weblogic安全漫谈

今天,我与大家探讨一下关于weblogic话题

在进入内网后,如图

当我们看到7001,我们就可以测试weblogic序列化漏洞,如图:

证明,漏洞存在查看一下权限,如图:

理论上,我们可以执行任意Linux命令了,但是,这样,好像不太好玩,如果非拿系统shell怎么办?Upload,对。

那么,我们怎么使一个upload

具体思路如下:

1.find / -name *.jsp

2. find / -name index.jsp

3.ssh破解root密码

4.破解系统后台密码

1.按照正常的思路,找到jsp执行路径,直接上传jsp后门如图:

/opt/Oracle/Middleware/wlserver_10.3/samples/server/docs/core/result.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/JWS_WebService.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/ExamplesUtils.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/Wsdl2Service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/extServletAnnotationsEar/extServletAnnotations.war/loginForm.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/extServletAnnotationsEar/extServletAnnotations.war/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/extServletAnnotationsEar/extServletAnnotations.war/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/asyncServletEar/asyncServlet.war/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/asyncServletEar/asyncServlet.war/logout.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/asyncServletEar/asyncServlet.war/main.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/asyncServletEar/asyncServlet.war/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/mainWebApp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webservices/jws_basic/simple/JWS_WebService.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webservices/jaxws/wsat/WsatBankTransfer.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webservices/wsdl2service/client/Wsdl2Service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/servlets/annotations/extension/loginForm.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/servlets/annotations/standard/loginForm.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/servlets/async/logout.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/servlets/async/main.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsf/basic/CustomerSearch.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/expressions/Expressions.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/tags/simple/SimpleTag.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/tags/simple/jspSimpleTagEar/jspSimpleTagWar/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/tags/simple/jspSimpleTagEar/jspSimpleTagWar/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/tags/simple/jspSimpleTagEar/jspSimpleTagWar/SimpleTag.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/jsp/tags/taghandler/TagHandler.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockEar/stockWar/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockEar/stockWar/publisher.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockWar/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockWar/publisher.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/splitdir/helloWorldEar/helloWebApp/hello.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jms/distributedDestination/signIn/src/main/webapp/response.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/spring/sconfig/WEB/web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/spring/sconfig/WEB/web/sayhello.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb20/basic/beanManaged/EJBeanManagedClient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb20/basic/beanManaged/ejb20BeanMgedEar/ejb20BeanMgedWar/EJBeanManagedClient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb20/basic/beanManaged/ejb20BeanMgedEar/ejb20BeanMgedWar/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb20/basic/beanManaged/ejb20BeanMgedEar/ejb20BeanMgedWar/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/common_service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/populateDB.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/showSpecificMusic_session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/addReview_service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/mdb.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/addBooks_session_ejb21.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/createArtist_session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/common_session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/viewCode.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/createArtist_service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/addReview_session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/transaction.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/showBooks_service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/showBooks_session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/exception.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/showSpecificMusic_service.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/xml/stax/StreamParserClient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/xml/xmlbean/xmlBean.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/xml/xmlbean/xmlBeanEar/xmlBeanWar/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/xml/xmlbean/xmlBeanEar/xmlBeanWar/xmlBean.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/xml/xmlbean/xmlBeanEar/xmlBeanWar/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/Edit.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/Search.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/Error.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/Patients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/Edit.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/Search.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/Error.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/Patients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/jdbcRowSetsEar/jdbcRowSetsWar/Confirmation.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/jdbc/rowsets/Confirmation.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/sslclient/SnoopServlet.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/loginapp/loginWar/loginerror.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/loginapp/loginWar/loginform.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/loginapp/loginWar/loginapp.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/targetapp/targetWar/target_cnm.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/targetapp/targetWar/defaulturl.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/security/samlsso/targetapp/targetWar/target.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/cluster/sessionrep/inmemrep/Session.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/common/base/webapp/ExamplesUtils.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/common/base/webapp/ExamplesHeader.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/common/base/webapp/ExamplesFooter.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/assembly/target/exploded/physician/physician-web/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/war/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/physician/web/target/exploded/physician-web/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/physician-web/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/physician/physician-web/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/login.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/viewRecordCreationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/addPrescription.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/createRecord.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/viewPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/physician/web/war/physician/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/viewPatientRegistrationResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/admin/viewApprovalResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/admin/home.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/admin/viewNewlyRegisteredPatients.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/admin/viewNewlyRegisteredPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/patient/viewRecordSummary.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/patient/viewLoginResult.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/patient/viewPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/patient/viewRecordDetail.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/loginPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/loginAdmin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/registerPatient.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/convergence/client/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/convergence/client/submit_profile.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/genericRegistrar/list.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/genericRegistrar/dump.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/terminating_proxy/b2bua/terminateAll.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/terminating_proxy/b2bua/terminateCall.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/terminating_proxy/b2bua/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/terminating_proxy/b2bua/admin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/registrar/list.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/registrar/dump.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/conf.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/list.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/dump.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/start_conf.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/convergence/client/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/convergence/client/src/submit_profile.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/genericRegistrar/src/list.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/genericRegistrar/src/dump.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/terminating_proxy/b2bua/src/terminateAll.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/terminating_proxy/b2bua/src/terminateCall.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/terminating_proxy/b2bua/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/terminating_proxy/b2bua/src/admin.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/registrar/src/list.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/findme/src/conf.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/findme/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/findme/src/start_conf.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/standalone_layout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/domainHealthTable.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/twoTablesLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/twoTablesWithButtonsLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/policyEditorLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/formAndTableLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configNoTransactAndTables_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/tablePreferencesLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/policyEditorLayoutNoMethods.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/formWithButtonsLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configBaseLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/assistantNoFieldsLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/webAppAndModulePolicyEditorLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/assistantBaseLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/tableBaseMonitoringLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/assistantTreeEditor.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/summarypage.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/roleEditorLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configBaseLayoutNoTransact.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/fourTablesLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/rootLevelPolicyEditorLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configTreeEditor.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/roFormAndTableLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/threeTablesLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/deploymentDependenciesTreeLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/tableBaseLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/deploymentVariableLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/roForm.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/filterAndTableLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/webAppAndModuleRoleEditorLayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configNoFieldsLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configIntroLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/assistantFormAndTableLayout_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/webapp/layouts/configBaseLayoutWithButtons_netui.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/page.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/buttondelete.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/theme.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/togglebutton.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/flowlayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/abstractbutton.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/twocollayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/body.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/shell.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/window.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/titlebar.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/borderlayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/book.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/nolayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/buttonfloat.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/footer.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/abstractmenu.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/placeholder.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/head.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/multilevelmenu.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/gridlayout.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/header.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/singlelevelmenu.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/framework/skeletons/console/desktop.jsp

