upload 1-21通关
Pass-01(前端验证)
将含一句话木马的文件修改为jpg后缀,上传并在burp中抓包,将图中所示位置由jpg改为php后放行,复制图片链接到蚁剑可以成功连接
Pass-02(MIME验证)
修改content-type为image/jpeg,image/png,image/gif任意一种均可
Pass-03(php3,phtml绕过黑名单)
本pass禁止上传.asp|.aspx|.php|.jsp后缀文件!
可以用php3,php5,phtml等绕过
在Apache的httpd.conf中查找addtype,找到AddType application/x-httpd-php,删除注释符#,添加.php3 .php5等,重启php后生效,
上传php文件,burp抓包,修改filename为php3,php5等
连接蚁剑
Pass-04(.htaccess)
".php",".php5",".php4",".php3",".php2",".php1",".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",".pHp1",".Html",".Htm",".pHtml",".jsp",".jspa",".jspx",".jsw",".jsv",".jspf",".jtml",".jSp",".jSpx",".jSpa",".jSw",".jSv"