ƵµÀÀ¸Ä¿
Ê×Ò³ > °²È« > ÍøÂ簲ȫ > ÕýÎÄ
°²È«¿ÆÆÕ£ºWafʵÏÖɨÃèÆ÷ʶ±ð ³¹µ×µÖµ²ºÚ¿ÍɨÃè
2021-04-18 11:31:19           
Êղؠ  ÎÒҪͶ¸å
Ŀǰ°²È«²âÊÔµÄÈí¼þÔ½À´Ô½¶à£¬Ò²Ô½À´Ô½Ç¿´ó£¬Ô½À´Ô½¶àµÄÈ˳ÉΪ[ºÚ¿Í]£¬½ñÌìÔÚÍøÉÏ¿´µ½Ò»¸öÎÄÕÂ˵À¹½ØwvsµÄɨÃ裬¹´ÆðÁËÎÒдÕâÆªÎÄÕµÄÓûÍû¡£
 
ÒòΪ¹«Ë¾µÄÈý´óÒµÎñÖ®Ò»¾ÍÓÐÒ»¸öÔÆwaf£¬Ã¿ÌìÀ¹½ØµÄÈÕÖ¾ÀïÃæ£¬Óн«½ü90%µÄÇëÇóÊÇɨÃèÆ÷·¢³ö£¬waf½ÓÊÕµ½ÇëÇó»á½âÎöÊý¾Ý°ü£¬È»ºó¹ýÒ»±é¹æÔò£¬¹ýÍê³É°ÙÉÏǧÌõ¹æÔò±Ø¶¨¶ÔÐÔÄÜÓÐÒ»¶¨µÄÓ°Ïì¡£Èç¹ûÄÜʶ±ð³öÀ´ÊÇÈË»¹ÊÇɨÃèÆ÷µÄÇëÇ󣬾ͿÉÒÔÔÚÕâ·½Ãæ½ÚÊ¡ºÜ´óµÄ×ÊÔ´¡£
 
ÏÂÃæµÄ·ÖÎö½éÉÜÖ»Õë¶Ôweb°²È«É¨ÃèÆ÷¡£
ĿǰȫÄÜÐ͵ÄɨÃèÆ÷Ö÷ÒªÊÇwvs£¨Acunetix Web Vulnerability Scanner£©¡¢AppScan¡¢WebInspect£¬¹úÄÚµÄÏñaisec¡¢bugscanµÈµÈ…»¹ÓйúÄÚÄÇЩÀϰ²È«³§É̵ÄɨÃèÆ÷¾Í²»ËµÁË£¬Ö÷ÒªÌáÒ»ÏÂÏñwvsÕâÖÖʹÓÃÂʱȽϸߵÄ¡£ÁíÍ⻹ÓÐĿ¼ÎļþÐ͵ÄɨÃèÆ÷¡¢×¢È빤¾ß(ÀàËÆsqlmap¡¢Havij)µÈµÈ¡£
 
ɨÃèÆ÷ʶ±ðÖ÷Òª´ÓÒÔϼ¸µãÀ´×ö£º
Ò»¡¢  ɨÃèÆ÷Ö¸ÎÆ(head×Ö¶Î/ÇëÇó²ÎÊýÖµµÈ)
¶þ¡¢  µ¥IP+ cookieijʱ¼ä¶ÎÄÚ´¥·¢¹æÔò´ÎÊý
Èý¡¢  Òþ²ØµÄÁ´½Ó±êÇ©(<a>)
ËÄ¡¢  CookieÖ²Èë
Îå¡¢  ÑéÖ¤ÂëÑéÖ¤
Áù¡¢  µ¥IPÇëÇóʱ¼ä¶ÎÄÚWebserver·µ»Øhttp״̬404±ÈÀý
 
 
Ò»¡¢É¨ÃèÆ÷Ö¸ÎÆ(head×Ö¶Î/ÇëÇó²ÎÊýÖµµÈ)
 
