首 页文章中心黑客软件黑客动画绿色软件私服技术私服下载本站论坛
您当前的位置:黑客之家文章中心漏洞公告 → 文章内容 退出登录 用户管理
本类热门文章
相关文章
站内广告
pjblog 程序物理路径暴露漏洞
作者:黑客之家  来源:www.hackjia.com  发布时间:2007-12-23 14:02:12

减小字体 增大字体

inurl:GuestBookForPJBlog   这个是博客留言插件,百度找到这个肯定是 pjblog。
inurl:trackback.asp              搜索可以找到90%以上为pjblog
    for each x in Request.ServerVariables
      response.write("<b>" & x & "</b>: " & Request.ServerVariables(x) & "<br />")
    next
   
%>
ALL_RAW: Connection: Keep-Alive Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, */* Accept-Encoding: gzip, deflate Accept-Language: zh-cn Cookie: xiaogunSetting=; ASPSESSIONIDSACSCBRT=OIJNIKFCAMPMAICLEAAGHNCH Host: www.luffyes.com User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
APPL_MD_PATH: /LM/w3svc/281/ROOT
APPL_PHYSICAL_PATH: f:\usr\cn20280\
AUTH_PASSWORD:
AUTH_TYPE:
AUTH_USER:
CERT_COOKIE:
CERT_FLAGS:
CERT_ISSUER:
CERT_KEYSIZE:
CERT_SECRETKEYSIZE:
CERT_SERIALNUMBER:
CERT_SERVER_ISSUER:
CERT_SERVER_SUBJECT:
CERT_SUBJECT:
CONTENT_LENGTH: 0
CONTENT_TYPE:
GATEWAY_INTERFACE: CGI/1.1
HTTPS: off
HTTPS_KEYSIZE:
HTTPS_SECRETKEYSIZE:
HTTPS_SERVER_ISSUER:
HTTPS_SERVER_SUBJECT:
INSTANCE_ID: 281
INSTANCE_META_PATH: /LM/W3SVC/281
LOCAL_ADDR: 218.244.136.31
LOGON_USER:
PATH_INF /life.asp
PATH_TRANSLATED: f:\usr\cn20280\life.asp
QUERY_STRING:
REMOTE_ADDR: 123.56.213.224
REMOTE_HOST: 123.56.213.224
REMOTE_USER:
REQUEST_METHOD: GET
SCRIPT_NAME: /life.asp
SERVER_NAME: www.luffyes.com
SERVER_PORT: 80
SERVER_PORT_SECURE: 0
SERVER_PROTOCOL: HTTP/1.1
SERVER_SOFTWARE: Microsoft-IIS/6.0
URL: /life.asp
HTTP_CONNECTION: Keep-Alive
HTTP_ACCEPT: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, */*
HTTP_ACCEPT_ENCODING: gzip, deflate
HTTP_ACCEPT_LANGUAGE: zh-cn
HTTP_COOKIE: xiaogunSetting=; ASPSESSIONIDSACSCBRT=OIJNIKFCAMPMAICLEAAGHNCH
HTTP_HOST: www.luffyes.com
HTTP_USER_AGENT: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
物理路径为:APPL_PHYSICAL_PATH: f:\usr\cn20280\life.asp
2、直接删除 life.asp 文件。(如果你本地有备份的话可以使用)

[] [返回上一页] [打 印]
关于本站 - 网站帮助 - 广告合作 - 下载声明 - 友情连接 - 网站地图 - 文章投稿 - 软件发布 -