当前位置:网站首页>Attack and defense world web advanced area unserialize3
Attack and defense world web advanced area unserialize3
2022-07-02 09:44:00 【hangshao0.0】
subject

Related content
In fact, a deserialization article has been recorded before .
PHP Deserialization -(web_php_unserialize)
The topic of deserialization , It's more complicated than this .
Since I haven't practiced for a long time , And I saw this in the offensive and defensive world unserialize3 The subject of , Just review deserialization .
The problem solving steps
First new An object , And then serialize it , The code is as follows :
The result of serialization is as follows :

"xctf":1: There is only one attribute in the serialized object , If the string to be deserialized , The number of attributes does not conform to the actual , be __wakeup() invalid .
therefore , take "xctf":1: Change it to "xctf":2: Bypass __wakeup() .
The results of parameter transmission are as follows :

边栏推荐
- Image recognition - data augmentation
- Operation and application of stack and queue
- Chrome browser plug-in fatkun installation and introduction
- Cmake command - Official Document
- 记录一下初次使用Xray的有趣过程
- Record the interesting process of using Xray for the first time
- vs+qt 设置应用程序图标
- C语言之判断直角三角形
- Vs+qt set application icon
- Learn combinelatest through a practical example
猜你喜欢

View the port of the application published by was

How to use pyqt5 to make a sensitive word detection tool

Supplier selection and prequalification of Oracle project management system

idea查看字节码配置

分享一篇博客(水一篇博客)

Navicat remote connection MySQL reports an error 1045 - access denied for user 'root' @ '222.173.220.236' (using password: yes)

2837xd Code Generation - stateflow (4)

图像识别-数据增广

图像识别-数据清洗

一次聊天勾起的回忆
随机推荐
C语言之二进制与十进制
Binary and decimal system of C language
Read Day6 30 minutes before going to bed every day_ Day6_ Date_ Calendar_ LocalDate_ TimeStamp_ LocalTime
自定義Redis連接池
Insight into cloud native | microservices and microservice architecture
每天睡前30分钟阅读Day6_Day6_Date_Calendar_LocalDate_TimeStamp_LocalTime
记录下对游戏主机配置的个人理解与心得
Idempotent design of Internet API interface
MySQL multi column in operation
Mathematics in machine learning -- point estimation (I): basic knowledge
Attributes of classfile
C语言之到底是不是太胖了
Save video opencv:: videowriter
Bugkuctf-web24 (problem solving ideas and steps)
图像识别-数据标注
Solutions to Chinese garbled code in CMD window
kinect dk 获取CV::Mat格式的彩色RGB图像(openpose中使用)
Read 30 minutes before going to bed every day_ day4_ Files
2837xd code generation - Summary
TD conducts functional simulation with Modelsim