Address: http://202.120.7.134:8888/html/array.php
Participate in the ISG (Information Security Competition) found a topic.
As a phper, meow I really feel this code no solution ah ...
Ask the big God to dispel doubts, how to give a user parameter, get to $flag ...
Update at 2015/20/22
Finally, through the "invitation to answer" to find the great God ~
The flaw is that PHP's array subscript is a bug that can take advantage of "integer Overflow" ...
You can refer to this:
https://bugs.php.net/bug.php?id=69892
I think the use of the bug to make a question, is simply ...
The game has been over, determined to write down their own code:
测试效果:
测试地址:
http://moonlordapi.sinaapp.com/1.php
补充,参数可以有好几种方式:
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[4294967297]=1445502008
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[]=1445502008
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[1]=1445502008
就此愉快地结题了。
Reply content:
Address: http://202.120.7.134:8888/html/array.php
Participate in the ISG (Information Security Competition) found a topic.
As a phper, meow I really feel this code no solution ah ...
Ask the big God to dispel doubts, how to give a user parameter, get to $flag ...
Update at 2015/20/22
Finally, through the "invitation to answer" to find the great God ~
The flaw is that PHP's array subscript is a bug that can take advantage of "integer Overflow" ...
You can refer to this:
https://bugs.php.net/bug.php?id=69892
I think the use of the bug to make a question, is simply ...
The game has been over, determined to write down their own code:
测试效果:
测试地址:
http://moonlordapi.sinaapp.com/1.php
补充,参数可以有好几种方式:
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[4294967297]=1445502008
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[]=1445502008
http://moonlordapi.sinaapp.com/1.php?user[4294967296]=admin&user[1]=1445502008
就此愉快地结题了。
Consulted my safe, great God classmate He said 0 can be bypassed by an integer overflow if judgment
Upstairs positive solution ....