Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

检测 PHP 文件上传是否成功的例子代码存在问题 #109

Merged
merged 1 commit into from
Sep 19, 2016

Conversation

harnnless
Copy link
Contributor

如果%s不加引号,并且randomStr()生成的随机字符串是数字开头,则md5会失败。文件上传成功但验证失败,则上传的文件没有自动删除。所以以前用到这种方式的poc都要检查修正一下。

如果%s不加引号,并且randomStr()生成的随机字符串是数字开头,则md5会失败。文件上传成功但验证失败,则上传的文件没有自动删除。所以以前用到这种方式的poc都要检查修正一下。
@nixawk
Copy link
Contributor

nixawk commented Aug 13, 2016

Thanks @harnnless . Could you show us the console errors ?

@harnnless
Copy link
Contributor Author

token 是随机生成的
success

token为数字1开头会失败,如果加上引号就没关系。pocsuite里的webshell没这个问题,只是例子代码没加引号而已。
fail

@nixawk nixawk merged commit ee7c7da into knownsec:dev Sep 19, 2016
@harnnless harnnless deleted the patch-1 branch September 19, 2016 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants