|
|
- 这篇文章介绍了当WordPress开启错误记录以后,根据error_log来发现SQL注入攻击的思路。- }/ c* M$ R- E0 o8 t! F: @
% J) s' f! L' F+ o) s- p吸引Cocoa的是这个博客其实是TrustWave公司下属的一个叫Spiderlab团队的官方博客,貌似比较有意思。例如它提到了Honeypot Alert这个标签里的文章都是分析他们一个Web蜜罐的Apache access_log日志的。" W' l/ E* S ?
) M3 R ^9 |4 e6 s
简单介绍一下这篇文章吧。5 P4 e$ t9 z- D& ~. L
3 _4 M! \5 P9 J9 x2 @! G+ I& x
开启WP错误记录功能& O& C$ _- a+ c6 M4 Z# C, \8 E6 a
只需要修改wp-config.php的如下几行:3 c4 b# V1 k2 S- q8 q% |$ b, i- F
4 a% }; n1 N: _2 q
@ini_set('log_errors','On'); @ini_set('display_errors','Off'); @ini_set('error_log','/home/example.com/logs/php_error.log');SQL 注入扫描
, J( q7 b' k( r% z( H, |* B$ ?' a
7 P) D4 o( [7 j( g[07-Dec-2012 02:40:49] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1\'' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1\') Q1 i$ y- K) o3 D5 ~6 f7 M3 `) @7 Y
[07-Dec-2012 02:40:50] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536--' at line 1 for query SELECT text, author_id, date FROM WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536--- r+ J/ l) z# {! Y( J4 u4 c
[07-Dec-2012 02:40:53] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536,0x313032353438303035' at line 1 for query SELECT text, author_id, date FROM WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536,0x31303235343830303536--3 v8 V! @+ }: y3 }" b8 {
上面的日志就是在暴力猜解表的列数,那个巨大的十六进制值会被解析成null。 ' O0 e& A. ^3 K
SQL盲注扫描
; ~: i) S0 U1 T2 l3 F# }攻击者使用了类似"waitfor delay"和"benchmark"这样的函数来盲注。
; f' n' o8 B, ~) n/ L0 x1 q6 x2 S% C" X
[07-Dec-2012 02:43:21] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1; if (1=1) waitfor delay \'00:00:05\'--' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1; if (1=1) waitfor delay \'00:00:05\'--, g: X, w0 H( c" m5 a+ Y
[07-Dec-2012 02:43:27] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1 and if(1=1,BENCHMARK(8623333,MD5(0x41)),0)' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1 and if(1=1,BENCHMARK(8623333,MD5(0x41)),0): e2 k: d9 T. j% ]
Google一下大规模扫描# X K5 O: T! U/ m
& Y; l$ _( L4 \# W1 T
6 ^9 c4 V& x1 f. m7 X& q 1 g' |5 Q4 P7 S `# L
7 ^- r" w8 I4 |$ ^; O2 @0 b
+ o, {1 d( G* i3 G" S: t
& N5 t3 u6 n$ l" y# Q5 ] 僵尸网络控制着可能使用被感染主机来识别潜在的目标。下面是该公司的蜜罐捕获到的一个RFI(远程文件包含)攻击代码里的片段: - sub google() { my @list; my $key = $_[0]; for (my $i=0; $i<=400; $i+=10){ my $search = ("http://www.google.com/search?q=".&key($key)."&num=100&filter=0&start=".$i); my $res = &search_engine_query($search); while ($res =~ m/<a href="\"?http:\/\/([^">\"]*)\//g) { if ($1 !~ /google/){ my $link = $1; my @grep = &links($link); push(@list,@grep); } } } return @list;
: X3 t; A5 c! R/ `6 s' u$ Z) { 4 `4 o3 ]% g# [* k
Cocoa总结:文章比较简单,但是从日志来检测攻击貌似是目前流行的一个方向。
+ x, E1 ?4 Z- [ a4 a |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有帐号?立即注册
x
|