PHPת»»ROOTÉí·Ý
PHP code:
<?
/* PHPÖÐÈçºÎÔö¼ÓÒ»¸öϵͳÓû§
ÏÂÃæÊÇÒ»¶ÎÀý³Ì£¬Ôö¼ÓÒ»¸öÃû×ÖΪjamesµÄÓû§,
rootÃÜÂëÊÇ verygood¡£½ö¹©²Î¿¼
*/
$sucommand = "su --login root --command";
$useradd = "useradd ";
$rootpasswd = "verygood";
$user = "james";
$user_add = sprintf("%s \"%s %s\"",$sucommand,$useradd,$user);
$fp = @popen($user_add,"w");
@fputs($fp,$rootpasswd);
@pclose($fp);
?>
ÇëÎÊ£ºÒ»
ͨ¹ýÉÏÊö³ÌÐò¿ÉÒÔ¼òµ¥ÊµÏÖPHPת»»ROOTÉí·Ý ´Ó¶øÖ´ÐÐROOTÃüÁî
ÎÒµÄÉϸöϵͳ¿ÉÒÔʵÏÖ µ«Êǹ¤×÷ÐèÒª ÏÖÔÚ»»ÁËRHEL5 ¾Í²»ÐÐÁË
Ìáʾ´íÎóΪ£ºstandard in must be a tty
ÊDz»ÊÇÒòΪ°²×°¹ý³ÌÖÐȱÉÙʲô¶«Î÷µ¼ÖÂÉÏÊöÎÊÌâµÄ³öÏÖ£¿
¿´¼ûÓÐÈËÉèÖÃphp.iniÀï ¹ØÓÚtty²»ÐèÒªÃÜÂë ´Ó¶ø½â¾ö µ«ÊÇ ÎÒÐèÒªºÍSHELL¶à´Î½øÐÐÊý¾Ý½»»¥
ÇëÎÊÓ¦¸ÃÊÇÄÄÀïµÄÎÊÌâÄØ£¿GOOGLEµÄÒªÍÂѪÁËҲûÕÒµ½ÂúÒâµÄ´ð°¸ Çë´ïÈËÖ¸µ¼
ÇëÎÊ£º¶þ
Èç¹ûʵÏÖÁËÉÏÊö¹¦ÄÜ ¼´²»ÔÙ³öÏÖstandard in must be a tty´íÎó ¿ÉÒÔÕý³£ÊäÈëpasswd
ת»»Éí·Ý ÄÇôÄܲ»ÄÜʵÏÖ@fputs($fp,$rootpasswd); µÄÁ¬Ðøµ÷Óà ÒÔ´«µÝ¸øshellÁ¬ÐøµÄÐÅÏ¢£¿
Èç¹û²»ÄÜ Ó¦¸Ã²ÉÓñðµÄÄÄÖÖ·½·¨ ʹPHP¶Ë¿ÉÒÔºÍSHELL½øÐжà´ÎÁ¬ÐøµÄÊý¾Ý½»»¥£¿
·¹ýµÄ°ïæ¶¥Æð£¬²»ÄܳÁ°¡~~~
Õâ¸ö²»»á,°ï¶¥
°ïÄã¶¥Æð¡£¡£¡£
ÎÊÏÂÂ¥Ö÷£¬Èç¹û±àдPHPÖ´ÐÐshellÃüÁÈçshutdown£¬ÈçºÎÅä
Ïà¹ØÎÊ´ð£º
ÎÒÓÃPHPÀ©Õ¹Cʱ£¬ÓõÄÊÇÔ´ÂëextĿ¼ÏµÄ./ext_skel
×îºó±àÒë×ÜÊDz»ÄÜÉú³ÉÀ©Õ¹Ä£¿éµÄ.so¶¯Ì¬¿â£¬ÎÒÓõİ汾ÊÇ5.3.0£¬
ÕâÊÇÔõô»ØÊ£¬¸ßÊÖ½â´ðÏÂ
²»ÄÜÉú³ÉʱÓÐɶÌáʾÐÅÏ¢£¿
ÔËÐÐÁË/ext_skel --extname=Ä ......
ʹÓÃPHPµÄexecº¯Êýµ÷ÓÃlinuxµÄshellÃüÁÈçdateÈ¥ÐÞ¸Äʱ¼ä»òshutdownȥʵÏֹػú/ÖØÆô£¬µ«ÊÇ·µ»ØÖµ¶¼ÊÇʧ°ÜµÄ¡£¾¹ý¶à´ÎÊÔÑ飬È϶¨ÊÇûÓÐȨÏÞµÄÎÊÌâ¡£
ËùÒÔ£¬Ð¡µÜÔÚ´ËÇë½Ì¸÷룬ÈçºÎ²ÅÄÜÉèÖÃȨÏÞ£¬µ÷ÓÃlinux shellà ......
<html>
<head>
<title>hello </title>
</head>
<body>
<input type="button" value="Click" onClick=" ......
ÕÐÆ¸
¹«Ë¾Ãû³Æ ʤÐÐÈí¼þ£¨ÉîÛÚ£©ÓÐÏÞ¹«Ë¾
ְλÃû³Æ PHP³ÌÐòÔ±
ÕÐÆ¸ÈËÊý 3-5
¹¤×÷µØµã ÉîÛÚÊÐÁú¸ÚÇøºá¸ÚËÄÁªÐÂÑÇÖ޹㳡ÐÂÐãÔ·B2-201
нˮ´ýÓö 4k-10k
ְλÃèÊö Ö÷Òª¸ºÔð¶ÔÈÕÍâ°üÏîÄ¿µÄÉè¼Æ£¬±àÂëºÍ ......
¿ª·¢PHPÓÃÓÃʲôÈí¼þ£¿
¶à½éÉܼ¸ÖÖ¡£
ÎÒ¶¼²»ÏþµÃ¡£¹þ¹þ¡£ºÃ¾ÍûÓÐÉÏcsdn£¬¿´¼ûÄã·¢ÁËÌù¡£×î½üÔõôÑù£¿£¿£¿
Îı¾±à¼Æ÷¶¼¿ÉÒÔµÄ
±±¾©Î弫ÐÇÐÅϢϵͳ¼¼ÊõÓÐÏÞ¹«Ë¾ÏÖÕÐÆ¸5ÃûPHP³ÌÐòÔ±¡£
ְλҪÇó£º ......