Author: angel article in Nature: Original release date: 2004-11-5 estimated that we all know this Chengdu "World Cup" contest news network security attack and defense, and since and network security related, it is estimated many of my friends want to know where Technical details, I will talk about the technical details. As for people who participated in the competition with me, they are more famous, opportunities, and the advantages are almost all of us, and I will not say it for the time being. There are also many people in the circle to know that we have participated, so I don't care if I don't care. Let me talk about the technology first, let me talk about my personal opinion. First talk about this attack environment: Web server (172.16.0.125) System: Windows Server 2003 / Apache 1.3.31 Open port: 80,3389web program: Discuz 2.2F Mysql Server (172.16.0.119) System: Windows Server 2003 / Mysql 4.0.21 Open Port: 3306, 3389 Note: The competition is not allowed to be online, all tools are tape. And the database server IP just started is unknown, our goal is to get the corresponding file of the D disk on the database. Although we have discussed several programs and division of labor, we still have some changes, I am almost responsible for attacking, others are responsible for interfering with opponents, sniffing, building a variety of services, we exchange, exchange tools Because it is not allowed to go to the Internet, we downloaded the QQ Enterprise Edition, built a web server on one of the people's servers, providing us to bring some tools, so we are guaranteed for the progress of the attack, each of us revised The default management password, disable all other system users, stop N more default services, prohibit empty connections, do local security policies, modify the IP address of the IP address, so that we are not in the same network segment, configured by others. Also almost started. After the careful configuration of safety experts, I want to directly start the possibility of the system or smaller, despite this, or allocated two people scanning the web server and generate reports, the other people sniffed a lot Sensitive information such as the password of the system, I don't say other people, because I am responsible for all attacks, I still write the process. I know that Discuz 2.2f has two fatal vulnerabilities, but the official also released the update version, I don't know if there is anything here, no matter what to say, getting WebShell is the most basic, otherwise it is impossible, just discuz 2.2f gives us Condition, visit http://172.16.0.125/forumdata/illegallog.php, return "Access Denied", the vulnerability does not exist, change one, this 2.2F version can register the same ID, but for the Chinese name of the traditional forum Registration will change, I only tested the English name, no matter, write a form first: