數組返回NULL繞過

來源:互聯網
上載者:User

標籤:div   自己   strpos   第一個   lock   pass   index.php   nbsp   span   

BUGKU:http://120.24.86.145:9009/19.php

還沒看完源碼,我就直接加了一個password[]=1結果就拿到flag了。然後再看源碼我自己都搞不懂為什麼可以得到源碼。真的,不信你看。

 1 <?php 2 $flag = "flag"; 3  4 if (isset ($_GET[‘password‘])) { 5 if (ereg ("^[a-zA-Z0-9]+$", $_GET[‘password‘]) === FALSE) 6 echo ‘You password must be alphanumeric‘; 7 else if (strpos ($_GET[‘password‘], ‘--‘) !== FALSE) 8 die(‘Flag: ‘ . $flag); 9 else10 echo ‘Invalid password‘;11 }12 ?>

先來談論一下標準的答案:

第一個條件:

    必須以數字或者字母開頭(其實看到ereg就可以想到%00截斷)

第二個條件:

    必須在password參數中找到--。

所以得出以下正解:

index.php?password=a%00--

那麼話又說回來了,為什麼直接password[]=a就可以繞過呢?

1.ereg只能處理字元,而你是數組,所以返回的是null,三個等號的時候不會進行類型轉換。所以null不等於false。

2.strpos的參數同樣不能夠是數組,所以返回的依舊是null,null不等於false也是正確。

所以可以拿到flag

小結:

  1.倘若函數的參數不符合其函數要求的時候返回的是null值

數組返回NULL繞過

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.