ÂÌÃ˰²È«¹¤³ÌÊ¦ÉøÍ¸²âÊÔ³£¹æË¼Â· ÏÂÔØ±¾ÎÄ

3¡¢ÐÅϢй¶£¬¶©µ¥±éÀú Óû§·ÃÎÊȨÏÞÎÊÌâ¡£

4¡¢ÃÜÂëÕÒ»ØÂ©¶´£¨ÃÜÂëÓʼþ/¶ÌÐÅÖØÖã©

Burp¿ÉÐÞ¸Ä×ֶεÄÇé¿öÏ£¬ÕÒ»ØÆäËûÓû§ÃÜÂ룬˵²»¶¨adminµÄÃÜÂë¾Í±»ÄãÕÒ»ØÁË¡£

5¡¢ºǫ́

ºǫ́ҲÊÇÒ»ÖÖÒµÎñ£¬Ö»ÊÇÒ»ÖÖרÕþµÄÒþ²ØµÄÒµÎñ¹þ¡£

ÈçºÎ½øÈëºóÌ¨ÄØ£¿ÔÚÕÒµ½ºǫ́µØÖ·µÄǰÌáÏ¡£ºÍÓ¦ÓÃÎ޹صģº±©Á¦ÆÆ½â£¬×²¿â£¬ÐÅÏ¢ÊÕ¼¯ÀûÓã¬Èõ¿ÚÁδÊÚȨ·ÃÎÊ¡£

¢Ù ÍòÄÜÃÜÂëÖ®ÀàµÄsql×¢È룬postÐÍ×¢ÈëÓÃsqlmap dump dbs.

¢Ú ÀûÓÃwebǰ¶ËµÄsql×¢Èë

¢Û ÃÜÂëÕÒ»ØÔËÆøºÃµÄ»°Ç°¶ËÓ¦ÓõÄadminÃÜÂëºÍºǫ́ÃÜÂëÒ»Ö¡££¨ÓÐʲô²éѯÃÜÂë88£©

¢Ü XSSä´ò cookie £¨³É¹¦ÂÊ£©

¢Ý ºǫ́¿ò¼Ü siteservercmsµÈÖªÃûºǫ́cms sebug

1¡¢Ê×ÏÈ»ñÈ¡Ãâ·Ñ°æÈí¼þ£¬È»ºó°²×°Ê¹Óò鿴ÊÇ·ñÓÐtest(admin)ÕË»§£¬ÄÜ·ñÖ±½ÓÀûÓ㬱£´æcookieÌá½»¿´ÄÜ·ñʹÓᣠ2¡¢¿´°æ±¾£¬SebugµÈÉÏÃæÓÐÎÞÖ±½ÓÀûÓ÷½·¨

3¡¢´úÂëÉó¼Æ £¨±±¾©2014ÂÌÃ˰²È«¶áÆì±±¾©·Ö¹«Ë¾ÀûÓô˷½·¨³É¹¦×ªÕË£© ¶þ£®ÔÚÄ£ÄâÓû§×¢²áµÇ½Çé¿öÏÂ

1¡¢ÈÏÖ¤ÈÆ¹ý

¢Ù ÍòÄÜÃÜÂë

¢Ú CookieÆÛÆ­

2¡¢Ô½È¨·ÃÎÊ

¢Ù ƽÐÐԽȨ£¬ÆäËûÓû§ÐÅÏ¢¶ÁÈ¡¡¢Ð޸ģ»

¢Ú ×ÝÏòԽȨ£¬Ö÷ÒªÌåÏÖÔÚÐÞ¸ÄÃÜÂëÄÜ·ñͨ¹ýÌØÊâ×ֶαê¼ÇµÄÐ޸ĹÜÀíÔ±ÃÜÂë¡£

3¡¢×¢Èë

Cookie post get ÐÍ£¬µÇ½ºóuserÏà¹ØÓ¦ÓÃ

4¡¢XSS Ó°ÏìÁ¦¡¢ÀàÐÍʵÔÚÌ«¶à

¢Ù userÌá½»µÄ¶«Î÷Èúǫ́¹ÜÀíԱȥÉóºË

1. Á˽âºǫ́µÄÌá½»ÉóºËÁ÷³Ì£¬CSRF£¬¸ø×Ô¼ºÌí¼ÓÓû§£¬£¨ÎÄÕ¹ÜÀíϵͳ£© 2. XSSÕÒºǫ́£¬¹ÜÀíÔ±ä¯ÀÀʱCookie´«Êäµ½XSSƽ̨ 3. XSSÈ䳿֮Àà 4. ¶©µ¥±éÀú

5¡¢ÉÏ´«µã

¢Ù Ò»¾ä»°Ä¾Âí

¢Ú WebshellÉÏ´«

ÔںܶàÇé¿öÏ£¬Ã»ÓÐ×¢ÈëµÄ£¬ºǫ́½ø²»È¥£¬ÉÏ´«µãÊÇ×îºÃµÄÕ󵨡£

ÍøÕ¾Ê®·ÖÖØÊÓ¶ÔÉÏ´«ÎļþµÄ±£»¤£¬ÊìϤÉÏ´«Á÷³Ì£¬±»×è¶ÏÔÚÄÄÀÔÚÄÄÀïÍ»ÆÆ¡£

6¡¢¶ÌÐÅ¡¢ÓÊÏäDDoS 7¡¢Ö§¸¶Â©¶´

¢Ù 0ÔªÈÎÒ⸶

¢Ú -1ÔªÍË¿î

¢Û ÊýÁ¿ÕûÐÍ/³¤ÕûÐÍÒç³ö