Jump to content

Title: Recording a commission earning scam to trace the source to the actual penetration of individuals

Featured Replies

Posted

When looking for TSRC assets in the Eagle Picture, when I was preparing to dig Tencent SRC, I saw the domain name of this site :qq.com.xxxx.top, the title is login 图片 The first feeling is that it is not a serious site, it should be found by the fishing station whois.图片webpack package 图片. This kind of site basically has some test accounts. I tried 18888888888888888 password 123456 图片. I saw this. This is the kind of people who earn commissions when doing tasks. The main feature is to cheat money.图片 图片 图片F12 searches for requests and js, the loaded resource file reports an error, use thinkphp but there is no hole, the IP is really available, and the background is disguised, called xxx check-in system 图片 Find other assets through fofa, the IP access is a template page for enterprise website building, add admin behind the IP and jump to the background of enterprise website building, tell the truth that this is really bad 图片 Enter the home /x again in thinkphp5.0.5, verified that there is RCE, the site that does tasks and earns commissions, has not yet carefully tested it and collected information, and found the side station and entered it. Basically, the database configuration is in data or config 图片 图片md5 decrypts the administrator password, enter the background to see other information and don’t pay much attention to it, mainly looking for site administrators 图片

图片

1. Sensitive mobile phone number is often passed through the recommendation number, which is a mobile phone number. 139xxxx2. Administrator log analysis : suspicious IP positioning is in Sichuan 3. Check WeChat through the mobile phone number and Alipay to find this person 4. Check this person through the social work library QQ, Weibo and his own photos 图片

图片

图片

图片

图片

Reprinted from the original link: https://mp.weixin.qq.com/s/9M0HEP1x-5Xt1JQeyVDrGA

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Important Information

HackTeam Cookie PolicyWe have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.