Ŀǰ×î³£¼ûµÄÊÖ·¨¾ÍÊÇÊÕ¼¯É¨ÃèÆ÷µÄÖ¸ÎÆÌØÕ÷À´×öʶ±ð£¬²»Í¬µÄɨÃèÆ÷¶¼ÓÐ×Ô¼ºµÄÒ»Ð©ÌØÕ÷£¬±ÈÈç·¢³öµÄÇëÇó»á¼ÓÒ»Ð©ÌØ¶¨µÄhead ×ֶΣ¬²âÊÔ©¶´µÄÇëÇó²ÎÊýµÄÖµ»á´øÉÏ×Ô¼ºÉ¨ÃèÆ÷µÄÃû³ÆµÈ¡£
ÏÂÃæÍ¨¹ý×¥ÍøÂçÊý¾Ý°üÀ´¿´³£¼ûɨÃèÆ÷µÄÖ¸ÎÆÌØÕ÷£º
 
wvs£¨Acunetix Web Vulnerability Scanner£©£º
ÏÂÃæÊÇÎÒ×¥µ½µÄÒ»¸öwvsµÄÇëÇó
\

GET /help/website-performance-settings/x HTTP/1.1
Pragma: no-cache
Cache-Control: no-cache
Referer: //www.anquanbao.com/help
Acunetix-Aspect: enabled
Acunetix-Aspect-Password: 082119f75623eb7abd7bf357698ff66c
Acunetix-Aspect-Queries: filelist;aspectalerts
Cookie: xxxxxxxxxxxx
Host: www.anquanbao.com
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36
Accept: */*

 
ÇëÇóÍ·ÀïÃæÓÐÈý¸öºÜÃ÷ÏԵıêÖ¾£º
Acunetix-Aspect: enabled
Acunetix-Aspect-Password: 082119f75623eb7abd7bf357698ff66c
Acunetix-Aspect-Queries: filelist;aspectalerts
 
ÁíÍâÔÚÇëÇóµÄ²ÎÊýÖµ£¬±ÈÈçURL¸úPOSTÊý¾ÝÖж¼ÓкÜÃ÷ÏÔµÄacunetix_wvs_security_testÌØÕ÷£¬ÏÂͼÊÇÎÒ´ÓwafÀ¹½ØÖе÷È¡µ½µÄ½á¹û¡£
\



¸ù¾ÝÒÔÉÏץȡµ½µÄÌØÕ÷£¬ÎÒÃÇ¿ÉÒÔ°ÑÕâ¸ö×÷ΪwvsµÄÒ»¸öÖ¸ÎÆ£¬ÔÚwafÖнøÐйýÂË¡£
 
Appscan£º
ͬÑùµÄ£¬appscanÒ²ÓÐ×Ô¼ºµÄÒ»Ð©ÌØÕ÷£¬ÈçÏÂ
\


Bugscan£º
¹ØÓÚBugscan£¬ÎÒ×ÉѯÁËÒ»ÏÂ×÷Õߣ¬×÷Õ߸øÁËXSSÄ£¿éµÄɨÃèÔ´ÂëÎÒ¿´ÁËÏ£¬Ö÷ÒªÌØÕ÷ÊÇ£º
-->'"><H1>XSS@HERE</H1>£¬ÁíÍ⻹ÓÐÒ»Ð©ÌØÕ÷¾Í²»Ò»Ò»ÁоÙ¡£
\




×¢Ò⣺²¢²»ÊÇËùÓеÄÇëÇó¶¼»á´øÓÐɨÃèÆ÷µÄÌØÕ÷£¬±ÈÈçÏÂÃæµÄÒ»¸ö°üÒ²ÊÇwvs·¢³öµÄ£¬µ«ÊÇûÓдøÉÏÃæÎÒÃÇ˵µÄÌØÕ÷£¬É¨ÃèÆ÷Ö¸ÎÆÌØÕ÷Ö»Äֵܵ²×¡Ò»²¿·ÖµÄɨÃ裬µ«ÊÇÎÒÃÇ¿ÉÒÔÀûÓÃÕâЩÐÅϢʶ±ð³öɨÃèÆ÷È»ºó¸ÉµôIPµÈ¡£


