,比Pass-01多了个对MIME的检测,但对于上传图片码来说就没啥区别
Pass-03
查看源码
image.png
后台进行了黑名单限制,但是黑名单不完整,常见的可执行PHP文件的后缀:
php2...,".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",".Html",".Htm",".pHtml",".jsp"...,".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",".Html",".Htm",".pHtml",".jsp"...upload
image.png
7z后缀并不被Apache服务器所识别,却在上传文件名后缀的白名单中,可以利用Apache的解析漏洞将上传的7z后缀文件当做php文件解析
image.png...环境下.会被默认去掉