提升权限获取服务器管理权限(国外英文资料).doc

提升权限获取服务器管理权限(国外英文资料).doc

  1. 1、本文档共14页,可阅读全部内容。
  2. 2、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
  3. 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载
  4. 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
提升权限获取服务器管理权限(国外英文资料)

提升权限获取服务器管理权限(国外英文资料) One: technical summary With the rapid development of the Internet, all kinds of big and small websites have sprung up, and in these big websites, the dynamic website is in fact Sex and diversity dominate the world. As the ASP system is widely used on the Internet, scripting attacks against ASP systems have recently been a red fire. In these attacks, Attackers gain access to administrators by means of injection, mob, side note, and cookies. Through direct uploading or backstage backup, etc Get a website This post hides the content Webshell then controls the entire station point The server administration authority is then acquired through the webshell promotion authority. What is a webshell? Webshell is a scripting language that can be edited, deleted, added files, and executed Script files, such as program and SQL statements, have the ability to change the target page, delete files, and so on. This is an ASP script file, such as the famous veteran and the top of the ocean. Second: the main means of intrusion Upload a bug One: we will visit the upload page directly if the typical network upload vulnerability. Two: get into the background of the website and upload the script Trojan, get webshell. Because some website systems trust the administrator, you can upload the script as soon as you get to the background. Third: add upload types. If the system code limits the upload of ASP files, then we can add the files that are allowed to upload ASACER and then the script Trojan The suffix name is changed to ASACER. Webshell can be used as well. Fourth: restore the ASP suffix name through the background backup function If you cant upload a suffix name file such as ASP. We modify the script Trojan suffix name ASP for JPG or GIF image suffix name After uploading successfully, restore the file ASP suffix by backstage backup database function. Five: grab bag upload Grab the actual address and the administrator authentication data COOKIES. Then upload the sc

您可能关注的文档

文档评论(0)

f8r9t5c + 关注
实名认证
内容提供者

该用户很懒,什么也没介绍

版权声明书
用户编号:8000054077000003

1亿VIP精品文档

相关文档