当前位置:网站首页>Introduction to rce in attack and defense world
Introduction to rce in attack and defense world
2022-07-04 07:09:00 【Distant sky】
Shooting range problem php_rce It has been shown that , This is the question rce( Remote instruction / Code Execution Vulnerability )
Open the range , See only this promotion page , Promote a framework and specifically specify the version . I guess the version of this framework may have public vulnerabilities . So I went to Baidu ThinkphpPHP V5
After searching online, I found that this version framework really exists rce Loophole .
Click into a blog address casually :https://www.cnblogs.com/backlion/p/10106676.html
See the vulnerability affecting the version 、 Vulnerability analysis and utilization are introduced
Refer directly to the code constructed here
Use instruction ls List the current catalog file
use cat After checking these files one by one , Didn't get flag, Guess it should be put in other directories ...... So I thought of using ../ Step up . Last ../../../ When backing up the third level directory, I found flag, This is actually in the root directory ...
And then use cat Command to view the file , Get flag.
Later I went to check , View root file , direct ls / This command will do , And use it directly cat /flag Just go , Or right linux The instructions are unfamiliar .. Ah ~~
边栏推荐
- MySQL 45 lecture learning notes (VI) global lock
- Responsive - media query
- tars源码分析之7
- Centos8 install mysql 7 unable to start up
- Su Weijie, a member of Qingyuan Association and an assistant professor at the University of Pennsylvania, won the first Siam Youth Award for data science, focusing on privacy data protection, etc
- Knowledge payment applet dream vending machine V2
- 提升复杂场景三维重建精度 | 基于PaddleSeg分割无人机遥感影像
- MySQL 45 lecture learning notes (XIII) delete half of the table data, and the table file size remains the same
- tornado项目之路由装饰器
- flask-sqlalchemy 循环引用
猜你喜欢
Vulhub vulnerability recurrence 77_ zabbix
[thread pool]
Research on an endogenous data security interaction protocol oriented to dual platform and dual chain architecture
Responsive - media query
[Mori city] random talk on GIS data (I)
flask-sqlalchemy 循环引用
Deep understanding of redis -- a new type of bitmap / hyperloglgo / Geo
Review of enterprise security incidents: how can enterprises do a good job in preventing source code leakage?
图的底部问题
Cervical vertebra, beriberi
随机推荐
Redis - detailed explanation of cache avalanche, cache penetration and cache breakdown
Paddleocr prompt error: can not import AVX core while this file exists: xxx\paddle\fluid\core_ avx
Redis interview question set
leetcode825. Age appropriate friends
MySQL 45 learning notes (XI) how to index string fields
Transition technology from IPv4 to IPv6
【FPGA教程案例7】基于verilog的计数器设计与实现
高薪程序员&面试题精讲系列119之Redis如何实现分布式锁?
How notepad++ counts words
[Mori city] random talk on GIS data (I)
Tar source code analysis Part 3
Recursive Fusion and Deformable Spatiotemporal Attention for Video Compression Artifact Reduction
Pangu open source: multi support and promotion, the wave of chip industry
【Kubernetes系列】Kubernetes 上安装 KubeSphere
[FPGA tutorial case 7] design and implementation of counter based on Verilog
Novel website program source code that can be automatically collected
Selenium ide plug-in download, installation and use tutorial
BasicVSR++: Improving Video Super-Resolutionwith Enhanced Propagation and Alignment
Responsive mobile web test questions
电脑通过Putty远程连接树莓派