#EducationalPurposes
https://github.com/codesiddhant/Jasmin-Ransomware
我在Jasmin勒索软件Web面板中发现了一个无需认证的路径遍历漏洞(CVE-2024-30851),攻击者可利用该漏洞去匿名化面板操作员并转储解密密钥。Jasmin勒索软件最近在一次针对TeamCity(CVE-2024-27198、CVE-2024-27199)的利用活动中被观察到(https://twitter.com/brody_n77/status/1765145148227555826)
Screencast from 2024-04-04 18-51-07.webm
受影响的端点(Jasmin-Ransomware/Web Panel/download_file.php)在发送Location头后未调用die()。这使得攻击者能够绕过身份验证要求。对readfile的调用未经清理,允许攻击者读取任意文件。
<?php
session_start();
if(!isset($_SESSION['username']) ){
header("Location: login.php");
}
$file=$_GET['file'];
if(!empty($file)){
// Define headers
header("Cache-Control: public");
header("Content-Description: File Transfer");
header("Content-Disposition: attachment; filename=$file");
header("Content-Type: text/encoded");
header("Content-Transfer-Encoding: binary");
// Read the file
readfile($file);
另外还存在大量SQL注入漏洞,其中一种被利用来绕过登录并获取解密密钥的文件名。