当前位置:网站首页>[BSidesCF 2020] Had a bad day1
[BSidesCF 2020] Had a bad day1
2022-08-08 06:37:00 【Joker..】
Knowledge point: nesting of pseudo-protocols

There are two pictures when you click, but here you should pay attention that when you click on the picture, the URL will pass in a variable
![]()
I tried template injection and found that it was not, and then directly constructing a sentence Trojan found that it was not enough, but when you open the picture and add a letter after the incoming variable, you will find that php is automatically added

Try to open index.php with a pseudo protocol, but php does not need to be added because it will be added automatically

Decrypt the base64 and get the php code
You can see that the variable must contain one of the three. At this time, you need to use the nesting of the pseudo-protocol
payload: /index.php?category=php://filter/read=convert.base64-encode/index/resource=flag
Or add to the front
/index.php?category=php://filter/read=index/convert.base64-encode/resource=flag

Decode to get

边栏推荐
- 有哪些可以“躺平”的技术开发岗位?------音视频开发畅谈
- 使用XGboost进行分类,判断该患者是否患有糖尿病
- vim 快捷键大全和插件大全
- 学习go语言,你要遵循什么样的学习路径才能学明白?
- 2021 mathematical modeling national competition question B
- 终于搞懂了 super(XXXX, self).__init__()的作用是啥了
- from sklearn import cross_validation 报错的解决方法
- 消费品行业报告:化妆品容器市场现状研究分析与发展前景预测
- YoloV4训练自己的数据集(六)之Yolo -Tiny
- UXDB丢失了数据库密码,如何恢复?
猜你喜欢
随机推荐
10道集合框架面试题(含解析),来看看你会多少
我的第一篇博客
聊一聊数据库中的锁
节流与防抖
有哪些可以“躺平”的技术开发岗位?------音视频开发畅谈
课堂作业--凯撒加密
CUDA10安装支持gpu的tensorflow版本
tf.train.MonitoredTrainingSession 控制 checkpoint 保存数量
使用XGboost进行分类,判断该患者是否患有糖尿病
Scrapy爬虫框架详解-----全面详解
Graphical LeetCode - 636. Exclusive Time of Functions (Difficulty: Moderate)
最完整的分布式架构设计图谱
JS截取字符串最后一个字符,截取“,”逗号前面字符,赋值集合
scikit-learn随机数据生成实例
分布式系统设计之高可用大全
遥远的救世主
化工行业现状分析:聚烯烃市场消费量近2亿吨
摔倒检测综述
图像融合简介
Neo4j service configuration








