您的位置:首页 > 其它

SniperOJ-CTF练习-web

2017-07-31 08:46 1186 查看
PHP weak type(50)

查看源码

I love vim~

那就是vim的备份文件了 访问index.php~

得到源码

<?php
$flag = 'SniperOJ{********************}';

if(isset($_POST['password'])){
$current_password = "QNKCDZO";
$password = $_POST['password'];
if (($current_password != $password)){
$current_password_md5 = md5($current_password);
$password_md5 = md5($password);
if($current_password_md5 == $password_md5){
echo '<script>alert("You know php well!")</script>';
echo $flag;
}else{
echo('<script>alert("Your password is wrong!")</script>');
}
}else{
echo('<script>alert("Your password is wrong!")</script>');
}
}else{
echo('<script>alert("Input your password!")</script>');
}
?>


md5弱类型,

PHP: md5(‘240610708’) == md5(‘QNKCDZO’)

那就POST这个呗!

弹出You know php well!然后就看到flag了。

SniperOJ{pHp_is_the_best_programming_language_in_the_world}
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: