edu信息收集

去挖edusrc的举办方学校,去找他们的学号,一般就是通过google去搜索xlsx文件。

site:sjtu.edu.cn filetype:xlsx "学号"

但可能找到的是很多年前的学号或者是部分打码的学号

很多系统的弱口令都是学生用户名是学号,教室用户名是工号,密码是身份证后6位

找回密码处可能问题验证很简单很容易猜

根域名收集

爱企查、企查查获得根域名

爱企查

企查查

天眼查

image-20241009103905841

ICP备案获得根域名

ICP备案

image-20241009104248171

站长之家历史查询

站长之家

image-20241009105341345

SSL证书获得根域名、子域名、偏远资产

image-20241009105559509

image-20241009110435188

注册人反查获得根域名

站长之家注册人反查

image-20241009111113934

ICP备案号获得根域名

由于域名最终指向的还是ip,因此可以搜到大量ip不带域名的资产!可以找隐藏资产!

image-20241009111427754

image-20241009111547226

子域名获取

子域名挖掘机、oneforall或者灯塔。

fofa,hunter

灯塔搜集子域名

image-20241009111722013

子域名挖掘机爆破子域名

子域名挖掘机

image-20241009111923583

SSL证书获得子域名

https://myssl.com

image-20241009123030520

FOFA获得子域名

domain="baidu,com"

image-20241009123258323

Virustotal获得子域名

virustotal

image-20241009125733416

image-20241009130133328

Oneforall获得子域名

https://github.com/shmilylty/OneForAll

python3 oneforall.py --target 域名 run

image-20241009130428679

模糊查询获得资产

ICP备案号:

1
2
FOFA:
icp="xxxx"

SSL证书:

1
2
FOFA:
cert="xxxx"

title关键词:

1
2
FOFA:
title="xxx公司"

body关键词:

1
2
3
4
FOFA:
body="xxx公司"

或者在静态资源中提取特殊内容,进行body语法搜索

Icon图标hash

点击图标后可以直接获得hash值

image-20241009131344741

1
icon_hash="-1374555452"

集团和子公司

子公司,一个企业src的全资的子公司一般都会收取,对于控股大于50%的是属于有概率收取,因为在护网中,控股大于50%也属于攻击目标

在爱企查中,可以直接看股权架构图

image-20241009131847977

自动化信息收集公司、子公司

ecscan,对目标企业进行快速信息收集

enscan

路径获取

dirsearch爆破路径

1
2
python3 dirsearch.py -u http://127.0.0.1/ -e *
python3 dirsearch.py -y http://目标/ -e *

谷歌语法-获得路径-破除空白页面

常用的搜集手机号,搜集站点,获取网站路径

domain="iqiyi.com" && body="Whitelabel Error Page"

springboot空白页面

image-20241009133800023

nginx空白页面

image-20241009133855870

这些路径放到谷歌,bing上搜,谷歌,bing可能会记录一些敏感路径

image-20241009134211951

谷歌语法搜集敏感信息

收集敏感信息

1
site:edu.cn filetype:xlsx 身份证

image-20241009135232945

在线谷歌语法搜集敏感信息

https://ght.se7ensec.cn/# 国内

image-20241009144128218

谷歌语法

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
目录遍历:site:edu.cn intitle:index.of

配置文件泄露:site:edu.cn ext:xml | ext:conf | ext:cnf | ext:reg | ext:inf | ext:rdp | ext:cfg | ext:txt | ext:ora | ext:ini

数据库文件泄露:site:.edu.cn ext:sql | ext:dbf | ext:db | ext:mdb

日志文件泄露:site:edu.cn ext:log

备份和历史文件:site:edu.cn ext:bkf | ext:bkp | ext:bak | ext:old | ext:backup

登录页面:site:edu.cn inurl:login | inurl:admin | inurl:manage | inurl:system | inurl:backend | intitle:登陆 | intitle:后台 | intitle:管理 | intitle:认证

SQL错误:site:edu.cn intext:"sql syntax near" | intext:"syntax error has occurred" | intext:"incorrect syntax near" | intext:"unexpected end of SQL command" | intext:"Warning: mysql_connect()" | intext:"Warning: mysql_query()" | intext:"Warning: pg_connect()"

公开文件信息:site:edu.cn ext:doc | ext:docx | ext:odt | ext:pdf | ext:rtf | ext:sxw | ext:psw | ext:ppt | ext:pptx | ext:pps | ext:csv
phpinfo():site:edu.cn ext:php intitle:phpinfo "published by the PHP Group"

搜索Pastebin.com和其他粘贴站点:site:pastebin.com | site:paste2.org | site:pastehtml.com | site:slexy.org | site:snipplr.com | site:snipt.net | site:textsnip.com | site:bitpaste.app | site:justpaste.it | site:heypasteit.com | site:hastebin.com | site:dpaste.org | site:dpaste.com | site:codepad.org | site:jsitor.com | site:codepen.io | site:jsfiddle.net | site:dotnetfiddle.net | site:phpfiddle.org | site:ide.geeksforgeeks.org | site:repl.it | site:ideone.com | site:paste.debian.net | site:paste.org | site:paste.org.ru | site:codebeautify.org | site:codeshare.io | site:trello.com "xxx.edu.cn"

