随笔分类 -  WAF绕过

摘要:PHP internally uses parse_str() to parse parameters so it sees the char "[" & "_" as the same. PHP by default will use the last param as valid. In cas 阅读全文
posted @ 2021-10-07 15:37 竹子与熊猫 阅读(71) 评论(0) 推荐(0)