当前位置:网站首页>Attack and defense world web advanced area unserialize3
Attack and defense world web advanced area unserialize3
2022-07-02 09:44:00 【hangshao0.0】
subject
Related content
In fact, a deserialization article has been recorded before .
PHP Deserialization -(web_php_unserialize)
The topic of deserialization , It's more complicated than this .
Since I haven't practiced for a long time , And I saw this in the offensive and defensive world unserialize3 The subject of , Just review deserialization .
The problem solving steps
First new An object , And then serialize it , The code is as follows :
The result of serialization is as follows :
"xctf":1:
There is only one attribute in the serialized object , If the string to be deserialized , The number of attributes does not conform to the actual , be __wakeup()
invalid .
therefore , take "xctf":1:
Change it to "xctf":2:
Bypass __wakeup()
.
The results of parameter transmission are as follows :
边栏推荐
- C语言之数据插入
- Methods of classfile
- Matplotlib swordsman line - first acquaintance with Matplotlib
- Enterprise level SaaS CRM implementation
- What is the function of laravel facade
- Int to string, int to qstring
- Alibaba /热门json解析开源项目 fastjson2
- Beats (filebeat, metricbeat), kibana, logstack tutorial of elastic stack
- Pool de connexion redis personnalisé
- zk配置中心---Config Toolkit配置与使用
猜你喜欢
随机推荐
Image recognition - Data Cleaning
Image recognition - data annotation
互联网API接口幂等设计
Image recognition - data augmentation
web安全与防御
因上努力,果上随缘
MySQL事务
C语言之二进制与十进制
Binary and decimal system of C language
Failed to configure a DataSource: ‘url‘ attribute is not specified and no embedd
What are the differences between TP5 and laravel
2837xd 代码生成——补充(2)
分布式锁的这三种实现方式,如何在效率和正确性之间选择?
QT qlabel style settings
Attributes of classfile
Safety production early warning system software - Download safety production app software
Pool de connexion redis personnalisé
C language programming problems
College Students' CET-4 and CET-6 composition template (self created version, successfully crossed CET-6)
Operation and application of stack and queue