\


 
¶þ¡¢µ¥IP+ cookieijʱ¼ä¶ÎÄÚ´¥·¢¹æÔò´ÎÊý
¸ù¾Ýij¸öIP+ cookieijʱ¼ä¶ÎÄÚ´¥·¢wafÀ¹½Ø¹æÔòµÄ´ÎÊý´óÓÚÉ趨µÄij¸ö·§Öµ£¬±ÈÈçÔÚ20ÃëÄÚ£¬Ä³¸öIP+cookie´¥·¢wafÀ¹½Ø¹æÔò10´Î¡£
Êý¾ÝÖ¤Ã÷ÈçÏÂͼ£º
\


ÁíÍ⻹¿ÉÒÔ¸ù¾ÝIP+user angentµÈ£¬»òÕ߸ü¶àά¶È¡£
 
 
 
Èý¡¢Òþ²ØµÄÁ´½Ó±êÇ©µÈ(<a>)
ɨÃèÆ÷µÄÅÀ³æ»á°ÑÒ³ÃæÀïÃæµÄËùÓÐÁ´½Ó¶¼×¥³öÀ´È¥×ö©¶´Ì½²â£¬ÌرðÊÇÏÖÔÚ»ùÓÚwebkitÒ»ÀàµÄɨÃèÆ÷£¬Äܹ»äÖȾcss¸újs£¬¿ÉÒÔÅÀ³ö¸ü¶àµÄÁ´½Ó²âÊÔ¡£
ÏÂÃæÌù³öÒ»¸ö°Ù¶È°Ù¿Æ¹ØÓÚwebkitµÄ½éÉÜ
WebKit ÊÇÒ»¸ö¿ªÔ´µÄä¯ÀÀÆ÷ÒýÇæ£¬ÓëÖ®Ïà¶ÔÓ¦µÄÒýÇæÓÐGecko£¨Mozilla Firefox µÈʹÓ㩺ÍTrident£¨Ò²³ÆMSHTML£¬IE Ê¹Óã©¡£Í¬Ê±WebKit Ò²ÊÇÆ»¹ûMac OS X ϵͳÒýÇæ¿ò¼Ü°æ±¾µÄÃû³Æ£¬Ö÷ÒªÓÃÓÚSafari£¬Dashboard£¬Mail ºÍÆäËûһЩMac OS X ³ÌÐò¡£WebKit ǰÉíÊÇ KDE С×éµÄ KHTML£¬WebKit Ëù°üº¬µÄ WebCore ÅŰæÒýÇæºÍ JSCore ÒýÇæÀ´×ÔÓÚ KDE µÄ KHTML ºÍ KJS£¬µ±ÄêÆ»¹û±È½ÏÁË Gecko ºÍ KHTML ºó£¬ÈÔȻѡÔñÁ˺óÕߣ¬¾ÍÒòΪËüÓµÓÐÇåÎúµÄÔ´Âë½á¹¹¡¢¼«¿ìµÄäÖȾËÙ¶È¡£Apple½« KHTML ·¢Ñï¹â´ó£¬ÍƳöÁË×°±¸ KHTML ¸Ä½øÐÍ WebKit ÒýÇæµÄä¯ÀÀÆ÷ Safari¡£
 
 
Òþ²ØµÄ±êÇ©Á´½ÓÊÇÖ¸ÈË¿´²»¼ûµÄÁ´½Ó£¬Èç<a href="//www.cnseay.com/"></a> ÐÎʽ£¬ÈËÊǵã»÷²»µ½µÄ£¬Ö»ÓÐÈí¼þÄܹ»Æ¥Åä³öÕâ¸öµØÖ·£¬ÎÒÃÇн¨Ò»¸öÍøÒ³£¬×¥É¨ÃèÆ÷Êý¾Ý°ü²âÊÔ¡£

<html> <head> <title>test</title> </head> <body> <a href="//localhost/1.php?id=1"></a> </body> </html>


