An inspection of China Security Information Network (the Administrator has fixed the vulnerability)

Source: Internet
Author: User

By: Qingtian Xiaozhu

Look at the side station, it's all his sub-domain name.

The source code of the main site is fengxun 4.0, which does not have 0 days. You can only view the side station ~!

A

It shows that the main site is not built, so I thought that since there is no construction, his settings are all the original default? Well, let's look at the source code.

Oh, it's 08cms. The administrators I 've studied have several default 08cms 08cms and admin08cms & admin08cms (it looks like the webshell left on the official website-.-|)

Two tests, RP full line!

There are several Breakthrough points in getting shell in the background:

1. attachments can be set by yourself (php Upload is expected)

2. SQL export is available (the path is expected to be known)

I thought the shell could be used successfully, but it happened again ~

The suffix name has changed to 23143316a7c1c87ef78724. _ php

This is depressing. I tried asp asa aspx and all of them failed. It seems that the source code is restricted?

You can only export the test results using SQL. The next task is to find the path.

The path where the database is imported can be exposed:

When the database is randomly imported, the path will pop up.

Now that you know the path, MYSQL exports a sentence immediately,

Just export a single sentence connection.

 

 

If the permission is large, it is OK to directly cross-directory.

Privilege Escalation makes it easier to locate the SA and ROOT direct KO!

This article is over. It is very important to find a solution to solve any technical problems ~!!!

The website administrator has fixed the vulnerability.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.