当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0100828

漏洞标题:基于全球首创的引擎对象识别技术自动化测试手游平台Getshell(含众多配置与数据库信息)

相关厂商:testbird.com

漏洞作者: 路人甲

提交时间:2015-03-17 10:19

修复时间:2015-05-01 11:10

公开时间:2015-05-01 11:10

漏洞类型:命令执行

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-03-17: 细节已通知厂商并且等待厂商处理中
2015-03-17: 厂商已经确认,细节仅向厂商公开
2015-03-27: 细节向核心白帽子及相关领域专家公开
2015-04-06: 细节向普通白帽子公开
2015-04-16: 细节向实习白帽子公开
2015-05-01: 细节向公众公开

简要描述:

看到此公司招聘WEB安全工程师、给我留个职位可好?哈哈。

详细说明:

TestBird(成都中云天下科技有限公司)成立于2013年,专注于为移动游戏的开发、推广、运营提供专业云端分析工具的创业公司。与移动游戏产业井喷时代并行,TestBird愿景是基于自有全球领先测试推广运营分析能力,为移动游戏行业领先公司创造更高产业价值保驾护航。 TestBird基于全球首创的引擎对象识别技术,可以为客户提供深入到移动游戏内部所有功能的深度解析能力。某自动化手游测试平台的核心技术人员来自华为等公司核心高层,既拥有十年的全球化移动硬件兼容性测试技术积累,还拥有全球移动互联网市场商务实力,为移动游戏开发商提供最专业和贴合的服务是公司的核心基因。最专业的人最专业的事!

Struts2命令执行测试入口:http://ct.testbird.com/a_a11.action


testbird,ct分站存在命令执行直接导致getshell!

1.png


漏洞证明:

0x02:包含众多数据库信息,进一步利用可能泄漏会员信息等

#jdbc.username=testbird
#jdbc.pwd=0987*()-
#jdbc.url=jdbc:postgresql://117.78.2.212:5432/tbtest
#jdbc.username=testbird
#jdbc.pwd=0987*()-
#jdbc.url=jdbc:postgresql://127.0.0.1:5432/tbtest
jdbc.username=TBtest
jdbc.pwd=zhongyunce~123
jdbc.url=jdbc:postgresql://tbpostgresql.cyhjdzhyjem3.rds.cn-north-1.amazonaws.com.cn:5432/tbtest


