[10617] 2016-10-18_注意了,使用Sqlmap的你可能踩中了“蜜罐”

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2016-10-18_注意了,使用Sqlmap的你可能踩中了“蜜罐” 使 S q l m a p   F r e e B u f   2 0 1 6 - 1 0 - 1 8 *   F r e e B u f   P a r 0 P a r 1 L i n u x s q l m a p o r s h e l l b a s h b a s h 使 B a s h b a s h L i n u x p i n g   ! ! , p i n g   ` r e b o o t ` ! ! ! + h i s t o r y , ! h t t p ! ! w e b s e r v e r w e b s e r v e r b a s h B a s h # s q l m a p   u   " h t t p : / / s a m p l e . c o m / a = x x x & b = x x x "   d a t a   " p o s t d a t a " B a s h # p y t h o n   s q l m a p . p y   u   " h t t p : / / s a m p l e . c o m / a = x x x & b = x x x "   c o o k i e   " c o o k e d a t a " b a s h #   s q l m a p   - u   " w w w . a s n i n e . c o m / t e s t "   - - d a t a " p o s t ! ! r e q u e s t = h a c k e d "
` ( 1 ) ` r e b o o t ( !   ,   ` ) g e t / p o s t / c o o k i e h t t p s q l m a p h t t p   p o s t B I P a r 2 s q l m a p   h o n e y p o t h t t p ! ,   ` h t t p h t t p g e t   r e q u e s t , c o o k i e , p o s t   r e q u e s t p o s t s q l p o s t p o s t s q l m a p d a t a p o s t   d a t a B u r p   S u i t e s q l m a p 使 f o r m e n c t y p e = t e x t / p l a i n 访 p o s t d a t a s q l m a p B o o m P a r 3 姿 姿 b a s h s q l m a p   u   " h t t p : / / s a m p l e . c o m / a = x x x & b = x x x "   d a t a   " e v i l c o d e "
使 L i n u x ( | ) ( ) 使 D o u b l e   K i l l P a r 4 c o o k i e s q l m a p b a s h 使 s q l m a p ( g e t / p o s t / c o o k i e ) s q l m a p 使 b a s h s q l m a p L i n u x S q l m a p D o n e ! *   F r e e B u f b a s h #   e x e c   " e v i l   c o d e " " | r e b o o t "   ( ) b a s h #   e x e c   " " | r e b o o t " " ' | r e b o o t ' " ! + n u m b e r "
 
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则