PHP文件上传绕过疑问:双扩展名文件为何无法被解析为PHP
PHP文件上传绕过:双扩展名文件无法执行的问题
我正在学习PHP文件上传绕过机制,涉及扩展名绕过、MIME类型绕过、添加魔术字节等技术。我用下面这段验证扩展名的脚本做测试:
if ($_SERVER['REQUEST_METHOD'] == 'POST') { $target_dir = "uploads/"; $target_file = $target_dir . basename($_FILES["file"]["name"]); $imageFileType = strtolower(pathinfo($target_file, PATHINFO_EXTENSION)); $check = getimagesize($_FILES["file"]["tmp_name"]); $allowedTypes = ['jpg', 'jpeg', 'gif', 'png']; print_r($imageFileType); echo "Response: ". in_array($imageFileType, $allowedTypes); if (in_array($imageFileType, $allowedTypes)) { if (move_uploaded_file($_FILES["file"]["tmp_name"], $target_file)) { echo "file=" . urlencode($target_file); } else { http_response_code(500); echo "Sorry, there was an error uploading your file."; } } else { http_response_code(400); echo "File is not an image or not allowed."; } }
测试过程如下:
- 上传PNG文件可以正常完成,但普通PHP文件无法上传;
- 给PHP文件添加魔术字节后还是传不上去,因为脚本只验证扩展名;
- 加了魔术字节,把文件名改成
hello.php.png后成功上传,但访问localhost/hello.php.png时,文件还是被当作PNG渲染,没有执行PHP代码。
我看教程里这种双扩展名文件会被当作PHP执行,请问我到底遗漏了什么环节?
内容的提问来源于stack exchange,提问作者Johnny
相关产品推荐
相关产品推荐

