WebD0n't pl4y g4m3!!! -FIX访问p0p.php 提示有hint.zip 下载后有尊嘟语,找个在线解码,提示了flag的位置人类语言与尊嘟语的转换器: https://zdjd.vercel.app/PHP/7.4.21 存在源码泄漏存在反序列化利用,构造利用链 直接读flagclass Yang{ public $now=array("YCB1"=>"show_source"); public function __call($name, $ary) { echo $name; if ($this->key === true || $this->finish1->name) { if ($this->finish->finish) { echo "\n"; var_dump($name); var_dump($this->now); echo $this->now[$name]; echo $ary[0]; call_user_func($this->now[$name], $ary[0]); } } } public function ycb() { echo "\n"; echo "
………………………………