<p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">脚本功能与优点：</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">一句话：记录用户对程序的访问日志，就这么简单。然而这个日志被人修改过：a、后缀名可控制 b、日志内容可控制 c、是否生成日志可控制 d、免杀</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">脚本研究综述：</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">1、利用xss打cookie的一点知识；</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">2、利用程序访问日志记录的一点知识；</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">3、利用php脚本的一些神奇特点(如单引号与双引号有何区别)等；</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">4、大家在修缮脚本的时候也可<a href="https://www.laimooc.cn/" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;">以放大你的脑洞就和打ctf那般</a>，祝高升~</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">研究思路过程：</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">正常的日志文件一般就是：用如下FINECMS举例:访问控制、日志的特点、print。一个日志文件就是这么简单，大家也可以用这个文件进行修改。鄙人用的是另一个文件，日志的特点写在了一个类文件中。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5353 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/1-2.png" alt="" width="712"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">如下我的：</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5354 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/11-2.png" alt="" width="684"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">其实我这两个脚本之间还有很大的不足，但是交给大家修改吧：比如require_once 可以用include；class文件可以把功能都利用起来或者并入log文件；get换成post或者其他等。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">Class文件完整版研究如下：</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5355 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/2-2.png" alt="" width="716"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">Log文件见附件，核心，哈哈。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">脚本运用演示：</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">1】先来一张D盾 主机卫士 安全狗共同扫描的结果图示：</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5356 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/3-2.png" alt="" width="721"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">2】正常运行日志脚本</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5357 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/4-2.png" alt="" width="624"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">是不允许的。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">3】带入访问控制参数访问日志脚本（log.php?c=1）</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5358 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/5-2.png" alt="" width="685"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">会发现有txt后缀的日志文件生成。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">4】带入后缀名控制参数访问日志脚本</strong>（log.php?c=1&php=.php）</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5359 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/6-2.png" alt="" width="693"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">5】带入内容控制参数访问日志脚本</strong>{（log.php?c=1&php=.php）（POST：content=<?php phpinfo()?>）}</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5360 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/7-2.png" alt="" width="713"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">访问生成的脚本试试看（生成格式log_日期.txt.php: log_20171014.txt.php）,对于日志生成的位置我是控制在了网站根目录</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5361 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/8-2.png" alt="" width="718"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><strong style="margin: 0px; padding: 0px; list-style-type: none;">6】content参数用一句话试试看</strong></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" style="margin: 0px; padding: 0px; list-style-type: none; color: rgb(66, 139, 202); text-decoration-line: underline;"><img class="aligncenter wp-image-5362 size-full" src="http://www.secist.com/wp-content/uploads/2017/10/9-2.png" alt="" width="723"  style="margin: 0px auto; padding: 0px; list-style-type: none; max-width: 100%; height: auto; vertical-align: middle; border: 0px; text-align: center; display: block;"/></a></p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">Success。此处有挑战：生成的日志文件会被干掉，因为你直接php脚本里面是最直接的一句话，so。It’s Not bypass.&nbsp;</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;">成品在此。</p><p style="margin-top: 20px; margin-bottom: 20px; list-style-type: none; color: rgb(85, 85, 85); font-family: "Microsoft Yahei", "Helvetica Neue", Helvetica, Arial, sans-serif;"><span style="color:#428bca"><span style="text-decoration:underline;"><a href="https://bbs.ichunqiu.com/thread-28060-1-1.html?from=jk" target="_self">&nbsp;laimooc_log.zip</a></span></span></p><p><br/></p>