go-fastdfs 是一个简单的分布式文件系统(私有云存储),具有无中心、高性能,高可靠,免维护等优点,支持断点续传,分块上传,小文件合并,自动同步,自动修复。Go-fastdfs is a simple distributed file system (private cloud storage), with no center, high performance, high reliability, maintenance free and other advantages, support breakpoint continuation, block upload, small file merge, automatic synchronization, automatic repair.(similar fastdfs).
When uploading files, there are no restrictions on file names and custom paths, so you can upload files to any directory through ../
Proof of Concept
1
2
3
You can see that the files we uploaded are uploaded to the root directory
Impact
If the user disables enable_distinct_file, RCE can be performed by rewriting the configuration file, such as rewriting the ssh password to take over
if enable_distinct_file is ture ,the ability to upload files to any location indicates that we may hijack the dynamic link library by uploading the dynamic link library to a high-priority directory, resulting in RCE
Description
When uploading files, there are no restrictions on file names and custom paths, so you can upload files to any directory through ../
Proof of Concept
1 2 3 You can see that the files we uploaded are uploaded to the root directory
Impact
If the user disables enable_distinct_file, RCE can be performed by rewriting the configuration file, such as rewriting the ssh password to take over
if enable_distinct_file is ture ,the ability to upload files to any location indicates that we may hijack the dynamic link library by uploading the dynamic link library to a high-priority directory, resulting in RCE