0x03:默认配置

{
"ct_url_1":{"zh_CN":"a/a1_zh_CN.html","en_US":"a/a1_en_US.html","ko_KR":"","ja_JP":""},
"ct_url_404":{"zh_CN":"404.html","en_US":"404.html","ko_KR":"","ja_JP":""},
"ct_str_0_a":{"zh_CN":"等待中...","en_US":"Waiting...","ko_KR":"","ja_JP":""},
"ct_str_0_b":{"zh_CN":"加载中...","en_US":"Loading...","ko_KR":"","ja_JP":""},
"ct_str_0_c":{"zh_CN":"网络异常!","en_US":"connection error!","ko_KR":"","ja_JP":""},
"ct_str_1":{"zh_CN":"兼容性测试","en_US":"Compatibility testing","ko_KR":"","ja_JP":""},
"ct_str_2":{"zh_CN":"游戏测试","en_US":"Game testing","ko_KR":"","ja_JP":""},
"ct_str_3":{"zh_CN":"测试记录","en_US":"Testing records","ko_KR":"","ja_JP":""},
"ct_str_4":{"zh_CN":"选择game版本","en_US":"Select game version","ko_KR":"","ja_JP":""},
"ct_str_5":{"zh_CN":"还没有game版本?点击添加","en_US":"Add game version","ko_KR":"","ja_JP":""},
"ct_str_6":{"zh_CN":"选择game","en_US":"Select game","ko_KR":"","ja_JP":""},
"ct_str_7":{"zh_CN":"请先选择game版本","en_US":"please select a game version first","ko_KR":"","ja_JP":""},
"ct_str_8":{"zh_CN":"还没有game?点击上传","en_US":"Click to upload game","ko_KR":"","ja_JP":""},
"ct_str_9":{"zh_CN":"待测游戏","en_US":"Pending games","ko_KR":"","ja_JP":""},
"ct_str_10":{"zh_CN":"下一步","en_US":"Next","ko_KR":"","ja_JP":""},
"ct_str_11":{"zh_CN":"选择测试终端","en_US":"Select testing devices","ko_KR":"","ja_JP":""},
"ct_str_12":{"zh_CN":"操作系统","en_US":"Operating system","ko_KR":"","ja_JP":""},
"ct_str_13":{"zh_CN":"全选","en_US":"Select all","ko_KR":"","ja_JP":""},
"ct_str_14":{"zh_CN":"终端品牌","en_US":"Device brands","ko_KR":"","ja_JP":""},
"ct_str_15":{"zh_CN":"屏幕分辨率","en_US":"Screen resolution","ko_KR":"","ja_JP":""},
"ct_str_16":{"zh_CN":"内存大小","en_US":"Internal storage","ko_KR":"","ja_JP":""},
"ct_str_17":{"zh_CN":"已选择终端","en_US":"Selected devices","ko_KR":"","ja_JP":""},
"ct_str_18":{"zh_CN":"款","en_US":"model","ko_KR":"","ja_JP":""},
"ct_str_19":{"zh_CN":"上一步","en_US":"Back","ko_KR":"","ja_JP":""},
"ct_str_20":{"zh_CN":"测试需求","en_US":"Testing requirements","ko_KR":"","ja_JP":""},
"ct_str_21":{"zh_CN":"请填写您的测试需求,如测试重点、特殊要求、已知问题等等(100个字符以内)","en_US":"Please specify testing requirements, such as testing priority, special requirement, known issues, ect.(Within 100 characters)","ko_KR":"","ja_JP":""},
"ct_str_22":{"zh_CN":"基本测试功能","en_US":"Basic testing functions","ko_KR":"","ja_JP":""},
"ct_str_23":{"zh_CN":"安装","en_US":"Install","ko_KR":"","ja_JP":""},
"ct_str_24":{"zh_CN":"启动","en_US":"Booting","ko_KR":"","ja_JP":""},
"ct_str_25":{"zh_CN":"登录/注册","en_US":"Login/Sign up","ko_KR":"","ja_JP":""},
"ct_str_26":{"zh_CN":"新手引导","en_US":"Beginners' tutorial","ko_KR":"","ja_JP":""},
"ct_str_27":{"zh_CN":"卸载","en_US":"Uninstall","ko_KR":"","ja_JP":""},
"ct_str_28":{"zh_CN":"开始测试","en_US":"Start","ko_KR":"","ja_JP":""},
"ct_str_29":{"zh_CN":"查找测试任务","en_US":"Search testing task","ko_KR":"","ja_JP":""},
"ct_str_30":{"zh_CN":"游戏信息","en_US":"Game info","ko_KR":"","ja_JP":""},
"ct_str_31":{"zh_CN":"测试状态","en_US":"Testing status","ko_KR":"","ja_JP":""},
"ct_str_32":{"zh_CN":"提交时间","en_US":"Submission time","ko_KR":"","ja_JP":""},
