当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0143335

漏洞标题:POS机行业巨头第二发(依然泄露上万商户/配套大量系统/大量交易详情/ROOT又入内网)

相关厂商:快易(天津)信息技术有限公司

漏洞作者: 路人甲

提交时间:2015-09-25 10:15

修复时间:2015-11-14 09:00

公开时间:2015-11-14 09:00

漏洞类型:命令执行

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-09-25: 细节已通知厂商并且等待厂商处理中
2015-09-30: cncert国家互联网应急中心暂未能联系到相关单位,细节仅向通报机构公开
2015-10-10: 细节向核心白帽子及相关领域专家公开
2015-10-20: 细节向普通白帽子公开
2015-10-30: 细节向实习白帽子公开
2015-11-14: 细节向公众公开

简要描述:

配套系统.....

详细说明:

http://**.**.**.**/bugs/wooyun-2015-0143242 危害参考
这个是完全不同的系统,是做APP端商户管理的,都是配套的东西,不小心挖到的。
这次直接上了个大马
IP跟上次的不一样,但是都是一个网段

漏洞证明:

**.**.**.**:8101/APP/system.jsp

Pass:9635789

笑了.png

11.png

555.png

6666.png

777.png

ifconfig.png

root.png

Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State Timer
tcp 0 0 **.**.**.**:111 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:35281 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:22 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:53337 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:25 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:34302 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:2049 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:50017 **.**.**.**:* LISTEN off (0.00/0/0)
tcp 0 0 **.**.**.**:2049 **.**.**.**:716 ESTABLISHED off (0.00/0/0)
tcp 0 0 :::9005 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::48015 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::111 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::8020 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::50965 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::22 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::45079 :::* LISTEN off (0.00/0/0)
tcp 0 0 ::1:25 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::2049 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::44290 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::8100 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::8101 :::* LISTEN off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8105 :::* LISTEN off (0.00/0/0)
tcp 0 0 :::8009 :::* LISTEN off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8106 :::* LISTEN off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:54365 FIN_WAIT2 timewait (39.87/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:41171 FIN_WAIT2 timewait (39.81/0/0)
tcp 0 0 ::ffff:**.**.**.**:40002 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:48044 TIME_WAIT timewait (53.32/0/0)
tcp 0 1 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:34817 FIN_WAIT1 on (17.23/8/0)
tcp 0 0 ::ffff:**.**.**.**:40726 ::ffff:**.**.**.**:8102 TIME_WAIT timewait (6.29/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:2115 TIME_WAIT timewait (37.90/0/0)
tcp 0 0 ::ffff:**.**.**.**:39998 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:42302 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:53107 FIN_WAIT2 timewait (54.43/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:57455 TIME_WAIT timewait (4.19/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45423 FIN_WAIT2 timewait (13.63/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:13512 FIN_WAIT2 timewait (16.43/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:48045 TIME_WAIT timewait (52.70/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:62611 FIN_WAIT2 timewait (43.27/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:15004 TIME_WAIT timewait (40.39/0/0)
tcp 0 0 ::ffff:**.**.**.**:33483 ::ffff:**.**.**.**:8081 TIME_WAIT timewait (29.04/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:40002 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:49652 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:42304 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:9005 ::ffff:**.**.**.**:34605 FIN_WAIT2 timewait (9.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:44226 FIN_WAIT2 timewait (56.07/0/0)
tcp 0 0 ::ffff:**.**.**.**:48894 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:41265 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:39809 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:51382 FIN_WAIT2 timewait (46.85/0/0)
