当前位置: 主页 > 日志 > 网络安全 >

improve power by ISAPI Filter

// by redice 2011.02.17
// just for study!
 
 
Usually the ISAPI run in a hight power level user.
 
Some virtual host management system support adding ISAPI Filter by client.
 
I have tested and found it can write into every web directory. 
I tested that successfully in a real web server which support adding ISAPI Filter.
 
 
Let's have a try! 
 
To protect the privacy,  now i just test it on local machine.
 
I will write a file into www.shenmafuyun.net directory from another site (on same server) www.redicecn.com.
 
 
I have wrote a ISAPI Filter for that, i name it ISAPISPY.
 
After installation, 
 
visit /isapispy/writemm.html?f=e:/wwwroot/shenmafuyun.net/help.php,
 
then a one sentence wooden horse will be written into e:/wwwroot/shenmafuyun.net/help.php,
the pass is 'cmd'.
 
 
 
enjoy yourself!  
 
Welcomt to join us!  QQ Group: 75471848
 
 
isapispy_dll.rar
isapispy_src.rar

[日志信息]

该日志于 2011-02-18 16:41 由 redice 发表在 redice's Blog ,你除了可以发表评论外,还可以转载 “improve power by ISAPI Filter” 日志到你的网站或博客,但是请保留源地址及作者信息,谢谢!!    (尊重他人劳动,你我共同努力)
   
验证(必填):   点击我更换验证码

redice's Blog  is powered by DedeCms |  Theme by Monkeii.Lee |  网站地图 |  本服务器由西安鲲之鹏网络信息技术有限公司友情提供

返回顶部