ͨ¹ýץȡwvsµÄÊý¾Ý°ü¿ÉÒÔ¿´µ½£¬É¨ÃèÆ÷ºÜ¿ìµÄ²¶»ñÁË//localhost/1.php?id=1Õâ¸öÁ´½Ó£¬²¢½øÐЩ¶´²âÊÔ¡£
\




µ±È»Èç¹ûÔÚÕý³£Çé¿öÏÂÒ²¸øËùÓÐÓû§Ö²ÈëÕâÖÖ´úÂëÊǷdz£ÁîÈË·´¸ÐµÄ£¬Óû§ÌåÑéÒ²»á´ó´òÕÛ¿Û£¬¿ÉÒÔÔÚǰÆÚÏÈ×öһЩÌõ¼þÏÞÖÆ£¬±ÈÈç¹Ì¶¨Ê±¼ä¶ÎÄÚ´¥·¢wafÀ¹½Ø¹æÔòµ½´ïÔ¤¶¨·§Öµ£¬ÔÙ¸øÕâ¸öÓû§µ¥¶ÀÖ²ÈëÒ»¸öÒþ²ØÁ´½Ó¡£
 
 
 
ËÄ¡¢CookieÖ²Èë
   CookieÖ²ÈëµÄ·½Ê½¸úÉÏÃæ½²µÄÒþ²ØÁ´½ÓÖ²Èë´óͬСÒ죬ʵÏÖÔ­ÀíÊÇ£ºµ±Ò»¸öIP+user angentÔڹ̶¨Ê±¼ä¶ÎÄÚ´¥·¢¹æÔòµÄ´ÎÊýµ½´ïÒ»¶¨·§Öµ£¬¸ø·¢ÆðÇëÇóµÄÕâ¸öÈËÖ²ÈëÒ»¸öcookie£¬Èç¹ûÏ´ÎÔÙÇëÇóûÓÐЯ´øÕâ¸öcookie£¬Ôò˵Ã÷ÊÇɨÃèÆ÷¡£
cookieÖ²ÈëÓÐÀûÓб×£¬ÓŵãÊǸüÖ±½Ó£¬ÖÖÏÂcookieÂíÉϾÍÄܸù¾ÝÏÂÒ»¸öÇëÇóÅжÏ¡£È±µãÊÇÕâ¸ö·½Ê½ÔÚ»ùÓÚwebkitµÄɨÃèÆ÷ÉÏÃæÐв»Í¨¡£
 
 
 
Îå¡¢ÑéÖ¤ÂëÑéÖ¤
  ÑéÖ¤ÂëÑéÖ¤µÄ·½Ê½¸úÉÏÃæµÄcookieÖ²ÈëÒ²´óͬСÒ죬²»¹ýÊǰÑcookie»»³ÉÁËÑéÖ¤ÂëµÄ·½Ê½£¬ÕâÖÖ·½·¨Ò²±»ÓÃÓÚ·ÀCC¹¥»÷¡£
 
 
 
Áù¡¢µ¥IPÇëÇóʱ¼ä¶ÎÄÚWebserver·µ»Øhttp״̬404±ÈÀý
  ÕâÖÖ·½·¨Ö÷ÒªÓÃÀ´Ó¦¶Ô̽²âÃô¸ÐĿ¼ºÍÎļþµÄɨÃèÆ÷£¬ÕâÀàµÄɨÃèÆ÷¶¼ÊÇ»ùÓÚ×ÖµäÎļþ£¬Í¨¹ý¶Ô×ÖµäÄÚµÄurl½øÐÐÇëÇó»ñµÃµÄ·µ»ØÐÅÏ¢À´½øÐÐÅжÏĿ¼»òÕßÎļþµÄÊÇ·ñ´æÔÚ¡£
  Èç¹ûij¸öIPÔÚÒ»¶Îʱ¼äÄÚÇëÇóƵÂʹý¿ì£¬Õâʱºòwaf¿ÉÒÔ½øÐÐÊÕ¼¯Ò»¶Îʱ¼äÄÚwebserver·µ»Ø404״̬ÊýÄ¿£¬µ½´ïÒ»¶¨·§Öµºó½øÐзâɱ¡£


