Yima

剑未佩妥,出门已是江湖;酒尚余温,入口不识乾坤。

0%

第三节课

SQL注入设置后门操作方式


image-20230714200455603

寻找到SQL注入漏洞,然后注入后门,然后创建一个新linux新用户,

用新用户远程登录linux,然后反向连接黑客机子,防止防火墙,接着就可以控制服务器了.

实际操作


黑进网站后台

image-20230714200649779

image-20230714200703646

image-20230714200711097

image-20230714200717685

image-20230714200723746

image-20230714200729472

image-20230714200737626

借助网站后台,黑进linux。

image-20230714200828953

image-20230714200835482

image-20230714200843706

image-20230714200851815

image-20230714200858767

image-20230714200906869

image-20230714200918059

image-20230714200924248

image-20230714200935795

image-20230714200945784

image-20230714200952795

image-20230714201000283

防范

image-20230714201013421

image-20230714201019656

image-20230714201104819

image-20230714201111713

image-20230714201119641

image-20230714201129200

image-20230714201200151

image-20230714201218669

image-20230714201228701

image-20230714201239177

image-20230714201306535

image-20230714201320934

XSS跨站攻击


image-20230714201418258

image-20230714201433330

rootkit后门

image-20230714201454309

image-20230714201543258

image-20230714201632198


解决rootkit后门

image-20230714201741817

image-20230714201749649

image-20230714201829896

image-20230714201842923

钓鱼攻击

image-20230714201918286

解决

image-20230714201938095

image-20230714201951685

配置web日志服务器实验


image-20230714202301075

image-20230714202308119

首先使用公钥和密钥验证免密登录

image-20230714202605880

image-20230714202613058

image-20230714202620019

image-20230714202626205

image-20230714202636307

image-20230714202654149

image-20230714202711708

系统加固


mysql加固


給特定的数据库一个特定的低权限用户

image-20230714202822559

image-20230714202933716

image-20230714202946485

账户安全策略


image-20230714203146611

image-20230714203153422

image-20230714203238471

image-20230714203309152

image-20230714203324689

image-20230714203333280

APACHE加固

image-20230714203453529

image-20230714203513690

image-20230714203529936

image-20230714203549853

image-20230714203611312

image-20230714203618670

image-20230714203720915

image-20230714203727400

image-20230714203803336

image-20230714203812132

image-20230714203838928

image-20230714203854174

image-20230714203914094

image-20230714203933980

image-20230714203940408