[11540] 2017-07-07_ApacheCVE-2017-7659漏洞重现及利用分析

文档创建者:s7ckTeam
浏览次数:17
最后更新:2025-01-18
2017-07-07_ApacheCVE-2017-7659漏洞重现及利用分析 A p a c h e   C V E - 2 0 1 7 - 7 6 5 9   F r e e B u f   2 0 1 7 - 0 7 - 0 7 a p a c h e C V E - 2 0 1 7 - 7 6 5 9 A   m a l i c i o u s l y   c o n s t r u c t e d   H T T P / 2   r e q u e s t   c o u l d   c a u s e   m o d _ h t t p 2   t o   d e r e f e r e n c e   a   N U L L   p o i n t e r   a n d c r a s h t h e   s e r v e r   p r o c e s s . a p a c h e   W E B h t t p d H T T P   2 . 0 0 x 0 1 r e d h a t b u g z i l l a h t t p s : / / b u g z i l l a . r e d h a t . c o m / s h o w _ b u g . c g i ? i d = 1 4 6 3 1 9 9 g i t h u b h t t p s : / / g i t h u b . c o m / a p a c h e / h t t p d / c o m m i t / 6 7 2 1 8 7 c 1 6 8 b 9 4 b 5 6 2 d 8 0 6 5 e 0 8 e 2 c a d 5 b 0 0 c d d 0 e 3 h 2 _ r e q u e s t _ r c r e a t e 2 . 4 . 2 6 0 x 0 2 h t t p s : / / a r c h i v e . a p a c h e . o r g / d i s t / h t t p d / h t t p d - 2 . 4 . 2 5 . t a r . g z     h 2 _ s t r e a m _ s e t _ r e q u e s t _ r e c h 2 _ r e q u e s t _ r c r e a t h t t p   2 . 0 r e q h 2 _ r e q u e s t _ r c r e a t r e q a p _ l o g _ r e r r o r r e q
h 2 _ r e q u e s t _ r c r e a t e r e q 0 4 r - > m e t h o d * * s c h e m e r - > h o s t n a m e p a t h * * r e q 0 4 s c h e m e p a t h r - > p a r s e d _ u r i a p r _ u r i _ u n p a r s e 使 p a t h r - > m e t h o d H T T P r - > h o s t n a m e H T T P 2 1 )   U R L U R L G E T   h t t p : / / w w w . e x a m p l e . c o m /   H T T P / 1 . 1   w w w . e x a m p l e . c o m a p _ p a r s e _ u r i 2 )   H o s t G E T   /   H T T P / 1 . 1 H o s t :   w w w . e x a m p l e . c o m f i x _ h o s t n a m e   a p _ p a r s e _ u r i     f i x _ h o s t n a m e   H o s t r - > h o s t n a m e   a p _ r e a d _ r e q u e s t   2
1 )   r - > h o s t n a m e H T T P 1 . 1 2 )   H o s t H T T P 1 . 1 4 0 0 H T T P / 1 . 1 R F C 2 6 1 6 1 4 . 2 3 H T T P / 1 . 1 H o s t H T T P 1 . 0 H T T P / 1 . 0 H T T P / 1 . 1 H T T P / 1 . 0 H o s t * * H T T P / 1 . 0 H o s t h 2 _ s t r e a m _ s e t _ r e q u e s t _ r e c r - > h o s t n a m e * * 0 x 0 3 1 )   H T T P / 2 2 )   H T T P / 1 . 0 3 )   H o s t s e r v e r H T T P / 2 使 a p a c h e m o d _ h t t p 2 . s o : a p a c h e   h t t p d : P O C a p a c h e   h t t p d 便 访 P O C b u r p s u i t e
h t t p d 访 访 a p a c h e a p a c h e w o r k e r a p a c h e w o r k e r 线 ( 1 0 0 线 ) w o r k e r a p a c h e w o r k e r
便
0 x 0 4   a p a c h e 2 . 4 . 2 5 h t t p d 2 . 4 . 1 7 h t t p d P O C h t t p d 2 . 4 . 1 7 H T T P   2 . 0 h t t p d H T T P   2 . 0 2 . 4 . 2 6 2 . 4 . 2 5 2 . 4 . 2 5 2 . 4 . 1 7 h 2 _ r e q u e s t _ r w r i t e P O C r - > h o s t n a m e r e q - > a u t h o r i t y a p _ s t r c h r _ c s t r c h r 0 x 0 5 a p a c h e H T T P   S e r v e r   2 . 4 . 2 6 w e i r a n . l a b s @ h u a w e i . c o m W e i R a n L a b s * F r e e B u f . C O M

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则