当前位置:网站首页>I spring and autumn blasting-2
I spring and autumn blasting-2
2022-07-05 15:11:00 【Golden silk】
Open the connection , Another one PHP Code , Then audit it
eval(" Code a") Function is to make code a image PHP Do the same , Using this function, you can add code to this php In the document
Method 1 :
file() function , Is to read the file into the array ,PHP file() function | Novice tutorial (runoob.com)
Using this function , Can output flag.php Contents of Li , structure payload
url?hello=file("flag.php")
Get flag
Method 2 :
utilize ); Add a few more codes to this php in , You can use the following two functions , Output flag The file of
PHP show_source() function | Novice tutorial (runoob.com)
PHP highlight_file() function | Novice tutorial (runoob.com)
structure payload
url?hello=);show_source("flag.php");highlight_file("flag.php"
Mainly integration eval Things in functions
); To integrate the previous var_dump(
highlight_file("flag.php" To integrate the latter );
The principle is based on the original code , hold
eval( "var_dump($a);");
Instead of
var_dump();show_source("flag.php");highlight_file("flag.php");
In view of :i spring and autumn CTF Training Misc Web Blast -2_ Coconut milk jelly unsafe blog -CSDN Blog
边栏推荐
- What are CSRF, XSS, SQL injection, DDoS attack and timing attack respectively and how to prevent them (PHP interview theory question)
- Reasons and solutions for redis cache penetration and cache avalanche
- Common PHP interview questions (1) (written PHP interview questions)
- 基于TI DRV10970驱动直流无刷电机
- 【华为机试真题详解】欢乐的周末
- 市值蒸发超百亿美元,“全球IoT云平台第一股”赴港求生
- Thymeleaf uses background custom tool classes to process text
- Brief introduction of machine learning framework
- Dark horse programmer - software testing -10 stage 2-linux and database -44-57 why learn database, description of database classification relational database, description of Navicat operation data, de
- [C question set] of Ⅷ
猜你喜欢
Selection and use of bceloss, crossentropyloss, sigmoid, etc. in pytorch classification
Run faster with go: use golang to serve machine learning
Under the crisis of enterprise development, is digital transformation the future savior of enterprises
NBA赛事直播超清画质背后:阿里云视频云「窄带高清2.0」技术深度解读
Behind the ultra clear image quality of NBA Live Broadcast: an in-depth interpretation of Alibaba cloud video cloud "narrowband HD 2.0" technology
Ecotone technology has passed ISO27001 and iso21434 safety management system certification
Common MySQL interview questions
Interview shock 62: what are the precautions for group by?
Thymeleaf uses background custom tool classes to process text
Coding devsecops helps financial enterprises run out of digital acceleration
随机推荐
CODING DevSecOps 助力金融企业跑出数字加速度
1330: [example 8.3] minimum steps
一键更改多个文件名字
Behind the ultra clear image quality of NBA Live Broadcast: an in-depth interpretation of Alibaba cloud video cloud "narrowband HD 2.0" technology
长列表优化虚拟滚动
爱可可AI前沿推介(7.5)
Go learning ----- relevant knowledge of JWT
Common interview questions about swoole
Redis' transaction mechanism
可视化任务编排&拖拉拽 | Scaleph 基于 Apache SeaTunnel的数据集成
Mysql---- function
Surpass palm! Peking University Master proposed diverse to comprehensively refresh the NLP reasoning ranking
Super wow fast row, you are worth learning!
Ecotone technology has passed ISO27001 and iso21434 safety management system certification
Jmeter性能测试:ServerAgent资源监控
Install PHP extension spoole
Interview shock 62: what are the precautions for group by?
STM32+BH1750光敏传感器获取光照强度
你童年的快乐,都是被它承包了
GPS原始坐标转百度地图坐标(纯C代码)