How to use third-party software to elevate FlashFXP privileges

WBOY
Release: 2023-05-15 16:16:18
forward
719 people have browsed it

Privilege escalation environment: windows 2003

Tools used: ASP environment, shell one

Privilege escalation idea: Using FlashFXP replacement file vulnerability, you can read the site account password linked by the administrator .

This is my first post in I Spring and Autumn.

1.flash fxp introduction

FlashFXP is a powerful FXP/FTP software that integrates the advantages of other excellent FTP software, such as CuteFTP directory comparison and supports color Text display; for example, BpFTP supports multiple directories to select files and temporary storage directories; another example is the interface design of LeapFTP.

2. Specific process

The following is the FTP software I installed in win03, there is nothing in it

Create a new link

How to use third-party software to elevate FlashFXP privileges

The linked account and password are saved in the file quick.dat

How to use third-party software to elevate FlashFXP privileges



Next open the webshell we got and download quick. dat file


How to use third-party software to elevate FlashFXP privileges

How to use third-party software to elevate FlashFXP privileges

After downloading, open FlashFTP on our local machine to extract and replace the original file. Open the local software and check the history. A miracle happened...


How to use third-party software to elevate FlashFXP privileges

A little trick for everyone:
In this way, you have obtained a permission. You can download an asterisk password viewer online, but I will not demonstrate it here.

The above is the detailed content of How to use third-party software to elevate FlashFXP privileges. For more information, please follow other related articles on the PHP Chinese website!

Related labels:
source:yisu.com
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template
About us Disclaimer Sitemap
php.cn:Public welfare online PHP training,Help PHP learners grow quickly!