webshell

 

It's a typical One Word Trojan, we can utilize AntSword(you can download this tool from github) to penetrate that above stuff. 

 

 'Shell pwd' is the POST parameter. 

 

And then connect into the web server. 

 

We find a flag.txt file under html directory. 

 

Here is the FLAG for which you seek. 

posted @ 2021-08-12 17:03  _4_FUN  阅读(46)  评论(0)    收藏  举报