网鼎杯网络安全大赛玄武组-SSRFME题
index.php可绕过本地条件判断,以下是源码:
>24 == $int_ip>>24 || ip2long('10.0.0.0')>>24 == $int_ip>>24 || ip2long('172.16.0.0')>>20 == $int_ip>>20 || ip2long('192.168.0.0')>>16 == $int_ip>>16;}function safe_request_url($url){ if (check_inner_ip($url)) { echo $url.' is inner ip&
来源地址:https://blog.csdn.net/yetaodiao/article/details/127638696