From 7e225946e5a00135c41b7f656aab3ae6de4ec2f1 Mon Sep 17 00:00:00 2001 From: Mrxn Date: Mon, 6 Jul 2020 18:04:44 +0800 Subject: [PATCH] =?UTF-8?q?add=20DEDECMS=E4=BC=AA=E9=9A=8F=E6=9C=BA?= =?UTF-8?q?=E6=BC=8F=E6=B4=9E=E5=88=86=E6=9E=90=20(=E4=B8=89)=20=E7=A2=B0?= =?UTF-8?q?=E6=92=9E=E7=82=B9(=E7=88=86=E7=A0=B4=EF=BC=8C=E4=BC=AA?= =?UTF-8?q?=E9=80=A0=E7=AE=A1=E7=90=86=E5=91=98cookie=E7=99=BB=E9=99=86?= =?UTF-8?q?=E5=90=8E=E5=8F=B0getshell?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- README.md | 2 + tools/dede_funcookie.php | 88 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 90 insertions(+) create mode 100644 tools/dede_funcookie.php diff --git a/README.md b/README.md index 2785041..42608ca 100644 --- a/README.md +++ b/README.md @@ -408,6 +408,7 @@ - [cloud-ranges-部分公有云IP地址范围](https://github.com/pry0cc/cloud-ranges) - [sqltools_ch-sqltools2.0汉化增强版](./ttools/sqltools_ch.rar) - [railgun-poc_1.0.1.7-多功能端口扫描/爆破/漏洞利用/编码转换等](./tools/railgun-poc_1.0.1.7.zip) +- [dede_funcookie.php-DEDECMS伪随机漏洞分析 (三) 碰撞点(爆破,伪造管理员cookie登陆后台getshell](./tools/dede_funcookie.php) ## 文章/书籍/教程相关 @@ -495,6 +496,7 @@ - [踩坑记录-Redis(Windows)的getshell](./books/踩坑记录-Redis(Windows)的getshell.pdf) - [Cobal_Strike踩坑记录-DNS Beacon](./books/Cobal_Strike踩坑记录-DNS%20Beacon.pdf) - [windows下隐藏webshell的方法](./books/windows下隐藏webshell的方法.md) +- [DEDECMS伪随机漏洞分析 (三) 碰撞点(爆破,伪造管理员cookie登陆后台getshell](./books/DEDECMS伪随机漏洞分析 (三) 碰撞点.pdf) ## 说明 diff --git a/tools/dede_funcookie.php b/tools/dede_funcookie.php new file mode 100644 index 0000000..450bc15 --- /dev/null +++ b/tools/dede_funcookie.php @@ -0,0 +1,88 @@ + \ No newline at end of file