The problem lies in the simplified business. First, apply for a simplified product. Enter the Intranet IP address for the website address to directly access the Intranet web.
Fill in the Intranet IP: 10.0.183.1 this guess a little difficult, if not set here, directly access the http://fjtct.now.cn: 7751/10. 0.183.1/will jump to the Intranet http: // 10.0.183.1 address, certainly cannot access.
Directory scan test
Let's talk about struts2, which is the old vulnerability. It was accidentally discovered because I wanted to test whether the subdomain name admin.now.cn exists. If the subdomain name exists and limits the Intranet, I may be able to access it using the above method. The result showed that it was struts2, test whether the vulnerability exists.
Solution:
1. Users are not allowed to set the domain name as an intranet IP address.
2. struts2 patch.