The source code is for testing only and should not be used commercially. The source code comes from the Internet. If there is any infringement, please contact me to remove it.
渗透测试指导之下载
  • attack scenarios

  1. Download without defense

    Description:

    Many application systems or components provide file download functions, such as downloading templates, executable files, etc. If the background code is not filtered, you can directly use directory jumpers (such as../ or..\) Changing the file download path allows the arbitrary download of files from the server (such as source code, configuration files and other sensitive information files).

    Test method:

    First, look for all links that can download files. For example, you can catch the following links, such as 127.0.0.1/test/test.php? file=test.png, pay attention to the value test.png of the file parameters (most names are filename,page,javascript:open, etc.), which is obviously directly associated with a static resource. If the background code is not filtered, you can download any file on the server through directory jump, such as the passwd file on the Linux system, the boot.ini file on the windows system, the website source code, etc.

    For example:file=../../../../ etc/passwd

Other test methods:

Truncate read files../../../../ etc/passwd.jpg

File name bypass modifies the file name in the request message The requested URL/upload/supplier/.../.../.../was not found on this server. etc/passwd

2.Bypass download defense mechanisms

Description:

Some background code filters downloaded files, but it is not rigorous, only filters../ or..\ etc., at this time you can bypass it through various coding changes.

Such as:

  • impact

This may cause attackers to arbitrarily download server files, application system code, etc.

read more
Resource download
PriceFree
The use is limited to testing, experiments, and research purposes. It is prohibited for all commercial operations. This team is not responsible for any illegal behavior of users during use. Please self-test all source codes! There is no guarantee of the integrity and validity of your source code. All source code is collected from the entire network
Original link:https://bcbccb.cn/en/11572.html, please indicate the source for reprinting. Disclaimer: This resource has not been authorized by the original rights holder and is not commercially available. It can only be used to learn and analyze the underlying code, CSS, etc., and is prohibited for commercial purposes. Any relevant disputes and legal liabilities arising from unauthorized commercial use shall be fully borne by the user. Everyone is responsible to support genuine copies. Please delete them within 24 hours after downloading. Thank you for your support!
1

Comments0

新物联网卡管理平台源码
New Internet of Things card management platform source code
Someone bought it 10 minutes ago Go and have a look

Site Announcements

The source code (theme/plug-in/application source code) and other resources provided by this site are only for learning and exchange

Commercial use is prohibited, otherwise all consequences will be borne by the downloading user!

Some resources are collected or copied online. If they infringe on your legitimate rights and interests, please write to us.

Currently, members have a big reward, and the current price for a lifetime member is 299 gold coins.Recent price adjustments

Join quickly, opportunities wait for no one! immediately participated in

Captcha

Fast login to social accounts

en_USEnglish