搜索github.com和gitlab.com:site:github.com | site:gitlab.com "xxx.edu.cn"

https://dorks.faisalahmed.me/ 国外

image-20241009144235309

更多语法

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
报告类的:
site:edu.cn "审计报告" "身份证号" filetype:pdf
site:edu.cn "财务报告" "身份证号" filetype:pdf

奖金类的:
site:edu.cn "科技奖" "身份证号" filetype:pdf
site:edu.cn "专利发明" "身份证号" filetype:pdf

证书类的:
site:edu.cn "营业执照" "身份证号" filetype:pdf
site:edu.cn "职称证" "身份证号" filetype:pdf

业务词:
site:edu.cn "无犯罪记录证明" "身份证号" filetype:pdf
site:edu.cn "情况属实,特此证明" "身份证号" filetype:pdf
site:edu.cn "特发此证" "身份证号" filetype:pdf
site:edu.cn "法定代表人" filetype:pdf

个人类的:
site:edu.cn "年月.*" "聘任时间" "SFZH" filetype:pdf -学号 -准考证
site:edu.cn "破格*" "身份证号" filetype:pdf -学号 -准考证
site:edu.cn "汉*" "身份证号" filetype:pdf -学号 -准考证
site:tongji.edu.cn "汉*" "身份证号" filetype:xlsx -学号 -准考证
site:sqxy.edu.cn "名单" "身份证号" "手机号" "考生号" filetype:xlsx -学号 -准考证

合同类的:
site:edu.cn "同意推荐其参评*" filetype:pdf +身份证号 -学号 -准考证
site:edu.cn "*出版合同" filetype:pdf +身份证号 -学号 -准考证
site:edu.cn "甲方代表" filetype:pdf +身份证号 -学号 -准考证
site:edu.cn "甲方代表人" filetype:pdf +身份证号 -学号 -准考证
site:edu.cn "甲方聘请乙方" filetype:pdf +身份证号 -学号 -准考证
site:edu.cn "甲方的权利和义务" filetype:pdf +身份证号 -学号 -准考证
--------------------------------------------
site:edu.cn inurl:"xxx/xxxx" filetype:pdf +身份证号 -学号 -准考证

APP层面信息收集

app版本迭代

在老版本中,可能会存在app不加壳,并且可以正常使用。存在很大风险。

豌豆荚下载老版本

image-20241009145750742

app提取url

1
https://github.com/kelvinBen/AppInfoScanner

可以直接提取未加壳的app里面的所有url等信息

1
python app.py android -i base.apk

端口扫描-添加上nmap

端口扫描非常重要,扫到服务如果没法访问,记得http和https来回切换访问

使用nmap和Tscanplus

tide团队的无影

image-20241009150258268

nmap的快速扫描命令

1
nmap -sS -Pn -n --open --min-hostgroup 4 --min-parallelism 1024 --host-timeout 30 -T4 -v -p 1-65535 -iL ip.txt -oX output.xml

image-20241009150707259

网络空间搜索引擎

1
2
3
4
5
6
FOFA		https://fofa.info/
Hunter https://hunter.qianxin.com/
360Quake https://quake.360.net/quake/#/index
Shadon https://www.shodan.io/dashboard
Zoomeye https://www.zoomeye.org/
00信安 https://0.zone/

常出现漏洞的敏感特征

1
2
3
4
5
6
SpringBoot:
actuator
body="Whitelabel Error Page"
body="\"timestamp\": \"2024"&& body="\"status\": 404,"
body="\"timestamp\": \"2024" && body="\"status\": 404," && port="8081"
body="\"timestamp\": \"2024" && body="\"status\": 404," && port="8081"&&country!="CN"

Springboot两个特征 报错页面和404

image-20241009152315168

image-20241009152419836

1
2
3
若依druid:
body="请通过前端地址访问"
进行路径拼接(/druid/login.html),然后进行druid弱口令(admin/admin123、admin/admin、admin/123456、ruoyi/123456、ry/123456)

image-20241009152828446

1
2
weblogic:
body="10.4.5 404 Not Found"
1
2
jeecg-boot:
app="JeecgBoot-企业级低代码平台"

搜集登录、后台、注册等

1
2
domain="xxx.com" && (title="登录"||title="后台"||"管理")
domain="xxx.com" && (body="注册"||body="验证码登录")

小程序/APP/根域名收集

小蓝本

https://sou.xiaolanben.compc

ICP备案查询小程序

image-20241009195141595

image-20241009195253429

让审核自己都找不到的小程序

手机,或者模拟器

image-20241009195820529

image-20241009195940343

image-20241009195855582

image-20241009200013982

网盘信息搜集

凌风云

https://www.yunpz.net/wangpan.html

http://ww.zhuzhupan2.com/

源码泄露搜索

https://searchcode.com

image-20241009200458826