[12608] 2018-04-20_现代版荆轲刺秦王:Struts2REST插件漏洞分析

文档创建者:s7ckTeam
浏览次数:8
最后更新:2025-01-18
2018-04-20_现代版荆轲刺秦王:Struts2REST插件漏洞分析 S t r u t s 2   R E S T   2 0 1 8   F r e e B u f   2 0 1 8 - 0 4 - 2 0 0 x 0 0   ( b e i ) ( c u i ) 便 ( j i n ) ( z h a n g ) 便 0 x 0 1   1 2 S t r u t s 2   R E S T U R L 便 西 便 P a y l o a d P a y l o a d
S t r u t s 2   R E S T 1 S t r u t s 2   R E S T X S t r e a m 2 X S t r e a m X M L 0 x 0 2   S 2 - 0 5 2 0 5 6 A p a c h e   S t r u t s 2 R E S T 使 X S t r e a m X M L X M L 便 S 2 1 J D K T o m c a t S t r u t s 2   U b u n t u - 1 2 . 0 4 . 5 - 6 4 J D K   1 . 8 - 6 4 T o m c a t   8 . 5 . 3 0 S t r u t s   2 . 5 . 1 2 J D K T o m c a t S t r u t s   2 a p p s t r u t s 2 - r e s t - s h o w c a s e . w a r t o m c a t w e b a p p 2 t o m c a t I P 3 使 P a y l o a d M o r i t z   B e c h l e r h t t p s : / / g i t h u b . c o m / m b e c h l e r / m a r s h a l s e c a m a v e n   m v n   c l e a n   p a c k a g e   - D s k i p T e s t s M a v e n
b P a y l o a d t a r g e t j a v a   - c p   m a r s h a l s e c - 0 . 0 . 3 - S N A P S H O T - a l l . j a r   m a r s h a l s e c . X S t r e a m   I m a g e I O   x c a l c   > p a y l o a d . t x t c p a y l o a d . t x t X M L p a y l o a d X M L M o r i t z   B e c h l e r P D F h t t p s : / / g i t h u b . c o m / m b e c h l e r / m a r s h a l s e c / b l o b / m a s t e r / m a r s h a l s e c . p d f 4 访   h t t p : / / 1 9 2 . 1 6 8 . 2 1 3 . 1 2 9 : 8 0 8 0 / s t r u t s 2 - r e s t - s h o w c a s e B u r p S u i t e 便 V i e w h t t p C o n t e n t - T y p e : a p p l i c a t i o n / x m l   3 P a y l o a d
5 6 D O S S 2 - 0 5 6 D O S p y t h o n N
0 x 0 3   使 1 s t r u t s 2 - r e s t - s h o w c a s e - 2 . 5 . 1 2 . w a r e c l i p s e F i l e > I m p o r t - > w a r   f i l e 便 s t r u t s 2 - r e s t - p l u g i n - 2 . 5 . 1 2 . j a r x s t r e a m - 1 . 4 . 8 . j a r x p p 3 _ m i n - 1 . 1 . 4 c - s o u r c e s . j a r 2 M a n   Y u e   M o h t t p s : / / l g t m . c o m / b l o g / a p a c h e _ s t r u t s _ C V E - 2 0 1 7 - 9 8 0 5 C o n t e n t T y p e H a n d l e r 3 C o n t e n t T y p e H a n d l e r a X M L s t r u t s - p l u g i n . x m l c o n t e n t - t y p e X M L X S t r e a m H a n d l e r C o n t e n t T y p e H a n d l e r
b o r g . a p a c h e . s t r u t s 2 . r e s t . C o n t e n t T y p e I n t e r c e p t o r C o n t e n t T y p e H a n d l e r   h a n d l e r   =   s e l e c t o r . g e t H a n d l e r F o r R e q u e s t ( r e q u e s t ) ; r e q u e s t X S t r e a m H a n d l e r   h a n d l e r . t o O b j e c t ( r e a d e r ,   t a r g e t ) ;   x m l 4 B u r p S u i t e p a y l o a d c o n t e n t T y p e p a y l o a d a p p l i c a t i o n / x m l
5 c o n t e n t T y p e h a n d l e r   X S t r e a m H a n d l e r x m l X S t r e a m H a n d l e r 6 X S t r e a m H a n l e r . t o O b j e c t 使 f r o m X M L X M L J a v a u n m a r s h a l u n m a r s h a l
0 x 0 4   1 S t r u t s   2 . 1 . 1     S t r u t s   2 . 5 . 1 4 . 1 2 A p a c h e   S t r u t s 2 . 5 . 1 6
使 A p a c h e   S t r u t s 2   R E S T X M L J a c k s o n   X M L J a c k s o n X m l H a n d l e r P . S .   P y t h o n - D O S h t t p s : / / p a n . b a i d u . c o m / s / 1 Z b g H B U 3 y P Z Z Z 3 q 4 8 q z 8 Q   z b 4 y *   2 0 1 8 F r e e B u f
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则