TGStat
TGStat
Type to search
Advanced channel search
  • flag English
    Site language
    flag Russian flag English flag Uzbek
  • Sign In
  • Catalog
    Channels and groups catalog Search for channels
    Add a channel/group
  • Ratings
    Rating of channels Rating of groups Posts rating
    Ratings of brands and people
  • Analytics
  • Search by posts
  • Telegram monitoring
黑客入侵 渗透拖库贷款投顾

28 Sep, 05:40

Open in Telegram Share Report

Prev Next
Apache Syncope 的连接器管理接口 POST /syncope/rest/connectors/check 接收一个完全由客户端控制的 ConnInstanceTO,直接实例化连接器并调用 test():
// core/idm/logic/src/main/java/org/apache/syncope/core/logic/ConnectorLogic.java:244
public void check(final ConnInstanceTO connInstanceTO) {
connectorManager.createConnector(binder.getConnInstance(connInstanceTO)).test();
}
内置的脚本化连接器 RESTConnector(net.tirasa.connid.bundles.rest)的配置项里包含 testScript、createScript 等脚本字段,test() 会把 testScript 交给 ConnId 框架的 GroovyScriptExecutor 执行。于是一个认证后的 HTTP 请求就等于一段服务端 Groovy 代码的执行入口(所需权限仅 CONNECTOR_READ):
ConnectorLogic.check()
→ ConnId ConnectorFacade
→ RESTConnector.test()
→ ScriptExecutorFactory.newInstance("GROOVY")
→ GroovyScriptExecutor 执行 testScript
4.1.1 时代这段代码没有任何防护,testScript 里直接 new ProcessBuilder(["sh","-c","id"]).start() 即可 RCE。当时的验证采用了三步利用链,顺带说明 bundles 目录动态加载缺乏完整性校验:第一步在 testScript 中解码 Base64 把恶意 ConnId bundle JAR 写入 /opt/syncope/bundles/,第二步调用 connectors/reload 让框架重新扫描目录加载该 JAR,第三步用恶意 bundle 的信息构造配置再次调用 connectors/check,其 test() 方法

7 0 0
Catalog
Channels and groups catalog Channels compilations Search for channels Add a channel/group
Ratings
Rating of Telegram channels Rating of Telegram groups Posts rating Ratings of brands and people
API
API statistics Search API of posts API Callback
Our channels
@TGStat @TGStat_Chat @telepulse @TGStatAPI
Read
Академия TGStat Telegram Research 2019 Telegram Research 2021 Telegram Research 2023
Contacts
Справочный центр Support Email Jobs
Miscellaneous
Terms and conditions Privacy policy Public offer
Our bots
@TGStat_Bot @SearcheeBot @TGAlertsBot @tg_analytics_bot @TGStatChatBot