웹찢남

Giant-writeup 본문

WEB_HACKING/los.rubiya.kr

Giant-writeup

harry595 2019. 12. 27. 21:36

<?php 
  
include "./config.php"
  
login_chk(); 
  
$db dbconnect(); 
  if(
strlen($_GET[shit])>1) exit("No Hack ~_~"); 
  if(
preg_match('/ |\n|\r|\t/i'$_GET[shit])) exit("HeHe"); 
  
$query "select 1234 from{$_GET[shit]}prob_giant where 1"
  echo 
"<hr>query : <strong>{$query}</strong><hr><br>"
  
$result = @mysqli_fetch_array(mysqli_query($db,$query)); 
  if(
$result[1234]) solve("giant"); 
  
highlight_file(__FILE__); 
?>

 

공백을 만들면 끝나는 문제다

%0b를 사용해 clear!!

'WEB_HACKING > los.rubiya.kr' 카테고리의 다른 글

Succubus-writeup  (0) 2019.12.28
Assassin-writeup  (0) 2019.12.27
Bugbear-writeup  (0) 2019.12.27
Darkknight-writeup  (0) 2019.12.27
Golem-writeup  (0) 2019.12.27
Comments