[Zer0pts2020]Can you guess it?1

打开题目

看到信息随便输入一个数,显示错误

查看源代码

看到php代码,代码审计

<?php

include 'config.php'; // FLAG is defined in config.php

if (preg_match('/config\.php\/*/i', _SERVER'PHP_SELF')) {

exit("I don't know what you are thinking, but I won't let you read it :)");

}

if (isset($_GET'source')) {

highlight_file(basename($_SERVER'PHP_SELF'));

exit();

}

$secret = bin2hex(random_bytes(64));

if (isset($_POST'guess')) {

guess = (string) _POST'guess';

if (hash_equals(secret, guess)) {

$message = 'Congratulations! The flag is: ' . FLAG;

} else {

$message = 'Wrong.';

}

}

?>

<!doctype html>

<html lang="en">

<head>

<meta charset="utf-8">

<title>Can you guess it?</title>

</head>

<body>

<h1>Can you guess it?</h1>

<p>If your guess is correct, I'll give you the flag.</p>

<p><a href="?source">Source</a></p>

<hr>

<?php if (isset($message)) { ?>

<p><?= $message ?></p>

<?php } ?>

<form action="index.php" method="POST">

<input type="text" name="guess">

<input type="submit">

</form>

</body>

</html>

basename()

会返回路径重的文件名部分。比如/index.php/config.php使用basename()之后返回config.php。
basename()会去掉文件名开头的非ASCII值。

看到提示,有config.php目录,跳转一下看看。

得到

、

我们要想访问config,但是config.php被正则过滤了

本题目利用的是basename()漏洞

用不可显字符绕过正则(后面加 %80 -- %ff 的任意字符)

我们构造payload:/index.php/config.php/%ff?source

访问得到flag

相关推荐
大圣编蚕6 小时前
初探 NDK 的世界:从零开始理解 Android 原生开发
android
云贝贝贝6 小时前
MySQL 慢查询定位与索引优化实战
android
骑着蜗牛撵大象3277 小时前
服务下线不再炸:分层关闭、TCP 存活探测与负载均衡排水的落地套路
android·tcp/ip·负载均衡·tcp·高可用·健康检查·优雅关闭
三少爷的鞋9 小时前
别再这么写协程了!Marcin Moskała 剖析的 几个常见协程误区与重构
android
mmsx11 小时前
Android 防二次打包第一道锁:签名校验与完整性校验
android·kotlin
mmsx11 小时前
Android 混淆不等于安全:二次打包链路完整走一遍
android·kotlin
小宋102113 小时前
Agent轨迹级评测实战:工具选择、预算超限与回归门禁
android·网络·人工智能·回归
墨天梦15 小时前
D05_ViewModel与单向数据流
android·kotlin
蒸鱼Yuzheng16 小时前
Android 构建可复现性:APK 指纹、文件级差异与供应链审计
android·apk·devops·软件供应链·可复现构建
墨天梦18 小时前
D03_Compose列表与稳定身份
android·gitee·kotlin