01 2021 档案

摘要:- 阅读全文
posted @ 2021-01-18 11:08 nnnnn_0c0 阅读(34) 评论(0) 推荐(0)
摘要:转载:https://www.fujieace.com/penetration-test/command-bypass.html 一、命令执行的分隔符 换行符 %0a 回车符 %0d 管道符 | 连续指令 ; 后台进程 & 逻辑 || && <?php #?1=123%0apwd $rse = "e 阅读全文
posted @ 2021-01-13 11:19 nnnnn_0c0 阅读(240) 评论(0) 推荐(0)
摘要:任意文件读取: 读../../../../../etc/passwd 然后提取passwd第一列 读history:../../../../..//root/.bash_history 爆破一下../../../../../../home/$root$/.bash_history 阅读全文
posted @ 2021-01-06 17:47 nnnnn_0c0 阅读(638) 评论(0) 推荐(0)
摘要:目录-未授权访问获取敏感信息 /actuator/actuator/archaius/actuator/auditevents/actuator/beans/actuator/conditions/actuator/configprops/actuator/env/actuator/features 阅读全文
posted @ 2021-01-06 17:42 nnnnn_0c0 阅读(1262) 评论(0) 推荐(0)