http://111.198.29.45:59603/index.phps(用御剑扫)
源码泄漏
<?php
if("admin"===$_GET[id]) {
echo("<p>not allowed!</p>");
exit();
}
$_GET[id] = urldecode($_GET[id]);
if($_GET[id] == "admin")
{
echo "<p>Access granted!</p>";
echo "<p>Key: xxxxxxx </p>";
}
?>
要使"admin"===$_GET[id]不成立
id!=admin
传入的时候解了一次码,代码中又解了一次
查表d对应%64,再编码一次%2564
http://111.198.29.45:59603/index.php/?id=a%2564min