Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

最新的struts2-046-2poc有问题 #35

Closed
f0ng opened this issue Mar 12, 2021 · 2 comments
Closed

最新的struts2-046-2poc有问题 #35

f0ng opened this issue Mar 12, 2021 · 2 comments

Comments

@f0ng
Copy link

f0ng commented Mar 12, 2021

用fscan扫到了一个poc-yaml-struts2_046-2,根据poc,应该是判断返回里面是否有"struts2_security_check"
这里遇到一个站点,直接返回的无效文件名,如下:
image
然而这里貌似没有漏洞,感觉这里可能需要改改

@shadow1ng
Copy link
Owner

这个struts2-046-2 poc硬编码确实有点问题。struts2-046-1可能比较准确,struts2-046-2把关键字符分开了。这个算是s2-46-1的补充。后面考虑删掉或修改命令执行内容吧

@shadow1ng
Copy link
Owner

由于误报率问题,只保留了 s2-046-1的poc 了,s2-046-2先删除了
.(#res.getWriter().print('struts2_security_')).(#res.getWriter().print('check'))

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants