Text/Figure Shangjian
Baidu found Cecilia Cheung's official website
Briefly click on it. Most of them are found to beHtmlStatic Page,You can't do it either. It looks a bit likeCms.
I want to see it nowGooglehackCan I find the background address. Check the program version..The right remedy!
As you can see, we all know that this is directory traversal. At the same time, we also found that the website is useful.AspxLanguage Program.
You can see the homepage generated. I suddenly thought of a thought in my mind. There is a version of tianyuan Yajing that can insert a sentence to a file. Then generate the homepageIs it connected in one sentence. But I thought about it later.,The file generated on the homepage does not know which one it is. Besides, it is not always inserted..Simply give up on this idea,
I looked at several other directories.,Observe the files in the directory. There is no found anything that is worth using,
No way! Next,
Before. I checked the server information. Actually yesLinux + apache. At the beginning, I thought the directory traversal wasIis.
(Ps:Later, I thought it wasIis6. Vulnerability resolution for half a day,Failed. Later I remembered that Apache was used on the server. Alas! It is a good thing to be careful during intrusion. Otherwise it will go around a big bend)
Continue.
Locate the same server.Robots.txtSearch for sensitive information
Cmseasy2.0Version. Go to the background page,Try to test several weak passwords. I did not expect to log on successfully.
Next, simulate the management.-Edit current template-Insert in TemplatePhpOne sentence. Capture the captured packets while saving them._ Left_htmlChangeCajjian. php. ExploitationNcUpload
Server display after uploading500Error.
Later1.php00001.jpg,1.php).jpgAnd other suffixes. An error occurred! Then I used it again.TxtSuffix upload,The content is displayed normally. Thinking,The trojan must have been uploaded. It may have been uploaded by the server.PhpFiles are filtered. The Administrator may also set the directory. Modified the uploaded directory.,Directly upload the Trojan horse to the root directory of the website.
Connect with the kitchen knife!