神刀安全网

漏洞标题: 山东省某市人社局GetShell影响千万敏感数据

漏洞详情

披露状态:

2016-04-18: 细节已通知厂商并且等待厂商处理中
2016-04-22: 厂商已经确认,细节仅向厂商公开
2016-05-02: 细节向核心白帽子及相关领域专家公开
2016-05-12: 细节向普通白帽子公开
2016-05-22: 细节向实习白帽子公开
2016-06-06: 细节向公众公开

简要描述:

详细说明:

code 区域

mask 区域
1.://**.**.**/hso/logon_370100.jsp

反序列getshell,发现了已有shell,直接引用

code 区域
**.**.**.**:8002/bea_wls_internal/test.jsp

pwd:

mask 区域
*****11*****

code 区域
<url>jdbc:oracle:thin:@**.**.**.**:1521:jnwsfwdb1</url>
<driver-name>oracle.jdbc.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>isso</value>
</property>
</properties>
<password-encrypted>{AES}jLCNt4LqaH4FXPOXIardbPeQlqvm51YyRcaZGOaXSzo=</password-encrypted>

code 区域
SI EMP_PLAN 710845465
SI MEDI_ACCOUNT 206113580
SIBK AGED_ACCOUNT 162101411
SI HARM_ACCOUNT 150955241
MD CARD_INCOME 146944271
MD CARD_PAYOUT 139296091
SI LOST_ACCOUNT 137231734
SI BIRTH_ACCOUNT 129290852
DE JOB_DATA 76295521
DE EMP_PLAN_BAK_2014 70936969
DE EMP_PLAN 70343287
SIBK AGED_ACCOUNT_HIS 48325928
SI EMP_PAY_HIS 42943980
SI BILL_DETL 25348181
SI ORGN_DUE_PAY_GENL 23845243
SI BILL_PART 23541691
SI EMP_ADD 22267670
SI AGED_ACCOUNT 21791494
SI AGED_ACCOUNT_SUM 17387020
SISO ORGN_DUE_PAY_GENL 15052854
SI EMP_CMPL 12587398
MD CARD_ACCOUNT 9460737
MD EMP_NATL 8392716
SI PER_REG 7714891
SI BILL_GENL 6197620
SISO BIZ_LOG_INFO160303 5347232
CSI EMP_NATL 5214840
SI CSI_EMP_NATL 5192421
AGED EMP_GIV_STD 4716356
SISO EMP_NATL 4695524
DE DECLARE_NATL 4241822
SI ORGN_RATE 4161692
DE DECLARE_NATL_BAK_2014 4025052
SI EMP_NATL 3639073
SYS WRM$_SNAPSHOT_DETAILS 3452909
DE DECLARE_NATL_20150706 3268305
DE DECLARE_NATL_BF 3244266
DE ORGN_PLAN 3136815
SI SI_DWS_USER_20151029 2421023
SIBK EMP_PAY_HIS 2174245
DE EMP_ADD_GRBH 2118020
MD PATIENT_INFO 2071436
SI LOGINRECORD 2007114
DE DECLARE_NATL_20150116_2_2 1664522
LOST EMP_GIV_HIS 1503376
SYS WRI$_OPTSTAT_HISTGRM_HISTORY 1265269
MD PATIENT_HOSP_SICK 1138878
SISO BA02 760478
SYS WRH$_EVENT_HISTOGRAM 737243
HSP SEND_MESSAGE 675045
SI ORGN_CMPL 664958
DE EMP_ADD 571087
SI ORGN_JOIN 502611

漏洞标题:  山东省某市人社局GetShell影响千万敏感数据

漏洞证明:

code 区域
SI EMP_PLAN 710845465
SI MEDI_ACCOUNT 206113580
SIBK AGED_ACCOUNT 162101411
SI HARM_ACCOUNT 150955241
MD CARD_INCOME 146944271
MD CARD_PAYOUT 139296091
SI LOST_ACCOUNT 137231734
SI BIRTH_ACCOUNT 129290852
DE JOB_DATA 76295521
DE EMP_PLAN_BAK_2014 70936969
DE EMP_PLAN 70343287
SIBK AGED_ACCOUNT_HIS 48325928
SI EMP_PAY_HIS 42943980
SI BILL_DETL 25348181
SI ORGN_DUE_PAY_GENL 23845243
SI BILL_PART 23541691
SI EMP_ADD 22267670
SI AGED_ACCOUNT 21791494
SI AGED_ACCOUNT_SUM 17387020
SISO ORGN_DUE_PAY_GENL 15052854
SI EMP_CMPL 12587398
MD CARD_ACCOUNT 9460737
MD EMP_NATL 8392716
SI PER_REG 7714891
SI BILL_GENL 6197620
SISO BIZ_LOG_INFO160303 5347232
CSI EMP_NATL 5214840
SI CSI_EMP_NATL 5192421
AGED EMP_GIV_STD 4716356
SISO EMP_NATL 4695524
DE DECLARE_NATL 4241822
SI ORGN_RATE 4161692
DE DECLARE_NATL_BAK_2014 4025052
SI EMP_NATL 3639073
SYS WRM$_SNAPSHOT_DETAILS 3452909
DE DECLARE_NATL_20150706 3268305
DE DECLARE_NATL_BF 3244266
DE ORGN_PLAN 3136815
SI SI_DWS_USER_20151029 2421023
SIBK EMP_PAY_HIS 2174245
DE EMP_ADD_GRBH 2118020
MD PATIENT_INFO 2071436
SI LOGINRECORD 2007114
DE DECLARE_NATL_20150116_2_2 1664522
LOST EMP_GIV_HIS 1503376
SYS WRI$_OPTSTAT_HISTGRM_HISTORY 1265269
MD PATIENT_HOSP_SICK 1138878
SISO BA02 760478
SYS WRH$_EVENT_HISTOGRAM 737243
HSP SEND_MESSAGE 675045
SI ORGN_CMPL 664958
DE EMP_ADD 571087
SI ORGN_JOIN 502611

漏洞标题:  山东省某市人社局GetShell影响千万敏感数据

修复方案:

更新补丁

版权声明:转载请注明来源 路人甲@乌云

转载本站任何文章请注明:转载至神刀安全网,谢谢神刀安全网 » 漏洞标题: 山东省某市人社局GetShell影响千万敏感数据

分享到:更多 ()

评论 抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址