当前位置:网站首页>Php:filter pseudo protocol [bsidescf 2020]had a bad day
Php:filter pseudo protocol [bsidescf 2020]had a bad day
2022-07-23 15:50:00 【A traveler】
Knowledge point :
php:filter//read=convert.base64-encode/resource= file name ;

If you write casually after the parameter, you will find that some files contain errors :

He has .php Suffix added , It means that the execution is parametric PHP file , Then it is likely to be flag;
Change directly flag try :
![]()
Only these two parameters are supported ; But as long as it contains woofers The string of will be another syntax error , After guessing the interview, there is a string matching function ; Parameters are file classes
Just thought of using php://filter Fake protocol :
It must contain those two characters : Just use php Pseudo protocol nesting :
therefore :
?category=php://filter/read=convert.base64-encode/woofers/resource=flag

Decrypt it flag;
It's fine too index Get the source code ;
边栏推荐
- VMware virtual machine download, installation and use tutorial
- 第五篇 Druid数据源介绍
- Fileinputformat of MapReduce inputformat
- harbor镜像仓库
- STL map操作
- [try to hack] SQL injection less7 (into outfile and Boolean blind annotation)
- 备份内容哈哈哈
- Safety 7.18 operation
- 什么是真正的 HTAP ?(二)挑战篇
- What is the real HTAP? (2) Challenge article
猜你喜欢

Guangzhou held a competition for quality and safety supervisors of agricultural products in the town and street

Can multithreading optimize program performance?

数据治理浅析

7.13web safety operation
![[pyGame practice] playing poker? Win or lose? This card game makes me forget to eat and sleep.](/img/ba/a174c5daccef7a6ea72c11dad8601d.png)
[pyGame practice] playing poker? Win or lose? This card game makes me forget to eat and sleep.

对C语言最基本的代码解释

重磅 | CertiK:2022年第二季度Web3.0行业安全报告发布(附PDF下载链接)

C语言经典例题-将输入的两位数转成英文

一个悄然崛起的国产软件,太强了!

Six ways of uniapp route jump
随机推荐
Idea starts multiple projects at once
Modify SSH command line[ [email protected] ]Color
【HiFlow】定期发送腾讯云短信发送群
Kirin V10 source code compilation qtcreater4.0.3 record
Start other independent programs through fmmonitoredprocess in unreal
Part II how to design an RBAC authority system
Opnsense - multifunctional, highly reliable and easy-to-use firewall (II)
day1
The current situation and history of it migrant workers
Fileinputformat of MapReduce inputformat
C语言经典例题-贷款余额
The difference between cookies and sessions
The exclamation point of vscode +tab shortcut key cannot be used, and the solution to the problem of a-soul-live2d plug-in
C语言宏定义
Find the source code of the thesis
一个悄然崛起的国产软件,太强了!
airserver在哪里下载?使用方法教程
【攻防世界WEB】难度三星9分入门题(中):ics-05、easytornado
C语言书写规范
bgp基本配置