Author: Diablo
Recently, I felt bored due to a pain point. A cow said that he had hacked a website and posted it on QQtz. Let me watch it.
It hurts to see this website.
It's just a black box, so it's my idea of intrusion.
I read the image address of the website, which looks amazing.
I directly set up a second-level domain name to put photos ....
All of a sudden, there was no upload. I typed a few addresses on my website... None.
Speechless. I thought about whether the image is a second-level domain name and the upload address is also a second-level domain name (⊙ o ⊙ )?
Upfile.qqtz.com upload.qqtz.com
Finally, the last address was guessed.
A little tricky .... I tried the parsing vulnerability.
Finally failed... Rename all directly...
Right-click to view the source code... This is the beginning
It seems that you can modify it ....
I modified the local file.
So I uploaded a page in lust... I hung up a black page and shot my ass !!!!!
Tutorial INSTRUCTOR: Noseay | Roc