php弱类型绕过
php弱类型绕过
1 | '' == 0 == false |
例题
secretjson
页面源码
<?php
include_once 'secret.php'; // $flag $key
if (isset($_POST['message'])) {
$message = json_decode($_POST['message']);
if ($message->key == $key) {
echo $flag;
}
else {
echo "fail";
}
}
else show_source(__FILE__);
?>
post –> message={“key”:true} 即可获取flag