感谢生生不息在freebuf社区”分享团”里给出线索,才有了本文5 p* Y3 F. C: s \$ `/ I0 H, }
/ A" R) k( a/ H0 {5 R' [原帖:http://club.freebuf.com/?/question/129#reply12
' U4 z0 t# k- C0 u6 F
u& a! B% B% [5 o2 O3 b: W) [FCKEditor 2.6.8文件上传漏洞
5 |- v' X' K0 J% ]" A2 w. U( [
" w4 Q0 o; W2 qExploit-db上原文如下:
3 G' p* X9 y( G& @( @; f
. K) H5 b- x) H' q) u- Title: FCKEditor 2.6.8 ASP Version File Upload Protection bypass* M9 l) s. h4 `- _: s; O
- Credit goes to: Mostafa Azizi, Soroush Dalili
/ |' {# `5 I" X. E9 F0 X- Link:http://sourceforge.net/projects/fckeditor/files/FCKeditor/ t, e1 n+ C# B
- Description:
* K& c" t+ C" U. B8 EThere is no validation on the extensions when FCKEditor 2.6.8 ASP version is
, W' n% j* d6 D& gdealing with the duplicate files. As a result, it is possible to bypass9 g5 \& s( l3 ]$ |9 u) W7 h
the protection and upload a file with any extension.
- c" Q {5 h9 e+ P: Q- Reference: http://soroush.secproject.com/blog/2012/11/file-in-the-hole/( P) X& q# Y8 w" i0 N/ L" w
- Solution: Please check the provided reference or the vendor website.) l9 G) T* W* j0 k6 C0 n
4 X1 f8 r7 L# j% A8 V+ P- _- PoC:http://www.youtube.com/v/1VpxlJ5 ... ;rel=0&vq=hd720* A+ ]9 l3 ?1 [: x+ \$ z6 w
"* b: U1 b9 E$ |6 ~$ I
Note: Quick patch for FCKEditor 2.6.8 File Upload Bypass:( I% r4 y) ]# V" t* D
) k$ k+ \; }# v1 Y1 g* ?
In “config.asp”, wherever you have:/ S# S7 V2 G9 A: R# h
ConfigAllowedExtensions.Add “File”,”Extensions Here”) V: X5 f z7 H" y9 ?
Change it to:
3 c+ |; t5 o0 d+ p( v ConfigAllowedExtensions.Add “File”,”^(Extensions Here)$”在视频(需翻墙)里,我们可以看的很清楚:
7 |1 F$ x2 U+ U! k
6 k" x6 m! k+ e4 J1.首先,aspx是禁止上传的! A$ k9 e- ^; V# g; [
2.使用%00截断(url decode),第一次上传文件名会被转成_符号
1 Z4 D6 z( X0 M; P, I( n8 b7 e8 z* W3 J {" D
8 z T' ~7 D) D- W R$ m$ q. L0 u' V0 j& z6 n
接下来,我们进行第二次上传时,奇迹就发生了1 L( p7 F4 u2 P: Y# [
3 s. {( r; `4 \2 T" T) c3 W9 s& n+ P- g' y& h
L1 c( z& N2 b* l
代码层面分析可以看下http://lanu.sinaapp.com/ASPVBvbscript/121.html! l6 f, z1 n: t! }
. ~* s* `% }" H2 }* [/ Y
J8 N+ f- y. ~( f
0 p( o3 W9 {7 d s3 sCKFinder/FCKEditor DoS漏洞. l0 \& ?: ]' K. d
7 l4 L, S3 h5 [' Q
相比上个上传bug,下面这个漏洞个人觉得更有意思
( }. ~) n) s& \6 Y$ O5 J+ P& \/ C0 k* U' k
; z) Q& P5 t4 [4 [8 N3 Q. w% I* N* }3 y ~8 r( S
CKFinder是一个强大而易于使用的Web浏览器的Ajax文件管理器。 其简单的界面使得它直观,快速学习的各类用户,从高级人才到互联网初学者。
; s! u( J% n T/ x; n: o( I, r2 u* A$ O6 t A8 q8 K1 h6 s9 z
CKFinder ASP版本是这样处理上传文件的:
/ s% Y4 j4 e2 }# A* P/ h, ~& G: T. q1 N; |5 Z
当上传文件名已存在时,会进行迭代重命名,比如file(1).ext存在了,会尝试重命名为file(2).ext……直到不重复为止。# C8 r( m* F6 i4 s2 P4 Y6 z0 b
& d3 T" r$ e, c1 m9 }% D- `4 W那么现在有趣的事情来了——windows是禁止”con”作为文件名的(关于这个问题我印象中很久以前,win也有过con文件名漏洞,有兴趣可以确认下), p# i: _9 M, B% i3 K
# f% Q1 L7 d( e0 Y8 ~) S* g. c. _dos方法也应运而生!" _7 ?" f2 y( b% d/ @
, b4 @& O5 ]6 O7 g3 q8 q& w `0 c9 D
. H. ~# m! |; i. P# s n7 E
3 A1 F) U: q% ?7 s9 x8 j) z" n2 _0 g1.上传Con.pdf.txt
6 A1 e# t3 I; O2.CKFinder认为“Con.pdf.txt” 已被占用,于是开始尝试Con.pdf(1).txt,Con.pdf(2).txt……Con.pdf(MaxInt).txt从而对服务器形成致命dos。& B3 W$ j. h. }! F
. w8 z4 ~& x) S u4 |0 O3 \ |