当前位置:网站首页>vulfocus入门靶机
vulfocus入门靶机
2022-06-30 07:52:00 【sec0nd_】
命令执行漏洞
漏洞描述:
命令执行(Command Execution)漏洞即黑客可以直接在Web应用中执行系统命令,从而获取敏感信息或者拿下shell权限
命令执行漏洞可能造成的原因是Web服务器对用户输入命令安全检测不足,导致恶意代码被执行
打开漏洞地址,直接把命令执行的参数写出来了
访问该地址,返回flag

目录遍历漏洞
漏洞描述:
目录浏览漏洞属于目录遍历漏洞的一种,目录浏览漏洞是由于网站存在配置缺陷,存在目录可浏览漏洞,这会导致网站很多隐私文件与目录泄露,比如数据库备份文件、配置文件等,攻击者利用该信息可以更容易得到网站权限,导致网站被黑。
风险:攻击者通过访问网站某一目录时,该目录没有默认首页文件或没有正确设置默认首页文件,将会把整个目录结构列出来,将网站结构完全暴露给攻击者;
攻击者可能通过浏览目录结构,访问到某些隐秘文件(如PHPINFO文件、服务器探针文件、网站管理员后台访问地址、数据库连接文件等)。
打开漏洞地址,是类似ftp站点的页面
来到tmp目录下,有个flag(本来以为这可能是个假的flag,提交试了下成功了,有点侮辱智商)
边栏推荐
- Final review -php learning notes 3-php process control statement
- min_ max_ Gray operator understanding
- Multi whale capital: report on China's education intelligent hardware industry in 2022
- JS代码案例
- Summary and common applications of direction and angle operators in Halcon
- Tue Jun 28 2022 15:30:29 GMT+0800 (中国标准时间) 日期格式化
- Deep learning - brnn and DRNN
- Efga design open source framework openlane series (I) development environment construction
- November 22, 2021 [reading notes] - bioinformatics and functional genomics (Section 5 of Chapter 5 uses a comparison tool similar to blast to quickly search genomic DNA)
- Cadence physical library lef file syntax learning [continuous update]
猜你喜欢

Examen final - notes d'apprentissage PHP 5 - Tableau PHP

Deep learning - goal orientation

期末複習-PHP學習筆記5-PHP數組

Analysis of cross clock transmission in tinyriscv

The counting tool of combinatorial mathematics -- generating function

More, faster, better and cheaper. Here comes the fastdeploy beta of the low threshold AI deployment tool!

深度学习——使用词嵌入and词嵌入特征

Cadence innovus physical implementation series (I) Lab 1 preliminary innovus
![November 22, 2021 [reading notes] - bioinformatics and functional genomics (Chapter 5, section 4, hidden Markov model)](/img/0d/77953ffa9f45a5acc16f02bf33293b.jpg)
November 22, 2021 [reading notes] - bioinformatics and functional genomics (Chapter 5, section 4, hidden Markov model)

Deep learning -- language model and sequence generation
随机推荐
你了解IP协议吗?
期末复习-PHP学习笔记7-PHP与web页面交互
期末复习-PHP学习笔记5-PHP数组
Account command and account authority
Final review -php learning notes 1
C language operators
Deep learning - goal orientation
December 4, 2021 - Introduction to macro genome analysis process tools
深度学习——特征点检测和目标检测
CRM能为企业带来哪些管理提升
期末複習-PHP學習筆記5-PHP數組
Examen final - notes d'apprentissage PHP 3 - Déclaration de contrôle du processus PHP
2021 China Enterprise Cloud index insight Report
Recurrence relation (difference equation) -- Hanoi problem
2022.01.20 [bug note] | qiime2: an error was encoded while running dada2 in R (return code 1)
min_ max_ Gray operator understanding
Cadence physical library lef file syntax learning [continuous update]
【Tensorflow-gpu】window11下深度学习环境搭建
Combinatorial mathematics Chapter 2 Notes
24C02