Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sangfor-vpn-supersession-rce.yaml #65

Open
SummerSec opened this issue May 22, 2023 · 3 comments
Open

sangfor-vpn-supersession-rce.yaml #65

SummerSec opened this issue May 22, 2023 · 3 comments

Comments

@SummerSec
Copy link

获取rsa key咋利用?

@zan8in
Copy link
Owner

zan8in commented May 22, 2023

没有 payload 可提供~ ^O^

@ViCrack
Copy link

ViCrack commented May 23, 2023

有时候sangfor-vpn-supersession-rce会报,我也没找到rce的出处是哪来的,网上搜索唯一有关系的似乎是2020年没有经过确认的口令爆破相关的?
图片

顺便发现这几个poc存在误报

thinkphp-2-rce
thinkphp-30-rce
thinkphp-50-rce
thinkphp-5010-rce
thinkphp-5022-5129-rce
thinkphp-5023-rce
thinkphp-5024-5130-rce

都是同样类似的判断,应该尽量避免使用phpinfo
如果目标网站baseurl页面就是个phpinfo地址,就会有误报

提供测试的目标网站:IGh0dHA6Ly90NC11cy1yb2QuYXJrZ2FtZXMuY29tLyA=

建议有些poc可以改成md5
图片

@zan8in
Copy link
Owner

zan8in commented Jul 9, 2023

@SummerSec afrog 近期版本已经删除该漏洞。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants