当前位置:网站首页>php:filter伪协议之[BSidesCF 2020]Had a bad day
php:filter伪协议之[BSidesCF 2020]Had a bad day
2022-07-23 11:18:00 【一只Traveler】
知识点:
php:filter//read=convert.base64-encode/resource=文件名;

在参数后面随便写会发现有文件包含报错:

他已经把.php后缀加上了,意思是执行的是参数的PHP文件,那么就很可能是flag;
直接换flag试试:
![]()
只支持这两个参数;但是只要是含有woofers的字符串就会是另外的语法错误,猜测后面试有一个字符串匹配函数;参数又是文件类
就想到用php://filter伪协议:
又必须包含那两个字符:就用php伪协议嵌套:
所以:
?category=php://filter/read=convert.base64-encode/woofers/resource=flag

解密得flag;
也可以index得到源码;
边栏推荐
- 查找论文源代码
- BGP routing principle
- BGP federal experiment
- Idea starts multiple projects at once
- Find the source code of the thesis
- [7.16] code source - [array division] [disassembly] [select 2] [maximum common divisor]
- PHP代码审计4—Sql注入漏洞
- 《代码之丑》学习总结
- (BFS) template + example (maze, eight digits)
- go : gin Urlencoded 格式
猜你喜欢

Smart headline: smart clothing forum will be held on August 4, and the whole house smart sales will exceed 10billion in 2022

After vscode is updated, the shortcut keys related to tab cannot be used

SCA在得物DevSecOps平台上应用

Analysis of data governance

Find the source code of the thesis

【运维】ssh tunneling 依靠ssh的22端口实现访问远程服务器的接口服务

Idea starts multiple projects at once

day14函数模块

C语言经典例题-贷款余额

Find a specific number in an ordered array (binary search or half search)
随机推荐
奔驰新能源产品线:豪华新能源市场或将改变格局
Idea five free plug-ins to improve efficiency
String and integer convert each other
记一次SQL优化
(Zset)Redis底层是如何用跳表进行存储的
[heuristic divide and conquer] the inverse idea of heuristic merging
可穿戴设备的自电容触摸控制器IT7259Q-13,IT7259EX-24
【Try to Hack】sql注入 Less7 (into outfile和布尔盲注)
Mercedes Benz new energy product line: luxury new energy market may change the pattern
BGP联邦实验
MySQL execution order
Chapter 4 event handling of quick mastering QML
SCA在得物DevSecOps平台上应用
软件测试周刊(第81期):能够对抗消极的不是积极,而是专注;能够对抗焦虑的不是安慰,而是具体。
STL deque
800V高压快充落地进程加快均胜电子获5亿欧元项目定点
Open source quadruped robot with design drawings and code "suggestions collection"
10100
超详细MP4格式分析
C语言经典例题-用4×4矩阵显示从1到16的所有整数,并计算每行、每列和每条对角线上的和