\


¿´¹ýÉÏÃæ¼¸ÖÖ·½·¨µÄ½éÉÜ£¬Ó¦¸Ã´ó²¿·ÖÈ˶¼»áÏëµ½Á½¸öÎÊÌ⣬
  1.  Ò»´ó²¦ÈËʹÓÃͬһ¸ö¹«ÍøIP£¬ÔõôÅжÏË­Êǹ¥»÷Õߣ¿
  2.  Ò»´ó²¦ÈËʹÓÃͬһ¸ö¹«ÍøIP£¬Ôõô²ÅÄܱ£Ö¤²»Îóɱ£¿
 
µÚÒ»£¬¶ÔÓÚÔõôÅжϹ¥»÷Õߣ¬µ±È»²»Äܵ¥´¿µÄ´ÓÒ»¸öIPÅжÏ£¬Ò»°ãÒ»¸öÍêÕûµÄhttpÇëÇó¶¼»á´øÓÐ
user angent¡¢cookieµÈÐÅÏ¢£¬ÎÒÃÇ¿ÉÒÔ½áºÏip+user angentÀ´ÅжÏÇëÇóµÄÈË£¬»òÕßÔÙ¼ÓÒ»¸öcookieµÄά¶È£¬µ±È»ÔÚ¸øÕâ¸ö¹¥»÷ÕßÖ²Òþ²ØÁ´½Ó¡¢cookie»òÕßÑéÖ¤Âë֮ǰ£¬ÐèÒªËü´¥·¢Ò»Ð©¹æÔò·§Öµ£¬ÒÔÃâÓ°ÏìÓû§ÌåÑé¡£
   µÚ¶þ£¬Ëµµ½Ôõô±£Ö¤²»Îóɱ£¬Ò²¾ÍÊÇÔõôȥ·âɱµÄÎÊÌ⣬¹Ø¼üÔÚÓÚÔõô¶þ´ÎÅжϹ¥»÷Õߣ¬Ä¿Ç°×îºÃµÄ·½·¨Ò²ÊÇÀûÓÃip+user angent£¬ÔÚÅжÏÊÇɨÃèÆ÷ÇëÇóºó£¬¸ù¾ÝIP+user angent½øÐзâɱ£¬ÁíÍâÒ²ÊÇ¿¿cookie·âɱ£¬¹Ø¼üÔÚÓÚÊÇЯ´øÄ³¸öcookie¼üµÄ·âɱµô»¹ÊDz»´øµÄ·âɱµô¡£


   PS£ºÈç¹ûÎóɱ̫´ó£¬Èç¹û¸ÕºÃÄĸöÃÃÖ½ÔÚÏß¿´Ð¡µçÓ°µ½¼¤Ç鯬¶Î£¬ÕâÊǶàÉËÈËÃÃÖ½µÄÐİ¡
µã»÷¸´ÖÆÁ´½Ó ÓëºÃÓÑ·ÖÏí!»Ø±¾Õ¾Ê×Ò³
ÉÏһƪ£ºÎÒÊÇÈçºÎÄÃÏÂ17173ÂÛ̳¹ÜÀíԱȨÏÞµÄ(QQµØÓòÐÅÏ¢ÀûÓü¼ÇÉ)
ÏÂһƪ£ºÄÇЩӦ¶ÔAPT¹¥»÷µÄ×îм¼Êõ
Ïà¹ØÎÄÕÂ
ͼÎÄÍÆ¼ö
µã»÷ÅÅÐÐ

¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ¹ã¸æ·þÎñ | Ͷ×ʺÏ×÷ | °æÈ¨ÉêÃ÷ | ÔÚÏß°ïÖú | ÍøÕ¾µØÍ¼ | ×÷Æ··¢²¼ | Vip¼¼ÊõÅàѵ | ¾Ù±¨ÖÐÐÄ

°æÈ¨ËùÓÐ: È«·å°²È«ÁªÃË--ÖÂÁ¦ÓÚ×öʵÓõÄIT¼¼ÊõÑ§Ï°ÍøÕ¾