Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

redis计划任务反弹shell失败 #60

Open
Secur1ty0 opened this issue Feb 27, 2023 · 2 comments
Open

redis计划任务反弹shell失败 #60

Secur1ty0 opened this issue Feb 27, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@Secur1ty0
Copy link

Secur1ty0 commented Feb 27, 2023

系统环境

  • OS: MacOs
  • JavaVersion 1.8.0_202

软件版本

  • Version 2.1.1

Bug 详细描述

redis计划任务反弹shell,正常情况下写入成功无法反弹。
image
但是改为root即可成功反弹,/var/spool/cron/计划任务下执行的计划任务应该 以每个任务以创建者的名字命名,比如tom建的crontab任务对应的文件就是/var/spool/cron/tom,随机字符串应该不行。
image

@Secur1ty0 Secur1ty0 added the bug Something isn't working label Feb 27, 2023
@Ch1ngg
Copy link
Contributor

Ch1ngg commented Mar 7, 2023

奇怪,我当时测试是可以的,谢谢师傅的issue。项目较多抽不出时间更新项目

@chenroot1
Copy link

redis 命令执行失败
图片

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants