摘要: 任意文件读取: 读../../../../../etc/passwd 然后提取passwd第一列 读history:../../../../..//root/.bash_history 爆破一下../../../../../../home/$root$/.bash_history 阅读全文
posted @ 2021-01-06 17:47 nnnnn_0c0 阅读(618) 评论(0) 推荐(0)
摘要: 目录-未授权访问获取敏感信息 /actuator/actuator/archaius/actuator/auditevents/actuator/beans/actuator/conditions/actuator/configprops/actuator/env/actuator/features 阅读全文
posted @ 2021-01-06 17:42 nnnnn_0c0 阅读(1239) 评论(0) 推荐(0)