After testing, this method kills ASP and aspx versions and is not applicable to PhP.
Many previous methods, such as uploading files of *. asp and creating directories such as *. asp ......
Today I met a fck Editor, which is the same as many times before.
Creating directories such as *. asp and *. php is fruitless. Uploading files such as * .asp;.jpg is fruitless.
The following is a mistaken method. I don't know if the black scalpers are released.
The following addresses are still used:
Http://www.somboy.com/fckeditor/editor/filemanager/connectors/test.html
Exploitation process:
1. Enter *. asp and other directory files in current folder, and enter the files as needed. Click Create folder to create a directory. Enter the directory name as needed.
2. Upload a Trojan horse in JPG format.
3. After the exploitation is completed, you can directly access the trojan address in one sentence and click the kitchen knife link.