|
CGI漏洞(12) 例如:count -h www.foo.bar -d 127.0.0.1:0 -v 22 用Count.cgi看图片 http://attacked.host.com/cgi-bin ... ath_to_gif/file.gif
(发帖时间:2003:9:15 07:39:30) ---玟ζ玟 (3): 二十三.finger.cgi lynx  http://www.victim.com/cgi-bin/finger?@localhost 得到主机上登陆的用户名. 二十四.man.sh Robert Moniot found followung. The May 1998 issue of SysAdmin Magazine contains an article, "Web-Enabled Man Pages", which includes source code for very nice cgi script named man.sh to feed man pages to a web browser. The hypertext links to other man pages are an especially attractive feature. Unfortunately, this script is vulnerable to attack. Essentially, anyone who can execute the cgi thru their web browser can run any system commands with the user id of the web server and obtain the output from them in a web page. 二十五.FormHandler.cgi 在表格里加上 你的邮箱里就有/etc/passwd 二十六.JFS 相信大家都看过"JFS 侵入 PCWEEK-Linux 主机的详细过程"这篇文章,他利用photoads 这个CGI模块攻入主机. 我没有实际攻击过,看文章的理解是这样 先lynx " http://securelinux.hackpcweek.com/photoads/cgi-bin/edit.cgi?
|