看了师傅们发的文章,蹭下热度,复现一下。
原理很简单,后台管理页面,登录框存在xss
管理员登录后,出发xss执行命令。
主要的还是js里面写个什么。
你可以直接alert弹窗,管理员登录后就会弹窗。
感觉和宝塔的日志xss一样的。
插入js脚本。登陆,这里验证码要打正确。不然无法传入。
在目标服务器上生成了文件。
贴上js脚本,这里是
rce的话可以后台添加计划任务实现写webshell、反弹shell等操作,这些交给js就可以实现自动化完成。
实测可以用于所有版本,win和linux都可以,根据系统不同,选择不同的rec手法。
Comments | 5 条评论
博主 Erma
Magnificent beast ! Iwoould like to apprentikce while you amednd your website,
hhow cann i sugscribe for a blog web site? Thee account
helped me a acceptable deal. I had beeen tinyy bit acquainted of this your
broadcast provijded bright clearr idea
博主 Blond hottie gets painful sex
It’s reallly a great and useful piece off info.
I amm happy that you simply shared this useful inf ith us.
Please keep us uup too dqte like this. Thankk yyou for sharing.
博主 jerome
@Blond hottie gets painful sex Thank you for your attention, I will continue to update some useful information.
博主 782
Hey! I jusst wanted to askk if yoou evr have any issues
woth hackers? My last blog (wordpress) was acked
and I ejded uup losinng many months of hard work ddue to no dzta backup.
Do you have any solutionhs too protct againat hackers?
博主 jerome
@782 You can use a server firewall, a web firewall, or any security blocking device.
Warning: Invalid argument supplied for foreach() in /www/wwwroot/blog.lw.al/wp-content/themes/Sakura/functions.php on line 1093