tcp 0 0 ::ffff:**.**.**.**:48903 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:44244 FIN_WAIT2 timewait (56.69/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:50834 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:39988 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:39254 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:50911 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:42763 FIN_WAIT2 timewait (52.18/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:49274 FIN_WAIT2 timewait (49.72/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:32841 FIN_WAIT2 timewait (43.87/0/0)
tcp 0 0 ::ffff:**.**.**.**:39990 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:34208 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:50835 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:57456 TIME_WAIT timewait (5.31/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:58468 TIME_WAIT timewait (47.19/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:2116 TIME_WAIT timewait (37.89/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:15007 TIME_WAIT timewait (40.13/0/0)
tcp 0 1 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:34894 FIN_WAIT1 on (17.04/8/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45420 FIN_WAIT2 timewait (12.03/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:57460 TIME_WAIT timewait (24.24/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:62610 FIN_WAIT2 timewait (34.62/0/0)
tcp 0 0 ::ffff:**.**.**.**:39256 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45949 FIN_WAIT2 timewait (48.29/0/0)
tcp 0 0 ::ffff:**.**.**.**:51951 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:39244 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:57461 TIME_WAIT timewait (45.32/0/0)
tcp 0 0 ::ffff:**.**.**.**:39245 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:48043 TIME_WAIT timewait (52.49/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45424 FIN_WAIT2 timewait (17.14/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:56389 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:39986 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:57457 TIME_WAIT timewait (5.25/0/0)
tcp 0 0 ::ffff:**.**.**.**:39994 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:38240 FIN_WAIT2 timewait (55.35/0/0)
tcp 0 0 ::ffff:**.**.**.**:49640 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:18273 FIN_WAIT2 timewait (19.08/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:40165 FIN_WAIT2 timewait (37.94/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:58467 TIME_WAIT timewait (47.18/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:58554 FIN_WAIT2 timewait (45.92/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45425 FIN_WAIT2 timewait (21.13/0/0)
tcp 0 0 ::ffff:**.**.**.**:50912 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:40730 ::ffff:**.**.**.**:8102 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:58480 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:49644 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:45422 FIN_WAIT2 timewait (13.41/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:39841 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:49648 ::ffff:**.**.**.**:1521 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:58479 ESTABLISHED off (0.00/0/0)
tcp 0 0 ::ffff:**.**.**.**:8101 ::ffff:**.**.**.**:2117 TIME_WAIT timewait (37.88/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:62605 TIME_WAIT timewait (14.59/0/0)
tcp 0 0 ::ffff:**.**.**.**:8100 ::ffff:**.**.**.**:50836 ESTABLISHED off (0.00/0/0)
udp 0 0 **.**.**.**:111 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:2049 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:773 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:41096 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:35736 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:37826 **.**.**.**:* off (0.00/0/0)
udp 0 0 **.**.**.**:48481 **.**.**.**:* off (0.00/0/0)
udp 0 0 :::111 :::* off (0.00/0/0)
udp 0 0 :::2049 :::* off (0.00/0/0)
udp 0 0 :::773 :::* off (0.00/0/0)
udp 0 0 :::50072 :::* off (0.00/0/0)
udp 0 0 :::36636 :::* off (0.00/0/0)
udp 0 0 :::46910 :::* off (0.00/0/0)
udp 0 0 :::35929 :::* off (0.00/0/0)
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags Type State I-Node Path
unix 2 [ ACC ] STREAM LISTENING 2172454 /var/run/rpcbind.sock
unix 2 [ ACC ] STREAM LISTENING 9275 @/com/ubuntu/upstart
unix 5 [ ] DGRAM 227393 /dev/log
unix 2 [ ACC ] STREAM LISTENING 12107 /var/run/dbus/system_bus_socket
