当前位置:网站首页>(5) Web security | penetration testing | network security operating system database third-party security, with basic use of nmap and masscan
(5) Web security | penetration testing | network security operating system database third-party security, with basic use of nmap and masscan
2022-07-03 20:49:00 【Black zone (rise)】
Remove the middleware to build the platform , Outside the website source code , The operating system is also vulnerable , database , Third party software platform, etc , Such attacks can also directly affect Web Or server security , Result in the acquisition of website or server permissions .
At the operating system level
Common ways to identify operating systems
If there is a website, go through the website , No, it can be identified by scanning relevant software
significance : Website path 、 Case write 、 Applicability of documents between the two systems , Compatibility
Different types of vulnerabilities will create conditions for exploiting this vulnerability , Exploit vulnerabilities to gain privileges or interfere with certain services
①windows The server is not case sensitive , So case has no effect on Web pages, that is windows
Changing the upper case and then loading will make it lower case and load it
Linux It's case sensitive , Case error , The page will go wrong
② adopt pnig after , Observe the returned data TTL Value , To determine the operating system
But when the user changes TTL When the value of , Can judge wrong , So this method is not necessarily accurate .
Of the original operating system TTL value :( This can be found online in Baidu )
WINDOWS NT/2k/2000/2003/XP-32bit TTL:128
WINDOWS 95/98 TTL:32
UNIX TTL:255
LINUX TTL:64
WIN7 TTL:64
64-13+1=52, It may be after 13 Nodes
It may also be a change ttl Of
③ Through the scanning tool , To determine the operating system
nmap -o ip (ip Determine the truth through scanning and analysis ip, Don't sweep it into cnd 了 )
sudo nmap -O ip
Device type :WAP | mobile phone function :Linux 2.4.x | 2.6.x, Sony Ericsson embedded OS CPE:CPE:/ O:Linux:Linux_kernel:2.4.20 CPE:/ O:Linux:Linux_Kernel:2.6.22 CPE:/ H:Sonyericsson:U8I_Vivaz
Sometimes true ip Scanning tools are still unreliable , Or do it yourself
Database level
Different database types , Its security mechanism , The writing structure will be different , The loopholes are different
Generally encounter weak password , Database vulnerability attack , Database permissions will be affected , Website permission , Content integrity
① Common methods for identifying database types
asp+Access/Mssql
php+Mysql port :3306
Aspx+Mssql port :1433
Jsp+Mssql/oracle port :1521
Python+mongodb port :27017
Common database port numbers
mysql The default port is 3306
sqlserver The default port number is :1433
oracle The default port number is :1521
PostgreSQL The default port number is :5432
DB2 The default port number is :5000
Non relational database :
MongoDB The default port number is :27017
Redis The default port number is :6379
memcached The default port number is :11211
This is through nmap Wait for software to scan ports
I opened a port when scanning , It hasn't been opened yet
Third party level
Multi level judgment : Port scanning + Application type analysis, etc
After identifying the third-party platform and version , It can be exploited according to the vulnerabilities of the latest relevant version that has been released on the Internet , If not patched , Will be successful
Port scan tool :
nmap Official website :
https://nmap.org/
masnmapscan:
https://github.com/hellogoldsnakeman/masnmapscan-V1.0
边栏推荐
- In 2021, the global revenue of thick film resistors was about $1537.3 million, and it is expected to reach $2118.7 million in 2028
- 2.2 integer
- Test access criteria
- Basic number theory -- Chinese remainder theorem
- In 2021, the global general crop protection revenue was about $52750 million, and it is expected to reach $64730 million in 2028
- From the behind the scenes arena of the ice and snow event, see how digital builders can ensure large-scale events
- The global industrial design revenue in 2021 was about $44360 million, and it is expected to reach $62720 million in 2028. From 2022 to 2028, the CAGR was 5.5%
- Global and Chinese market of full authority digital engine control (FADEC) 2022-2028: Research Report on technology, participants, trends, market size and share
- Machine learning support vector machine SVM
- Global and Chinese market of charity software 2022-2028: Research Report on technology, participants, trends, market size and share
猜你喜欢
Based on laravel 5.5\5.6\5 X solution to the failure of installing laravel ide helper
Rhcsa third day operation
Qtablewidget control of QT
Discussion Net legacy application transformation
【愚公系列】2022年7月 Go教学课程 002-Go语言环境安装
Example of peanut shell inner net penetration
[gd32l233c-start] 5. FLASH read / write - use internal flash to store data
Scientific research document management Zotero
An old programmer gave it to college students
Go learning notes (4) basic types and statements (3)
随机推荐
The 12th Blue Bridge Cup
2.1 use of variables
11-grom-v2-04-advanced query
Hcie security Day11: preliminarily learn the concepts of firewall dual machine hot standby and vgmp
Global and Chinese market of charity software 2022-2028: Research Report on technology, participants, trends, market size and share
Sightseeing - statistics of the number of shortest paths + state transfer + secondary small paths
Fingerprint password lock based on Hal Library
Global and Chinese markets of lithium chloride 2022-2028: Research Report on technology, participants, trends, market size and share
@Transactional注解失效的场景
In 2021, the global foam protection packaging revenue was about $5286.7 million, and it is expected to reach $6615 million in 2028
First knowledge of database
Battle drag method 1: moderately optimistic, build self-confidence (1)
[postgresql]postgresql custom function returns an instance of table type
6006. Take out the minimum number of magic beans
The "boss management manual" that is wildly spread all over the network (turn)
Preliminary practice of niuke.com (11)
MDM mass data synchronization test verification
阻塞非阻塞和同步异步的区分 参考一些书籍
Global and Chinese market of electrolyte analyzers 2022-2028: Research Report on technology, participants, trends, market size and share
LabVIEW training