Lysithea @ 2023-11-07 23:23:22 👍0
日志在默认路径/var/log/nginx/access.log,可以日志挂马
yUjdjasdjJ_ @ 2023-09-07 23:23:22 👍0
http://82.157.146.43:12265/?file=php://filter/convert.base64-encode/resource=flag.php
可通过日志挂马和php://filter伪协议来获取flag 日志挂马:/var/log/nginx/access.log成功访问,在user agent添加一句话木马,通过蚁剑连接 php://filter伪协议:php://filter/read=convert.base64-encode/resource=flag.php,再base64解码即可