[SUCTF 2019]EasyWeb --- no parameter RCE

SUCTF 2019]EasyWeb Test site: No alphanumeric shellUse htaccess upload fileBypass open_basedir Source code audit <?php function get_the_flag(){ // web admin will remove your upload file every 20 min!!!! $userdir = "upload/tmp_".md5($_SERVER['REMOTE_ADDR']); //Naming format (upload/tmp_md5(ip)) if(!file_exists($userdir)){ ...

Posted by chintupintu03 on Sat, 29 Jan 2022 01:15:05 +0100