求分析個php代碼

來源:互聯網
上載者:User
listOptions($actionTaskId); // We will actually store it for use in a second...            break;          case "stop": // Stop a specified running Task ID            $sqlmap->stopScan($actionTaskId);            break;          case "kill": // Forcefully Kill a specified running Task ID            $sqlmap->killScan($actionTaskId);            break;          case "del": // Delete a specified running Task ID            $sqlmap->deleteTaskID($actionTaskId);            break;          default: // Do Nothing if nothing is specified...            break;        }      }    }  }?>      SQLMAP Web GUI - Admin Panel                                    
SQLMAP Web GUI - Admin Panel"; if(isset($_SESSION['myAdminID'])) { $taskList = $sqlmap->adminListTasks(trim($_SESSION['myAdminID'])); if(!$taskList) {?>
[WARNING] '' - Appears to be an Invalid Admin ID!


Admin ID:
Total Number of Known Tasks:




'; echo 'ScanID: ' . htmlentities(trim($_GET['task']), ENT_QUOTES, 'UTF-8') . ', API Scan Configuration'; echo ''; echo "[*] API Scan Configuration:\n"; print_r(htmlentities($sqlmap->listOptions(trim($_GET['task']))['options']), ENT_QUOTES, 'UTF-8'); echo '
'; } else { ?> checkScanStatus($t); $taskConfig = $sqlmap->listOptions($t); echo " "; echo " "; if(sizeof($taskConfig) > 0) { $targetHost = parse_url($taskConfig['options']['url'], PHP_URL_HOST); echo " "; } else { echo " "; } if(isset($status['status'])) { echo " "; } else { echo " "; } echo " "; if($status['status'] == 'running') { echo " "; echo " "; } else { echo " "; echo " "; } echo " "; echo " "; } ?>
TaskID Target Status Options
"; echo htmlentities($t, ENT_QUOTES, 'UTF-8'); echo "" . htmlentities($targetHost, ENT_QUOTES, 'UTF-8') . " - " . htmlentities($status['status'], ENT_QUOTES, 'UTF-8') . " - Conf Stop Kill - - Del

[WARNING] NO Admin ID Set!




Logout
Want to learn more about SQLMAP, Visit the Project Page!
SQLMAP Web Operator Copyright © 2015, Coded By: HR, All rights reserved.


這是後台登入首頁(index.php)的代碼,帳號密碼在config.php中寫死了,是admin,admin。現在登入後台後,顯示[WARNING] NO Admin ID Set!,然後然我輸入一串密文token,token密文貌似是

  $salt = "!SQL!";                            // Salt for form token hash generation  $token = sha1(mt_rand(1, 1000000) . $salt); // Generate CSRF Token Hash  $_SESSION['token'] = $token;                // Set CSRF Token for Form SubmitVerification

是1-1000000加SALT的sha1加密,然後我在

          [WARNING] NO Admin ID Set!


Admin ID:
Total Number of Known Tasks:




'; echo 'ScanID: ' . htmlentities(trim($_GET['task']), ENT_QUOTES, 'UTF-8') . ', API Scan Configuration'; echo ''; echo "[*] API Scan Configuration:\n"; print_r(htmlentities($sqlmap->listOptions(trim($_GET['task']))['options']), ENT_QUOTES, 'UTF-8'); echo '
'; } else { ?> checkScanStatus($t); $taskConfig = $sqlmap->listOptions($t); echo " "; echo " "; if(sizeof($taskConfig) > 0) { $targetHost = parse_url($taskConfig['options']['url'], PHP_URL_HOST); echo " "; } else { echo " "; } if(isset($status['status'])) { echo " "; } else { echo " "; } echo " "; if($status['status'] == 'running') { echo " "; echo " "; } else { echo " "; echo " "; } echo " "; echo " "; } ?>
TaskID Target Status Options
"; echo htmlentities($t, ENT_QUOTES, 'UTF-8'); echo "" . htmlentities($targetHost, ENT_QUOTES, 'UTF-8') . " - " . htmlentities($status['status'], ENT_QUOTES, 'UTF-8') . " - Conf Stop Kill - - Del

[WARNING] NO Admin ID Set!




Logout
Want to learn more about SQLMAP, Visit the Project Page!
SQLMAP Web Operator Copyright © 2015, Coded By: HR, All rights reserved.


這是後台登入首頁(index.php)的代碼,帳號密碼在config.php中寫死了,是admin,admin。現在登入後台後,顯示[WARNING] NO Admin ID Set!,然後然我輸入一串密文token,token密文貌似是

  $salt = "!SQL!";                            // Salt for form token hash generation  $token = sha1(mt_rand(1, 1000000) . $salt); // Generate CSRF Token Hash  $_SESSION['token'] = $token;                // Set CSRF Token for Form SubmitVerification

是1-1000000加SALT的sha1加密,然後我在

          [WARNING] NO Admin ID Set!

看到了輸出token的語句,在前台查看原始碼後,把密文輸入,但是還是不行。求解,怎麼才能過去?謝謝!!

你通過POST傳遞 myAdminID,但問題是你自己輸入的myAdminID是應該怎麼產生的?

那個token是防止CSRF的,不是用來產生myAdminID的,至於myAdminID應該怎麼產生,你應該看看這段代碼:

$sqlmap->adminListTasks(trim($_SESSION['myAdminID']));
  • 相關文章

    聯繫我們

    該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

    如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

    A Free Trial That Lets You Build Big!

    Start building with 50+ products and up to 12 months usage for Elastic Compute Service

    • Sales Support

      1 on 1 presale consultation

    • After-Sales Support

      24/7 Technical Support 6 Free Tickets per Quarter Faster Response

    • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.