Fading Coder

One Final Commit for the Last Sprint

Home > Tech > Content

Security Analysis of Zhiyuan OA Unauthorized Access and File Upload Vulnerabilities

Tech Sep 28 15

Vulnerability Reproduction Process

The vulnerability reproduction consists of three main components:

1.1 Unauthorized Access Detection

Following the analysis by unicodeSec, we can identify the vulnerability by making a request to the endpoint eyon/thirdpartyController.do.css/…;/ajax.do. If the response shows an exception as depicted below, the system likely contains the vulnerability.

By capturing network traffic, we can observe the following request and response structure:

The response status code is 200, and the returned data contains the string "java.lang.NullPointerException:null".

1.2 Arbitrary File Upload

We can utilize the unauthorized file upload interface to upload arbitrary files. For example, uploading a test.txt file to the /seeyon directory with content "test123" generates the following request:

The response status code is 500, which indicates successful file upload, returning:

{
  "message":null,
  "code":"0844135702",
  "details":null
}

Note that the code value may vary.

Failed file uploads return:

{
  "message": "Forced offline, reason: lost connection to server",
  "code": "-1",
  "details": null
}

1.3 Accessing Uploaded Files

By making a request to the uploaded file, we can verify if the upload was successful:

Goby EXP Development

2.1 Vulnerability Information Configuration

The query rule for Zhiyuan OA is: app=Yonyou-Seeyon-OA (you can detremine this by scanning the target and examining its asset type).

Fill in the vulnerability information as shown below:

In the advanced configuraiton, provide details such as tags, description, product, product homepage, author, source, vulnerability impact, and remediation solutions.

2.2 ScanSteps Configuration

2.2.1 Unauthorized Access Verification

Based on the vulnerability reproduction section, send a GET request to /seeyon/thirdpartyController.do.css/…;/ajax.do. Determine if the target is vulnerable by checking if the response status code is 200 and if the response contains the string "java.lang.NullPointerException:null". Configure the corresponding rules as follows:

The Accept field must be included in the headers.

2.2.2 File Upload Secondary Verification

After consulting with technical experts from the Goby team, we determined that relying solely on the unauthorized access check might generate false positives. Therefore, we need to use file upload for further verification.

Send POST data to perform arbitrary file upload, including the header Content-Type: application/x-www-form-urlencoded. Determine if the upload was successful by checking if the response contains message, code, and details fields, while excluding responses where the code is -1 (indicating upload failure).

The POST data can reference existing resources available online.

Pro tip: After configuring the test data, use the "Single IP Scan" option in the upper right corner of the custom PoC interface. Enter an IP:port combination to perform a scan on a single IP and verify if your defined test logic is correct.

2.3 ExploitSteps Configuration

Extract the POST data from the ScanSteps section of the generated seeyou_OA_ajaxAction_formulaManager_File_Upload.json file and add it to the ExploitSteps section as shown below:

Related Articles

Understanding Strong and Weak References in Java

Strong References Strong reference are the most prevalent type of object referencing in Java. When an object has a strong reference pointing to it, the garbage collector will not reclaim its memory. F...

Comprehensive Guide to SSTI Explained with Payload Bypass Techniques

Introduction Server-Side Template Injection (SSTI) is a vulnerability in web applications where user input is improper handled within the template engine and executed on the server. This exploit can r...

Implement Image Upload Functionality for Django Integrated TinyMCE Editor

Django’s Admin panel is highly user-friendly, and pairing it with TinyMCE, an effective rich text editor, simplifies content management significantly. Combining the two is particular useful for bloggi...

Leave a Comment

Anonymous

◎Feel free to join the discussion and share your thoughts.