Use of third-party software to-FLASHFXP rights

Source: Internet
Author: User

Lecturer: Deadwood _soul


Power Environment: Windows 2003


Using tools: ASP environment, Shell one


The right idea: the use of FLASHFXP replacement file vulnerability, you can read the Administrator link to the site account password.


This is my starting in the spring and autumn.


1.Flash FXP Introduction


The FLASHFXP is a powerful FXP /ftp software, which integrates the advantages of other excellent FTP software, such as cuteftp 's directory comparison, support color text display, such as BPFTP support multiple directory selection files, staging directory, and LEAPFTP interface design.


2. Specific process


Here is the FTP software I installed in win03, there is nothing inside





Jianxin a link



650) this.width=650; "id=" aimg_11742 "src=" http://bbs.ichunqiu.com/data/attachment/forum/201606/10/ 131810czbbbffppt7p7few.png "class=" Zoom "width=" "alt=" 131810czbbbffppt7p7few.png "/>"




The linked account password is stored in the Quick.dat file.




650) this.width=650; "id=" aimg_11744 "src=" http://bbs.ichunqiu.com/data/attachment/forum/201606/10/ 132006t9ul4gt7tidtitgx.png "class=" Zoom "width=" "alt=" 132006t9ul4gt7tidtitgx.png "/>



Next Open the Webshell we got, download Quick.dat this file


650) this.width=650; "id=" aimg_11745 "src=" http://bbs.ichunqiu.com/ Data/attachment/forum/201606/10/132111whzrdo9roddog2rt.png "class=" Zoom "width=" "alt=" 132111whzrdo9roddog2rt.png "/>

650) this.width=650," id= "aimg_11746" src= "http://bbs.ichunqiu.com/data/ Attachment/forum/201606/10/132146mh0iyy41a11ixf42.png "class=" Zoom "width=" "alt=" 132146mh0iyy41a11ixf42.png "/

after downloading, open our native flashftp to replace the original file. Turn on the native software, view the history, the miracle thing happened ...


650) this.width=650; "id=" aimg_11747 "src=" http:/ Bbs.ichunqiu.com/data/attachment/forum/201606/10/132355esls62lgh9lwzl7s.png "class=" Zoom "width=" "alt=" 132355esls62lgh9lwzl7s.png "/>

Give us a little tip:
So you get a permission, you can go online to download an asterisk password viewer, here I do not show.


This article is from the "Deadwood Technology Blog" blog, please be sure to keep this source http://xmusec.blog.51cto.com/11702349/1787815

Use of third-party software to-FLASHFXP rights

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.