By: Xiao Kai
Today, I read the blog's traffic statistics and found a hacker website ..
So I want to check it... find fate, and together, he won a side station. You do not have any permissions. Upload An aspx Trojan to find the writable directory.
Initially, the server permission is still acceptable. The out-of-the-stars permission is quite good. I followed the fate for a long time. There was no result .. (The head is a little too curved .)
When I wanted to give up, I used the command to input a dir c: column... directory file .. A little excited.
So again dir d: Is also a column. But the web disk is e: the disk Column cannot. However, when columns the D disk. Several compressed packages are found. hack ***. rar
So we downloaded the file and found that it was not the website. So we copied the second file. Download the hack6 program. Over 900 mb for a long time
Decompress the package and find the hack6 program. Find the background directory. Find the old dedecms 5.5 version. I remember a getshell and tried to fix it ..
Check the database link information in config. php. Pick up the kitchen knife link. It seems that rp does not work. No link .. (I thought there was a backup, but the old administrator may have changed all mysql)
No way at this time, social engineering. Some database connection information accounts are mostly idc login accounts .. find the idc address ** idc.net and try to find the account. A few other passwords are not logged on.
In fact, this process is very long. So I saw an independent panel on the top and pulled out the database link information... login... I did not expect to log on...
So enter .. phpmyadmin .... find dede_admin. three administrators .. password cannot be unlocked .. the dedecms password is 20-bit md5. Use phpmyadmin to change the management password to 123456.
Logging on to the background... dededecms the background is too simple to use the shell... it took a long time to get the shell and hung up a black page... Let's look at the previous figure ..