iisÎÞ·¨ä¯ÀÀaspÎļþ½â¾ö·½·¨
Ò»´óÔçÆðÀ´×°IIS¡£ÏÖÔÚÖÕÓÚ×°ºÃÁË¡£Ê®·Ö¸ÐлÒÔϵIJ©ÎÄ£¬ÌØת¹ýÀ´·ÖÏí :)
תÖÁ£ºhttp://blog.sina.com.cn/s/blog_50070c4c0100bkq6.html
ÿÿװIIS£¬×Ü»áÅöµ½ÕâÑùÄÇÑùµÄÎÊÌ⣬´ÓÄ¿Ç°·´Ó¦Çé¿öÀ´¿´£¬IIS°²×°ºó¿Éä¯ÀÀHTML¾²Ì¬Îļþ£¬È´ÎÞ·¨ä¯ÀÀaspΪºó׺µÄ¶¯Ì¬Ò³Ãæ¡£
ͨ¹ý¼¸´Îµ÷ÊÔºó£¬ÕÒµ½ÒÔϼ¸ÖÖ·½·¨£¬ÕâЩ·½·¨¶¼²Î¿¼ÍøÂç¸÷¸ö½éÉÜ£¬²¢Í¨¹ýÁ˱¾È˵IJâÊÔ¡£Ï£ÍûÄܸø´ó¼Ò¼õÉÙIIS°²×°¹ÊÕÏ´øÀ´µÄ·³ÄÕ¡£
Ò»°ãÀ´Ëµ£¬¶ÔÓڴ˹ÊÕÏͨ³£¶¼·¢ÉúÔÚÕâôһÖÖÇé¿ö£¬¼´windows xp ghost°æ±¾¡£ºÜÈÝÒ×Àí½â£¬ghostÖÆ×÷·½Í¨³£ÎªÁ˸øϵͳ¼õ·Ê£¬°ÑÆÕͨÓû§²»ÐèÒªµÄ·þÎñ¸øÍ£Ö¹ÁË£¬½á¹ûµ¼Öµ±ÎÒÃÇÐèҪʹÓÃһЩ²»³£ÓõķþÎñʱ£¬È´ÔõôҲ²»ÄÜÕý³£¡£ËùÒÔ£¬¶Ô´ó¶àÊý³õѧÕßÀ´Ëµ£¬Èç¹ûÄãÏëʹÓÃIIS£¬ÄÇôÄãʹÓð²×°°æµÄ²Ù×÷ϵͳ±È½Ï·½±ã¡£
¶ÔÓÚaspÎļþÎÞ·¨´ò¿ª£¬htmlÈ´ÄÜÕý³£ä¯ÀÀ£¨Çë×¢Òâ´ËÌØÕ÷£¬²»ÒªÓëÆäËû´íÎó»ìÏý£©£¬Äã¿ÉÒÔ¿¼ÂÇÒÔÏÂÁ½ÖÖÇé¿ö¡£
Ò». ѸÀ×ÈǵĻö¡£
Èç¹ûѸÀ×´ò¿ªÁË£¬IIS¾Í»áʧЧ¡£ÒòΪѸÀ×»áÕ¼ÓÃϵͳ80¶Ë¿Ú£¬¶øIISµÄĬÈ϶˿ھÍÊÇ80£¬ËùÒÔ£¬ÓÐÈ˵±×ÅÄã¼ÒÃÅ¿Ú£¬Ä㵱Ȼ½ø²»È¥ÁË£¬ÊÂÇéºÃ°ì£¬°ÑѸÀ×Í˳ö¾ÍOKÁËÂï¡£
¶þ. windows©¶´²¹¶¡ËùÖ¡£
Ê×ÏÈ£¬Äã¼ì²éÏÂÊÇ·ñ°²×°ÁËKB939373²¹¶¡£¬¸üÐÂÎļþWindowsXP-KB939373-x86-CHS.exe²¹¶¡»áµ¼ÖÂaspÎļþÎÞ·¨Õý³£ÔËÐеġ£½â¾ö·½·¨£¬¿ªÊ¼——¿ØÖÆÃæ°å——Ìí¼Óɾ³ý³ÌÐò °ÑÏÔʾ¸üÐÂÑ¡ÉÏ£¬È»ºóÕÒµ½KB939373,жÔؼ´¿É¡£
KB939373£¬ÓÃÓÚ·ÀÖ¹¹¥»÷Õß¿ÉÄÜ»áÔ¶³ÌÀûÓôËÎÊÌâΣ¼°Ê¹Óà Internet ÐÅÏ¢·þÎñ (IIS) µÄ Windows ϵͳµÄ°²È«²¢»ñÈ¡¶Ô¸ÃϵͳµÄ¿ØÖÆȨµÄ·À·¶£¬µ«Õâ²¹¶¡ºÃÏñ±¾Éí¾ÍÓÐÎÊÌâ¡£
Èý. COM+Ó¦ÓóÌÐò´íÎó£¬Õâ¸öÆäʵÎÒҲûȥŪÇå³þ£¬ÒòΪÎÒÒ²ÊÇ°´ÕÕ±ðÈ˵ķ½·¨°´²½Åųý³öÀ´µÄ¡£ÏÂÃæÊDZðÈ˵IJ½Ö裬ÎÒ½èÓÃһϡ£
IIS·þÎñÆ÷³öÏÖ´íÎóµÄÔÒòºÜ¶à£¬Çë³¢ÊÔÒÔϲÙ×÷£º
1¡¢²é¿´ÍøÕ¾ÊôÐÔ——Îĵµ
