Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

测试了php、asp的shell,但都无法发现密码 #14

Open
tysmlq opened this issue Apr 19, 2019 · 5 comments
Open

测试了php、asp的shell,但都无法发现密码 #14

tysmlq opened this issue Apr 19, 2019 · 5 comments

Comments

@tysmlq
Copy link

tysmlq commented Apr 19, 2019

已经测试了php和asp的shell,而且密码已经手工测试过,即使只将已知密码写入新的字典(只有这1条密码),也无法发现。更换get、post方式都无效。

@shmilylty
Copy link
Owner

shmilylty commented Apr 19, 2019 via email

@tysmlq
Copy link
Author

tysmlq commented Apr 19, 2019

传不上图片,把破解会话过程传上来了
root@kali:~/cheetah-master# python cheetah.py -u http://192.168.100.25:8000/ecshop/lq.php -p ./1.txt

[10:55:46] [INFO] the cheetah start execution
[10:55:46] [HINT] using POST request mode
[10:55:46] [HINT] setting request interval seconds 0
[10:55:46] [HINT] using dictionary-based password attack
[10:55:46] [INFO] cracking password of http://192.168.100.25:8000/ecshop/lq.php
[10:55:46] [WARN] not specify the web server or shell type
[10:55:46] [INFO] detecting server info of http://192.168.100.25:8000/ecshop/lq.php
[10:55:46] [HINT] the shell type may be php
[10:55:46] [HINT] web server may be Apache/2.4.10 (Win32) OpenSSL/0.9.8zb PHP/5.2.17
[10:55:46] [HINT] web server may be x-powered-by PHP/5.2.17
[10:55:46] [WARN] you did not specify the maximum request parameter
[10:55:46] [INFO] setting the number of request parameters 1000
[10:55:46] [INFO] opening password file ./1.txt
[10:55:46] [HINT] using password file ./1.txt
[10:55:46] [INFO] cracking password of http://192.168.100.25:8000/ecshop/lq.php
[10:55:46] [WARN] the cheetah did not find the webshell password
[10:55:46] [HINT] try to change a better password dictionary file
[10:55:46] [HINT] try to specify a smaller value of parameter -n
[10:55:46] [HINT] try to specify parameter -r for GET request
[10:55:46] [INFO] the cheetah end execution

@shmilylty
Copy link
Owner

shmilylty commented Apr 19, 2019 via email

@tysmlq
Copy link
Author

tysmlq commented Apr 19, 2019

传不上附件,已发邮件。

@shmilylty
Copy link
Owner

shmilylty commented Apr 19, 2019 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants