[网络安全 CTF] BUUCTF极客大挑战2019PHP解题详析(Dirsearch使用实例+php反序列化)_[极客大挑战 2019]php

    

Get传参传入一个参数select,后端将其序列化

class.php:

username = $username;
        $this->password = $password;
    }

    function \_\_wakeup(){
        $this->username = 'guest';
    }

    function \_\_destruct(){
        if ($this->password != 100) {
            echo "
NO!!!hacker!!!
"; echo "You name is: "; echo $this->username;echo "
"; echo "You password is: "; echo $this->password;echo "
";

你可能感兴趣的:(程序员,web安全,php,服务器)