Upload Vulnerability Analysis during one penetration

Source: Internet
Author: User

Author: Shao

A friend lost a station in an acquaintance group a few days ago (it seems that I gave him an address to make him a little money) and said there was an upload that could be used, but it could not be parsed. I read it.

I thought this could be a direct deception, but I couldn't try any common methods.

Changed to upload. asp. I tried to truncate it. I was trying to try it. A nc friend sent a message saying that the nc couldn't solve it.

The whole site should be a better breakthrough. After reading the source file, we suddenly found a place that seems to be usable.

 

ASP/Visual Basic Code
  1. <Td bgcolor = # ffffff align = center> <font color = red> uploading files. Please wait... </font> </td>
  2. </Tr>
  3. </Table>
  4. </Td> <td width = 20%> </td>
  5. </Tr> </table> </div> <Table class ="TableBorder"Width ="90%"Border ="0"Align ="Center"Cellpadding ="3"Cellspacing ="1"
  6. Bgcolor ="# FFFFFF">
  1. <Tr>
  2. <Td align ="Center"Background ="../Images/admin_bg_1.gif"> <B> <font color ="# Ffffff"> Image Upload
  3. <Input type ="Hidden"Name ="Filepath"Value ="GoodsPic /">
  4. <Input type ="Hidden"Name ="Filetype"Value ="Jpg, gif">
  5. <Input type ="Hidden"Name ="EditName"Value ="Goodspic">
  6. <Input type ="Hidden"Name ="FormName"Value ="Myform">
  7. <Input type ="Hidden"Name ="Act"Value ="Previusfile"> </Font> </B>

Hey, I hope you can change all hidden to test, delete previusfile, and add the action.

Then save the local file. For this type of upload, you can directly upload asp files. However, I tried to find that it still does not work, so I had to modify the path.

The path is changed to 1.asp. Changing 1.asp;/still does not work. Ping it and check that TLL (although this can be changed, but few people change it) 117 may be killed. It's still a bit annoying if I change to a kill-free one. After smoking a cigarette, I wondered if I could modify the Upload File name without parsing it? Isn't it IIS? However, all of his servers are asp and php-free. Suddenly. Since any file name can be changed to 1.asp;.jpg and so on, it may be possible to lose a pony for parsing.

No idea in this article is nothing more than careful observation ..

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.