当前位置:网站首页>Php:filter pseudo protocol [bsidescf 2020]had a bad day
Php:filter pseudo protocol [bsidescf 2020]had a bad day
2022-07-23 15:50:00 【A traveler】
Knowledge point :
php:filter//read=convert.base64-encode/resource= file name ;

If you write casually after the parameter, you will find that some files contain errors :

He has .php Suffix added , It means that the execution is parametric PHP file , Then it is likely to be flag;
Change directly flag try :
![]()
Only these two parameters are supported ; But as long as it contains woofers The string of will be another syntax error , After guessing the interview, there is a string matching function ; Parameters are file classes
Just thought of using php://filter Fake protocol :
It must contain those two characters : Just use php Pseudo protocol nesting :
therefore :
?category=php://filter/read=convert.base64-encode/woofers/resource=flag

Decrypt it flag;
It's fine too index Get the source code ;
边栏推荐
- Time series data in industrial Internet of things
- Kirin V10 source code compilation qtcreater4.0.3 record
- C语言经典例题-商品检验码
- md5强碰撞,二次解码,
- The difference between cookies and sessions
- day14函数模块
- Part V Druid data source introduction
- aws篇3 go语言如何publish message 到iot的MQTT
- MySQL execution order
- Can multithreading optimize program performance?
猜你喜欢
![[7.16] code source - [array division] [disassembly] [select 2] [maximum common divisor]](/img/fd/ffddb3ac35e946215a0582f09f278a.png)
[7.16] code source - [array division] [disassembly] [select 2] [maximum common divisor]

第二篇 如何设计一个RBAC权限系统

C语言注释的方法

超详细MP4格式分析
![[200 opencv routines] 225. Fourier descriptor for feature extraction](/img/4b/1f373505ffd5c0dbaa5c20431c4b42.png)
[200 opencv routines] 225. Fourier descriptor for feature extraction

Idea starts multiple projects at once

BGP联邦实验

Kirin V10 source code compilation qtcreater4.0.3 record

Six ways of uniapp route jump

用rpm -e --nodeps进行批量删除
随机推荐
Application of ERP management system in equipment manufacturing enterprise management
Conda设置代理
STL map attribute
String and integer convert each other
深入理解L1、L2正则化
3D math - vector
自定义封装弹出框(带进度条)
查找论文源代码
PHP代码审计4—Sql注入漏洞
3D数学 - 矢量
适用于顺序磁盘访问的1分钟法则
2022最NB的JVM基础到调优笔记,吃透阿里P6小case
C语言宏定义
10100
AWS篇1
种种迹象表明,Apple将有望支持AV1
[pyGame actual combat] aircraft shooting masterpiece: fierce battle in the universe is imminent... This super classic shooting game should also be taken out and restarted~
浅谈‘过早优化’
超详细MP4格式分析
ClickHouse,让查询飞起来!!!