The method of penetration testing for the target site,Objective: To obtain the target operating system control permission(Windows: administrator,Linux: root)
Let's add other frequently used methods! By the way, correct the errors in this article. Only on the Web layer. For password cracking of 21, 22, 3306, 1433, and 3389, or XX overflow, ddos, cc, etc ...... You don't have to discuss it.
1,SQLInjection(Find the admin background user password and log on to the background to continue)
Other solutions:
Access (in general, this can only produce the management background password, there is nothing to raise the right. If the SQL script can be executed in the background, you can export the parsing Shell of IIS6 );
MSSQL (if the SA permission is used, xp .. mongoshell directly executes the command. Dbowner can find the physical path of the site for differential backup or log export Shell. You can also use the sa permission account to execute commands after obtaining the shell .);
MySQL (if the permission is large enough, find the physical site path into outfile/into dumpfile to export the shell. After obtaining the webshell, consider udf. dll and mix. dll to improve the permission );
Oracle (I am not a good user. I have not used Oracle for permission escalation !);
Other databases ...... (I do not know how to do it .);
2,XSS(In general, it is to obtain the Administrator's cookie, and then find a breakthrough in the background .)
Other solutions:
I didn't say you couldn't pop up the window and ask the Administrator to fill in his password. But no matter how you try to do it, not all managers are SB!
When you are familiar with a system, CSRF asks the Administrator to work for you.
3, Directory file information(This is a general auxiliary test. This information can be used to expand your understanding of the entire system, and may be used to obtain management backend portals and sensitive files ......)
Note: directory file information leakage may be caused by improper configuration, or may be caused by directory file traversal and full-site packaging due to some code considerations of the target site. However, these two cases are rare, and they look at the character. None of them. Scan wwwscan.
4, Code Execution("Special" functions of some files or containers, including file inclusion execution)
Note: This "special" function is generally very good, so it is a Shell, and the system will fall into the heavy! What does webdav mean? I said: I don't know. Could you tell me a professional!
5, File upload(When the character is good, you can directly upload webshell. When the character is not good, you can also upload the parsing shell, cut off the shell, and bypass the JS verification to transfer the shell. When the character is bad, you will be waiting to drink the northwest wind !)
Note: You can change the name after it is uploaded! There are a lot of techniques for uploading files!
6, Side Station:
Note: Sometimes the target site may not be able to determine how much time is wasted when the peer site is done!
7,CSegment:
Note: The target cannot be set, nor can the peer site be used. So proceed to section C, and a lot of secrets will be discovered!
8Social Engineering:
Note: This is the omnipotent key. If you do a good job, you can open any lock! The safe deposit box is also good!
9Elevation of Privilege:
Note: there are too many methods to describe them. For more information, see the XX Privilege Escalation toolkit ......
My ideas are too spam. I have read them and I will try again later!