admin 发表于 2022-3-31 01:58:46

实战从注入点到服务器权限

<p style="margin:0cm 0cm 0.0001pt;text-align:justify;">
        <br />
</p>
<p style="font-family:等线;font-size:10.5pt;margin:0cm;text-align:justify;text-justify:inter-ideograph;">
        <span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">sqlmap</span><span style="background:white;color:#444444;">测试注入点为</span><span lang="EN-US"><a href="http://www.xxoo.cn/newsDetail.jsp?id=10" target="_blank"><span style="background:white;color:#333333;font-family:Verdana,sans-serif;">http://www.xxoo.cn/newsDetail.jsp?id=10</span></a></span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">&nbsp;mssql dba</span><span style="background:white;color:#444444;">权限,用最新版的</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">sqlmap</span><span style="background:white;color:#444444;">发现不能使用</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">--os-shell</span><span style="background:white;color:#444444;">执行命令,提示不支持,差点就放弃,后来经过多次测试,用一个旧版本可以成功执行,既然权限是</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">system</span><span style="background:white;color:#444444;">,那么问题就简单了,思路是找到</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">web</span><span style="background:white;color:#444444;">绝对路径,那么就用</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;"> dir /S /D </span><span style="background:white;color:#444444;">命令找,先用网站上传点上传一个</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">jsp</span><span style="background:white;color:#444444;">的</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">jpg</span><span style="background:white;color:#444444;">文件,然后执行</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;"> dir /S /D d:\2014050xxoo.jpg &lt;1.txt</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">这里只是举个例子,然后执行结果就在</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">system32</span><span style="background:white;color:#444444;">目录下,用</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">type</span><span style="background:white;color:#444444;">命令可以查询,我这里执行回显了如图:</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><img width="600" height="305" src="https://www.2k8.org/content/uploadfile/202203/17/1df22824.jpg" alt="1-1.jpg" style="vertical-align:middle;" /><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">注:</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;"> dir /S /D d:\2014050xxoo.jpg &lt;1.txt </span><span style="background:white;color:#444444;">这里可以分别列</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">c</span><span style="background:white;color:#444444;">、</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">d</span><span style="background:white;color:#444444;">、</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">e</span><span style="background:white;color:#444444;">都可以列,这个命令适合注入点为盲注,速度慢的时候,这个命令还是相当快速的。。</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">2014050xxoo.jpg </span><span style="background:white;color:#444444;">是通过上传点上传的</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">jsp</span><span style="background:white;color:#444444;">大马。。</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><img width="600" height="387" src="https://www.2k8.org/content/uploadfile/202203/17/1c68ef08.png" alt="1-2.png" style="vertical-align:middle;" /><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">如上图获取到网站路径,由于权限是</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">system</span><span style="background:white;color:#444444;">,可以直接用</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">copy</span><span style="background:white;color:#444444;">命令改</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">jpg</span><span style="background:white;color:#444444;">为</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">jsp</span><span style="background:white;color:#444444;">或者想要的格式</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">如图:</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><img width="600" height="378" src="https://www.2k8.org/content/uploadfile/202203/17/fe3b88eb.jpg" alt="1-3.jpg" style="vertical-align:middle;" /><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">注意:有空格和</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">&amp;</span><span style="background:white;color:#444444;">连接符的时候记得要把路径用双引号括起来,否则不成功</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">然后用</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">lcx</span><span style="background:white;color:#444444;">反弹出来,激活</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">guest</span><span style="background:white;color:#444444;">账号进服务器,内网服务器很卡,其实还可以试试</span><span lang="EN-US" style="background:white;color:#444444;font-family:Verdana,sans-serif;">sqlmap</span><span style="background:white;color:#444444;">的另一个上传方法上传,因为权限大嘛</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><span style="background:white;color:#444444;">如图:</span><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
</span><img width="599" height="356" src="https://www.2k8.org/content/uploadfile/202203/17/f667503a.jpg" alt="1-4.jpg" style="vertical-align:middle;" /><span lang="EN-US" style="color:#444444;font-family:Verdana,sans-serif;"><br />
<br />
</span><span style="background:white;color:red;">主要思路是</span><span lang="EN-US" style="background:white;color:red;font-family:Verdana,sans-serif;">type</span><span style="background:white;color:red;">出网站路径,然后</span><span lang="EN-US" style="background:white;color:red;font-family:Verdana,sans-serif;">copy jpg</span><span style="background:white;color:red;">为</span><span lang="EN-US" style="background:white;color:red;font-family:Verdana,sans-serif;">jsp</span><span style="background:white;color:red;">,有时候渗透就是这样,不比考试,只要记住一种方法把题作对</span><span lang="EN-US" style="background:white;color:red;font-family:Verdana,sans-serif;">OK</span><span style="background:white;color:red;">,渗透则需要掌握全部的方法才行啊,由于是政府网站所以没考虑进行内网渗透测试</span><span lang="EN-US"></span>
</p>
<p>
        <br />
</p>
页: [1]
查看完整版本: 实战从注入点到服务器权限