The site fell due to many reasons!
1. This is the site. Although I don't know what the mobile bidding procurement management system is, it looks very good.
Http://rat.lenovomobile.com
2. the admin password is weak. log on to cs1/cs1 directly. You need to change the password. Otherwise, it will be rolled out after the announcement.
3.product overview here, you can upload an image file. The verification is done on the client side. Uploading a file test.jpg can be successful, but uploading the file test. asp is rejected!
4. Run the burp suitecommand and submit it again in the repeater. This time, the original test.jpg is changed to test. asp to upload a bird.
5. The returned information contains the address saved after upload. It's time to go to the kitchen knife.
6. There are a lot of services that can be enabled. Remote Desktop 3389 is also enabled. Do I want to connect to it? Forget it. I am a good guy. This is not what I should do.
7. This is the end. In addition, this site is too fragile and there are injection holes!
Solution:
We recommend that you deprecate the site for rectification first. asp sites will be rotated in!
I am a good guy!