3¡¢ÐÅϢй¶£¬¶©µ¥±éÀú Óû§·ÃÎÊȨÏÞÎÊÌâ¡£
4¡¢ÃÜÂëÕÒ»ØÂ©¶´£¨ÃÜÂëÓʼþ/¶ÌÐÅÖØÖã©
Burp¿ÉÐÞ¸Ä×ֶεÄÇé¿öÏ£¬ÕÒ»ØÆäËûÓû§ÃÜÂ룬˵²»¶¨adminµÄÃÜÂë¾Í±»ÄãÕÒ»ØÁË¡£
5¡¢ºǫ́
ºǫ́ҲÊÇÒ»ÖÖÒµÎñ£¬Ö»ÊÇÒ»ÖÖרÕþµÄÒþ²ØµÄÒµÎñ¹þ¡£
ÈçºÎ½øÈëºóÌ¨ÄØ£¿ÔÚÕÒµ½ºǫ́µØÖ·µÄǰÌáÏ¡£ºÍÓ¦ÓÃÎ޹صģº±©Á¦ÆÆ½â£¬×²¿â£¬ÐÅÏ¢ÊÕ¼¯ÀûÓã¬Èõ¿ÚÁδÊÚȨ·ÃÎÊ¡£
¢Ù ÍòÄÜÃÜÂëÖ®ÀàµÄsql×¢È룬postÐÍ×¢ÈëÓÃsqlmap dump dbs.
¢Ú ÀûÓÃwebǰ¶ËµÄsql×¢Èë
¢Û ÃÜÂëÕÒ»ØÔËÆøºÃµÄ»°Ç°¶ËÓ¦ÓõÄadminÃÜÂëºÍºǫ́ÃÜÂëÒ»Ö¡££¨ÓÐʲô²éѯÃÜÂë88£©
¢Ü XSSä´ò cookie £¨³É¹¦ÂÊ£©
¢Ý ºǫ́¿ò¼Ü siteservercmsµÈÖªÃûºǫ́cms sebug
1¡¢Ê×ÏÈ»ñÈ¡Ãâ·Ñ°æÈí¼þ£¬È»ºó°²×°Ê¹Óò鿴ÊÇ·ñÓÐtest(admin)ÕË»§£¬ÄÜ·ñÖ±½ÓÀûÓ㬱£´æcookieÌá½»¿´ÄÜ·ñʹÓᣠ2¡¢¿´°æ±¾£¬SebugµÈÉÏÃæÓÐÎÞÖ±½ÓÀûÓ÷½·¨
3¡¢´úÂëÉó¼Æ £¨±±¾©2014ÂÌÃ˰²È«¶áÆì±±¾©·Ö¹«Ë¾ÀûÓô˷½·¨³É¹¦×ªÕË£© ¶þ£®ÔÚÄ£ÄâÓû§×¢²áµÇ½Çé¿öÏÂ
1¡¢ÈÏÖ¤ÈÆ¹ý
¢Ù ÍòÄÜÃÜÂë
¢Ú CookieÆÛÆ
2¡¢Ô½È¨·ÃÎÊ
¢Ù ƽÐÐԽȨ£¬ÆäËûÓû§ÐÅÏ¢¶ÁÈ¡¡¢Ð޸ģ»
¢Ú ×ÝÏòԽȨ£¬Ö÷ÒªÌåÏÖÔÚÐÞ¸ÄÃÜÂëÄÜ·ñͨ¹ýÌØÊâ×ֶαê¼ÇµÄÐ޸ĹÜÀíÔ±ÃÜÂë¡£
3¡¢×¢Èë
Cookie post get ÐÍ£¬µÇ½ºóuserÏà¹ØÓ¦ÓÃ
4¡¢XSS Ó°ÏìÁ¦¡¢ÀàÐÍʵÔÚÌ«¶à
¢Ù userÌá½»µÄ¶«Î÷Èúǫ́¹ÜÀíԱȥÉóºË
1. Á˽âºǫ́µÄÌá½»ÉóºËÁ÷³Ì£¬CSRF£¬¸ø×Ô¼ºÌí¼ÓÓû§£¬£¨ÎÄÕ¹ÜÀíϵͳ£© 2. XSSÕÒºǫ́£¬¹ÜÀíÔ±ä¯ÀÀʱCookie´«Êäµ½XSSƽ̨ 3. XSSÈ䳿֮Àà 4. ¶©µ¥±éÀú
5¡¢ÉÏ´«µã
¢Ù Ò»¾ä»°Ä¾Âí
¢Ú WebshellÉÏ´«
ÔںܶàÇé¿öÏ£¬Ã»ÓÐ×¢ÈëµÄ£¬ºǫ́½ø²»È¥£¬ÉÏ´«µãÊÇ×îºÃµÄÕ󵨡£
ÍøÕ¾Ê®·ÖÖØÊÓ¶ÔÉÏ´«ÎļþµÄ±£»¤£¬ÊìϤÉÏ´«Á÷³Ì£¬±»×è¶ÏÔÚÄÄÀÔÚÄÄÀïÍ»ÆÆ¡£
6¡¢¶ÌÐÅ¡¢ÓÊÏäDDoS 7¡¢Ö§¸¶Â©¶´
¢Ù 0ÔªÈÎÒ⸶
¢Ú -1ÔªÍË¿î
¢Û ÊýÁ¿ÕûÐÍ/³¤ÕûÐÍÒç³ö