找回密码
 立即注册
查看: 2964|回复: 0
打印 上一主题 下一主题

最新FCKEditor ASP上传绕过漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2012-12-10 10:18:50 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
exploiut-db:) H$ U( ~+ f# h5 Y, a4 t

. p3 V  G/ @* S4 X  k% _- WFCKEditor ASP Version 2.6.8 File Upload Protection Bypass& @7 f, g1 D" Y8 K' U9 y4 S
4 [4 Q2 k8 v6 ~$ U) |& c* O7 j
- Title: FCKEditor 2.6.8 ASP Version File Upload Protection bypass
5 D  e. M7 w! s. M& g- Credit goes to: Mostafa Azizi, Soroush Dalili: O/ B4 A! U/ W" y
- Link:http://sourceforge.net/projects/fckeditor/files/FCKeditor/" Y( o0 n* a( C- n
- Description:. C! d% i8 l7 ~8 E" ]7 o6 U1 j. b
There is no validation on the extensions when FCKEditor 2.6.8 ASP version is
5 ^7 m# d- W  M9 x5 x! sdealing with the duplicate files. As a result, it is possible to bypass/ E8 \) `0 f& M7 @
the protection and upload a file with any extension.
6 D# K) e5 R) q/ W4 Y- z- Reference: http://soroush.secproject.com/blog/2012/11/file-in-the-hole/6 F3 D+ o6 ~6 ^* d$ `' u
- Solution: Please check the provided reference or the vendor website.
. H/ w( R2 z' s0 P% s- PoC:http://www.youtube.com/v/1VpxlJ5 ... ;rel=0&vq=hd720; c" U% Y" a; A7 |$ z( `0 Q
"$ t# J8 x2 Q4 L& o5 z
Note: Quick patch for FCKEditor 2.6.8 File Upload Bypass:
  j: g. @  x. m7 ?8 N6 A( VIn “config.asp”, wherever you have:
) a% N, U7 r0 x/ c      ConfigAllowedExtensions.Add    “File”,”Extensions Here”
; e( L: C$ T9 m1 V  {! `* oChange it to:  v7 ?: Y3 z- x; w
      ConfigAllowedExtensions.Add    “File”,”^(Extensions Here)$”
# b. s* n9 y; ~$ D/ R
/ I# g, Z  z; Y  t) c) j
% W3 m6 d9 y* i- E% c
) ^$ t) y3 M# m$ x7 ~* a2 ^
% D* x1 o3 t0 r/ Y7 u, {
: `# ?5 D  N2 O8 B* o/ Rphp测试无效
4 k" i% ^. i: T" K4 j6 easp/aspx测试成功:
# G! b& {7 ?6 H8 T( w来到/FCKeditor/editor/filemanager/connectors/test.html9 V5 O) j& I7 k6 g
因为结合了之前二次上传的漏洞,所以先上传任意内容的文件:asd.asp.txt/ p4 e* N' @! M, \! o2 A" X
0 Z) I  }$ M) t$ }: n
burpsuite上传包并修改,repeater
/ E: \0 E& K: D3 ?名字改为asd.asp%00txt    然后把%00专为URL编码上传后得到asd(1).asp
- m# h* b* T5 h: v. u- ?5 r9 ~2 L6 W( G, O$ H7 v
如图,webshell为:http://localhost/userfiles/file/asd(1).asp
7 J: T! v8 w6 ~5 l
. H, [2 h# O% k% C/ l8 J- L
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表