目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-28948 PoC — Pear Archive_Tar 代码问题漏洞

来源
关联漏洞
标题: Pear Archive_Tar 代码问题漏洞 (CVE-2020-28948)
Description:Pear Archive_Tar是Pear(PEAR)团队的一个基于Php的可以对tar包进行创建、提取等操作的软件。 Archive_Tar 1.4.10版本及之前版本存在安全漏洞,该漏洞允许反序列化攻击,因为phar:被阻塞而phar:没有被阻塞。
介绍
## POC for CVE-2020-28948 & CVE-2020-28949

The files here contain PoC for CVE-2020-28948 & CVE-2020-28949 to achieve remote exploit

### The server

The server folder contains a simple upload server which uses the vulnerable Archive_Tar library, located in `server/Archive`. The server accepts a Tar archive from the user, extracts and store it in the `server/uploads/` folder.

To start the server with the vulnerable library:
```sh
cd server
make build
make start
```

To start the server with the patched library:
```sh
cd server
make build-patched
make start-patched
```

Access the remote server through http://localhost:8080

### CVE-2020-28948 (PHAR deserialisation attack)

1. Navigate to corresponding PoC folder.
2. Specify target for arbitrary file deletion, by modifiying the `$delete_target` in `create_phar.php`
    - To view confidential `secret.md` file, delete `.htaccess` file
    - To do DoS, delete `index.html`
3. Create `exploit.tar`
    ```
    make create_exploit
    ```
4. Upload `exploit.tar` to remote server
5. Observe the file deletion on the server.
    - Can access http://localhost:8080/uploads/secret.md if `.htaccess` is deleted.

### CVE-2020-28949 (PHAR inclusion attack)

1. Navigate to corresponding PoC folder.
2. Create `exploit.tar`
    ```
    make create_exploit
    ```
3. Upload `exploit.tar` to remote server
4. Observe that `shell.php` is uploaded.
    - Can access http://localhost:8080/shell.php
5. Achieve some RCE (eg. execute `whoami` on server)
    - http://localhost:8080/shell.php?cmd=whoami
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →