总字符数: 9.66K
代码: 无, 文本: 2.49K
预计阅读时间: 11 分钟
data:image/s3,"s3://crabby-images/e34ac/e34acb35cc2a633886741b7f93931433974af5f8" alt=""
一、什么是业务逻辑漏洞?
业务逻辑漏洞就是指攻击者利用业务/功能上的设计缺陷,获取敏感信息或破坏业务的完整性.一般出现在密码修改、越权访问、密码找回、交易支付金额等功能处. 逻辑漏洞的破坏方式并非是向程序添加破坏内容,而是利用逻辑处理不严密或代码问题或固有不足,进行漏洞利用的一个方式.
二、BP靶场之11关
Security Issue | Description |
---|---|
Excessive trust in client-side controls | 过度信任客户端控件 |
High-level logic vulnerability | 高级逻辑漏洞 |
Inconsistent security controls | 不一致的安全控制 |
Flawed enforcement of business rules | 业务规则执行上的缺陷 |
Low-level logic flaw | 低级逻辑缺陷 |
Inconsistent handling of exceptional input | 异常输入的不一致处理 |
Weak isolation on dual-use endpoint | 两用端点上的弱隔离 |
Insufficient workflow validation | 工作流验证不足 |
Authentication bypass via flawed state machine | 通过有缺陷的状态机绕过认证 |
Infinite money logic flaw | 无限金钱逻辑缺陷 |
Authentication bypass via encryption oracle | 通过加密oracle绕过身份验证 |
三、靶场实践
1、Excessive trust in client-side controls(过度信任客户端控件)
用户可控数据:一个根本性的错误假设是用户将只通过提供的Web界面与应用程序交互,导致进一步假设客户端验证将防止用户提供恶意输入.但攻击者可以简单地使用Burp Proxy等工具,在浏览器发送数据之后、传递到服务器端逻辑之前篡改数据.这实际上使客户端控件变得无用
数据完整性检测:如果只接受数据的表面价值,而不执行适当的完整性检查和服务器端验证,攻击者就可以以相对最小的努力进行各种破坏.它们能够实现的具体效果取决于功能以及它对可控数据所做的操作.在适当的情况下,这种缺陷可能会对业务相关功能和网站本身的安全性造成破坏性后果.
data:image/s3,"s3://crabby-images/49fc7/49fc7207f033608dfccaefd6af98285f7a791295" alt=""
data:image/s3,"s3://crabby-images/0b667/0b6674e5f11c0b2b920592c1e26f916ca3dbd3a8" alt=""
data:image/s3,"s3://crabby-images/71a8b/71a8b1c56399ae33acfa1ef1e0492c856e73d34e" alt=""
data:image/s3,"s3://crabby-images/444dd/444dd0562a5f5734c3f0ab317e36063b67be7bf0" alt=""
然后我们查看一下HTPTP历史,寻找具有支付信息的数据包
data:image/s3,"s3://crabby-images/d36dd/d36dd064afe7ebca640315780556079cfe568ff3" alt=""
然后我们将这个数据包发送给repeater(也就是重发器)
data:image/s3,"s3://crabby-images/caee7/caee77f7491cd1fd58828c9ac6d34536f535821d" alt=""
发送到重发器后进行更改金额
data:image/s3,"s3://crabby-images/7902b/7902be03f3b7beb6bad28feecef5636dbded5ce1" alt=""
关闭代理刷新一下,然后看一下刷新后的页面
data:image/s3,"s3://crabby-images/484da/484da2ac90bc6fe42254bf4543aa4892dce3034c" alt=""
点击支付后,这个靶场就会显示通关
data:image/s3,"s3://crabby-images/e8cda/e8cda05510fa9df94be19217baa9ceee83188a1c" alt=""
2、High-level logic vulnerability(高级逻辑漏洞)
data:image/s3,"s3://crabby-images/b3878/b3878fe3e6b8ff655468f5c3f5b4e9835638af12" alt=""
抓一个发现没有价格金额这个参数
data:image/s3,"s3://crabby-images/35b04/35b045b591fa29d14fc07bc6ce51234f263f62d8" alt=""
data:image/s3,"s3://crabby-images/9c42a/9c42a23bd72e6c22995c933653c4072217c8be0d" alt=""
但是我们发现这个数目可以是负数,那我们就试一下是否可以增加其他的商品,试一下是否可以将他们的数目更改为负数.
