PHPת»»ROOTÉí·Ý
PHP code:
<?
/* PHPÖÐÈçºÎÔö¼ÓÒ»¸öϵͳÓû§
ÏÂÃæÊÇÒ»¶ÎÀý³Ì£¬Ôö¼ÓÒ»¸öÃû×ÖΪjamesµÄÓû§,
rootÃÜÂëÊÇ verygood¡£½ö¹©²Î¿¼
*/
$sucommand = "su --login root --command";
$useradd = "useradd ";
$rootpasswd = "verygood";
$user = "james";
$user_add = sprintf("%s \"%s %s\"",$sucommand,$useradd,$user);
$fp = @popen($user_add,"w");
@fputs($fp,$rootpasswd);
@pclose($fp);
?>
ÇëÎÊ£ºÒ»
ͨ¹ýÉÏÊö³ÌÐò¿ÉÒÔ¼òµ¥ÊµÏÖPHPת»»ROOTÉí·Ý ´Ó¶øÖ´ÐÐROOTÃüÁî
ÎÒµÄÉϸöϵͳ¿ÉÒÔʵÏÖ µ«Êǹ¤×÷ÐèÒª ÏÖÔÚ»»ÁËRHEL5 ¾Í²»ÐÐÁË
Ìáʾ´íÎóΪ£ºstandard in must be a tty
ÊDz»ÊÇÒòΪ°²×°¹ý³ÌÖÐȱÉÙʲô¶«Î÷µ¼ÖÂÉÏÊöÎÊÌâµÄ³öÏÖ£¿
¿´¼ûÓÐÈËÉèÖÃphp.iniÀï ¹ØÓÚtty²»ÐèÒªÃÜÂë ´Ó¶ø½â¾ö µ«ÊÇ ÎÒÐèÒªºÍSHELL¶à´Î½øÐÐÊý¾Ý½»»¥
ÇëÎÊÓ¦¸ÃÊÇÄÄÀïµÄÎÊÌâÄØ£¿GOOGLEµÄÒªÍÂѪÁËҲûÕÒµ½ÂúÒâµÄ´ð°¸ Çë´ïÈËÖ¸µ¼
ÇëÎÊ£º¶þ
Èç¹ûʵÏÖÁËÉÏÊö¹¦ÄÜ ¼´²»ÔÙ³öÏÖstandard in must be a tty´íÎó ¿ÉÒÔÕý³£ÊäÈëpasswd
ת»»Éí·Ý ÄÇôÄܲ»ÄÜʵÏÖ@fputs($fp,$rootpasswd); µÄÁ¬Ðøµ÷Óà ÒÔ´«µÝ¸øshellÁ¬ÐøµÄÐÅÏ¢£¿
Èç¹û²»ÄÜ Ó¦¸Ã²ÉÓñðµÄÄÄÖÖ·½·¨ ʹPHP¶Ë¿ÉÒÔºÍSHELL½øÐжà´ÎÁ¬ÐøµÄÊý¾Ý½»»¥£¿
·¹ýµÄ°ïæ¶¥Æð£¬²»ÄܳÁ°¡~~~
Õâ¸ö²»»á,°ï¶¥
°ïÄã¶¥Æð¡£¡£¡£
ÎÊÏÂÂ¥Ö÷£¬Èç¹û±àдPHPÖ´ÐÐshellÃüÁÈçshutdown£¬ÈçºÎÅä
Ïà¹ØÎÊ´ð£º
ÎÒÓÃPHPÀ©Õ¹Cʱ£¬ÓõÄÊÇÔ´ÂëextĿ¼ÏµÄ./ext_skel
×îºó±àÒë×ÜÊDz»ÄÜÉú³ÉÀ©Õ¹Ä£¿éµÄ.so¶¯Ì¬¿â£¬ÎÒÓõİ汾ÊÇ5.3.0£¬
ÕâÊÇÔõô»ØÊ£¬¸ßÊÖ½â´ðÏÂ
²»ÄÜÉú³ÉʱÓÐɶÌáʾÐÅÏ¢£¿
ÔËÐÐÁË/ext_skel --extname=Ä ......
<?php
if($_SERVER['HTTP_REFERER']!=''){
@header("Content-type:image/jpeg");
echo file_get_contents("xlight.jpg");
}
else{
@header("location:ht ......
¹«Ë¾Ãû³Æ Ò½ÔªÍø
ְλÃû³Æ PHP¿ª·¢¸ß¼¶¹¤³Ìʦ
ÕÐÆ¸ÈËÊý 1
¹¤×÷µØµã ÉϺ£
нˮ´ýÓö ÃæÒé
µç×ÓÓÊÏä zik@yynet.cn
¹«Ë¾ÍøÖ· http://www.yynet.cn
¹«Ë¾½éÉÜ Ò½ÔªÍø-רעҽ»¼»¥¶¯£¬¼ÜÆðÒ½»¼ ......
webclient.phpÎļþ£º
<?php
$arrOptions = array( 'uri'=>'http://10.10.19.111/','location'=>'http://10.10.19.111/webservice/webservice.php','trace' ......
PHPÖÐtitleÈçºÎ¶¯Ì¬ÏÔʾµ±Ç°ÎÄÕµıêÌâ?
ÔÚtitleÖÐÿƪÎÄÕ¶¼ÊÇÏÔʾͬÑùµÄÄÚÈÝ.ÏëÈÃËû¶¯Ì¬ÏÔʾ.²»ÖªµÀÒªÈçºÎд²ÅÄܶ¯Ì¬ÏÔʾµ±Ç°ÎÄÕµıêÌâÄØ?
лл
PHPÖÐtitle£¿Ã»Ã÷°×£¬ÊDz»ÊÇHTMLµÄtitle°¡
Èç¹ûÊǵϰ£¬Äã¿ÉÒÔ ......