iwebsec

此网站中集合了SQL注入、文件包含、命令执行、XXE、反序列化、SSRF、XSS、文件上传等常见的web漏洞环境

反序列化漏洞

反序列化漏洞

/index.php?re=hello

<?php

  
require_once('../../header.php');
  
?>
<html>
    <head>
        <title>反序列化漏洞</title>
    </head>
    <h2>反序列化漏洞</h2>
        <div class="alert alert-success">
            <p>/index.php?re=hello </p>
        </div>
    <body>
<?php
    highlight_file
(__FILE__);
    class 
a {
        var 
$test = 'hello';
        function 
__destruct(){
            
$fp = fopen("/var/www/html/unserialize/01/hello.php","w");
            
fputs($fp,$this->test);
            
fclose($fp);
        }
    }
    
$class = stripslashes($_GET['re']);
    
$class_unser = unserialize($class);
    require 
'/var/www/html/unserialize/01/hello.php';
    require_once 
'../../footer.php';
?>


( ! ) Warning: system() [<a href='function.system'>function.system</a>]: Cannot execute a blank command in /var/www/html/unserialize/01/hello.php on line 1
Call Stack
#TimeMemoryFunctionLocation
10.001195584{main}( )../index.php:0
20.002198232require( '/var/www/html/unserialize/01/hello.php' )../index.php:26
30.002198312system ( )../hello.php:1