php高危

  • yes 需要 no 不需要

  • 文件类型操作

    • file() 函数读取整个文件
    • fgets() 读取一行数据
    • fgetc() 读取一个字符
    • fwrite()函数 可以进行文件写入操作
    • file_put_contentt()函数 可以对文件进行写入操作
    • file_get_contents()函数 可以进行读取文件 yes
    • unlink() 函数 进行文件的删除
    • rmdir() 直接删除一个目录
    • tempanam() 创建一个临时文件
    • tmofile() 创建一个临时文件
    • fopen() 函数 打开或者远程读取一个url
    • readfile() 输出一个文件
    • fread() 读取里面文件,no
    • rename 重命名一个文件
    • fputs 文件上传类似于fwrite
  • 其他

    • 目录遍历

      • opendir()

      • readdir()

      • closedir()

        • 函数都会导致一个目录遍历
  • 命令执行函数

    • exec() 函数 执行命令 yes
    • system() 函数 no
    • shell_exec() 函数 执行命令 yes
    • passthru()函数 执行命令类似于exec no
    • preg_replace()函数 执行命令但是需要/e模式
    • escapeshellcmd()函数
    • popen() 此函数需要写入一个文本当中 > D:/1.txt’, ‘r’ ); ?>
    • proc_open()
    • pcntl_exec() 也是写入一个文件当中pcntl_exec( “/bin/bash” , array(“whoami”));
    • create_funtion()
    • array_map()
  • 文件包含

    • require()
    • include()
    • require_once()
    • include_once()
  • SSRF漏洞

    • curl_exec()
    • file_get_content() 在内容当中参数可控可以进行SSRF漏洞读取
    • fopen()
    • fsockopen()
  • 变量覆盖

    • $$
  • 反序列化

    • unserialize反序列化函数,参数可控,存在可利用类和魔术方法
    • serialize
  • 文件下载

    • header(‘Content-Disposition: attachment; filename=’.$filename);
  • URL跳转

    • header(“Location:

http://www.baidu.com“)

  • XML外部实体加载

    • PHP XML解析函数
    • simplexml_load_file
    • simplexml_load_string
    • SimpleXMLElement
    • DOMDocument
    • xml_parse
  • 正则表达式小技巧

    • file_get_contents($this->([a-zA-Z0-9]+)
    • 适用于pop链分析
  • 文件上传

    • $_file[‘file’][‘name’] 客户端上传的原名称

    • $_file[‘file’][‘type’] 文件·类型

    • $_file[‘file’][‘size’] 文件大小

    • $_file[‘file’][‘tmp_name’] 文件上传之后在服务器临时存储的名称

    • $_file[‘file’][‘error’] 上传之后产生的错误代码

      • 最终 move_upload_file 进行文件移动

php高危
http://example.com/2025/10/27/php高危/
作者
Piggy Sprint
发布于
2025年10月27日
许可协议