文件上传-Windows点空格点绕过

[题目信息]:

题目名称 题目难度
文件上传-Windows点空格点绕过 1

[题目考点]:

Windowsw文件特性考察

[Flag格式]:

SangFor{UDOaJfziTs4c-dceIyGxa53-Ybrg9dtF}

[环境部署]:

docker-compose.yml文件或者docker tar原始文件。

docker-compose up -d

[题目writeup]:

1、实验主页

2、使用dirsearch扫描备份文件;

扫描到index.txt备份文件;

修改Url地址内容,将index.txt修改为indeX.txt;发现可以成功访问;

证明服务端服务器是Linux系统;

3、代码分析

<?php
include "config.php";
function deldot($s){
    for($i = strlen($s)-1;$i>0;$i--){
        $c = substr($s,$i,1);
        if($i == strlen($s)-1 and $c != '.'){
            return $s;
        }

`if($c != '.'){ return substr($s,0,$i+1); } } `

}

$is_upload = false;
$msg = null;
if (isset($_POST['submit'])) {
if (file_exists(UPLOAD_PATH)) {
$deny_ext = array(".php",".php5",".php4",".php3",".php2",".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",".Html",".Htm",".pHtml",".jsp",".jspa",".jspx",".jsw",".jsv",".jspf",".jtml",".jSp",".jSpx",".jSpa",".jSw",".jSv",".jSpf",".jHtml",".asp",".aspx",".asa",".asax",".ascx",".ashx",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",".aScx",".aShx",".aSmx",".cEr",".sWf",".swf",".htaccess");
$file_name = trim($_FILES['upload_file']['name']);
$file_name = deldot($file_name);//删除文件名末尾的点 #1
$file_ext = strrchr($file_name, '.');
$file_ext = strtolower($file_ext); //转换为小写 #2
$file_ext = str_ireplace('::$DATA', '', $file_ext);//去除字符串::$DATA #3
$file_ext = trim($file_ext); //首尾去空 #4

`    if (!in_array($file_ext, $deny_ext)) {
        $temp_file = $_FILES['upload_file']['tmp_name'];
        $img_path = UPLOAD_PATH.'/'.$file_name;
        if (move_uploaded_file($temp_file, $img_path)) {
            $is_upload = true;
        } else {
            echo $msg = '上传出错!';
        }
    } else {
        echo $msg = '此文件类型不允许上传!';
    }
} else {
    echo $msg = UPLOAD_PATH . '文件夹不存在,请手工创建!';
}
`

}
?>

  1. #1处删除末尾的点;
  2. #2处将上传的文件名转换为小写;
  3. #3处如果上传文件后缀包含::$DATA,会替换为空;
  4. #4处去除前后空格;

那么前面所述的4种Windows绕过方案均无法使用;

但是假设我们上传的文件后缀为.php. .(php点号空格点号)

#1删除点号,剩余点号空格,#4删除空格,剩余点号,那么php.可以绕过黑名单验证;

3、上传jpg文件进行抓包;

抓包之后修改文件后缀为.php进行测试;

修改文件后缀为. .(点空格点)

证明该文件已经上传成功

访问upload/1.php

php文件成功解析;

相关推荐
逆鱼_045 分钟前
Unix-进程和线程
java·服务器·unix
总是学不会.8 分钟前
EasyExcel 实践案例:打印工资条
java·开发
m0_7482507416 分钟前
Spring Boot 多数据源解决方案:dynamic-datasource-spring-boot-starter 的奥秘(上)
java·spring boot·后端
quo-te1 小时前
【JavaWeb学习Day19】
java·spring·maven·mybatis
m0_748244961 小时前
2024 JAVA面试题
java·开发语言·python
终端行者1 小时前
k8s使用containerd作为容器运行时配置Harbor私有仓库与阿里云私有仓库以及镜像加速器,k8s基于containerd如何配置harbor私有仓库
阿里云·容器·kubernetes
JiaJunRun1 小时前
Java Collections工具类面试题
java·开发语言·windows·学习·安全
澄江静如练_1 小时前
小程序高度问题&背景scss
java·前端·小程序
27669582921 小时前
快手弹幕 websocket 分析
java·python·websocket·go·快手·快手弹幕·ks
阿湯哥1 小时前
再论Spring MVC中Filter和HandlerInterceptor的优先级
java·spring·mvc