萌新web1

萌新web1

 

 We notice that it's related to bypassing. 

The below annotation reminds us that the true id is 1000, so we need bypass the function intval(). 

萌新web1

 

 In order to make SQL query successful, we could use hex string '0x3e8' to bypass the constraint. 

The function intval() will return 0 when you upload the above value by GET method. 

萌新web1

 

Noteworthily, the parameter $_GET['id'] is a string type, if not, for example, intval(0x3e8) will return integer 1000 cuz intval() will decode the hex value to decimal as the prefix '0x'. 

 

上一篇:dom


下一篇:CTFSHOW-PHP特性