本 pass 中禁止上传
.php",".php5",".php4",".php3",".php2","php1",
".html",".htm",".phtml",".pht",".pHp",".pHp5",".pHp4",".pHp3",".pHp2",
"pHp1",".Html",".Htm",".pHtml",".jsp",".jspa",".jspx",".jsw",".jsv",".jspf",
".jtml",".jSp",".jSpx",".jSpa",".jSw",".jSv",".jSpf",".jHtml",".asp",".aspx",
".asa",".asax",".ascx",".ashx",".asmx",".cer",".aSp",".aSpx",".aSa",".aSax",
".aScx",".aShx",".aSmx",".cEr",".sWf",".swf");
可是,没有禁止.htaccess,这时,我们可以上传.htaccess 文件,进行漏洞利用
(2).htaccess 文件内容
.htaccess 文件解析规则的增加,是可以按照组合的方式去做的,不过具体得
自己多测试。
第一种、虽然好用,但是会误伤其他正常文件,容易
被发现
第二种、精确控制能被解析成 php 代码的文件,不容
易被发现
第三种、简洁明了,但是也很容易被发现
利用方式:
评论0
最新资源