Jump to content

Title: Common entry points for penetration of Spinach Website (APP)

Featured Replies

Posted

I made a lot of qp (chess and cards), and BC penetrated. I spent 2 nights all night and drank a few plates. I briefly talked about the process and summarized it.

Let me first talk about qp. Taking my penetration success case as an example, first of all, information collection is essential. What are the characteristics of qp?

His background will be set up in different ports behind the server domain name, as shown in the figure:

图片

You can find the basics about the port.

Point of entry:

Find the location of SQL injection or feedback in the app, XSS

There is a situation where the packet capture shows 127.0.0.1 and the packet cannot be caught. This situation is more than that of the large plate, and it does not necessarily follow the TCP UDP protocol. You can refer to the Proxifier global proxy mentioned by T-ice

After you have the background, you can fuzz it. Some administrators will have the habit of backup and may make new discoveries.

Relatively speaking, qp is quite simple.

Let’s talk about BC and see the case of penetration last night.

图片

Basically, large BC plates are equipped with various protection + cdn standard. After all, others don’t care about this little device money after making so much money.

图片

图片

I registered an account and found that there was no place to call XSS. Stop

Because this kind of large-scale service is generally quite good, the cards are very generous in every aspect, such as navigation and points mall.

There should be a messy one. On a VIP query page of its main site, it is a sql injection, and it is a thinkphp framework.

图片

图片

图片

Thinkphp3.2.3, because there is a CDN that doesn't know the real IP, the background is a very troublesome thing. I originally wanted to see if there is any discovery in the log in the database.

图片

图片

Nothing for use in birds. Try reading the log file, no.

图片

Finally, reading the configuration file confirmed something very stupid.

Maybe after all night, people's mind is a little stiff.

I forgot that this kind of BC background must be separated. Hi. Stay up late less.

then. I have manually added some possible parameters to the main domain name based on my previous experience. admin.XXXX.com agdw.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Important Information

HackTeam Cookie PolicyWe have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.