<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>未授权 &#8211; ChaBug安全</title>
	<atom:link href="/tags/%E6%9C%AA%E6%8E%88%E6%9D%83/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Fri, 23 Aug 2019 01:27:11 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>redis 未授权 getshell</title>
		<link>/web/369.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Tue, 06 Mar 2018 09:19:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[redis]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[未授权]]></category>
		<guid isPermaLink="false">/?p=273</guid>

					<description><![CDATA[开学了，文章更新会慢，见谅。 @X1r0z原文 利用 redis 获取 webshell 端口 6379 server telnet 连接 redis 配置里有 dir 和 dbf...]]></description>
										<content:encoded><![CDATA[<blockquote><p>开学了，文章更新会慢，见谅。<br />
<a href="https://exp10it.cn/index.php/archives/1052/">@X1r0z原文</a></p></blockquote>
<p>利用 <span class="wpcom_tag_link"><a href="/tags/redis" title="redis" target="_blank">redis</a></span> 获取 web<span class="wpcom_tag_link"><a href="/tags/shell" title="shell" target="_blank">shell</a></span></p>
<p>端口 6379</p>
<p>server<br />
<img title="1.jpg" src="/wp-content/uploads/2018/03/1863303020.jpg" alt="1.jpg" /><br />
telnet 连接</p>
<p>redis 配置里有 dir 和 dbfilename</p>
<p>dir 存储路径 dbfilename 存储文件名<br />
<img title="2.jpg" src="/wp-content/uploads/2018/03/3775888799.jpg" alt="2.jpg" /><br />
save 保存<br />
<img title="3.jpg" src="/wp-content/uploads/2018/03/2062167655.jpg" alt="3.jpg" /><br />
写 webshell</p>
<p>config set dir 路径<br />
config dbfilename 文件名<br />
set web 内容<br />
save<br />
<img title="4.jpg" src="/wp-content/uploads/2018/03/1393395390.jpg" alt="4.jpg" /><br />
访问 info.php<br />
<img title="5.jpg" src="/wp-content/uploads/2018/03/230823239.jpg" alt="5.jpg" /><br />
另外 config set 不存在的 dir 会报错<br />
<img title="6.jpg" src="/wp-content/uploads/2018/03/184389156.jpg" alt="6.jpg" /><br />
可以写个脚本爆破路径</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
