Internet of the times can penetrate the Intranet and execute commands on a certain site.

Source: Internet
Author: User
Tags subdomain subdomain name

The problem lies in the simplified business. First, apply for a simplified product. Enter the Intranet IP address for the website address to directly access the Intranet web.

Fill in the Intranet IP: 10.0.183.1 this guess a little difficult, if not set here, directly access the http://fjtct.now.cn: 7751/10. 0.183.1/will jump to the Intranet http: // 10.0.183.1 address, certainly cannot access.




Directory scan test


Let's talk about struts2, which is the old vulnerability. It was accidentally discovered because I wanted to test whether the subdomain name admin.now.cn exists. If the subdomain name exists and limits the Intranet, I may be able to access it using the above method. The result showed that it was struts2, test whether the vulnerability exists.
 


 

Solution:

1. Users are not allowed to set the domain name as an intranet IP address.

2. struts2 patch.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.