php高危
yes 需要 no 不需要
文件类型操作
- file() 函数读取整个文件
- fgets() 读取一行数据
- fgetc() 读取一个字符
- fwrite()函数 可以进行文件写入操作
- file_put_contentt()函数 可以对文件进行写入操作
- file_get_contents()函数 可以进行读取文件 yes
- unlink() 函数 进行文件的删除
- rmdir() 直接删除一个目录
- tempanam() 创建一个临时文件
- tmofile() 创建一个临时文件
- fopen() 函数 打开或者远程读取一个url
- readfile() 输出一个文件
- fread() 读取里面文件,no
- rename 重命名一个文件
- fputs 文件上传类似于fwrite
其他
目录遍历
opendir()
readdir()
closedir()
- 函数都会导致一个目录遍历
命令执行函数
- exec() 函数 执行命令 yes
- system() 函数 no
- shell_exec() 函数 执行命令 yes
- passthru()函数 执行命令类似于exec no
- preg_replace()函数 执行命令但是需要/e模式
- escapeshellcmd()函数
- popen() 此函数需要写入一个文本当中 > D:/1.txt’, ‘r’ ); ?>
- proc_open()
- pcntl_exec() 也是写入一个文件当中pcntl_exec( “/bin/bash” , array(“whoami”));
- create_funtion()
- array_map()
文件包含
- require()
- include()
- require_once()
- include_once()
SSRF漏洞
- curl_exec()
- file_get_content() 在内容当中参数可控可以进行SSRF漏洞读取
- fopen()
- fsockopen()
变量覆盖
- $$
反序列化
- unserialize反序列化函数,参数可控,存在可利用类和魔术方法
- serialize
文件下载
- header(‘Content-Disposition: attachment; filename=’.$filename);
URL跳转
- header(“Location:
XML外部实体加载
- PHP XML解析函数
- simplexml_load_file
- simplexml_load_string
- SimpleXMLElement
- DOMDocument
- xml_parse
正则表达式小技巧
- file_get_contents($this->([a-zA-Z0-9]+)
- 适用于pop链分析
文件上传
$_file[‘file’][‘name’] 客户端上传的原名称
$_file[‘file’][‘type’] 文件·类型
$_file[‘file’][‘size’] 文件大小
$_file[‘file’][‘tmp_name’] 文件上传之后在服务器临时存储的名称
$_file[‘file’][‘error’] 上传之后产生的错误代码
- 最终 move_upload_file 进行文件移动
php高危
http://example.com/2025/10/27/php高危/