实战 | 记一次反制骗子的钓鱼网站渗透经历
作者:admin | 时间:2022-6-7 02:43:53 | 分类:黑客技术 隐藏侧边栏展开侧边栏
文章来源:先知社区
地址:https://xz.aliyun.com/t/11132
作者:Fright一Moch
0x01 事件起因
一个好兄弟QQ号被盗了,当时给我说让我看一下
data:image/s3,"s3://crabby-images/577dd/577ddac21dcf29c0b5590754a419fff5fb381668" alt=""
data:image/s3,"s3://crabby-images/6b7a4/6b7a47411101f5e90afd6d0f2196c007f3da91e5" alt=""
data:image/s3,"s3://crabby-images/3f5d4/3f5d4a3bac6425e2ebce2899e463d14eedd157a4" alt=""
0x02 信息搜集
旁站查找(一般这种网站都是打一地方换一个地方)
data:image/s3,"s3://crabby-images/31584/3158425d0427e676129f746430f96da417b7eb64" alt=""
查找注册信息
data:image/s3,"s3://crabby-images/90ccc/90ccc236e6ea518c811cbe9664bcde164d18404e" alt=""
端口信息
data:image/s3,"s3://crabby-images/81a47/81a477f926d0b0a2b5faedbf3b092da514eb7722" alt=""
可以看出这个人是有宝塔面板,而且22端口也是开放的
后面查找到网站注册人信息全是假的,这个网站使用的人家的QQ邮箱,别人的身份信息注册的网站和域名,最后如下总结
个人信息泄露--》被注册域名--》本人并不知情--》在我们之前很多人都被骗过
data:image/s3,"s3://crabby-images/e45ab/e45abb2d61df178194f10e648b6af476d081ac42" alt=""
data:image/s3,"s3://crabby-images/b7cf5/b7cf595c3b480b7af1098407e3faa22a5504ee22" alt=""
翻阅个人空间可以看到这个人并不知情,也是受害者,自己身份信息被盗用,确实挺惨的
0x03 开始渗透测试
御剑扫描
data:image/s3,"s3://crabby-images/a3478/a3478181aa43a2a0e6bb64a58651ced5b4caf918" alt=""
data:image/s3,"s3://crabby-images/065d6/065d6bbd7e04db38e74fb3d4d21678b00c4b15cd" alt=""
sqlmap.py -r g:1.txt --random-agent --skip-waf -v3 --dbs --batch --threads 10 --technique E
当我一筹莫展时候,我选择了更换字典,继续扫描目录
data:image/s3,"s3://crabby-images/2765f/2765fe2c068f38e58700d6d46eb817c89e135ca7" alt=""
$set_username="admin"; $set_password="e19d5cd5af0378da05f63f891c7467af"; $set_loginauth="123456"; $set_loginrnd="YFfd33mV2MrKwDenkecYWZETWgUwMV"; $set_outtime="60"; $set_loginkey="1";
data:image/s3,"s3://crabby-images/3561e/3561e1f9600fa54851e76f326bbbceae0b19f259" alt=""
/config/sbak/admin.php 账号/密码admin/abcd1234
当我继续打下去发现对方应该是发现了,然后跑路了。不过没事,有旁站(看来开始收集的旁站果然没问题)
data:image/s3,"s3://crabby-images/c4b0b/c4b0b0bf549eda56b036142086687da1e4948f68" alt=""
0x04 getshell
data:image/s3,"s3://crabby-images/077b7/077b7a9f8704aa95f7c79f0019900fc3a44789ee" alt=""
替换config里面的字符,我把它替换成哥斯拉和冰蝎的木马,但是在替换前需要连接远程数据库,由于我没有远程库,我把自己虚拟机穿透出去在连接
data:image/s3,"s3://crabby-images/2d358/2d358f6bd06481630d53dd8a290b8aa07ae1b134" alt=""
进入mysql: mysql -uroot -p 运行mysql: use mysql; 查看用户表: SELECT `Host`,`User` FROM user; 更新用户表: UPDATE user SET `Host` = '%' WHERE `User` = 'root' LIMIT 1; 强制刷新权限: flush privileges;
data:image/s3,"s3://crabby-images/2bd20/2bd20b6a7a7ca9e74c1a4a365c5527ac661381e1" alt=""
data:image/s3,"s3://crabby-images/73ad2/73ad2e3ad7a1edc34c2ad506988bf8d51c7ea411" alt=""
/config/sbak/bdata/yy_gxjbh58_com_20210303185300/config.php
密码如下:
哥斯拉:config123
冰蝎:rebeyond
data:image/s3,"s3://crabby-images/afcb9/afcb97925feb4bb79e51c963ef1579744dacfd66" alt=""
/w5/admin.php
data:image/s3,"s3://crabby-images/c6c03/c6c031edbaa8c98445792342d1e70c0df3eecf7e" alt=""
data:image/s3,"s3://crabby-images/e6790/e6790f03257ea738aa8dee83b8f0b5f9584a2e4b" alt=""
登录进去,发现收集到的大量个人信息
0x05 权限提升
data:image/s3,"s3://crabby-images/94491/94491746c17258adaff4d71ae20fc73f63442917" alt=""
权限很低只有一个www权限而且啥也干不了
绕过disable_function,工作原理如下
为了安全,运维人员会禁用PHP的一些“危险”函数,将其写在php.ini配置文件中,就是我们所说的disable_functions了。例如:
passthru,exec,system,chroot,chgrp,chown,shell_exec,proc_open,proc_get_status,popen,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,link等
data:image/s3,"s3://crabby-images/6968e/6968ee6d9483ecfbe8e5c875da65e4f4c895fe72" alt=""
data:image/s3,"s3://crabby-images/e5dc2/e5dc2bfec4c1eea1dc3c59e702d8f52a5cd862d8" alt=""
data:image/s3,"s3://crabby-images/51891/51891c49ac2c016830865d89294990044713fef3" alt=""
data:image/s3,"s3://crabby-images/7652d/7652de7aa2a0d2ee660ecfbc87720d3934bfdab3" alt=""
data:image/s3,"s3://crabby-images/11ee9/11ee94474eacff992856ed0249859180ec8065c7" alt=""
data:image/s3,"s3://crabby-images/3fb8a/3fb8a015cbe96125a8448a9ef1350f9df1b36a19" alt=""
data:image/s3,"s3://crabby-images/05e4c/05e4c34de285ebe72c7c5d2652218da48486e61d" alt=""
data:image/s3,"s3://crabby-images/581ee/581ee873211dbb3b6ba4733437f26d85487602c2" alt=""
data:image/s3,"s3://crabby-images/cd239/cd2390fbf76538cc2f135d58114d808049da3bc4" alt=""
0x06 最后总结
最后我紧急联系了几个同学,大多数为贵州同学,几乎全校沦陷,当时同学接到我电话都是很感激,很惊讶
data:image/s3,"s3://crabby-images/6bf9a/6bf9a25f913f417d4b9e70adab6d52e5507e3f89" alt=""
本文作者:HACK_Learn
本文为安全脉搏专栏作者发布,转自:https://www.secpulse.com/archives/179631.html