当前位置:网站首页>Set up discuz forum and break the stolen database
Set up discuz forum and break the stolen database
2022-07-27 21:05:00 【Cwillchris】
One 、 Quickly build discuz Forum
Attack ideas
Want to take down a host A Authority :
(1) Take a look at this server : port , Server version , Operating system version . Look for loopholes .
(2) Get it right A Identity with certain authority . If the other party is a WEB The server , Just exploit the vulnerability of the other party's website application , Upload webshell Then raise the right
(3) Pass it on , obtain apache User general permission , Then raise the right root
Quickly build the experimental environment
Building a LAMP Environmental Science . Deploy with vulnerabilities discuz Forum
1、 Summary of vulnerability :
This vulnerability appears in a DZ X Inside the series' own conversion tool .
Vulnerability path :utility/convert/data/config.inc.php
The cause of the vulnerability is :config.inc.php This file was hacked through post When writing , No filter detection , So hackers can pass post Way to config.inc.php Write Trojan horse program .
Trigger vulnerability process :
a、 Access and open in the browser
边栏推荐
- 《SRE:Google运维解密》读后有感
- 人脸识别5.1- insightface人脸检测模型训练实战笔记
- Airiot Q & A issue 6 | how to use the secondary development engine?
- Kingbasees heterogeneous database migration guide (4. Application migration process)
- 如何查看蓝牙耳机的蓝牙版本
- The variable "lattice" or class "lattice.latticeeasy" (matlab) is not defined
- [dart] a programming language for cross end development
- 五大知名人士对于AI的忧虑
- Sscanf caused the address to be out of bounds
- 基于ATX自动化测试解决方案
猜你喜欢
![[deep learning] pytoch torch Autograd automatic differential engine](/img/c8/2ce1e5c02283965f8690ac5a9971a9.png)
[deep learning] pytoch torch Autograd automatic differential engine

How to translate the address in the program?

Source Insight 4.0使用介绍

Leetcode-209- subarray with the smallest length

Best practices for Oracle kingbasees migration of Jincang database (4. Oracle database migration practice)

Face recognition 5.1- insightface face face detection model training practice notes

AIRIOT答疑第6期|如何使用二次开发引擎?

知识管理系统推动企业信息化发展

Ue5 uses DLSS (super sampling) to improve the FPS of the scene away from the optimization scheme of Caton

【历史上的今天】7 月 27 日:模型检测先驱出生;微软收购 QDOS;第一张激光照排的中文报纸
随机推荐
Source Insight 4.0使用介绍
sscanf 导致地址越界
How to check the Bluetooth version of Bluetooth headset
How to realize document collaboration?
Best practices for Oracle kingbasees migration of Jincang database (4. Oracle database migration practice)
R语言使用dplyr包左连接两个dataframe数据(left join)
Ue5 uses DLSS (super sampling) to improve the FPS of the scene away from the optimization scheme of Caton
Brand list cases
knife4j通过js动态刷新全局参数
五大知名人士对于AI的忧虑
Introduction to source insight 4.0
hcip第五天
vant组件库
R语言使用t.test函数执行t检验验证总体均值是否是某个特定的值(从样本集推论总体均值)
坚持做一件事情
SRE相关问题答疑
MySQL design optimization generates columns
Know the transmission medium, the medium of network communication
Understanding network model TCPIP model
认识网络模型数据的封装和解封装