"ct_str_33":{"zh_CN":"评分","en_US":"Rating","ko_KR":"","ja_JP":""},
"ct_str_34":{"zh_CN":"测试信息","en_US":"Testing info","ko_KR":"","ja_JP":""},
"ct_str_35":{"zh_CN":"操作","en_US":"Operating","ko_KR":"","ja_JP":""},
"ct_str_36":{"zh_CN":"请选择需要测试的终端","en_US":"Please select testing devices","ko_KR":"","ja_JP":""},
"ct_str_37":{"zh_CN":"game版本读取中","en_US":"Identifying game version","ko_KR":"","ja_JP":""},
"ct_str_38":{"zh_CN":"请选择","en_US":"Please select","ko_KR":"","ja_JP":""},
"ct_str_39":{"zh_CN":"game版本读取失败","en_US":"Unable to identify game version","ko_KR":"","ja_JP":""},
"ct_str_40":{"zh_CN":"上传失败:网络异常","en_US":"Unable to upload: connection error","ko_KR":"","ja_JP":""},
"ct_str_41":{"zh_CN":"添加失败:网络异常","en_US":"Unable to add: connection error","ko_KR":"","ja_JP":""},
"ct_str_42":{"zh_CN":"添加game版本(为了提高您的游戏报告的行业指标对比准确度,请尽量填写准确。)","en_US":"Add game version (in order to improve the accuracy of your game report, please complete this entry).","ko_KR":"","ja_JP":""},
"ct_str_43":{"zh_CN":"关闭","en_US":"Close","ko_KR":"","ja_JP":""},
"ct_str_44":{"zh_CN":"终端数据获取异常","en_US":"Unable to access device data","ko_KR":"","ja_JP":""},
"ct_str_45":{"zh_CN":"创建中","en_US":"Creating","ko_KR":"","ja_JP":""},
"ct_str_46":{"zh_CN":"测试任务创建失败,请选择需要测试的game","en_US":"Unable to create testing task, please select game","ko_KR":"","ja_JP":""},
"ct_str_47":{"zh_CN":"测试任务创建失败,请选择需要测试的终端","en_US":"Unable to create testing task, please select devices","ko_KR":"","ja_JP":""},
"ct_str_48":{"zh_CN":"测试任务创建失败:网络异常","en_US":"Testing task creation failed, connection error","ko_KR":"","ja_JP":""},
"ct_str_49":{"zh_CN":"没有数据","en_US":"No data","ko_KR":"","ja_JP":""},
"ct_str_50":{"zh_CN":"共0条信息","en_US":"0 notification","ko_KR":"","ja_JP":""},
"ct_str_51":{"zh_CN":"点击重传本次任务的game","en_US":"Click to re-upload game ","ko_KR":"","ja_JP":""},
"ct_str_52":{"zh_CN":"重传game","en_US":"Re-upload ","ko_KR":"","ja_JP":""},
"ct_str_53":{"zh_CN":"没有相关备注","en_US":"No remark","ko_KR":"","ja_JP":""},
"ct_str_54":{"zh_CN":"实测$num$部终端","en_US":"$num$ devices tested","ko_KR":"","ja_JP":""},
"ct_str_55":{"zh_CN":"总体评分$num$分","en_US":"Overall rating: $num$","ko_KR":"","ja_JP":""},
"ct_str_56":{"zh_CN":"覆盖人群$num$万","en_US":"Covering $num$*10k people","ko_KR":"","ja_JP":""},
"ct_str_57":{"zh_CN":"兼容性评分$num$分","en_US":"Compatibility rating: $num$","ko_KR":"","ja_JP":""},
"ct_str_58":{"zh_CN":"性能评分$num$分","en_US":"Performance rating: $num$","ko_KR":"","ja_JP":""},
"ct_str_59":{"zh_CN":"分","en_US":"Scores","ko_KR":"","ja_JP":""},
"ct_str_60":{"zh_CN":"测试通过$num$部","en_US":"Completed testing $num$ devices","ko_KR":"","ja_JP":""},
"ct_str_61":{"zh_CN":"成功","en_US":"Success","ko_KR":"","ja_JP":""},
"ct_str_62":{"zh_CN":"不兼容","en_US":"Incompatible","ko_KR":"","ja_JP":""},
"ct_str_63":{"zh_CN":"待优化","en_US":"Optimization needed","ko_KR":"","ja_JP":""},
"ct_str_64":{"zh_CN":"未测试","en_US":"Untested","ko_KR":"","ja_JP":""},
"ct_str_65":{"zh_CN":"任务尚未完成,无法下载","en_US":"Task incomplete, unable to download","ko_KR":"","ja_JP":""},
