[18545] 2021-04-12_记一次代码审计的APP渗透

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2021-04-12_记一次代码审计的APP渗透 A P P   R a i l g u n   H A C K   2 0 2 1 - 0 4 - 1 2 : 0 x 0 1   访
访 U A P C 访 c m s 2 1 8 8 8 8 s u n - a n s w e r b o o k B T 线 0 x 0 2  
2 1 3 3 8 9 0 x 0 3   0 x 3 . 1   e m m m c m s c m s n g i n x 0 x 3 . 2   访 / a d m i n - p a n e l / a u t o l o a d . p h p
a u t o l o a d . p h p p h p / a j a x . p h p ( a j a x p h p ) p a y l o a d : : h t t p : / / w w w . m y . c o m / a j a x . p h p ? t y p e = . . / a d m i n - p a n e l / a u t o l o a d & p a g e = m a n a g e - u s e r s
$ i s _ e r r o r 1 G E T h a s h C h e c k M a i n S e s s i o n t r u e ( p r i n t _ r ( ) ) S e c u r e ( ) C h e c k M a i n S e s s i o n ( ) t r u e $ h a s h _ i d $ _ S E S S I O N [ m a i n _ h a s h _ i d ] / a s s e t s / i n c l u d e s / f u n c t i o n _ g e r n e l . p h p m a i n _ h a s h _ i d 1 1 1 1 - 9 9 9 9 s h a 1 p y P y t h o n m a i n _ h a s h _ i d b u r p s u i t e
r e s p o n s e h a s h n o t i f i c a t i o n s h a s h : p a y l o a d : h t t p : / / w w w . m y . c o m / a j a x . p h p ? h a s h = 9 0 d 6 f f 0 d 9 3 5 b 8 3 1 6 9 1 5 5 f 1 3 6 5 1 0 5 2 2 4 7 d a 5 8 e 4 1 6 & t y p e = . . / a d m i n - p a n e l / a u t o l o a d & p a g e = m a n a g e - u s e r s
p h p f t p 访 s 3 ( f t p ) 0 x 3 . 3   / i n s t a l l / i n d e x . p h p
s q l c o n f i g . p h p m y s q l c m s 便 s q l g e t s h e l l u r l u r l p u r c h a r s e _ c o d e 便 : 访 / i n s t a l l n e x t 仿 访 : h t t p : / / w w w . m y . c o m / i n s t a l l / ? p a g e = i n s t a l l a t i o n
g e t s h e l l 0 x 3 . 3   R C E $ S e r v e r E r r o r s [ ] : u r l ( c h e c k _ ( ) s u c c e s s )
g e t s h e l l
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则