当前位置:网站首页>CISP-PTE实操练习讲解
CISP-PTE实操练习讲解
2022-07-06 08:19:00 【炫彩@之星】
CISP-PTE实操练习讲解
前言
这次给大家讲解一下考试的各个题型
一、文件上传
这道题就很简单,上传一个木马进行蚁剑连接就可以了
答案就在key.php文件中
我们创建一个文件,注入一段一句话木马,改成zhi.jpg文件上传
GIF89a?
写GIF89a?这个的目的是为了证明是图片文件
上传之后进行抓包重发即可,但是要修改后缀名为.php,且要修改为大小写绕过,就是将eval改为Eval就可以了
我们打开图片看看是否可不可以打开
http://150.158.27.164:82/zhi.php
发现可以打开,我们用蚁剑进行连接
答案就是:key2:adahhsh8
二、反序列化漏洞
反序列化漏洞就是一些php魔法函数导致出现的一些漏洞,具体的原理和方法在我之前的渗透测试的课程有讲过,同样,大家要回头好好复习,这里就不在讲了。
接下来,我们进行答题
先简单的讲解一下php反序列化的形成原因
首先是php中的魔法函数如下
__construct()当一个对象创建时被调用
__destruct()当一个对象销毁时被调用
__toString()当一个对象被当作一个字符串使用
__sleep() 在对象在被序列化之前运行
__wakeup将在序列化之后立即被调用
这些就是我们要关注的几个魔术方法了,如果服务器能够接收我们反序列化过的字符串、并且未经过滤的把其中的变量直接放进这些魔术方法里面的话,就容易造成很严重的漏洞了。
此时代码里看不到方法或者是数组,这样的话反而简单很多;他只有一个unserialize()
unserialize() 函数用于将通过 serialize() 函数序列化后的对象或数组进行反序列化,并返回原始的对象结构
我们构造如下 vul.php?str=s:8:“CISP-PTE”;
进行代码审计,可以看到
if (unserialize( s t r ) = = = " str) === " str)==="PTE")
{
echo “$key4”;
}
符合这个条件就可以输出答案了,在网址后面加上这个条件,就可以了
http://49.232.193.10:84/start/vul.php?str=s:8:“CISP-PTE”;
进行重发之后
答案就是:key4:pw3yx7fa
三.失效的访问控制
看题目就知道了,需要管理员用户访问,那么说白了就是伪造管理员身份权限,SSO越权?
二话不说,刷新浏览器,抓包
直接把false改成true;吧username字段改成admin对应的base64编码即可
答案就是:key5:m9gbqjr6
总结
本次总结了考试中常见的几种考试题型,接下来会为大家讲解第二次实操练习的讲解。
边栏推荐
- Résumé des diagrammes de description des broches de la série ESP
- PHP - Common magic method (nanny level teaching)
- Machine learning - decision tree
- Epoll and IO multiplexing of redis
- 649. Dota2 Senate
- LDAP应用篇(4)Jenkins接入
- Analysis of Top1 accuracy and top5 accuracy examples
- Chinese Remainder Theorem (Sun Tzu theorem) principle and template code
- It's hard to find a job when the industry is in recession
- Personalized online cloud database hybrid optimization system | SIGMOD 2022 selected papers interpretation
猜你喜欢
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
"Designer universe": "benefit dimension" APEC public welfare + 2022 the latest slogan and the new platform will be launched soon | Asia Pacific Financial Media
Sanzi chess (C language)
Convolution, pooling, activation function, initialization, normalization, regularization, learning rate - Summary of deep learning foundation
Step by step guide to setting NFT as an ens profile Avatar
The Vice Minister of the Ministry of industry and information technology of "APEC industry +" of the national economic and information technology center led a team to Sichuan to investigate the operat
让学指针变得更简单(三)
【云原生】手把手教你搭建ferry开源工单系统
"Friendship and righteousness" of the center for national economy and information technology: China's friendship wine - the "unparalleled loyalty and righteousness" of the solidarity group released th
Asia Pacific Financial Media | "APEC industry +" Western Silicon Valley invests 2trillion yuan in Chengdu Chongqing economic circle to catch up with Shanghai | stable strategy industry fund observatio
随机推荐
1. Color inversion, logarithmic transformation, gamma transformation source code - miniopencv from zero
Flash return file download
Summary of MySQL index failure scenarios
What are the ways to download network pictures with PHP
Asia Pacific Financial Media | art cube of "designer universe": Guangzhou community designers achieve "great improvement" in urban quality | observation of stable strategy industry fund
07- [istio] istio destinationrule (purpose rule)
NFT smart contract release, blind box, public offering technology practice -- contract
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
Mobile Test Engineer occupation yyds dry goods inventory
Circular reference of ES6 module
Grayscale upgrade tidb operator
08- [istio] istio gateway, virtual service and the relationship between them
使用 TiDB Lightning 恢复 S3 兼容存储上的备份数据
Epoll and IO multiplexing of redis
从 SQL 文件迁移数据到 TiDB
24. Query table data (basic)
1202 character lookup
远程存储访问授权
Asia Pacific Financial Media | "APEC industry +" Western Silicon Valley invests 2trillion yuan in Chengdu Chongqing economic circle to catch up with Shanghai | stable strategy industry fund observatio
[t31zl intelligent video application processor data]