DASCTF Jul.2023
Web
MyPicDisk
0x00 获取源代码
admin' 1=1#登录成功!
you are not admin!!!!!<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>MyPicDisk</title>
</head>
<body>
<script>alert('you are not admin!!!!!');</script><script>location.href='/index.php';</script><!-- /y0u_cant_find_1t.zip -->
<form action="index.php" method="post" enctype="multipart/form-data">
选择图片:<input type="file" name="file" id="">
<input type="submit" value="上传"></form>
</body>
</html>0x01 代码逻辑
0x02 解题逻辑
0x03 构造反序列化
Last updated