웹찢남

Vampire-writeup 본문

WEB_HACKING/los.rubiya.kr

Vampire-writeup

harry595 2019. 12. 27. 21:10


<?php 
  
include "./config.php"
  
login_chk(); 
  
$db dbconnect(); 
  if(
preg_match('/\'/i'$_GET[id])) exit("No Hack ~_~");
  
$_GET[id] = strtolower($_GET[id]);
  
$_GET[id] = str_replace("admin","",$_GET[id]); 
  
$query "select id from prob_vampire where id='{$_GET[id]}'"
  echo 
"<hr>query : <strong>{$query}</strong><hr><br>"
  
$result = @mysqli_fetch_array(mysqli_query($db,$query)); 
  if(
$result['id'] == 'admin'solve("vampire"); 
  
highlight_file(__FILE__); 
?>

 

admin을 preg_match가아닌 replace를 사용한다

이러면 id=adadminmin 이런식으로 하면 id=admin이 된다

 

'WEB_HACKING > los.rubiya.kr' 카테고리의 다른 글

Golem-writeup  (0) 2019.12.27
Skeleton-writeup  (0) 2019.12.27
Troll-writeup  (0) 2019.12.27
Orge - writeup  (0) 2019.12.27
Darkelf-writeup  (0) 2019.12.27
Comments