終端技巧 終端機常見繞過沙盤方法

1.命令:win+R win+D ctrl+P
2.找“關于”信息調(diào)用IE。文件、打開、C:\WINDOWS\system32\cmd.exe
3.XSS彈窗調(diào)用IE。如<script>window.open(/s/)</script>
4.文字頁面,ctrl+P,打印機。
5.輸入法,虛擬鍵盤。
6.四個腳亂按 可能會出現(xiàn)開始菜單(順序:上左右,下右左)
長按某處,會出屬性對話框
雙擊某處,會出現(xiàn)登陸界面
7.故意輸入錯誤的不符合業(yè)務邏輯的數(shù)據(jù),也有一定概率繞過
8.找圖片, 然后長按住圖片。。效果相當于鼠標右鍵
一般來說,直接運行命令行是幾乎不行的。
flash頁面、打印機、輸入法是常用的
相關文章
- 昨晚跟@Sunshine 請教了下終端機的玩法,順便翻了翻資料??偨Y了以下的幾種方法2013-06-19
Wysi Wiki Wyg 1.0 (index.php c) Local File Inclusion Vulnerability
--== ========================================================= ==-- --== Wizi Wiki Wig Local File Inclusion Vulnerability ==-- --== =============2008-10-08File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities
| File Store PRO 3.2 Blind SQL Injection | |________________________________________| Download from: http://upoint.info/cgi/demo/fs/filestore.zip2008-10-08Facebook Newsroom CMS 0.5.0 Beta 1 Remote File Inclusion Vulnerabi
##################################################################### # # Facebook Newsroom Application Remote File Inclusion Vulnerability # ######2008-10-08DreamNews Manager (id) Remote SQL Injection Vulnerability
######################################################### # # dreamnews ( rss) Remote SQL Injection Vulnerability #================================2008-10-08gapicms 9.0.2 (dirDepth) Remote File Inclusion Vulnerability
###################################################################################################### gapicms v9.0.2 (dirDepth) Remote File Inclusion Vulner2008-10-08phpDatingClub (website.php page) Local File Inclusion Vulnerabilit
######################################################### # # phpDatingClub Local File Include Vulnerability #=====================================2008-10-08Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Expl
<html> <body> <object classid=clsid:32E26FD9-F435-4A20-A561-35D4B987CFDC id=target /> </object> <script language=javascript2008-10-08Quicksilver Forums 1.4.1 forums[] Remote SQL Injection Exploit
<?php /* . vuln.: Quicksilver Forums 1.4.1 (forums[]) Remote SQL Injection Exploit . download: http://www.quicksilverforums.com/ . . author: irk4z[2008-10-08IntelliTamper 2.07 HTTP Header Remote Code Execution Exploit
/** ** ** IntelliTamper 2.07 Location: HTTP Header Remote Code Execution exploit. ** ** Based on exploit by Koshi (written in Perl). This one should be2008-10-08