
- SAP UI5 DynamicPage 控件介绍
- Flutter 绘制波浪移动动画效果,曲线和折线图
- Write macro with word
- Yyds dry goods inventory # solve the real problem of famous enterprises: move the round table
- mysql econnreset_ Nodejs socket error handling error: read econnreset
- About the single step debugging of whether SAP ui5 floating footer is displayed or not and the benefits of using SAP ui5
- My colleague didn't understand selenium for half a month, so I figured it out for him in half an hour! Easily showed a wave of operations of climbing Taobao [easy to understand]
- Talk about my drawing skills in my writing career
- RHCSA2
- APICloud Studio3 WiFi真机同步和WiFi真机预览使用说明
猜你喜欢

Leetcode20. Valid parentheses

Android本地Sqlite数据库的备份和还原

Introduction to sap ui5 dynamicpage control

Introduction to the principle of DNS

Lb10s-asemi rectifier bridge lb10s

一文详解ASCII码,Unicode与utf-8

Cf:a. the third three number problem

The Research Report "2022 RPA supplier strength matrix analysis of China's banking industry" was officially launched

函数传递参数小案例

Principle and performance analysis of lepton lossless compression
随机推荐
使用Dom4j解析XML
【Hot100】33. 搜索旋转排序数组
JPA规范总结和整理
946. Verify stack sequence
简单上手的页面请求和解析案例
There is no monitoring and no operation and maintenance. The following is the commonly used script monitoring in monitoring
Halcon template matching actual code (I)
leetcode:221. 最大正方形【dp状态转移的精髓】
碎片化知识管理工具Memos
时钟周期
Get to know linkerd project for the first time
潘多拉 IOT 开发板学习(HAL 库)—— 实验7 窗口看门狗实验(学习笔记)
go 数组与切片
RHCSA7
将函数放在模块中
Reflection and imagination on the notation like tool
MySQL splits strings for conditional queries
RHCSA4
爱可生SQLe审核工具顺利完成信通院‘SQL质量管理平台分级能力’评测
Rocky basics 1