Causes of vulnerabilities in EDR environment
This article introduces the relevant knowledge of "the causes of loopholes in the EDR environment". In the operation of actual cases, many people will encounter such a dilemma, so let the editor lead you to learn how to deal with these situations. I hope you can read it carefully and be able to achieve something!
Build an edr environment
Https://XXX.com/tool/log/c.php?strip_slashes=system&host=id
Https://XXX.com/tool/log/c.php?strip_slashes=system&host=whoami
Copy the c.php file locally for analysis, and you can see that this file was originally used to view ldb logs. However, when it is repeated, it is found that this interface can be accessed without login, so there is also a danger of unauthorized access.
First look at the output
$_ REQUEST saves the accessed parameters as an array, and then passes the parameters obtained by the foreground to $show_form ()
Follow up $show_form
$show_form is an anonymous function, and use is a call to external variables $strip_slashes, $show_input.
The extract () function imports variables from the array into the current symbol table. It turns the array into a variable, using the array key name as the variable name and the array key value as the variable value.
Therefore, extract () has the problem of variable coverage, and the above poc takes advantage of the variable coverage here.
So the passed parameters become $strip_slashes=system and $host=id.
$strip_slashes ($host) is used in line 91, combined with poc, so it becomes sysytem (id) that executes system commands, resulting in the vulnerability.
This is the end of the content of "reasons for loopholes in the EDR environment". Thank you for reading. If you want to know more about the industry, you can follow the website, the editor will output more high-quality practical articles for you!