Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      »Æ½ð³Ç¹ÙÍøÊµÑéÊÒ | PHPÎļþ°üº¬Â©¶´Ô­Àí·ÖÎö
      ·¢²¼Ê±¼ä£º2020-08-14 ÔĶÁ´ÎÊý£º 327 ´Î

      PHPÊÇĿǰ·Ç³£Á÷ÐеÄWeb¿ª·¢ÓïÑÔ£¬µ«ÊÇÔÚÀûÓÃPHP¿ª·¢WebÓ¦ÓÃʱ£¬Èç¹ûÉÔÓв»×¢Ò⣬¾Í»á²úÉúPHPÎļþ°üº¬Â©¶´¡£PHPÎļþ°üº¬Â©¶´ÊÇÒ»ÖÖ³£¼ûµÄ©¶´£¬¶øÍ¨¹ýPHPÎļþ°üº¬Â©¶´ÈëÇÖÍøÕ¾£¬ÉõÖÁÄõ½ÍøÕ¾µÄWebShellµÄ°¸ÀýÒ²ÊDz»Ê¤Ã¶¾Ù¡£±¾ÆÚ»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ½«´ø´ó¼ÒÁ˽âPHPÎļþ°üº¬Â©¶´µÄ²úÉúÔ­ÒòºÍ©¶´Ô­Àí¡£


      ©¶´¼ò½é


      Îļþ°üº¬Â©¶´£¨File Inclusion£©ÊÇÒ»ÖÖ³£¼ûµÄÒÀÀµÓڽű¾ÔËÐдӶøÓ°ÏìWebÓ¦ÓõÄ©¶´¡£ÑϸñÀ´Ëµ£¬Îļþ°üº¬Â©¶´ÊÇ¡°´úÂë×¢È롱µÄÒ»ÖÖ£¬Ðí¶à½Å±¾ÓïÑÔ£¬ÀýÈçPHP¡¢JSP¡¢ASP¡¢.NETµÈ£¬¶¼ÌṩÁËÒ»ÖÖ°üº¬ÎļþµÄ¹¦ÄÜ£¬ÕâÖÖ¹¦ÄÜÔÊÐí¿ª·¢Õß½«¿ÉʹÓõĽű¾´úÂë²åÈëµ½µ¥¸öÎļþÖб£´æ£¬ÔÚÐèÒªµ÷ÓõÄʱºò¿ÉÒÔÖ±½Óͨ¹ýÔØÈëÎļþµÄ·½Ê½Ö´ÐÐÀïÃæµÄ´úÂ룬µ«ÊÇÈç¹û¹¥»÷Õß¿ØÖÆÁË¿ÉÖ´ÐдúÂëµÄ·¾¶£¬Ò²¾ÍÊÇÎļþλÖÃʱ£¬¹¥»÷Õß¿ÉÒÔÐÞ¸ÄÖ¸¶¨Â·¾¶£¬½«ÆäÖ¸ÏòÒ»¸ö°üº¬Á˶ñÒâ´úÂëµÄ¶ñÒâÎļþ¡£


      Îļþ°üº¬Â©¶´Í¨³£¶¼»áʹWeb·þÎñÆ÷µÄÎļþ±»Íâ½çä¯ÀÀµ¼ÈëÐÅϢй¶£¬Ö´ÐеĶñÒâ½Å±¾»áµ¼ÖÂÍøÕ¾±»´Û¸Ä£¬Ö´ÐзǷ¨²Ù×÷£¬¹¥»÷ÆäËûÍøÕ¾£¬»ñÈ¡WebShellµÈÑÏÖØÎ£º¦¡£


      ©¶´²úÉúÔ­Àí


      ÔÚÉÏÒ»½ÚµÄÃèÊöÖÐÎÒÃÇÌáµ½£¬¹¥»÷Õßͨ¹ý¿ØÖÆ¿ÉÖ´ÐдúÂëµÄ·¾¶¾Í¿ÉÒÔʵÏÖÎļþ°üº¬Â©¶´£¬ÕâÖ»ÊÇÒ»¸ö¶ÔÕûÌå¹¥»÷Á÷³ÌµÄ¼ò»¯ÃèÊö£¬ÔÚʵ¼ÊÇ龳ϣ¬·þÎñÆ÷½âÎöÖ´ÐÐphpÎļþʱͨ¹ý°üº¬º¯Êý¿ÉÒÔ¼ÓÔØÁíÒ»¸öÎļþÖеÄphp´úÂ룬µ±±»°üº¬µÄÎļþÖдæÔÚľÂíʱ£¬¾ÍÒâζ×ÅľÂí³ÌÐò»áÔÚ·þÎñÆ÷ÉϼÓÔØÖ´ÐС£


      ËùÒÔ²úÉúÎļþ°üº¬Â©¶´µÄ¸ù±¾Ô­ÒòÔÚÓÚ¿ª·¢ÕßÊÇ·ñ¶Ôͨ¹ý°üº¬º¯Êý¼ÓÔØµÄÎļþ½øÐÐÁËÑϸñÇÒºÏÀíµÄУÑ飬ÔÚPHPÖÐ×ܹ²ÓÐËÄÖÖÎļþ°üº¬º¯Êý£º


      1£©Include£¨£©£º°üº¬²¢ÔËÐÐÖ¸¶¨µÄÎļþ£¬Ö»ÓÐÔÚ³ÌÐòÖ´Ðе½includeʱ²Å°üº¬Îļþ£¬ÇÒµ±°üº¬Îļþ·¢Éú´íÎóʱ£¬³ÌÐò¾¯¸æ£¬µ«»á¼ÌÐøÖ´ÐС£

      2£©Require£¨£©£ºÖ»Òª³ÌÐòÒ»ÔËÐоͻáÖ´Ðиðüº¬Îļþº¯Êý£¬µ±°üº¬Îļþ·¢Éú´íÎóʱ£¬³ÌÐòÖ±½ÓÖÕÖ¹Ö´ÐС£

      3£©Include_once£¨£©£ººÍinclude£¨£©ÀàËÆ£¬²»Í¬Ö®´¦ÔÚÓÚinclude_once»á¼ì²éÕâ¸öÎļþÊÇ·ñÒѾ­±»µ¼È룬Èç¹ûÒѵ¼Èë¡¢ÏÂÎı㲻»áÔÙµ¼Èë¡£

      4£©Require_once£¨£©£ººÍrequire£¨£©ÀàËÆ£¬²»Í¬´¦ÔÚÓÚrequire_onceÒ²ÊÇÓëinclude_onceÒ»ÑùÖ»µ¼ÈëÒ»´Î¡£


      ¸ù¾Ý±»°üº¬ÎļþµÄλÖò»Í¬£¬PHPÎļþ°üº¬Â©¶´¿ÉÒÔ·ÖΪ±¾µØÎļþ°üº¬Â©¶´£¨Local File Inclusion£¬LFI£©£¬ºÍÔ¶³ÌÎļþ°üº¬Â©¶´£¨Remote File Inclusion£¬RFI£©¡£¹ËÃû˼Ò壬ËùνµÄ±¾µØÎļþ°üº¬Â©¶´Ö¸µÄÊǹ¥»÷Õßͨ¹ý¿ØÖưüº¬Îļþº¯Êý£¬Èçinclude£¨£©£¬require£¨£©µÈ£¬¼ÓÔØ·þÎñÆ÷±¾µØÉϵÄPHP½Å±¾Îļþ£¬µ±È»Èç¹û±¾µØµÄPHP½Å±¾Îļþ¶¼ÊÇһЩ¶ÔϵͳÎÞº¦µÄ¹¦ÄÜÐÔÎļþ£¬¹¥»÷ÕßÒ²ÎÞ·¨½øÐнøÒ»²½µÄÀûÓ㬵«ÈôÊǹ¥»÷ÕßÄܹ»ÅäºÏÈÎÒâÎļþÉÏ´«Â©¶´£¬½«¶ñÒâÎļþÉÏ´«½ø·þÎñÆ÷ÖУ¬ÔÙͨ¹ý±¾µØÎļþ°üº¬Ö´ÐиöñÒâ½Å±¾¾Í¿ÉÒÔ´ïµ½»ñµÃÍøÕ¾¿ØÖÆÈ¨µÄÄ¿µÄ¡£


