See how I step by step fall into a game Enterprise (mobile game security case)
Step by step, like the devil's pace ~
I don't know if there are any gifts, whether there are home pages, whether there are any excellent news, whether there are monthly reports, and whether there are any bonuses. I am very excited when I submit this kind of information for the first time (although many of them have not been submitted before ..)..~
I downloaded a game called {storm legend}
Let's have a look.
Go
Nima, I am on fire to guide the gameplay,
So, I will see if I can recharge the gold coins, use the same vulnerability as the previous one, and then the result fails.
Try other methods ,..
Click your avatar, select the user center, and capture an im.xxwan.com /***
Then access im.xxwan.com
Execute the s2 command ~
Getshell
Haha, svn is still on ~
Aizhan.com
Oh ~ Some of them are playing. First, find out the password of the Customer Service im.xxwan.com website.
Logon successful
Okay, it seems that there is nothing to play with (PS: chrome is used when logging on, you cannot click to log on, and then change the button to submit to log on ....)
OK, continue
The admin
Let's go and see
Let's take a look at this.
/Usr/local/tomcat_xxwan_admin/webapps/ROOT/WEB-INF/classes/config. properties
# Whether to debug the module test. The exception information is printed on each page of the module test.
* ***** Mode =, 192.1 **************************** ** xmail. * ******** ouwan @ c ************ ouwan **************** * *** location? * ***** 1. ://**. **. ** // 192.168.1.175 \: 1218/name \ = unionQueue & opt \ = put & auth \ = e0fPYn5Gwhf6wagbibEm & data \ = _ 2. ://**. **. ** // 192.168.200.187: 1218/name = queue_union_1 & opt = put & auth = bwAQakn4Rdu3MQXEK4GA & data = _*****?? Box? * ***** 3. ://**. **. ** // 192.168.1.114 \: 8080/dw/bindsafe. action _***************?? ? * ***** 4.: // **. **. ** // user.xxwan.com/userinterfacea?????=== _***************?? Address? * ***** 5. ://**. **. ** // 192.168.1.114 \: 8080/dw/uf_6. ://**. **. ** // m.xxwan.com
# Basic file upload path
1.://**.**.**/workspace/xxwansdkadmin/WebRoot/UploadFile_*****a/apps/xxw********************ver *****2.://**.**.**//bbs.cmge.com/uc_server_*****addr**********.cmge********************y**********34i3Q5UeubT3H5Tan********** **********pi**********PID********************t value is **********NNE********************###*****3.://**.**.**//192.168.1.114\:8080/dw/_*****ction*****4.://**.**.**//192.168.1.114\:8080/dw/douwan.apk_*****Bind.*****5.://**.**.**//192.168.1.114\:8080/dw/interfaces/mailModel.jsp_*****ay.*****6.://**.**.**//192.168.1.114\:8080/dw/payresult_yee_*****sV100**********kefu@do*****
# Display address of customer product information, guidance, and strategy content
GameInfoClickUrl = http \: // client.cmge.com/gameInfoAction \! GetGameInfoDetailByArticleId? ArticleId \ =
# ID of the first screen displayed on the client, 1 for displaying my games, 0 for displaying recommendations
IndexMod = 0
# Whether to pre-load the first screen
IsLaunchFirst = 1
# Whether to display client request logs
ShowRequestLog = 1
# Whether to display the response client content log
ShowResponseLog = 1
# Startup project type
InitType = sdk
OK, some of them are playing ..
I don't know if this is the station admin.xxwan.com .. Find the database connection.
Alright ~ Found
db.driver=com.mysql.jdbc.Driver
*****xwanadmin?useUnicode\=t**********me=sd**********p5TqG55o********************e=xxwa**********rd=31Kb8kA********************.mysql.jd**********xwanpay?characterEncoding**********name=s**********ifp5TqG55********************mysql.jdb**********xxwanim?characterEncodin**********ame=xx**********V6ubQrRRE******************************om.mysql.j**********/xxwanuser?characterEncodi**********ername=**********=rifp5TqG5********************.mysql.jd**********xwanbbs?characterEncoding**********name=x**********Be91D1Fjx*****
XDB
*****dbc.Dr**********2.168.20**********min**********5oCNH*****
*****? Ad *********** oxow ************ inbound? *****
* ***** 71bfdf85e2c45e52.png "al ********************** f4db91aeeed1.jpg" alt = & quo ****** ****? All have? * ******************* 9e601169291a.jpg "alt = & quo **********? ? * Ode * B *> * dbc. ****** ********** **********? ? . *****
* ***** REhJb ***** solution: