微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

Null Byte Injection

以前不知道,记下来。
Perl PHP Null Byte Injection

rain.forest.puppy outlined in Phrack issue 55 the uses of NUL Byte Injection within Perl,and how these Could be exploited. The results were very similar in PHP.

An example of a NULL byte vulnerable PHP script is as follows:

$file = $_GET['file'];
require_once("/var/www/$file.PHP");

While the above script appears to be secured by forcing the ".PHP" file extension,it Could be exploited as follows: @L_502_1@

The above NULL byte injection would result in the mandatory appended file extension (.PHP) to be dropped,and the /etc/passwd file to be loaded.

Perl PHP Null Byte Injection

rain.forest.puppy outlined in Phrack issue 55 the uses of NUL Byte Injection within Perl,and the /etc/passwd file to be loaded.

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 [email protected] 举报,一经查实,本站将立刻删除。

相关推荐