ååï¼ãããã¢ã㪠BadTodo - 25.1 è²ã æ··ãã¦ãã£ã¦ã¿ãï¼ï¼XSS - CSRF -WebShellï¼ - demandosigno ååãBadTodoä¸ã«WebShellãè¨ç½®ãããã¨ãã§ãã¾ããã WebShellï¼Webä¸ã§ã·ã§ã«ãåããããã¨ãããã¨ã§è²ã ãªãã¨ãã§ããããã«ãªãã¾ãã (WebShellãããã«ã¯ç¨æã§ããªãã¨ããæ¹ã¯ãé常ã®ã¿ã¼ããã«ã§ã³ãã³ããæã¤ã»ç·¨éã»ã³ãã¼ãããªã©ãã¦ãã¡ã¤ã«ã®æ¹ãã以éã ãã§ã試ãã¦ã¿ã¦ãã ãã) å¹¾ã¤ãã³ãã³ãã試ã ãã¡ã¤ã«ã®æ¹ãã 次ã«BadTodoã®Webãã¡ã¤ã«ãæ¹ãããã¦ã¼ã¶ã®å ¥åå¤ãçããããã«ãããã¨æãã¾ãããããã ãã®WebShellã¯ç°¡åãªæ©è½ãããªãããã¨ãã£ã¿ãªã©ã¯éãã¾ãã ã¯ã³ã©ã¤ãã¼ã§æ¸ãè¾¼ããã¨ãã§ãããé¢åãããâå¾æ¥ wget ã curl ã使ããã°ãå¤é¨ãããã¡ã¤ã«ãã¨ãã¦ã³ã
{{#tags}}- {{label}}
{{/tags}}