当前位置:网站首页>I spring and autumn blasting-2
I spring and autumn blasting-2
2022-07-05 15:11:00 【Golden silk】
Open the connection , Another one PHP Code , Then audit it
eval(" Code a") Function is to make code a image PHP Do the same , Using this function, you can add code to this php In the document
Method 1 :
file() function , Is to read the file into the array ,PHP file() function | Novice tutorial (runoob.com)
Using this function , Can output flag.php Contents of Li , structure payload
url?hello=file("flag.php")
Get flag
Method 2 :
utilize ); Add a few more codes to this php in , You can use the following two functions , Output flag The file of
PHP show_source() function | Novice tutorial (runoob.com)
PHP highlight_file() function | Novice tutorial (runoob.com)
structure payload
url?hello=);show_source("flag.php");highlight_file("flag.php"
Mainly integration eval Things in functions
); To integrate the previous var_dump(
highlight_file("flag.php" To integrate the latter );
The principle is based on the original code , hold
eval( "var_dump($a);");
Instead of
var_dump();show_source("flag.php");highlight_file("flag.php");
In view of :i spring and autumn CTF Training Misc Web Blast -2_ Coconut milk jelly unsafe blog -CSDN Blog
边栏推荐
- Behind the ultra clear image quality of NBA Live Broadcast: an in-depth interpretation of Alibaba cloud video cloud "narrowband HD 2.0" technology
- 美团优选管理层变动:老将刘薇调岗,前阿里高管加盟
- Calculate weight and comprehensive score by R entropy weight method
- Can I pass the PMP Exam in 20 days?
- 漫画:优秀的程序员具备哪些属性?
- JS bright blind your eyes date selector
- Common MySQL interview questions
- Install PHP extension spoole
- 729. 我的日程安排表 I :「模拟」&「线段树(动态开点)」&「分块 + 位运算(分桶)」
- Mongdb learning notes
猜你喜欢
B站做短视频,学抖音死,学YouTube生?
qt creater断点调试程序详解
计算中间件 Apache Linkis参数解读
Differences between IPv6 and IPv4 three departments including the office of network information technology promote IPv6 scale deployment
Interview shock 62: what are the precautions for group by?
Creation and optimization of MySQL index
你童年的快乐,都是被它承包了
"Sequelae" of the withdrawal of community group purchase from the city
30岁汇源,要换新主人了
Huawei Hubble incarnation hard technology IPO harvester
随机推荐
Ctfshow web entry explosion
超越PaLM!北大硕士提出DiVeRSe,全面刷新NLP推理排行榜
Anaconda uses China University of science and technology source
Selection and use of bceloss, crossentropyloss, sigmoid, etc. in pytorch classification
Au - delà du PARM! La maîtrise de l'Université de Pékin propose diverse pour actualiser complètement le classement du raisonnement du NLP
裁员下的上海
Jmeter性能测试:ServerAgent资源监控
基于TI DRV10970驱动直流无刷电机
CODING DevSecOps 助力金融企业跑出数字加速度
MySQL----函数
美团优选管理层变动:老将刘薇调岗,前阿里高管加盟
mapper.xml文件中的注释
1330: [example 8.3] minimum steps
Stm32+bh1750 photosensitive sensor obtains light intensity
Machine learning notes - gray wolf optimization
No one consults when doing research and does not communicate with students. UNC assistant professor has a two-year history of teaching struggle
[C question set] of Ⅷ
Ecotone technology has passed ISO27001 and iso21434 safety management system certification
Thymeleaf uses background custom tool classes to process text
Creation and optimization of MySQL index