Tipask uses shell in the background

Source: Internet
Author: User

Recently I saw a vulnerability in the tipask system. It seems that only the root user can get the shell, but the background features are so rich. I tried another shell method, although it is not a killer, it is barely usable.

Isn't the SQL Execution function provided in the tipask background?

Insert a sentence in the database, and then back up the file like XX. ASP; _. SQL through the database backup function, because the backup database file is added at the beginning of each # <? Exit ();?>, Therefore, it can only be used on IIS6 that supports both asp.

At the same time, the file name is verified during database backup, so it is OK to submit the local breakthrough verification.
No technical skills. Please forgive me.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.