[SUCTF 2019]EasyWeb --- no parameter RCE
SUCTF 2019]EasyWeb
Test site:
No alphanumeric shellUse htaccess upload fileBypass open_basedir Source code audit
<?php
function get_the_flag(){
// web admin will remove your upload file every 20 min!!!!
$userdir = "upload/tmp_".md5($_SERVER['REMOTE_ADDR']); //Naming format (upload/tmp_md5(ip))
if(!file_exists($userdir)){ ...
Posted by chintupintu03 on Sat, 29 Jan 2022 01:15:05 +0100