- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
提升权限获取服务器管理权限(国外英文资料)
提升权限获取服务器管理权限(国外英文资料)
One: technical summary
With the rapid development of the Internet, all kinds of big and small websites have sprung up, and in these big websites, the dynamic website is in fact
Sex and diversity dominate the world.
As the ASP system is widely used on the Internet, scripting attacks against ASP systems have recently been a red fire. In these attacks,
Attackers gain access to administrators by means of injection, mob, side note, and cookies.
Through direct uploading or backstage backup, etc
Get a website
This post hides the content
Webshell then controls the entire station
point
The server administration authority is then acquired through the webshell promotion authority.
What is a webshell? Webshell is a scripting language that can be edited, deleted, added files, and executed
Script files, such as program and SQL statements, have the ability to change the target page, delete files, and so on.
This is an ASP script file, such as the famous veteran and the top of the ocean.
Second: the main means of intrusion
Upload a bug
One: we will visit the upload page directly if the typical network upload vulnerability.
Two: get into the background of the website and upload the script Trojan, get webshell.
Because some website systems trust the administrator, you can upload the script as soon as you get to the background.
Third: add upload types.
If the system code limits the upload of ASP files, then we can add the files that are allowed to upload ASACER and then the script Trojan
The suffix name is changed to ASACER. Webshell can be used as well.
Fourth: restore the ASP suffix name through the background backup function
If you cant upload a suffix name file such as ASP. We modify the script Trojan suffix name ASP for JPG or GIF image suffix name
After uploading successfully, restore the file ASP suffix by backstage backup database function.
Five: grab bag upload
Grab the actual address and the administrator authentication data COOKIES.
Then upload the sc
您可能关注的文档
最近下载
- 银行业专业人员资格考试银行业法律法规与综合能力分类模拟108含答案.pdf VIP
- 课件中国的行政区划全国优质课一等奖课件.ppt
- 上市股份有限责任公司章程(标准版).docx
- 兴业证券-电子行业跟踪报告:比亚迪开启全民智驾时代车载摄像头迎机遇.pdf VIP
- 2024年家庭房产分配协议书范本6篇.docx VIP
- 汽车机械制图(第二版)模拟试题及答案2套.docx VIP
- DB33T 817-2010 基础地理信息要素分类与图形表达代码.docx VIP
- 煤制合成气单位产品能源消耗限额.pdf VIP
- 第1讲:平面向量的线性运算及坐标表示.docx VIP
- 第一次中华民国教育年鉴 教科书发刊概况.pdf VIP
文档评论(0)