当前位置:网站首页>远程文件包含实操
远程文件包含实操
2022-07-03 15:53:00 【MUNG东隅】
这是我第一次尝试用远程文件包含解题,没想到成功了
首先,在服务器上传一个木马文本
老规矩,.user.ini文件搞上去,指向1.txt
1.txt里直接包含一开始上传木马文本文件的地址
然后就可以进行快乐的RCE了
另外,另提一嘴,如果过滤了小数点,其实也可以利用ip地址转10进制进行远程文件包含
边栏推荐
- App mobile terminal test [5] file writing and reading
- Detailed pointer advanced 2
- How idea starts run dashboard
- Semi supervised learning
- Concurrency-02-visibility, atomicity, orderliness, volatile, CAS, atomic class, unsafe
- Tensorflow realizes verification code recognition (III)
- [combinatorial mathematics] binomial theorem and combinatorial identity (binomial theorem | three combinatorial identities | recursive formula 1 | recursive formula 2 | recursive formula 3 Pascal / Ya
- do{}while()的妙用
- Brush questions -- sword finger offer
- 六月 致 -.-- -..- -
猜你喜欢
Jvm-02-class loading subsystem
Jmeter线程组功能介绍
Halcon and WinForm study section 1
nifi从入门到实战(保姆级教程)——flow
关于网页中的文本选择以及统计选中文本长度
App移动端测试【3】ADB命令
Popular understanding of random forest
App mobile terminal test [5] file writing and reading
Please be prepared to lose your job at any time within 3 years?
Popular understanding of gradient descent
随机推荐
Tensorflow realizes verification code recognition (II)
Persisting in output requires continuous learning
Create gradle project
MongoDB 的安装和基本操作
The difference between mutually exclusive objects and critical areas
工资3000,靠“视频剪辑”月入40000:会赚钱的人,从不靠拼命!
Microservice API gateway
Download and install common programs using AUR
“用Android复刻Apple产品UI”(3)—优雅的数据统计图表
How to use annotations such as @notnull to verify and handle global exceptions
关于网页中的文本选择以及统计选中文本长度
Concurrency-02-visibility, atomicity, orderliness, volatile, CAS, atomic class, unsafe
Summary of JVM knowledge points
Reflection on some things
Go language self-study series | if else if statement in golang
Visual upper system design and development (Halcon WinForm) -1 Process node design
QT common sentence notes
软件安装信息、系统服务在注册表中的位置
详解指针进阶1
Tensorflow realizes verification code recognition (III)