Shanda's website source code leaks. Getshell goes directly to the Intranet.
Git leaks, causing source code to be downloaded to the http://minigame.sdo.com/taojin/.git/config
Here, we will not describe the specific vulnerability exploitation details too much.
I looked at the source code and found that any file was uploaded.
Upfile. php
<Html>
After the upload is successful, the output server is on the Intranet.
# Do not remove the following line, or various programs# that require network functionality will fail.127.0.0.1localhost.localdomain localhost::1localhost6.localdomain6 localhost610.127.19.82 gitsource.sdpintra.com10.129.1.13 ebs.billing.snda.com
The Intranet is not going deep.
/Etc/passwd root: x: 0: 0: root:/bin/bash bin: x: 1: 1: bin:/sbin/nologin daemon: x: 2: 2: daemon:/sbin/nologin adm: x: 3: 4: adm:/var/adm:/sbin/nologin lp: x: 4: 7: lp:/var/spool/lpd:/sbin/nologin sync: x: 5: 0: sync:/sbin:/bin/sync shutdown: x: 6: 0: shutdown:/sbin/shutdown halt: x: 7: 0: halt:/sbin/halt mail: x: 8: 12: mail: /var/spool/mail:/sbin/nologin news: x: 9: 13: news:/etc/news: uucp: x: 10: 14: uucp: /var/spool/uucp:/sbin/nologin operator: x: 11: 0: operator:/root:/sbin/nologin games: x: 12: 100: games: /usr/games:/sbin/nologin gopher: x: 13: 30: gopher:/var/gopher:/sbin/nologin ftp: x: 14: 50: FTP User: /var/ftp:/sbin/nologin nobody: x: 99: 99: Nobody: // sbin/nologin nscd: x: 28: 28: NSCD Daemon :/: /sbin/nologin vcsa: x: 69: 69: virtual console memory owner:/dev:/sbin/nologin rpc: x: 32: Portmapper RPC user :/: /sbin/nologin mailnull: x: 47: 47:/var/spool/mqueue:/sbin/nologin smmsp: x: 51: 51:/var/spool/mqueue: /sbin/nologin oprofile: x: 16: 16: Special user account to be used by OProfile:/home/oprofile:/sbin/nologin sshd: x: 74: 74: privilege-separated SSH:/var/empty/sshd:/sbin/nologin pcap: x: 77: 77:/var/arpwatch:/sbin/nologin ntp: x: 38: 38:/etc/ntp:/sbin/nologin messages: x: 81: 81: System message bus: // sbin/nologin avahi: x: 70: 70: avahi daemon: // sbin/nologin rpcuser: x: 29: 29: RPC Service User:/var/lib/nfs:/sbin/nologin nfsnobody: x: 65534: 65534: anonymous NFS User:/var/lib/nfs:/sbin/nologin haldaemon: x: 68: 68: HAL daemon: // sbin/nologin avahi-autoipd: x: 100: 104: avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin xfs: x: 43: 43: X Font Server:/etc/X11/fs: /sbin/nologin cacti: x: 500: 500:/home/cacti:/bin/bash mysql: x: 501: 501:/home/mysql: /bin/bash solution: Filter