当前位置:网站首页>Attack and defense world web advanced area unserialize3
Attack and defense world web advanced area unserialize3
2022-07-02 09:44:00 【hangshao0.0】
subject

Related content
In fact, a deserialization article has been recorded before .
PHP Deserialization -(web_php_unserialize)
The topic of deserialization , It's more complicated than this .
Since I haven't practiced for a long time , And I saw this in the offensive and defensive world unserialize3 The subject of , Just review deserialization .
The problem solving steps
First new An object , And then serialize it , The code is as follows :
The result of serialization is as follows :

"xctf":1: There is only one attribute in the serialized object , If the string to be deserialized , The number of attributes does not conform to the actual , be __wakeup() invalid .
therefore , take "xctf":1: Change it to "xctf":2: Bypass __wakeup() .
The results of parameter transmission are as follows :

边栏推荐
- Read 30 minutes before going to bed every day_ day4_ Files
- Failed to configure a DataSource: ‘url‘ attribute is not specified and no embedd
- vs+qt 设置应用程序图标
- Record the interesting process of using Xray for the first time
- QT QLabel样式设置
- PI control of three-phase grid connected inverter - off grid mode
- Tools used for Yolo object recognition and data generation
- Record personal understanding and experience of game console configuration
- BugkuCTF-web24(解题思路及步骤)
- In SQL injection, why must the ID of union joint query be equal to 0
猜你喜欢

hystrix 实现请求合并

Share a blog (water blog)

Failed to configure a DataSource: ‘url‘ attribute is not specified and no embedd

QT qlabel style settings

2837xd 代码生成——补充(2)

2837xd code generation - stateflow (4)

每天睡前30分钟阅读Day6_Day6_Date_Calendar_LocalDate_TimeStamp_LocalTime

How to install PHP in CentOS

Record the interesting process of using Xray for the first time

并网逆变器PI控制(并网模式)
随机推荐
分享一篇博客(水一篇博客)
What is the function of laravel facade
Hystrix implements request consolidation
Inverter Simulink model -- processor in the loop test (PIL)
Difference between redis serialization genericjackson2jsonredisserializer and jackson2jsonredisserializer
YOLO物体识别,生成数据用到的工具
kinect dk 获取CV::Mat格式的彩色RGB图像(openpose中使用)
MySQL multi column in operation
C语言之数据插入
记录下对游戏主机配置的个人理解与心得
idea查看字节码配置
Chrome browser tag management plug-in – onetab
TD联合Modelsim进行功能仿真
Timed thread pool implements request merging
Customize redis connection pool
定时线程池实现请求合并
Record personal understanding and experience of game console configuration
图像识别-数据标注
View the port of the application published by was
Say goodbye to 996. What are the necessary plug-ins in idea?