乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-12-19: 细节已通知厂商并且等待厂商处理中 2014-12-24: 厂商已经确认,细节仅向厂商公开 2015-01-03: 细节向核心白帽子及相关领域专家公开 2015-01-13: 细节向普通白帽子公开 2015-01-23: 细节向实习白帽子公开 2015-02-02: 细节向公众公开
苏宁易购某分站配置不当导致核心配置文件泄露
http://sopbbs.suning.com/config/config_global.php.1
discuz 在知道security authkey的情况下,可间接利用获取WEBSHELL
$_config['security']['authkey'] = 'e64aedC23CIadC7Y';
<?php$_config = array();// ---------------------------- CONFIG DB ----------------------------- //$_config['db']['1']['dbhost'] = '192.168.52.65';$_config['db']['1']['dbuser'] = 'snsopbbsdb';$_config['db']['1']['dbpw'] = 'Qbbs*****nsop';$_config['db']['1']['dbcharset'] = 'utf8';$_config['db']['1']['pconnect'] = '0';$_config['db']['1']['dbname'] = 'db_suning_sopbbs';$_config['db']['1']['tablepre'] = 'pre_';$_config['db']['slave'] = array();$_config['db']['slave']['1']['dbhost'] = '192.168.52.65';$_config['db']['slave']['1']['dbuser'] = 'snsopbbsdb';$_config['db']['slave']['1']['dbpw'] = 'Qbbs*****nsop';$_config['db']['slave']['1']['dbcharset'] = 'utf8';$_config['db']['slave']['1']['pconnect'] = '0';$_config['db']['slave']['1']['dbname'] = 'db_suning_sopbbs';$_config['db']['slave']['1']['tablepre'] = 'pre_';$_config['db']['common']['slave_except_table'] = '';// -------------------------- CONFIG MEMORY --------------------------- //$_config['memory']['prefix'] = 'EoEjyx_';$_config['memory']['redis']['server'] = '';$_config['memory']['redis']['port'] = 6379;$_config['memory']['redis']['pconnect'] = 1;$_config['memory']['redis']['timeout'] = '0';$_config['memory']['redis']['serializer'] = 1;$_config['memory']['memcache']['server'] = '';$_config['memory']['memcache']['port'] = 11211;$_config['memory']['memcache']['pconnect'] = 1;$_config['memory']['memcache']['timeout'] = 1;$_config['memory']['apc'] = 0;$_config['memory']['xcache'] = 0;$_config['memory']['eaccelerator'] = 0;$_config['memory']['wincache'] = 1;// -------------------------- CONFIG SERVER --------------------------- //$_config['server']['id'] = 1;// ------------------------- CONFIG DOWNLOAD -------------------------- //$_config['download']['readmod'] = 2;$_config['download']['xsendfile']['type'] = '0';$_config['download']['xsendfile']['dir'] = '/down/';// --------------------------- CONFIG CACHE --------------------------- //$_config['cache']['type'] = 'sql';// -------------------------- CONFIG OUTPUT --------------------------- //$_config['output']['charset'] = 'utf-8';$_config['output']['forceheader'] = 1;$_config['output']['gzip'] = '1';$_config['output']['tplrefresh'] = 1;$_config['output']['language'] = 'zh_cn';$_config['output']['staticurl'] = 'static/';$_config['output']['ajaxvalidate'] = '0';$_config['output']['iecompatible'] = '0';// -------------------------- CONFIG COOKIE --------------------------- //$_config['cookie']['cookiepre'] = 'R2RI_';$_config['cookie']['cookiedomain'] = 'sopbbs.suning.com';$_config['cookie']['cookiepath'] = '/';// ------------------------- CONFIG SECURITY -------------------------- //$_config['security']['authkey'] = 'e64aedC23CIadC7Y';$_config['security']['urlxssdefend'] = 1;$_config['security']['attackevasive'] = '0';$_config['security']['querysafe']['status'] = 1;$_config['security']['querysafe']['dfunction']['0'] = 'load_file';$_config['security']['querysafe']['dfunction']['1'] = 'hex';$_config['security']['querysafe']['dfunction']['2'] = 'substring';$_config['security']['querysafe']['dfunction']['3'] = 'if';$_config['security']['querysafe']['dfunction']['4'] = 'ord';$_config['security']['querysafe']['dfunction']['5'] = 'char';$_config['security']['querysafe']['daction']['0'] = '@';$_config['security']['querysafe']['daction']['1'] = 'intooutfile';$_config['security']['querysafe']['daction']['2'] = 'intodumpfile';$_config['security']['querysafe']['daction']['3'] = 'unionselect';$_config['security']['querysafe']['daction']['4'] = '(select';$_config['security']['querysafe']['daction']['5'] = 'unionall';$_config['security']['querysafe']['daction']['6'] = 'uniondistinct';$_config['security']['querysafe']['dnote']['0'] = '/*';$_config['security']['querysafe']['dnote']['1'] = '*/';$_config['security']['querysafe']['dnote']['2'] = '#';$_config['security']['querysafe']['dnote']['3'] = '--';$_config['security']['querysafe']['dnote']['4'] = '"';$_config['security']['querysafe']['dlikehex'] = 1;$_config['security']['querysafe']['afullnote'] = '0';// -------------------------- CONFIG ADMINCP -------------------------- //// -------- Founders: $_config['admincp']['founder'] = '1,2,3'; --------- //$_config['admincp']['founder'] = '1';$_config['admincp']['forcesecques'] = '0';$_config['admincp']['checkip'] = 0;$_config['admincp']['runquery'] = '0';$_config['admincp']['dbimport'] = 1;// -------------------------- CONFIG REMOTE --------------------------- //$_config['remote']['on'] = '0';$_config['remote']['dir'] = 'remote';$_config['remote']['appkey'] = '62cf0b3c3e6a4c9468e7216839721d8e';$_config['remote']['cron'] = '0';// --------------------------- CONFIG INPUT --------------------------- //$_config['input']['compatible'] = 1;//论坛导航链接配置,$_config['forumlink']['1'] = array('name'=>'公告','url'=>'forum.php?mod=forumdisplay&fid=40');$_config['forumlink']['2'] = array('name'=>'资料下载','url'=>'forum.php?mod=forumdisplay&fid=49');$_config['forumlink']['3'] = array('name'=>'帮助中心','url'=>'http://sop.suning.com/sel/help/toMain.htm','target'=>'_blank');// ------------------- THE END -------------------- //?>
删除
危害等级:高
漏洞Rank:20
确认时间:2014-12-24 16:58
感谢提交
暂无