当前位置:网站首页>Middleware vulnerability recurrence Apache
Middleware vulnerability recurrence Apache
2022-07-06 13:57:00 【Lazy and talented】
Catalog
0x0a httpd-conf Improper configuration ( Multiple file name parsing vulnerability )
0x0b .htaccess Parsing vulnerabilities
0x0c .user.ini Parsing vulnerabilities
Environmental Science ctfshow web 153
principle :php File contains .user.ini
0x0d Apache HTTPD Newline parsing vulnerability (CVE-2017-15715)
Affects version :2.4.0~2.4.29 edition
0x0a httpd-conf Improper configuration ( Multiple file name parsing vulnerability )
AddHandler application/x-httpd-php .php
In the case of multiple suffixes , As long as it contains .php suffix , Can be identified as PHP file .
Local reproduction :
Edit the file h:ttpd-conf(apache/conf/http-conf):
add to :AddHandler application/x-httpd-php .php
Edit the file :phpinfo.php.jpg
write in :<?php phpinfo();?>
visit :127.0.0.1/phpinfo.php.jpg
0x0b .htaccess Parsing vulnerabilities
AddType application/x-httpd-php .jpg Under this path jpg File by http Will be interpreted as php file
Local reproduction :
Upload .htaccess file ( Local )
edit :AddType application/x-httpd-php .jpg
Upload phpinfo.jpg file ( Local )
edit :GIF89a<?php phpinfo();?>
visit : 127.0.0.1/phpinfo.jpg
0x0c .user.ini Parsing vulnerabilities
Environmental Science ctfshow web 153
principle :php File contains .user.ini
auto_append_file=filename // Each of the peer directories php Add... At the end of the file include(“filename”)
auto_prepend_file=filename // Add include(“filename”)
Upload 1.png
<?php phpinfo();?>
Be careful : Then access any one under the file php that will do Because there is index.php So you don't need to upload php To analyze
0x0d Apache HTTPD Newline parsing vulnerability (CVE-2017-15715)
Environmental Science :vulhub
Affects version :2.4.0~2.4.29 edition
Environment startup :
- stay CVE-2017-15715 Right click the folder to open the terminal
- sudo docker-compose up -d
- visit ip+8000
burp Grab the bag Modify parameter value
stay evil.php Back plus c——> Choose code modify ——>0a
visit url:192.168.0.10:8080/evil.php%oadata:image/s3,"s3://crabby-images/8ea79/8ea79ea0d03f1259bd6d998162024538bed5716c" alt=""
summary : Mind mapping
边栏推荐
- Strengthen basic learning records
- Relationship between hashcode() and equals()
- [the Nine Yang Manual] 2017 Fudan University Applied Statistics real problem + analysis
- FAQs and answers to the imitation Niuke technology blog project (III)
- HackMyvm靶机系列(1)-webmaster
- Inaki Ading
- [面試時]——我如何講清楚TCP實現可靠傳輸的機制
- Strengthen basic learning records
- . How to upload XMIND files to Jinshan document sharing online editing?
- 7-8 7104 约瑟夫问题(PTA程序设计)
猜你喜欢
Have you encountered ABA problems? Let's talk about the following in detail, how to avoid ABA problems
QT meta object qmetaobject indexofslot and other functions to obtain class methods attention
Matlab opens M file garbled solution
Programme de jeu de cartes - confrontation homme - machine
Attach the simplified sample database to the SQLSERVER database instance
撲克牌遊戲程序——人機對抗
About the parental delegation mechanism and the process of class loading
Relationship between hashcode() and equals()
Strengthen basic learning records
Using spacedesk to realize any device in the LAN as a computer expansion screen
随机推荐
2022 Teddy cup data mining challenge question C idea and post game summary
仿牛客技术博客项目常见问题及解答(一)
Difference and understanding between detected and non detected anomalies
[hand tearing code] single case mode and producer / consumer mode
【MySQL数据库的学习】
一段用蜂鸣器编的音乐(成都)
Meituan dynamic thread pool practice ideas, open source
The difference between abstract classes and interfaces
canvas基础1 - 画直线(通俗易懂)
Using qcommonstyle to draw custom form parts
Intensive literature reading series (I): Courier routing and assignment for food delivery service using reinforcement learning
甲、乙机之间采用方式 1 双向串行通信,具体要求如下: (1)甲机的 k1 按键可通过串行口控制乙机的 LEDI 点亮、LED2 灭,甲机的 k2 按键控制 乙机的 LED1
Implementation principle of automatic capacity expansion mechanism of ArrayList
MySQL锁总结(全面简洁 + 图文详解)
[the Nine Yang Manual] 2021 Fudan University Applied Statistics real problem + analysis
仿牛客技术博客项目常见问题及解答(二)
Attach the simplified sample database to the SQLSERVER database instance
Experiment 7 use of common classes
7-1 output all primes between 2 and n (PTA programming)
[the Nine Yang Manual] 2020 Fudan University Applied Statistics real problem + analysis