data:image/s3,"s3://crabby-images/e2cea/e2cea0cc79f2e46f4ee83c0d13ec8a34f9764d93" alt=""
然后我们进行抓包,查看是否能更改数目为负数
data:image/s3,"s3://crabby-images/ca118/ca118a8174de66d2feef2928a3e7a08be8e78b86" alt=""
data:image/s3,"s3://crabby-images/e901b/e901beb468b8fc6d8749435d9b37ee209226e57c" alt=""
但是我们的余额为100,所以还得继续增加负数,直到价格合适
data:image/s3,"s3://crabby-images/c4d48/c4d487e0c8d3f7d0387458b125f95989d0347da4" alt=""
data:image/s3,"s3://crabby-images/04203/0420346fe6b6010e9b2e0713d2315b6e1cf482b6" alt=""
成功
3、Inconsistent security controls(不一致的安全控制)
data:image/s3,"s3://crabby-images/961b5/961b524ede5c6d1faaade21ee118c207ae9b330e" alt=""
然后登录的时候发现还是不行,那就看一下页面中的其他信息,其中EMAIl client
data:image/s3,"s3://crabby-images/fc4a5/fc4a585dbd23271902b05bddfc1c455197655f35" alt=""
data:image/s3,"s3://crabby-images/7ee94/7ee94d0fe07779893bd91989f73ac1ac49fea6ec" alt=""
然后我们重新注册一下
data:image/s3,"s3://crabby-images/3d86a/3d86aaea3de9b0f5e5371a878f9e00a429552578" alt=""
重新到email client中
data:image/s3,"s3://crabby-images/f3a72/f3a729cc540f2242616e511364c704f3b697ca37" alt=""
发现注册成功
data:image/s3,"s3://crabby-images/99ac5/99ac50219d54ac32d08e728990df9a598473dd74" alt=""
data:image/s3,"s3://crabby-images/48404/48404c5f23fc52d3f3115f27cb971ad4371913c6" alt=""
data:image/s3,"s3://crabby-images/e4de8/e4de875df989339f5f5e0b7b420149c42441c98d" alt=""
data:image/s3,"s3://crabby-images/c7c7d/c7c7d627adadee771529a705a4c6716aae8ff550" alt=""
删除后发现成功了
4、Flawed enforcement of business rules(商业规则的执行有缺陷)
这里其实是一个优惠卷重复使用
data:image/s3,"s3://crabby-images/26050/26050909e2055571cce8599c87ec139715eab1d7" alt=""
data:image/s3,"s3://crabby-images/92687/92687762f3d2db8c77d72bbf02d83eeeec44ceaf" alt=""
data:image/s3,"s3://crabby-images/92687/92687762f3d2db8c77d72bbf02d83eeeec44ceaf" alt=""
发现弹窗
data:image/s3,"s3://crabby-images/e1497/e14973d9c7f4b39514667ed2481f22d158d18d4e" alt=""
data:image/s3,"s3://crabby-images/48a25/48a253703b37655badb521c6b22ee4c2a20c0578" alt=""
但是总体价格还是不够,尝试一下能不能再重复利用一下
data:image/s3,"s3://crabby-images/58dfa/58dfa47f9ec3b822d9cac06bd7360e3f985ea8ef" alt=""
发现只能交替使用
data:image/s3,"s3://crabby-images/07ff9/07ff9d6f10598899e10c10991cbf6d4de3c25243" alt=""
data:image/s3,"s3://crabby-images/c7a7f/c7a7f87eec431c9f30db9f5e2afc3d21700bdf73" alt=""
5、Low-level logic flaw(低级逻辑缺陷)
data:image/s3,"s3://crabby-images/31f06/31f0609b2eaefe9be7211687c8199616a3fc60c0" alt=""
data:image/s3,"s3://crabby-images/145e9/145e9fd7109a3d32165dc83f84172adbb9689187" alt=""
修改数值为99(100和负数不行),并发送,这里不使用负载相当于重放攻击
data:image/s3,"s3://crabby-images/1baf0/1baf0d7f60b13a98aab968d7a5503085e8062fab" alt=""
data:image/s3,"s3://crabby-images/0e102/0e102b6cba0e3b651e3b261a21ddac161f90f326" alt=""
接下来添加另一个商品,将总金额控制在100一下
data:image/s3,"s3://crabby-images/801ca/801ca490f9df433209cdff0a9507020e7212e76a" alt=""
data:image/s3,"s3://crabby-images/53108/531089d582c92851eff52125df3065c72ab39ebd" alt=""
价格上可以进行改动一下
6、Inconsistent handling of exceptional input(异常输入的不一致处理)
7、Weak isolation on dual-use endpoint(两用端点上的弱隔离)
登录我们自己的账号后出现以下页面
data:image/s3,"s3://crabby-images/e0e1f/e0e1f2248beef4b6d405ec2a9fe8eecd26a6a167" alt=""
我们可以尝试对账号密码进行修改,是否可以修改其他人的账号密码,先抓个包测试一下
data:image/s3,"s3://crabby-images/c029d/c029da59cfe5af37bee0826551abb033e3263943" alt=""
删除后发现修改成功
data:image/s3,"s3://crabby-images/c2952/c295256bf61f1e464e0512c799075e8a529bda0a" alt=""
我们继续尝试修改username为administrator
data:image/s3,"s3://crabby-images/249bc/249bcbf3cdf99121c62a353b200d791ef3350346" alt=""
修改成功,我们用这个账号重新登录
data:image/s3,"s3://crabby-images/ac90a/ac90addb534b304939bcea2041df4bad0b30585e" alt=""
data:image/s3,"s3://crabby-images/c12fe/c12feea660bfa104b1ae95f3ea8f094455fe7159" alt=""
然后删除,修改成功
8、Insufficient workflow validation(工作流验证不足)
这里我们先随便买一个在100刀以内的商品,看一下流程
data:image/s3,"s3://crabby-images/7639f/7639fa1abe5f36566b844fc1894438563ab3d9e6" alt=""
data:image/s3,"s3://crabby-images/47d34/47d34d3e3ed9ccb99a041164ec44e3b1d1d286b0" alt=""
data:image/s3,"s3://crabby-images/fe9ef/fe9ef138eb16555b16a599e428c5ed9eb6a7422d" alt=""
现在我们买皮夹克,虽然价格不够,但是我们再观察观察
data:image/s3,"s3://crabby-images/da8ba/da8baf9102091e91f60be8cc00d813370a43270e" alt=""
抓个包分析一下
data:image/s3,"s3://crabby-images/edb04/edb04201a37c4ed47f050472ef7fedf34f48e443" alt=""
跟上面的数据包对比一下,发现POST和GET传的不一样,我们修改一下,尝试一下
data:image/s3,"s3://crabby-images/6e41a/6e41ab7c5635abde24d88159ab3a6e2ba4e70fc3" alt=""
一直放包,可以购买成功
9、Authentication bypass via flawed state machine(通过有缺陷的状态机绕过认证)
先按照自己的账号登录一下
data:image/s3,"s3://crabby-images/25067/2506746c215b3b442113b70e9c380a5c241ce994" alt=""
发现这里有个身份的选择
data:image/s3,"s3://crabby-images/fa9eb/fa9eba5619c24b0ff70f86a0176c17ed30670bd4" alt=""
抓个包看一下
data:image/s3,"s3://crabby-images/e5624/e5624e5ed10344a18e9917da4fcdaf219c57d8be" alt=""
data:image/s3,"s3://crabby-images/1332d/1332dffe0637fde6d55b3e44b34baed0213a4a3e" alt=""
对比一下,发现好像没啥区别,但是我们尝试一下删除/role-selector直接访问首页,因为跳过了角色选择默认为administrator当访问首页是以administrator权限进行访问的因此会有Admin panel,再登录页面登录,我们再废掉这个身份选择这个数据包
data:image/s3,"s3://crabby-images/f8412/f8412af05b0791f7cf3c113137ae8b81d0211c5a" alt=""
data:image/s3,"s3://crabby-images/7b526/7b526ecd44565c2929957795f5366ce802775c37" alt=""
删除rola-selector这个路径
data:image/s3,"s3://crabby-images/9e122/9e122c9c935c1ed52b8c9e880f21e789cd7e7180" alt=""
发现出现amin panel这个页面
data:image/s3,"s3://crabby-images/b76de/b76de68ee8466b3f45ebe61fb6796b58abd210b6" alt=""
10、Infinite money logic flaw(无限金钱逻辑缺陷)
data:image/s3,"s3://crabby-images/66c85/66c85d3834d7dc501ac0107c1976d29b50ec864a" alt=""
获得优惠卷
data:image/s3,"s3://crabby-images/ba245/ba2458be7a69137af9c499676fac131ae8ae817e" alt=""
使用优惠券购买Gift Card礼品卡(礼品卡相当于一个10元的购物券可以赠送),当用3元优惠券购买10元的礼品卡,就相当于7元购买了10元然后再进行使用用户的余额就会多了3元将优惠券金额转换为真实的余额.
data:image/s3,"s3://crabby-images/3d126/3d126ea727cda57c559870897446007c390ff429" alt=""
data:image/s3,"s3://crabby-images/300ca/300ca4eb7c63cf60a172c089aa2ebae82e49334a" alt=""
data:image/s3,"s3://crabby-images/2b132/2b132a32b901d59f17a6021c25b28d7851453ee1" alt=""
如果优惠券可以重复使用,就可以利用该操作达到无限金额的效果,成功复用优惠券,接下来就用bp的宏指令
data:image/s3,"s3://crabby-images/ec88d/ec88daefd7178f316542dadcc836caaf70dfdd2e" alt=""
data:image/s3,"s3://crabby-images/12fa1/12fa16c5cd3b021cc679add4b908d95a548da717" alt=""
找到以下几个页面
data:image/s3,"s3://crabby-images/c5fde/c5fde88faa7629b4496d6ef56c717aa4fc98754e" alt=""
data:image/s3,"s3://crabby-images/235ff/235ff8debdd3238698808d3d0b88ca82548a3991" alt=""
data:image/s3,"s3://crabby-images/66026/660264b68309ba9d4286ef1d06276d50f68de99c" alt=""
继续给第五个配置项目
data:image/s3,"s3://crabby-images/44c01/44c01c74de309b65d09a428059f4bf2e2329df89" alt=""
data:image/s3,"s3://crabby-images/c3134/c3134c26d2e3d1157c842b25ced9bac2ec94d53c" alt=""
data:image/s3,"s3://crabby-images/4c12b/4c12b5103e95e50fbb8ad843af1a0bcda28a733b" alt=""
data:image/s3,"s3://crabby-images/a5ecd/a5ecdc47af99975d1a6955180c7e20f6d318dd92" alt=""
线程设置为1