      ¶øÔ¶³ÌÎļþ°üº¬Â©¶´ÊÇÖ¸¹¥»÷Õß¿ÉÒÔͨ¹ýÎļþ°üº¬º¯Êý¼ÓÔØÆäËû·þÎñÆ÷ÉϵÄPHPÎļþ£¬ÔÚʵ¼ÊÏîÉøÍ¸Ä¿ÖУ¬¹¥»÷Õß¿ÉÒÔÔÚ×Ô¼ºµÄ·þÎñÆ÷ÉÏ´æ·ÅÒ»¸ö¿ÉÖ´ÐеĶñÒâÎļþ£¬È»ºóͨ¹ýÄ¿±êÍøÕ¾´æÔÚÔ¶³ÌÎļþ°üº¬Â©¶´À´¼ÓÔØÏà¹ØÎļþ£¬ÊµÏÖÈÎÒâÃüÁîÖ´ÐС£


      ©¶´¸´ÏÖ


      01PHP±¾µØÎļþ°üº¬Â©¶´»ñÈ¡·þÎñÆ÷Ãô¸ÐÐÅÏ¢


      ´î½¨²âÊÔ»·¾³£¬ÎªÁË·½±ãÑÝʾ£¬ÎÒÃǼòµ¥Éè¼ÆÁËÒ»¸ö·þÎñÆ÷ÉϵÄPHP½Å±¾´úÂ룬ÈçÏ£º



      ÆäÖÐPHPÅäÖÃÎļþÖУ¬allow_url_fopenºÍallow_url_includeÁ½¸ö²ÎÊýĬÈÏÊÇONµÄ״̬¡££¨ÔÚ±¾µØÎļþ°üº¬Â©¶´ÖУ¬allow_url_fopen±ØÐëÊÇONµÄ״̬allow_url_includeµÄ״̬¿ÉÒÔ²»ÓñØÐëÖ¸¶¨¡££©



      ͨ¹ý·ÃÎʸÃ×ÊÔ´£¬¿ÉÒÔÅжÏʹÓÃÁËÎļþ°üº¬º¯Êý¡£



      ·þÎñÆ÷Ö±½Ó½«file²ÎÊýµ±×÷Îļþ°üº¬µÄ²ÎÊý·¾¶£¬²¢Î´×öÈκιýÂË£¬¹¥»÷Õß¿ÉÒÔÖ±½ÓÔÚfile²ÎÊýºóÃæÌîд·þÎñÆ÷Ãô¸ÐÎļþ·¾¶£¬´Ó¶ø»ñµÃ·þÎñÆ÷Ãô¸ÐÐÅÏ¢£¬ÀýÈçÔÚfileºó¼ÓÉÏ../../MYSQL/my.ini¼´¿É¶ÁÈ¡µ½·þÎñÆ÷±¾µØµÄMysqlÅäÖÃÎļþ¡£



      02PHPÔ¶³ÌÎļþ°üº¬Â©¶´»ñµÃÍøÕ¾WebShell


      ͬÑù»¹ÊDzÉÓÃÏàͬµÄ·þÎñÆ÷´úÂ룬ÆäÖÐPHPÅäÖÃÎļþÖУ¬allow_url_fopenºÍallow_url_includeÁ½¸ö²ÎÊý¶¼±ØÐëÊÇONµÄ״̬¡£


      Ä¿±ê·þÎñÆ÷µØÖ·£º192.168.20.35


      ¹¥»÷ÕßÔ¶³Ì·þÎñÆ÷£º192.168.210.102


      ÔÚ¹¥»÷Õ߸öÈË·þÎñÆ÷ÉÏ£¬·ÅÖÃÁËÒ»¸ö¶ñÒâÎļþ£¨index.txt£©£¬ÈçÏ£º



      ¸ÃÎļþ¿ÉÒÔÏòÄ¿±ê·þÎñÆ÷ÉÏ´´½¨Ò»¸öhack.php½Å±¾Îļþ£¬²¢ÏòÆäÖÐдÈëÒ»¾ä»°Ä¾Âí£¨Òѱ»Base64¼ÓÃÜ£©,ÕâÀïҪעÒâµÄÊǶñÒâÎļþ²»ÄÜÊÇphp¿É½âÎöµÄÀ©Õ¹Ãû£¬Ò²¾ÍÊDz»ÄÜÒÔphp½áβ¡£