¿´¿´ÆôÓÃĬÈÏÎĵµÖÐÊÇ·ñ´æÔÚ£ºindex.asp index.htm index.html (×îºÃÈ«¶¼ÓУ¬Ã»ÓпÉÌí¼Ó)
2¡¢²é¿´ÍøÕ¾ÊôÐÔ——Ö÷Ŀ¼
A¡¢±¾µØ·¾¶ÊÇ·ñÖ¸¶¨ÕýÈ·
B¡¢ÊÇ·ñ¹´Ñ¡“½Å±¾×ÊÔ´·ÃÎ
Ïà¹ØÎĵµ£º
asp³£ÓõÄÕýÔò±í´ïʽʵÏÖ×Ö·û´®µÄÌæ»»,Ö÷Òª°üÀ¨È¥³ýhtml±êÇ©£¬È¥³ýclass±êÇ©ºÍÈ¥³ýscript±êÇ©µÈ
È¥³ýhtml±êÇ©ÕýÔò<\/*[^<>]*>
Function LoseHtml(ContentStr)
Dim ClsTempLoseStr,RegEx
ClsTempLoseStr = Cstr(ContentStr)
Set RegEx = New RegExp
RegEx.Pattern = "<\/*[^<>]*>"
......
using System;
using System.Data;
using System.Configuration;
using System.Linq;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.HtmlControls;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Xml.Linq;
namespace W ......
ÏÖÔڱȽÏÁ÷ÐеÄSQL×¢È빤¾ßµÄ¹¤×÷·½Ê½ÊÇͨ¹ýGETºÍPOSTÀ´Íê³É¾ßÌåµÄ×¢Èë¡£ÎÒÃÇ¿ÉÒÔ½«×¢ÈëʱËùÓõ½µÄÒ»ÇзûºÅ¹ýÂ˵ô¡£ÄÇôÎÒÃÇ¿ÉÒÔͨ¹ý¼òµ¥µÄÅжÏÓï¾äÀ´´ïµ½Ä¿µÄ¡£ÎÒÃÇÏÈÀ´¹ýÂËGET°É¡£
´úÂëÈçÏ£º
dim sql_injdata SQL_inj SQL_Get
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|mast ......
ÏÂÔصØÖ·£º/download/rar/tot-cms-5.5(sp2).rar
꿅᣼http://www.totcms.com/html/200910-30/20091030001212.htm
¸üÐÂ˵Ã÷£º
1¡¢Ôö¼ÓÁË×Ô¶¨Ò庯Êý¹¦ÄÜ£¬Ö»Òª¹ÜÀíÔ±ÊìϤSQL²éѯ£¬¾Í¿ÉÒÔʹÓÃÆÕͨSQLÓï·¨²éѯÊý¾Ý¿âÉú³Éǰ̨¾²Ì¬HTM¼Ç¼¡£
2¡¢ÎÄÕÂÌí¼Ó²ÉÈ¡Á½¼¶Ä¿Â¼±£´æ£¬²»ÊÇʹÓÃÔÀ´µÄÈý²ãĿ¼·½Ê½¡£
3¡¢½â¾öÐ޸ı ......
´Ë·½·¨¿ÉÒÔ²»ÐèҪרÃÅÖÆ×÷Ä£°åÎļþ£¬Ö»ÐèÕý³£ÔËÐеĶ¯Ì¬Ò³Ãæ¼´¿É£¬¾ßÌå·½·¨ÈçÏ£¬×îÖÕʹÓüû×îºóÒ»¸öº¯Êý£º
Function getHTTPPage(url) ‘Ê×Ò³Éú³É¿ªÊ¼
dim Http
set Http=server.createobject("MSXML2.XMLHTTP")
Http.open "GET",url,false
Http.send()
if Http ......