,好多jsp执行路径啊,那我们选一个执行路径来上传

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/index.jsp

上传之后,你会发现,无论如何在执行的时候,他都会直接跳转到正常页面

上传页面:http://10.80.1.61:7001/console/consolehelp/abc.jsp

正常页面http://10.80.1.61:7001/console/login/LoginForm.jsp

说明代码设置了错误自动重定向,怎么改,我也改不来。

那么,没办法咯~

2. 按照正常的思路,找到index.jsp执行路径,直接修改index.jsp如图:

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/examplesWebApp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/build/mainWebApp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockEar/stockWar/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/webapp/pubsub/stock/stockWar/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/spring/sconfig/WEB/web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/examples/src/examples/ejb/ejb30/src/jsp/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/assembly/target/exploded/medrec/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/war/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/modules/medrec/web/target/exploded/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/modules/exploded/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec/dist/standalone/exploded/medrec/medrec-web/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/server/medrec-spring/modules/medrec/web/war/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/convergence/client/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/terminating_proxy/b2bua/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/build/findme/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/convergence/client/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/terminating_proxy/b2bua/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/samples/sipserver/examples/src/findme/src/index.jsp

/opt/Oracle/Middleware/wlserver_10.3/server/lib/consoleapp/consolehelp/index.jsp

其实,你会发现,只要代码设置了错误自动重定向无论你怎么修改基本没戏。

也就是代码设置了错误自动重定向,上传=修改。

3. 按照正常的思路,ssh,破解root密码的话Linux主机reboot,不够隐蔽,那么,我们就不要这样做了。

4.破解系统后台密码,研究了下,后台不能shell

山重水复疑无路~

研究下3,发现其实,只要2条件就可以远程管理系统

1.新建一个/etc/passwd文件不含x

2.新建一个ssh文件,开22

Reboot Linux完成

也,可以回到从前http://10.80.1.61:7001/console/login/LoginForm.jsp如图:

我们想LoginForm.jsp替换成我们自己的后文件vim编辑修改不了代码那么,我们可以采用覆盖替换的方式来实现。

但是,这里有一个问题,拿到shell之后,需要还原LoginForm.jsp代码内容,否则,涉及法律问题,后果自负

原文地址:https://www.cnblogs.com/milantgh/p/6108402.html