当前位置:网站首页>uplad_ Labs first three levels
uplad_ Labs first three levels
2022-07-05 13:43:00 【Sex sex ~ ~】
Catalog
Pass_01
Pass_02
Pass_03
The problem solving process
Pass_01

First upload a picture and try , Upload successful 
The title says to upload one webshell Get to know webshell
webshell:webshell That is to say asp、php、jsp perhaps cgi etc. Webpage A code execution environment in the form of a file , Mainly used for website management 、 Server management 、 Permission management and other operations . Just upload a code file , Visit through website , Many daily operations can be carried out .
So I want to upload one php Documents of the same type , Upload PHP When you file 
Take another look at the tips

The description is the front end js verification
Upload a php The file of , Change the foot code to the one allowed on the title .jpg|.png|.gif Image format , Upload successfully and then burpsuite Carry out the bag . First, find the agent in the settings

Manual use burpsuite Proxy for port

Construct a PHP The file of , Then change the file format to .png, open burpsuite Carry out the bag

Show the inside png Change it to php

Then put the bag d
Pass_02
The second level is still uploaded php File to try

The second level is somewhat similar to the first level , Let's check the source code

Only upload is allowed jpeg/.png/.gif Files of type , Like the first level, first find the agent in the setting , Manual use burpsuite Proxy for port , Upload the allowed file types first , And then with burpsuite Carry out the bag .
Pass_03
Take a look at the source code

The front clearance is only allowed to upload image type files , And the third level is not allowed to upload php Documents of the same type , It is called blacklist verification , Special suffixes . Convert case , No way to remove strings .
Put the document corner code php Change it to php1 Try to find that the upload is successful

边栏推荐
- 南理工在线交流群
- asp.net 读取txt文件
- 个人组件 - 消息提示
- MySQL --- 数据库查询 - 排序查询、分页查询
- When using Tencent cloud for the first time, you can only use webshell connection instead of SSH connection.
- 4年工作经验,多线程间的5种通信方式都说不出来,你敢信?
- Prefix, infix, suffix expression "recommended collection"
- Introduction to Chapter 8 proof problem of njupt "Xin'an numeral base"
- French scholars: the explicability of counter attack under optimal transmission theory
- Network security HSRP protocol
猜你喜欢

【华南理工大学】考研初试复试资料分享

Usage, installation and use of TortoiseSVN

MySQL - database query - sort query, paging query

The real king of caching, Google guava is just a brother

Write API documents first or code first?

Shandong University Summer Training - 20220620

Laravel framework operation error: no application encryption key has been specified

搭建一个仪式感点满的网站,并内网穿透发布到公网 2/2

Wonderful express | Tencent cloud database June issue

Summit review | baowanda - an integrated data security protection system driven by compliance and security
随机推荐
Summit review | baowanda - an integrated data security protection system driven by compliance and security
龙芯派2代烧写PMON和重装系统
今年上半年,通信行业发生了哪些事?
Godson 2nd generation burn PMON and reload system
Personal component - message prompt
Datapipeline was selected into the 2022 digital intelligence atlas and database development report of China Academy of communications and communications
Intranet penetration tool NetApp
多人合作项目查看每个人写了多少行代码
49. 字母异位词分组:给你一个字符串数组,请你将 字母异位词 组合在一起。可以按任意顺序返回结果列表。 字母异位词 是由重新排列源单词的字母得到的一个新单词,所有源单词中的字母通常恰好只用一次。
Redis6 master-slave replication and clustering
个人组件 - 消息提示
Clock cycle
ELFK部署
Get you started with Apache pseudo static configuration
A detailed explanation of ASCII code, Unicode and UTF-8
[daily question] 1200 Minimum absolute difference
Laravel框架运行报错:No application encryption key has been specified
MySQL - database query - sort query, paging query
Redis6 data type and operation summary
MySQL --- 数据库查询 - 排序查询、分页查询