phpMyAdminÔ¶³ÌÖ´ÐдúÂëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-03Îó²î±àºÅºÍ¼¶±ð
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄϵͳ°æ±¾£º
phpMyAdmin 4.8.1
Îó²î¸ÅÊö
phpMyAdmin ÊÇÒ»¸öÒÔPHPΪ»ù´¡£¬ÒÔWeb-Base·½·¨¼Ü¹¹ÔÚÍøÕ¾Ö÷»úÉϵÄMySQLµÄÊý¾Ý¿âÖÎÀí¹¤¾ß£¬ÈÃÖÎÀíÕß¿ÉÓÃWeb½Ó¿ÚÖÎÀíMySQLÊý¾Ý¿â¡£
ÔÚphpMyAdmin 4.8.x°æ±¾ÖУ¬³ÌÐòûÓÐÑÏ¿á¿ØÖÆÓû§µÄÊäÈ룬¹¥»÷Õß¿ÉÒÔʹÓÃË«ÖØ±àÂëÈÆ¹ý³ÌÐòµÄ°×Ãûµ¥ÏÞÖÆ£¬Ôì³ÉÎļþ°üÀ¨Îó²î¡£
´ËÎó²îʹ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐí§ÒâPHP´úÂë¡£
phpMyAdminµÄº£ÄÚÊý¾Ýͳ¼ÆÍ¼ÈçÏ£º
Îó²îÆÊÎö
ÔÚ/index.php
ÕâÀïµÄtarget ¿ÉÒÔÖ±½Ó´«ÖµÊäÈë¡£ÎÒÃÇ¿ÉÒÔ´«ÈëÒ»¸öÍâµØÎļþ·¾¶È¥ÈÃÆä°üÀ¨£¬¾Í»áÔì³ÉLFIÎó²î¡£
Ê×ÏÈ£¬ÎÒÃÇÖª×ã4¸öÌõ¼þ£º
2£®²»¿ÉÒÔ/index/ ¿ªÍ·¡£
3£®²»¿ÉÔÚ$target_blacklistÊý×éÄÚ¡£
¸ú×ÙÒ»ÏÂcheckPageValidityº¯Êý
ÔÚ/libraries/classes/Core.php
¸Ãº¯ÊýÄÚ£¬ÓÐÈý´¦·µ»ØtureµÄµØ·½£¬Ö»ÒªÓÐí§ÒâÒ»´¦·µ»Øture¾Í¿ÉÒÔ¡£ÊÓ²ìÕâÈý´¦£¬ÓÐÒ»¸öÅäºÏµã£¬¶¼ÊÇÐèÒª$pageÔÚ$whitelistÊý×éÖÐÄڲŻ᷵»Øtrue¡£
ÎÒÃÇÏÈ¿´µÚÒ»¸ö·µ»ØtrueµÄµØ·½¡£

ÕâÀïµÄ$pageÔÚin_array֮ǰûÓоÓÉÈκεÄÐÞÊΣ¬Ö±½Ó¾ÍÓë$whitelist×÷½ÏÁ¿¡£Ã»Óв½·¥Èƹý£¬´«ÈëµÄtargetÖµÖ»ÄÜΪ°×Ãûµ¥ÀïµÄÎļþÃû²ÅÐС£ºÜÏÔ×Å£¬µÚÒ»¸ö²¢²»¿ÉʹÓá£
ÔÙÀ´¿´µÚ¶þ¸ö

ÏÈÏÈÈÝÏÂÕâЩº¯ÊýµÄ×÷Óãº
mb_strpos()º¯ÊýµÄÒâ˼ÊDzéÕÒ×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖÐÊ״ηºÆðµÄλÖá£
mb_substr()º¯ÊýµÄÒâ˼ÊÇ£º
´Ó$str×Ö·û´®ÖУ¬ÌáÈ¡´Ó$startλÖÃ×îÏÈ£¬³¤¶ÈΪ$lengthµÄ×Ö·û´®¡£
¿ÉÒÔ¿´³ö£¬µÚ¶þ¸ö¿ÉÒÔ·µ»Øture£¬ÎÒÃÇʹÓÃdb_sql.php?/../../ÃûÌþͿÉÒÔµÖ´ïÄ¿µÄ£¬Èƹý°×Ãûµ¥ÏÞÖÆ¡£ÄÇÊDz»ÊÇÕâÑù¾Í¿ÉÒÔÔì³ÉÎó²îÁËÄØ£¿
¼ÙÉèÎÒÃÇÓÃdb_sql.php?/../../../aaa.txtÀ´Èƹý°×Ãûµ¥ÏÞÖÆ¾ÙÐаüÀ¨Îļþ¡£

ÄÇÕâÀï¾ÍÊÇ include ¡®db_sql.php?/../../../aaa.txt¡¯¡£
ÕâÖÖÃûÌò¢²»¿É¿ç·¾¶°üÀ¨£¬ÓÉÓÚphp³ÌÐò°Ñ£¿ºÅºóÃæµÄ¹¤¾ßµ±³ÉÊÇ´«Èëdb_sql.phpÎļþµÄ²ÎÊý¡£
ÔÙÀ´¿´µÚÈý¸ö£º

µÚÈý¸öºÍµÚ¶þ¸ö±ÈÕÕ¶à³öÁ˸öurldecode()º¯Êý¡£
¶øÎÊÌâǡǡ³öÔÚÁËÕâ¸öurldecode()º¯Êý¡£
Ôµ¹ÊÔÓÉÊÇ£º
%253f ´«Èëʱ£¬Ê×ÏȻᱻ×Ô¶¯½âÂëÒ»´Î£¬Äð³É%3f¡£È»ºóurldecode()ÔÙ½âÂëÒ»´Î£¬¾ÍÄð³ÉÁË ?¡£ ÀÖ³ÉÈÆ¹ýÁ˰×Ãûµ¥ÏÞÖÆ¡£
ÕâÖÖÇéÐÎÏÂincludeµÄ°üÀ¨ÇéÐξÍÊÇÕâÑùµÄ£¬Ò²¾Í¿ÉÒÔí§Òâ°üÀ¨ÍâµØÎļþÁË¡£
Îó²îʹÓÃ
ÍêÕûµÄexp£º
tips£º
1¡¢%3f ½«±»½âÂë²¢³ÉΪ?¡£
2¡¢Core::checkPageValidity°þÀëËùÓÐÄÚÈÝ?²¢sql.phpÔÚ°×Ãûµ¥ÄÚÕÒµ½£º¼ì²é±»Èƹý£¡3¡¢index.phpÔËÐÐinclude 'sql.php?/../../etc/passwd'£¬PHPµÄħÊõÀ´×ª»»Â·¾¶ ../etc/passwd£¬¶ø²»¼ì²éĿ¼ÊÇ·ñsql.php?±£´æ¡£×îºó£¬Ëü°üÀ¨../etc/passwdÀֳɡ£
ҪдÕâ¸öÎó²î£¬¿ÉÒÔö¾ÙÎļþ·¾¶£¬È磺
/etc/passwd
../../etc/passwd../windows/win.ini
../../windows/win.ini
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£¬Ðû²¼ÁË×îа汾4.8.2£¬¿É´Ó¹ÙÍøÏÂÔØ×îа汾¡£
²Î¿¼Á´½Ó
https://www.securityfocus.com/bid/104532
https://nvd.nist.gov/vuln/detail/CVE-2018-12613


¾©¹«Íø°²±¸11010802024551ºÅ