This article is a mirror article of machine translation, please click here to jump to the original article.

View: 19073|Reply: 3

[Mutual Assistance] Alibaba hinted at the solution to the Discuz memcache+ssrf GETSHELL vulnerability

[Copy link]
Posted on 6/8/2016 11:58:23 AM | | | |
Many students must have received Alibaba Cloud tips about the discuz memcache+ssrf GETSHELL vulnerability, but you need to pay at least 100 yuan to purchase Alibaba Cloud Cloud Shield Knight.

Vulnerability description: An SSRF vulnerability exists in discuz, which allows an attacker to use SSRF to write WEBSHELL malicious code to disk through memcache mediation when memcache is configured, resulting in database leakage

Use the Cloud Shield Knight Repair /source/function/function_core.php, you don't need to overwrite it with the following file before purchasing.

Here is a screenshot after the fix is complete:



Since it is repaired by itself, Alibaba Cloud will prompt "the vulnerability file has been modified".

Repair principle, on line 1089 of the function_core.php, modify two sentences:


Lazy Pack Download:


function_core_gbk.rar (18.19 KB, Number of downloads: 20)

function_core_utf.rar (18.21 KB, Number of downloads: 4)







Previous:Newtonsoft.Json ignores null values
Next:C#/Winform version 12306 login, you can manually click the image verification code
Posted on 6/14/2016 1:04:22 PM |
Looking for this
Posted on 6/14/2016 6:26:08 PM |
I kept emailing me about this bug for the first two days
Posted on 6/20/2016 2:33:27 PM |
Good things
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com