当前位置:网站首页>基于DVWA的文件上传漏洞测试
基于DVWA的文件上传漏洞测试
2022-07-06 01:06:00 【wishLifeJumP】
目录
DVWA
Low
DVWA Security的“low”级别可以直接上传“一句话”木马。
1.1 编写测试木马
<?php
phpinfo();
?>1.2 没有后缀过滤直接上传

1.3回显上传路径,直接访问即可
http://localhost/dvwa/hackable/uploads/info.php

Medium
Medium级别不同于Low级别,Medium界别对前端做了上传限制,通过绕过检测机制,抓包更改后缀名达到上传效果。
2.1 上传合法文件,此时打开代理

2.2 待抓到数据包后,send to repeater

info.png 改为info.php
响应码为200说明书上传成功。

2.3 执行php脚本
https://localhost/dvwa/hackable/uploads/info.php

边栏推荐
- Interview must brush algorithm top101 backtracking article top34
- Intensive learning weekly, issue 52: depth cuprl, distspectrl & double deep q-network
- Zhuhai laboratory ventilation system construction and installation instructions
- [day 30] given an integer n, find the sum of its factors
- Exciting, 2022 open atom global open source summit registration is hot
- Cf:h. maximum and [bit operation practice + K operations + maximum and]
- MIT博士论文 | 使用神经符号学习的鲁棒可靠智能系统
- Questions about database: (5) query the barcode, location and reader number of each book in the inventory table
- Cve-2017-11882 reappearance
- Meta AI西雅图研究负责人Luke Zettlemoyer | 万亿参数后,大模型会持续增长吗?
猜你喜欢

Daily practice - February 13, 2022

esxi的安装和使用

Dede collection plug-in free collection release push plug-in

View class diagram in idea

The inconsistency between the versions of dynamic library and static library will lead to bugs

Illustrated network: the principle behind TCP three-time handshake, why can't two-time handshake?

For a deadline, the IT fellow graduated from Tsinghua suddenly died on the toilet

Finding the nearest common ancestor of binary tree by recursion

The third season of ape table school is about to launch, opening a new vision for developers under the wave of going to sea

2020.2.13
随机推荐
Installation and use of esxi
Why can't mathematics give machine consciousness
synchronized 和 ReentrantLock
SSH login is stuck and disconnected
Mysql--- query the top 5 students
JVM_ 15_ Concepts related to garbage collection
esxi的安装和使用
Leetcode 44 Wildcard matching (2022.02.13)
View class diagram in idea
Dedecms plug-in free SEO plug-in summary
Introduction to robotics I. spatial transformation (1) posture, transformation
In the era of industrial Internet, we will achieve enough development by relying on large industrial categories
Gartner released the prediction of eight major network security trends from 2022 to 2023. Zero trust is the starting point and regulations cover a wider range
FFT 学习笔记(自认为详细)
测试/开发程序员的成长路线,全局思考问题的问题......
STM32按键消抖——入门状态机思维
Cf:c. the third problem
The inconsistency between the versions of dynamic library and static library will lead to bugs
CTF daily question day44 rot
MYSQL---查询成绩为前5名的学生