"ct_str_66":{"zh_CN":"下载测试报告","en_US":"Download testing report","ko_KR":"","ja_JP":""},
"ct_str_67":{"zh_CN":"点击下载","en_US":"Click to download","ko_KR":"","ja_JP":""},
"ct_str_68":{"zh_CN":"共$num$页","en_US":"$num$ pages in total","ko_KR":"","ja_JP":""},
"ct_str_69":{"zh_CN":"$num$条记录","en_US":"$num$ entries of record","ko_KR":"","ja_JP":""},
"ct_str_70":{"zh_CN":"上传中...","en_US":"Uploading...","ko_KR":"","ja_JP":""},
"ct_str_71":{"zh_CN":"上传失败:网络异常","en_US":"Unable to upload: connection error","ko_KR":"","ja_JP":""},
"ct_str_72":{"zh_CN":"上传失败","en_US":"Uploading failed","ko_KR":"","ja_JP":""},
"ct_str_73":{"zh_CN":"关闭","en_US":"Close","ko_KR":"","ja_JP":""},
"ct_str_74":{"zh_CN":"还没有游戏版本,请创建","en_US":"Please create a game version","ko_KR":"","ja_JP":""},
"ct_str_75":{"zh_CN":"还没有游戏文件,请上传","en_US":"Please upload game file","ko_KR":"","ja_JP":""},
"ct_str_76":{"zh_CN":"game上传成功","en_US":"Game uploading completed","ko_KR":"","ja_JP":""},
"ct_str_77":{"zh_CN":"无法获取到测试任务","en_US":"Unable to access testing task","ko_KR":"","ja_JP":""},
"ct_str_78":{"zh_CN":"重传game成功","en_US":"Re-sending completed","ko_KR":"","ja_JP":""},
"ct_str_79":{"zh_CN":"请选择测试游戏及测试终端","en_US":"Please select game and testing devices","ko_KR":"","ja_JP":""},
"ct_str_80":{"zh_CN":"等待测试","en_US":"Pending","ko_KR":"","ja_JP":""},
"ct_str_81":{"zh_CN":"没有相关备注","en_US":"No remark","ko_KR":"","ja_JP":""},
"ct_str_82":{"zh_CN":"无法获取到测试任务","en_US":"Unable to access testing task","ko_KR":"","ja_JP":""},
"ct_str_83":{"zh_CN":"该任务尚未就绪","en_US":"This task is not ready","ko_KR":"","ja_JP":""},
"ct_str_84":{"zh_CN":"已上传脚本","en_US":"Script uploaded","ko_KR":"","ja_JP":""},
"ct_str_85":{"zh_CN":"报告尚未生成","en_US":"Report still in process","ko_KR":"","ja_JP":""},
"ct_str_86":{"zh_CN":"正在测试","en_US":"Testing","ko_KR":"","ja_JP":""},
"ct_str_87":{"zh_CN":"结果分析中","en_US":"Analysing","ko_KR":"","ja_JP":""},
"ct_str_88":{"zh_CN":"测试完成","en_US":"Testing completed","ko_KR":"","ja_JP":""},
"ct_str_89":{"zh_CN":"执行成功","en_US":"Execution successful","ko_KR":"","ja_JP":""},
"ct_str_90":{"zh_CN":"安装失败","en_US":"Installation failure","ko_KR":"","ja_JP":""},
"ct_str_91":{"zh_CN":"启动失败","en_US":"Booting failure","ko_KR":"","ja_JP":""},
"ct_str_92":{"zh_CN":"游戏闪退","en_US":"Crashes","ko_KR":"","ja_JP":""},
"ct_str_93":{"zh_CN":"流量[bps]","en_US":"data traffic (bps)","ko_KR":"","ja_JP":""},
"ct_str_94":{"zh_CN":"启动时延[ms]","en_US":"Booting delay (ms)","ko_KR":"","ja_JP":""},
"ct_str_95":{"zh_CN":"CPU占用率[%]","en_US":"CPU utilization (%)","ko_KR":"","ja_JP":""},
"ct_str_96":{"zh_CN":"内存占用[kb]","en_US":"Internal storage utilization (kb)","ko_KR":"","ja_JP":""},
"ct_str_97":{"zh_CN":"IO等待率[%]","en_US":"IO rate (%)","ko_KR":"","ja_JP":""},
"ct_str_98":{"zh_CN":"温度[°C]","en_US":"Temperature (°C)","ko_KR":"","ja_JP":""},
"ct_str_99":{"zh_CN":"帧速率[fps]","en_US":"Frame rate (fps)","ko_KR":"","ja_JP":""},
"ct_str_100":{"zh_CN":"终端异常","en_US":"Device error","ko_KR":"","ja_JP":""},
"ct_str_101":{"zh_CN":"脚本异常","en_US":"Script error","ko_KR":"","ja_JP":""},
"ct_str_102":{"zh_CN":"app异常","en_US":"app error","ko_KR":"","ja_JP":""},
