中国网络渗透测试联盟
标题:
最新FCKEditor ASP上传绕过漏洞
[打印本页]
作者:
admin
时间:
2012-12-10 10:18
标题:
最新FCKEditor ASP上传绕过漏洞
exploiut-db:
. L0 H* g& I( \) |+ E) v2 C5 c- a
2 o( Q& E5 u) n, X& M! S
FCKEditor ASP Version 2.6.8 File Upload Protection Bypass
6 Z: `, w8 n! M, N$ O
' O A4 _% h( Y0 X+ R2 g4 @$ a
- Title: FCKEditor 2.6.8 ASP Version File Upload Protection bypass
% ] s' J9 Z* ~. i3 x" m, x; {7 A4 v
- Credit goes to: Mostafa Azizi, Soroush Dalili
s9 N& _7 S1 D/ k9 p# Q9 F
- Link:
http://sourceforge.net/projects/fckeditor/files/FCKeditor/
( v: F& c$ v$ B7 {# n: |
- Description:
) Z4 x2 k1 s7 B P" ?% j0 y9 s
There is no validation on the extensions when FCKEditor 2.6.8 ASP version is
; z6 _8 e- q$ |
dealing with the duplicate files. As a result, it is possible to bypass
5 U) j) a- m7 x1 u f
the protection and upload a file with any extension.
+ V' D. J/ A+ S1 [5 W( w
- Reference:
http://soroush.secproject.com/blog/2012/11/file-in-the-hole/
& n6 y0 X2 g) p# B) \
- Solution: Please check the provided reference or the vendor website.
! r+ ]9 a6 q4 H# u9 A t! d
- PoC:
http://www.youtube.com/v/1VpxlJ5 ... ;rel=0&vq=hd720
( q: v `) `0 S" ~' W
"
9 P- c9 }9 D) j0 U
Note: Quick patch for FCKEditor 2.6.8 File Upload Bypass:
$ y" @( Q9 {( _# S% v
In “config.asp”, wherever you have:
4 _/ U5 R% K8 t& J4 ^& S0 i
ConfigAllowedExtensions.Add “File”,”Extensions Here”
. N9 q& C! j5 Q5 C( H# j* }/ e
Change it to:
) c$ r, |1 @: r, c7 A/ h
ConfigAllowedExtensions.Add “File”,”^(Extensions Here)$”
^% j3 Y G+ l0 K( ?# K9 z
7 a8 N5 j0 l0 e' h* C
5 ?+ g1 L+ _- S9 Q G! A
+ e& s9 U6 w) ]+ n. \
5 R0 w2 W% }- o! S
5 z, L2 N' |. H
php测试无效
/ ]) `" j" { `: Z
asp/aspx测试成功:
% W+ C" Q2 ] d2 a }$ Y% L0 Q
来到/FCKeditor/editor/filemanager/connectors/test.html
! \9 b8 N% `# C1 B0 `' v) X) J2 d
因为结合了之前二次上传的漏洞,所以先上传任意内容的文件:asd.asp.txt
2 P5 P: V; J2 A
3 o. ~$ j2 M! d' n
burpsuite上传包并修改,repeater
8 D6 d- S" x! e/ H# V. S
名字改为asd.asp%00txt 然后把%00专为URL编码上传后得到asd(1).asp
8 ?& m6 O! B- Z! d
% `. Q! e/ H& z
如图,webshell为:http://localhost/userfiles/file/asd(1).asp
! b* T. t- q+ h. X! H7 M& ~6 K! Q6 M
" Z! V; h0 t, w0 \% K8 K* C
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2