upload-labs第九关教程 一、源代码分析 代码审计 ::$DATA介绍 二、绕过分析 特殊字符::$data绕过 上传eval.php 使用burpsuite抓包进行修改 放包,查看是否上传成功 使用中国蚁剑进行连接 一、源代码分析 代码审计 $is_upload = false; $msg = null; if (isset($_POST['submit'])) { if (file_exists(UPLOAD_PATH)) { $deny_ext = array(".php",".php5",".php4",".php3",".php2",".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",".Html"