image.png
    robots.txt 提示 /src/code/code.txt
    打开后显示源码:

    1. <?php
    2. if (isset ($_GET['password'])) {
    3. if (preg_match ("/^[a-zA-Z0-9]+$/", $_GET['password']) === FALSE)
    4. {
    5. echo '<p>You password must be alphanumeric</p>';
    6. }
    7. else if (strlen($_GET['password']) < 8 && $_GET['password'] > 9999999)
    8. {
    9. if (strpos ($_GET['password'], '*-*') !== FALSE)
    10. {
    11. die('Flag: ' . $flag);
    12. }
    13. else
    14. {
    15. echo('<p>*-* have not been found</p>');
    16. }
    17. }
    18. else
    19. {
    20. echo '<p>Invalid password</p>';
    21. }
    22. }
    23. ?>

    看见数字比大小直接科学计数法绕过