unix 2 [ ACC ] STREAM LISTENING 12423 public/cleanup
unix 2 [ ACC ] STREAM LISTENING 12430 private/tlsmgr
unix 2 [ ACC ] STREAM LISTENING 12434 private/rewrite
unix 2 [ ACC ] STREAM LISTENING 12438 private/bounce
unix 2 [ ACC ] STREAM LISTENING 12442 private/defer
unix 2 [ ACC ] STREAM LISTENING 12446 private/trace
unix 2 [ ACC ] STREAM LISTENING 12450 private/verify
unix 2 [ ACC ] STREAM LISTENING 12454 public/flush
unix 2 [ ACC ] STREAM LISTENING 12458 private/proxymap
unix 2 [ ACC ] STREAM LISTENING 12462 private/proxywrite
unix 2 [ ACC ] STREAM LISTENING 12466 private/smtp
unix 2 [ ACC ] STREAM LISTENING 12470 private/relay
unix 2 [ ACC ] STREAM LISTENING 12474 public/showq
unix 2 [ ACC ] STREAM LISTENING 12478 private/error
unix 2 [ ACC ] STREAM LISTENING 12482 private/retry
unix 2 [ ACC ] STREAM LISTENING 12486 private/discard
unix 2 [ ACC ] STREAM LISTENING 12490 private/local
unix 2 [ ACC ] STREAM LISTENING 12494 private/virtual
unix 2 [ ACC ] STREAM LISTENING 12498 private/lmtp
unix 2 [ ACC ] STREAM LISTENING 12502 private/anvil
unix 2 [ ACC ] STREAM LISTENING 12506 private/scache
unix 2 [ ] DGRAM 10214 @/org/kernel/udev/udevd
unix 2 [ ] DGRAM 6132719
unix 2 [ ] STREAM CONNECTED 5970894
unix 3 [ ] STREAM CONNECTED 5970821
unix 3 [ ] STREAM CONNECTED 5970820
unix 2 [ ] STREAM CONNECTED 5970806
unix 2 [ ] STREAM CONNECTED 5260161
unix 3 [ ] STREAM CONNECTED 5260029
unix 3 [ ] STREAM CONNECTED 5260028
unix 2 [ ] STREAM CONNECTED 5260022
unix 3 [ ] STREAM CONNECTED 5195278
unix 3 [ ] STREAM CONNECTED 5195277
unix 2 [ ] STREAM CONNECTED 5195272
unix 3 [ ] STREAM CONNECTED 2172907
unix 3 [ ] STREAM CONNECTED 2172906
unix 2 [ ] DGRAM 2172762
unix 2 [ ] DGRAM 396183
unix 3 [ ] STREAM CONNECTED 12974 /var/run/dbus/system_bus_socket
unix 3 [ ] STREAM CONNECTED 12973
unix 3 [ ] STREAM CONNECTED 12948 /var/run/dbus/system_bus_socket
unix 3 [ ] STREAM CONNECTED 12947
unix 3 [ ] STREAM CONNECTED 12933 /var/run/dbus/system_bus_socket
unix 3 [ ] STREAM CONNECTED 12932
unix 2 [ ] DGRAM 12547
unix 2 [ ] DGRAM 12533
unix 3 [ ] STREAM CONNECTED 12509
unix 3 [ ] STREAM CONNECTED 12508
unix 3 [ ] STREAM CONNECTED 12505
unix 3 [ ] STREAM CONNECTED 12504
unix 3 [ ] STREAM CONNECTED 12501
unix 3 [ ] STREAM CONNECTED 12500
unix 3 [ ] STREAM CONNECTED 12497
unix 3 [ ] STREAM CONNECTED 12496
unix 3 [ ] STREAM CONNECTED 12493
unix 3 [ ] STREAM CONNECTED 12492
unix 3 [ ] STREAM CONNECTED 12489
unix 3 [ ] STREAM CONNECTED 12488
unix 3 [ ] STREAM CONNECTED 12485
unix 3 [ ] STREAM CONNECTED 12484
unix 3 [ ] STREAM CONNECTED 12481
unix 3 [ ] STREAM CONNECTED 12480
unix 3 [ ] STREAM CONNECTED 12477
unix 3 [ ] STREAM CONNECTED 12476
unix 3 [ ] STREAM CONNECTED 12473
unix 3 [ ] STREAM CONNECTED 12472
unix 3 [ ] STREAM CONNECTED 12469
unix 3 [ ] STREAM CONNECTED 12468
unix 3 [ ] STREAM CONNECTED 12465
unix 3 [ ] STREAM CONNECTED 12464
unix 3 [ ] STREAM CONNECTED 12461
unix 3 [ ] STREAM CONNECTED 12460
unix 3 [ ] STREAM CONNECTED 12457
unix 3 [ ] STREAM CONNECTED 12456
unix 3 [ ] STREAM CONNECTED 12453
unix 3 [ ] STREAM CONNECTED 12452
unix 3 [ ] STREAM CONNECTED 12449
unix 3 [ ] STREAM CONNECTED 12448
unix 3 [ ] STREAM CONNECTED 12445
unix 3 [ ] STREAM CONNECTED 12444
unix 3 [ ] STREAM CONNECTED 12441
unix 3 [ ] STREAM CONNECTED 12440
unix 3 [ ] STREAM CONNECTED 12437
unix 3 [ ] STREAM CONNECTED 12436
unix 3 [ ] STREAM CONNECTED 12433
unix 3 [ ] STREAM CONNECTED 12432
unix 3 [ ] STREAM CONNECTED 12429
unix 3 [ ] STREAM CONNECTED 12428
unix 3 [ ] STREAM CONNECTED 12426
unix 3 [ ] STREAM CONNECTED 12425
unix 3 [ ] STREAM CONNECTED 12422
unix 3 [ ] STREAM CONNECTED 12421
unix 3 [ ] STREAM CONNECTED 12419
unix 3 [ ] STREAM CONNECTED 12418
unix 2 [ ] DGRAM 12373
unix 3 [ ] STREAM CONNECTED 12127 /var/run/dbus/system_bus_socket
unix 3 [ ] STREAM CONNECTED 12126
unix 3 [ ] STREAM CONNECTED 12121
unix 3 [ ] STREAM CONNECTED 12120
unix 3 [ ] DGRAM 10234
unix 3 [ ] DGRAM 10233

dataSource.driver=oracle.jdbc.driver.OracleDriver
dataSource.url=jdbc:oracle:thin:@**.**.**.**:1521:orcl
dataSource.username=chen
dataSource.password=chen

dataSource2.driver=oracle.jdbc.driver.OracleDriver
dataSource2.url=jdbc:oracle:thin:@**.**.**.**:1521:orcl
dataSource2.username=weba
dataSource2.password=weba

数据库配置竟然相同,真是懒得可以

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:12

确认时间:2015-09-30 08:58

厂商回复:

CNVD确认所述情况,已由CNVD尝试通过网站公开联系渠道向其邮件通报。

最新状态:

暂无