Hi.baidu.com/cncxz
Today, I accidentally browsed the website of a high school in my hometown and turned it around.
"Background management" is directly available at the bottom of the page. Click to enter directly
The background address is
Http://www.xxxxx.net/xyadmin/login.asp
I guessed the database and found that http://www.xxxxx.net/xyadmin/dbdata/data.mdbis the address of the data warehouse and can be downloaded directly.
After the download, the Administrator's MD5 password is obtained. You can query the Internet to obtain the original password.
Next is the focus!
Upload of JPG bmp gif swl doc xls files is not allowed for normal image uploading.
However, the "Basic Information" area can contain buttons for uploading homepage logos and ad banners.
Click to go to the page. The address is
Http://www.xxxxx.net/xyadmin/situjiaduotu.asp? Formname=baseinfoform&editname=logol&uppath=baseinfo&filelx;.swf.gif.jpg
Have you found any problems? Filter filename Suffixes by assigning values to variables.
Change the upload page address
Http://www.xxxxx.net/xyadmin/situjiaduotu.asp? Formname=baseinfoform&editname=logol&uppath=baseinfo&filelx;.swf.gif.jpg. asp
Open
Directly upload the ASPSHELL file and view the source file to obtain the WEBSHELL address.
GOOGLE: inurl: xyadmin
I found that there are still a lot of school websites using this system.
END... Not much technical skills .. Just by coincidence ..
However, I found that all websites using this system have changed their copyright information .. I don't know what the original name of this system is ......