      ¹¥»÷Õßͨ¹ýÔ¶³ÌÎļþ°üº¬Â©¶´£¬´¥·¢¸ÃÎļþ£¨ÔÚfile²ÎÊý´¦Ð´Èëhttp://192.168.210.35/index.txt¼´¿É£©£¬ÈçÏ£º



      È»ºó¹¥»÷Õ߾ͿÉÒÔͨ¹ýÁ¬½Ó¹¤¾ß£¬Ô¶³ÌÁ¬½ÓľÂí²¢»ñµÃÍøÕ¾WebShell



      ·ÀÓù·½°¸


      01¡¢ÉèÖð×Ãûµ¥


      ´úÂëÔÚ½øÐÐÎļþ°üº¬Ê±£¬Èç¹ûÎļþÃû¿ÉÒÔÈ·¶¨£¬¿ÉÒÔÉèÖð×Ãûµ¥¶Ô´«ÈëµÄ²ÎÊý½øÐбȽÏ¡£


      02¡¢¹ýÂËΣÏÕ×Ö·û


      ÓÉÓÚInclude/Require¿ÉÒÔ¶ÔPHP WrapperÐÎʽµÄµØÖ·½øÐаüº¬Ö´ÐУ¨ÐèÒªÅäÖÃphp.ini£©£¬ÔÚLinux»·¾³ÖпÉÒÔͨ¹ý¡±../../¡±µÄÐÎʽ½øÐÐÄ¿Â¼ÈÆ¹ý£¬ËùÒÔÐèÒªÅжÏÎļþÃû³ÆÊÇ·ñΪºÏ·¨µÄPHPÎļþ¡£


      03¡¢ÉèÖÃÎļþĿ¼


      PHPÅäÖÃÎļþÖÐÓÐopen_basedirÑ¡Ïî¿ÉÒÔÉèÖÃÓû§ÐèÒªÖ´ÐеÄÎļþĿ¼£¬Èç¹ûÉèÖÃĿ¼µÄ»°£¬PHP½ö½öÔÚ¸ÃĿ¼ÄÚËÑË÷Îļþ¡£


      04¡¢¹Ø±ÕΣÏÕÅäÖÃ


      PHPÅäÖÃÖеÄallow_url_includeÑ¡ÏîÈç¹û´ò¿ª£¬PHP»áͨ¹ýInclude/Require½øÐÐÔ¶³ÌÎļþ°üº¬£¬ÓÉÓÚÔ¶³ÌÎļþµÄ²»¿ÉÐÅÈÎÐÔ¼°²»È·¶¨ÐÔ£¬ÔÚ¿ª·¢ÖнûÖ¹´ò¿ª´ËÑ¡ÏPHPĬÈÏÊǹرյÄ¡£


      05¡¢ÌáÉý»Æ½ð³Ç¹ÙÍø¿ª·¢Òâʶ


      ÈÎÒâÎļþ°üº¬Â©¶´µÄÖ÷Òª³öÏÖÔÚÄܹ»½âÎö´¦Àí½Å±¾ÎļþµÄº¯ÊýÉÏ£¬Ã»ÓжÔÊäÈëµÄ±äÁ¿½øÐйýÂË£¬µ¼ÖÂÈÎÒâÎļþ°üº¬£¬½ø¶øµ¼Ö¶ñÒâ´úÂëÖ´ÐС£ÔÚ¿ª·¢´¦ÀíÕâÀ๦Äܺ¯ÊýÉÏ£¬Ò»¶¨Òª×ñÑ­±à³Ì¹æ·¶£»ÔÚ´úÂëºËÐÄ´¦£¬¶Ô±äÁ¿½øÐйýÂËÏÞÖÆ£¬ÉèÖÃÎļþ·¾¶»òÕß°×Ãûµ¥£¬±ÜÃâÖ´ÐÐÈÎÒâÎļþ°üº¬¡£


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