zoukankan      html  css  js  c++  java
  • PHP代码审计-File Inclusion-dvwa靶场

    low

    <!DOCTYPE html>
    <html>
    <head>
    	<title></title>
    </head>
    <body>
    <div class="vulnerable_code_area">
    		<em><a href="?page=file1.php">file1.php</a></em>
    		<em><a href="?page=file2.php">file2.php</a></em>
    		<em><a href="?page=file3.php">file3.php</a></em>
    </div>
    </body>
    </html>
    
    <?php
    $file = $_GET['page'];
    if(isset($file)){
    	include($file);
    }
    ?>
    

    medium

    <!DOCTYPE html>
    <html>
    <head>
    	<title></title>
    </head>
    <body>
    <div class="vulnerable_code_area">
    		<em><a href="?page=file1.php">file1.php</a></em>
    		<em><a href="?page=file2.php">file2.php</a></em>
    		<em><a href="?page=file3.php">file3.php</a></em>
    </div>
    </body>
    </html>
    <?php
    $file = $_GET['page'];
    $file = str_replace(array("https://","http://"), "", $file);
    $file = str_replace(array("../","./"), "", $file);
    echo $file;
    if(isset($file)){
    	include($file);
    }
    ?>
    

    high

    <!DOCTYPE html>
    <html>
    <head>
    	<title></title>
    </head>
    <body>
    <div class="vulnerable_code_area">
    		<em><a href="?page=file1.php">file1.php</a></em>
    		<em><a href="?page=file2.php">file2.php</a></em>
    		<em><a href="?page=file3.php">file3.php</a></em>
    </div>
    </body>
    </html>
    <?php
    $file = $_GET['page'];
    if(!(fnmatch("file*", $file)) && $file !="include.php"){
    	echo "ERROR file not found!";
    }else{
    	include($file);
    }
    ?>
    

    PHP知识点

    fnmatch() 函数根据指定的模式来匹配文件名或字符串。
    
  • 相关阅读:
    java 基础笔记 基本数据类型对象包装类
    java String 类 基础笔记
    java 线程 笔记 基础
    java 线程 基础笔记2
    java 异常学习 笔记
    广告简单概念整理-持续更新
    curl一些使用技巧
    简单学习正则表达式
    Linux命令简单操作之lsof
    Linux命令简单操作之find和xargs
  • 原文地址:https://www.cnblogs.com/renhaoblog/p/14325596.html
Copyright © 2011-2022 走看看