This article is a mirror article of machine translation, please click here to jump to the original article.

View: 16377|Reply: 1

[Security Vulnerability] Infiltrate the big blue bird in Jinbei (Quancheng Main School)

[Copy link]
Posted on 12/24/2014 5:11:24 PM | | | |
Target Sites:www.0531accp.com

According to personal infiltration habits, the first step after taking the site is to scan the directory
First scan with the Imperial Sword as follows:

The resulting directory has robots check out what sensitive directories are available



At a glance, you can tell that it is a dream weaver
Watching the login background



Getting a cms is DedeCMSV57_GBK_SP1
I went online to find some versions of 0day, but it has been blocked by the administrator.




Download it and take a look


Open it and see:




As a rule of thumb, take a look at these two file directories







Found a username and Dreamweaver special encrypted ciphertext, say change the ciphertext, and encrypt it to 20
How to crack it? That is, remove the first three characters of the ciphertext and the last character, get a 16-bit encrypted MD5 encrypted ciphertext, and then get it to the MD5 online decryption website to decrypt it.



After obtaining the ciphertext through decryption, log in to the background





Previous:【Easy language】Mobile phone remote monitoring management source code and modification tutorial
Next:Christmas Eve "Wuhan Optics Valley Plaza" is dressed up
Posted on 12/24/2014 9:42:19 PM |
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com