Preface:
A female in the circle. I should have heard of it before. Start with passion:
Process:
Let's take a look at the target site. Empire CMS. No 0 day. Use the old Brother Yu Jian !!!
Discovery is out of the stars. The process of taking the bypass station here is very simple, so I will not introduce it much.
Off-star, supports aspx and only one writable file C: \ DocumentsandSettings \ AllUsers \ Application
Data \ HagelTechnologies \ DUMeter \ log.csv
There are no other writable directories and files. replace them with cmd. Most out of the stars can use the for command.
However, it is difficult to write files.
Same first: for/d % iin (d: \ xx \ *) do @ echo % I to list all directories.
However, what hurts is that the empire site cannot beat the website path. So I am very good at using the for column for a station.
Directory, and finally found the root directory of the target site.
But afterwards, I came up with a way to quickly find the root directory of the target station. I didn't pay attention to this.
Status. Share with you.
For/rd: \ % iin(2002910021.jpg) do @ echo % I use this command to search for
The Directory of the image 2002910021.jpg.
I did a test and found a picture with no duplicate names on the target site. Search for d: \ freehost \
Directory. At last, the target station has a directory that uses the text search function to find the target path.
It shows that all folders have this image, but it does not affect it. Because it lists all the root directories. We
You only need to search for a directory on the target site.
Then, the type is used to read the database connection information of config. inc. php.
Use the database connection function of php Trojan to find and crack the management account in the database.
A small problem occurs here: the password is cracked, but the login fails. Then I flipped it over, and there was another
Subdirectory is also the source code of the Empire.
Take the password and kill it in seconds.
This figure is not marked. We should all know that it was the station of the woman. Shell in the background
Summary:
If you have more than one friends, you are doing a good job.