"ct_str_103":{"zh_CN":"脚本未完成","en_US":"Script incomplete","ko_KR":"","ja_JP":""},
"ct_str_104":{"zh_CN":"未知原因","en_US":"Unknown factors","ko_KR":"","ja_JP":""},
"ct_str_105":{"zh_CN":"执行器异常","en_US":"Actuator error","ko_KR":"","ja_JP":""},
"ct_str_106":{"zh_CN":"等待重测","en_US":"Pending for re-testing","ko_KR":"","ja_JP":""},
"ct_str_107":{"zh_CN":"测试被终止","en_US":"Testing terminated","ko_KR":"","ja_JP":""},
"ct_str_108":{"zh_CN":"闪退误报","en_US":"False alarm for crashes","ko_KR":"","ja_JP":""},
"ct_str_109":{"zh_CN":"游戏卡死","en_US":"Frozen screen","ko_KR":"","ja_JP":""},
"ct_str_110":{"zh_CN":"游戏卡顿","en_US":"Slowness","ko_KR":"","ja_JP":""},
"ct_str_111":{"zh_CN":"UI异常","en_US":"UI error","ko_KR":"","ja_JP":""},
"ct_str_112":{"zh_CN":"游戏黑屏","en_US":"Black screen","ko_KR":"","ja_JP":""},
"ct_str_113":{"zh_CN":"数据异常","en_US":"Data error","ko_KR":"","ja_JP":""},
"ct_str_114":{"zh_CN":"程序异常","en_US":"Programming error","ko_KR":"","ja_JP":""},
"ct_str_115":{"zh_CN":"游戏链接异常","en_US":"Game link error","ko_KR":"","ja_JP":""},
"ct_str_116":{"zh_CN":"其他异常","en_US":"Other errors","ko_KR":"","ja_JP":""},
"ct_str_117":{"zh_CN":"闪退误报(Adb异常)","en_US":"False alarm for crashes (Adb error)","ko_KR":"","ja_JP":""},
"ct_str_118":{"zh_CN":"启动失败误报(Adb异常)","en_US":"False alarm for booting failure (Adb error)","ko_KR":"","ja_JP":""},
"ct_str_119":{"zh_CN":"TestBird手游测试报告","en_US":"TestBird mobile game testing report","ko_KR":"","ja_JP":""},
"ct_str_120":{"zh_CN":"App名称(版本)","en_US":"App title (version)","ko_KR":"","ja_JP":""},
"ct_str_121":{"zh_CN":"总体评分","en_US":"Overall rating","ko_KR":"","ja_JP":""},
"ct_str_122":{"zh_CN":"兼容性评分","en_US":"Compatibility rating","ko_KR":"","ja_JP":""},
"ct_str_123":{"zh_CN":"性能评分","en_US":"Performance rating","ko_KR":"","ja_JP":""},
"ct_str_124":{"zh_CN":"测试时间","en_US":"Testing duration","ko_KR":"","ja_JP":""},
"ct_str_125":{"zh_CN":"测试终端数","en_US":"Number of devices","ko_KR":"","ja_JP":""},
"ct_str_126":{"zh_CN":"使用人数","en_US":"Number of users","ko_KR":"","ja_JP":""},
"ct_str_127":{"zh_CN":"行业指标以本次$num$部测试终端为参考依据","en_US":"Taking $num$ tested devices per time as indicator in the industry as reference","ko_KR":"","ja_JP":""},
"ct_str_128":{"zh_CN":"测试通过终端","en_US":"Devices that passed testing","ko_KR":"","ja_JP":""},
"ct_str_129":{"zh_CN":"不兼容终端","en_US":"Incompatible devices","ko_KR":"","ja_JP":""},
"ct_str_130":{"zh_CN":"安装失败","en_US":"Installation failure","ko_KR":"","ja_JP":""},
"ct_str_131":{"zh_CN":"启动失败","en_US":"Booting failure","ko_KR":"","ja_JP":""},
"ct_str_132":{"zh_CN":"新手引导","en_US":"Beginners' tutorial","ko_KR":"","ja_JP":""},
"ct_str_133":{"zh_CN":"合计","en_US":"Total","ko_KR":"","ja_JP":""},
"ct_str_134":{"zh_CN":"使用人数","en_US":"Number of users","ko_KR":"","ja_JP":""},
"ct_str_135":{"zh_CN":"行业最优指标","en_US":"Optimal indicator in the industry","ko_KR":"","ja_JP":""},
"ct_str_136":{"zh_CN":"终端数/占比","en_US":"Number of devices / percentage","ko_KR":"","ja_JP":""},
"ct_str_137":{"zh_CN":"不兼容终端数","en_US":"Number of incompatible devices","ko_KR":"","ja_JP":""},
