当前位置:网站首页>Vulnerability discovery - vulnerability probe type utilization and repair of web applications
Vulnerability discovery - vulnerability probe type utilization and repair of web applications
2022-07-06 04:28:00 【Dark white earphone】
Site judgment
It is known that CMS
As is common dedecms.discuz,wordpress And so on , This is generally developed using non framework classes , But there are also a few
Is framework class development , Security detection for such source programs , We're going to test with open holes , If not, use
White box code audit self mining .
Development framework
As is common thinkphp,spring,flask And so on , This kind of source code procedure normal security test mentality : Get right first
The development framework information should be ( name , edition ), Test through the exposed framework class security issues , If it does not exist, white box code review can be used
Plan to dig by yourself .
Unknown CMS
Such as the common enterprise or individual internal program source code , It can also be some CMS Secondary development of the source structure , For this kind of source code program testing
Try ideas : If you can identify the secondary development, just press the known CMS Train of thought , If the secondary development cannot be determined, the conventional comprehensive class scanning can be adopted
Tools or scripts to probe , You can also use artificial probes ( The function point , Parameters , Blind guess ), Similarly, when there is source code, you can
Conduct code audit and mine by yourself .
The demo case
Development framework class source code penetration test report - information -thinkphp,spring
It is known that CMS Non framework penetration test report - Tool scripts -wordpress
It is known that CMS Non framework penetration test report - Code audit -qqyewu_php
Unknown CMS Non framework penetration test report - artificial - You and I love wg Oh ~
CVE-2018-1273 Demonstrate the execution of commands ( Known framework :spring frame )
vulhub Up lookup
Capture the registration page , modify payload Corresponding poc Submit Successfully in the other server directory tmp Created in succes Folder
It is known that CMS by wordpress
( Because it is known as wordpress, Tools are used here wpscan To test )
It can be identified by various methods cms
Direct start kali Of wpscan Scan the target
The new version of the wpscan You need to apply for an account on the official website , And get the account api-token, Only when copied into the tool can it be used normally
https://wpscan.com/register
Add parameters again api-token To test
The red exclamation point is the corresponding vulnerability scanned , Can be used ( adopt sqlmap Wait for tools to test )
It is known that CMS Non framework class — Code audit —qqyewu_php
1. Identify website cms
2. Look for a match cms Loophole , see cms Upgrade time
3. Looking for backstage , Weak password test
4. Scan ports to collect information
5. Looking for website backup files
边栏推荐
- Recommendation system (IX) PNN model (product based neural networks)
- 1291_ Add timestamp function in xshell log
- 满足多元需求:捷码打造3大一站式开发套餐,助力高效开发
- 图应用详解
- Leetcode32 longest valid bracket (dynamic programming difficult problem)
- Several important classes in unity
- 2/13 review Backpack + monotonic queue variant
- Script lifecycle
- Basic explanation of turtle module - draw curve
- How do programmers teach their bosses to do things in one sentence? "I'm off duty first. You have to work harder."
猜你喜欢
Deep learning framework installation (tensorflow & pytorch & paddlepaddle)
Fedora/REHL 安装 semanage
Comprehensive ability evaluation system
Recommendation | recommendation of 9 psychotherapy books
ETCD数据库源码分析——etcdserver bootstrap初始化存储
Understanding of processes, threads, coroutines, synchronization, asynchrony, blocking, non blocking, concurrency, parallelism, and serialization
Stable Huawei micro certification, stable Huawei cloud database service practice
lora网关以太网传输
食品行业仓储条码管理系统解决方案
Practical development of member management applet 06 introduction to life cycle function and user-defined method
随机推荐
HotSpot VM
2/13 review Backpack + monotonic queue variant
JVM garbage collector concept
Redis —— Redis In Action —— Redis 实战—— 实战篇一 —— 基于 Redis 的短信登录功能 —— Redis + Token 的共享 session 应用— 有代码
颠覆你的认知?get和post请求的本质
Sorting out the latest Android interview points in 2022 to help you easily win the offer - attached is the summary of Android intermediate and advanced interview questions in 2022
[tomato assistant installation]
729. My schedule I (set or dynamic open point segment tree)
Comprehensive ability evaluation system
Practical development of member management applet 06 introduction to life cycle function and user-defined method
2328. 网格图中递增路径的数目(记忆化搜索)
Unity中几个重要类
题解:《单词覆盖还原》、《最长连号》、《小玉买文具》、《小玉家的电费》
2/13 qaq~~ greed + binary prefix sum + number theory (find the greatest common factor of multiple numbers)
. Net interprocess communication
P2022 有趣的数(二分&数位dp)
Certbot failed to update certificate solution
Implementation of knowledge consolidation source code 2: TCP server receives and processes half packets and sticky packets
[HBZ sharing] how to locate slow queries in cloud database
About some basic DP -- those things about coins (the basic introduction of DP)