当前位置:网站首页>基於DVWA的文件上傳漏洞測試
基於DVWA的文件上傳漏洞測試
2022-07-06 01:07:00 【wishLifeJumP】
目錄
DVWA
Low
DVWA Security的“low”級別可以直接上傳“一句話”木馬。
1.1 編寫測試木馬
<?php
phpinfo();
?>1.2 沒有後綴過濾直接上傳

1.3回顯上傳路徑,直接訪問即可
http://localhost/dvwa/hackable/uploads/info.php

Medium
Medium級別不同於Low級別,Medium界別對前端做了上傳限制,通過繞過檢測機制,抓包更改後綴名達到上傳效果。
2.1 上傳合法文件,此時打開代理

2.2 待抓到數據包後,send to repeater

info.png 改為info.php
響應碼為200說明書上傳成功。

2.3 執行php脚本
https://localhost/dvwa/hackable/uploads/info.php

边栏推荐
- 直播系统代码,自定义软键盘样式:字母、数字、标点三种切换
- KDD 2022 | EEG AI helps diagnose epilepsy
- 云导DNS和知识科普以及课堂笔记
- China Taiwan strategy - Chapter 8: digital marketing assisted by China Taiwan
- curlpost-php
- Promise
- [pat (basic level) practice] - [simple mathematics] 1062 simplest fraction
- C language programming (Chapter 6 functions)
- 程序员搞开源,读什么书最合适?
- Spark AQE
猜你喜欢

Convert binary search tree into cumulative tree (reverse middle order traversal)

Spark SQL null value, Nan judgment and processing

For a deadline, the IT fellow graduated from Tsinghua suddenly died on the toilet

KDD 2022 | EEG AI helps diagnose epilepsy

IP storage and query in MySQL

Recursive method to realize the insertion operation in binary search tree

282. Stone consolidation (interval DP)
![[groovy] XML serialization (use markupbuilder to generate XML data | set XML tag content | set XML tag attributes)](/img/09/9076de099147b2d0696fe979a68ada.jpg)
[groovy] XML serialization (use markupbuilder to generate XML data | set XML tag content | set XML tag attributes)

毕设-基于SSM高校学生社团管理系统

从 1.5 开始搭建一个微服务框架——调用链追踪 traceId
随机推荐
[groovy] compile time metaprogramming (compile time method interception | find the method to be intercepted in the myasttransformation visit method)
Finding the nearest common ancestor of binary tree by recursion
DD's command
Keepalive component cache does not take effect
[day 30] given an integer n, find the sum of its factors
Modify the ssh server access port number
I'm interested in watching Tiktok live beyond concert
Leetcode study - day 35
Kotlin core programming - algebraic data types and pattern matching (3)
cf:D. Insert a Progression【关于数组中的插入 + 绝对值的性质 + 贪心一头一尾最值】
cf:C. The Third Problem【关于排列这件事】
Novice entry depth learning | 3-6: optimizer optimizers
synchronized 和 ReentrantLock
China Taiwan strategy - Chapter 8: digital marketing assisted by China Taiwan
SSH login is stuck and disconnected
Dedecms plug-in free SEO plug-in summary
[groovy] JSON serialization (jsonbuilder builder | generates JSON string with root node name | generates JSON string without root node name)
VMware Tools安装报错:无法自动安装VSock驱动程序
Differences between standard library functions and operators
Five challenges of ads-npu chip architecture design