|
|
- 这篇文章介绍了当WordPress开启错误记录以后,根据error_log来发现SQL注入攻击的思路。) B& \8 o; N' B% T6 c# q# H! F
4 Y; L8 U% `1 O; K/ P9 W: z* f吸引Cocoa的是这个博客其实是TrustWave公司下属的一个叫Spiderlab团队的官方博客,貌似比较有意思。例如它提到了Honeypot Alert这个标签里的文章都是分析他们一个Web蜜罐的Apache access_log日志的。
. G ` v2 [+ R% ?( S
) E* A3 }+ G, s, Y& r8 w% M1 T简单介绍一下这篇文章吧。
# V% V9 l/ f8 @$ n. t" c4 C& B2 j3 l" h' J
开启WP错误记录功能
8 k' y3 x" c' ~, F: X& p" D; f只需要修改wp-config.php的如下几行:
+ m. y/ k0 n: n" Y( X; g6 d: U/ R
@ini_set('log_errors','On'); @ini_set('display_errors','Off'); @ini_set('error_log','/home/example.com/logs/php_error.log');SQL 注入扫描+ R0 i) g. q# ?+ _7 I
3 D' {6 x# A1 }0 K* ][07-Dec-2012 02:40:49] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1\'' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1\'8 D: g- \ u9 O" p6 s# m. B! E& ^! |
[07-Dec-2012 02:40:50] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536--' at line 1 for query SELECT text, author_id, date FROM WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536--
4 o2 Y0 s. T9 {+ g[07-Dec-2012 02:40:53] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536,0x313032353438303035' at line 1 for query SELECT text, author_id, date FROM WHERE id = 999999.9 UNION ALL SELECT 0x31303235343830303536,0x31303235343830303536--9 d! w" \% A. M g
上面的日志就是在暴力猜解表的列数,那个巨大的十六进制值会被解析成null。
. x( g T0 A6 uSQL盲注扫描
6 }. q) |5 {! r: c1 m攻击者使用了类似"waitfor delay"和"benchmark"这样的函数来盲注。1 H4 Y* H4 a" z4 w+ O& |
* h4 q% F3 \2 e+ G7 O# ?% {
[07-Dec-2012 02:43:21] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1; if (1=1) waitfor delay \'00:00:05\'--' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1; if (1=1) waitfor delay \'00:00:05\'--/ l8 K# G$ N2 f9 ]4 `" X# e
[07-Dec-2012 02:43:27] WordPress database error You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE id = -1 and if(1=1,BENCHMARK(8623333,MD5(0x41)),0)' at line 1 for query SELECT text, author_id, date FROM WHERE id = -1 and if(1=1,BENCHMARK(8623333,MD5(0x41)),0)
3 P# q7 D( p. h& @# s1 b& q+ L& RGoogle一下大规模扫描! f8 f1 A: x4 B2 @
: e6 H1 m" U5 Q) y8 O8 A! T
5 j! T) p! f$ { , B) h3 A7 l' ^; v
; ?# o* m4 L& O x8 n2 Z. N4 ]
( r7 n0 f/ w4 R* m: [6 o3 x, z
1 Y3 }3 U2 f" r$ { 僵尸网络控制着可能使用被感染主机来识别潜在的目标。下面是该公司的蜜罐捕获到的一个RFI(远程文件包含)攻击代码里的片段: - sub google() { my @list; my $key = $_[0]; for (my $i=0; $i<=400; $i+=10){ my $search = ("http://www.google.com/search?q=".&key($key)."&num=100&filter=0&start=".$i); my $res = &search_engine_query($search); while ($res =~ m/<a href="\"?http:\/\/([^">\"]*)\//g) { if ($1 !~ /google/){ my $link = $1; my @grep = &links($link); push(@list,@grep); } } } return @list;
9 c5 w; H1 w& o! A& i7 I+ ~
( V4 g5 @8 r; t) o$ wCocoa总结:文章比较简单,但是从日志来检测攻击貌似是目前流行的一个方向。
- t3 H9 }) ~* C4 x |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有帐号?立即注册
x
|