"ct_str_138":{"zh_CN":"使用人数","en_US":"Number of users","ko_KR":"","ja_JP":""},
"ct_str_139":{"zh_CN":"游戏玩家流失率","en_US":"Clientèle loss rate","ko_KR":"","ja_JP":""},
"ct_str_140":{"zh_CN":"100万用户可能流失玩家数","en_US":"Possible clientèle loss per 1 million gamers","ko_KR":"","ja_JP":""},
"ct_str_141":{"zh_CN":"100万用户可能损失成本","en_US":"Possible revenue loss per 1 million gamers","ko_KR":"","ja_JP":""},
"ct_str_142":{"zh_CN":"万","en_US":"10,000","ko_KR":"","ja_JP":""},
"ct_str_143":{"zh_CN":"万元","en_US":"10,000 RMB","ko_KR":"","ja_JP":""},
"ct_str_144":{"zh_CN":"备注:本表假设游戏中导入100万用户,每用户导入成本为10元计","en_US":"PS: This chart scale numbers to per million of hypothetical players, 10rmb invest for each player. ","ko_KR":"","ja_JP":""},
"ct_str_145":{"zh_CN":"分类/性能指标","en_US":"Category / Performance indicator","ko_KR":"","ja_JP":""},
"ct_str_146":{"zh_CN":"行业最优指标","en_US":"Optimal indicator in the industry","ko_KR":"","ja_JP":""},
"ct_str_147":{"zh_CN":"行业平均指标","en_US":"Average indicator in the industry","ko_KR":"","ja_JP":""},
"ct_str_148":{"zh_CN":"本游戏平均指标","en_US":"Average indicator of this game","ko_KR":"","ja_JP":""},
"ct_str_149":{"zh_CN":"本游戏指标","en_US":"Indicator of this game","ko_KR":"","ja_JP":""},
"ct_str_150":{"zh_CN":"兼容性测试(包括:安装测试,启动测试,新手引导测试)","en_US":"Compatibility testing (includes: installation testing, booting testing and beginners' tutorial testing)","ko_KR":"","ja_JP":""},
"ct_str_151":{"zh_CN":"功能点","en_US":"Functions","ko_KR":"","ja_JP":""},
"ct_str_152":{"zh_CN":"卡顿&卡死","en_US":"Slow & frozen screen","ko_KR":"","ja_JP":""},
"ct_str_153":{"zh_CN":"不兼容问题数","en_US":"Incompatible issues","ko_KR":"","ja_JP":""},
"ct_str_154":{"zh_CN":"安装","en_US":"Install","ko_KR":"","ja_JP":""},
"ct_str_155":{"zh_CN":"启动","en_US":"Booting","ko_KR":"","ja_JP":""},
"ct_str_156":{"zh_CN":"新手引导","en_US":"Beginners' tutorial","ko_KR":"","ja_JP":""},
"ct_str_157":{"zh_CN":"汇总","en_US":"Summary","ko_KR":"","ja_JP":""},
"ct_str_158":{"zh_CN":"总体概括","en_US":"Overview","ko_KR":"","ja_JP":""},
"ct_str_159":{"zh_CN":"终端数","en_US":"Devices","ko_KR":"","ja_JP":""},
"ct_str_160":{"zh_CN":"通过终端","en_US":"Devices that passed testing","ko_KR":"","ja_JP":""},
"ct_str_161":{"zh_CN":"待优化终端","en_US":"Devices that need optimization","ko_KR":"","ja_JP":""},
"ct_str_162":{"zh_CN":"不兼容终端","en_US":"Incompatible devices","ko_KR":"","ja_JP":""},
"ct_str_163":{"zh_CN":"未测试终端","en_US":"Untested devices","ko_KR":"","ja_JP":""},
"ct_str_164":{"zh_CN":"不兼容终端分布(终端类型)","en_US":"Distribution of incompatible devices (by device model)","ko_KR":"","ja_JP":""},
"ct_str_165":{"zh_CN":"高端终端","en_US":"High-end devices","ko_KR":"","ja_JP":""},
"ct_str_166":{"zh_CN":"中端终端","en_US":"Intermediate devices","ko_KR":"","ja_JP":""},
"ct_str_167":{"zh_CN":"低端终端","en_US":"Low-end devices","ko_KR":"","ja_JP":""},
"ct_str_168":{"zh_CN":"不兼容终端分布(品牌)","en_US":"Distribution of incompatible devices (by brand)","ko_KR":"","ja_JP":""},
"ct_str_169":{"zh_CN":"不兼容终端数","en_US":"Incompatible devices","ko_KR":"","ja_JP":""},
"ct_str_170":{"zh_CN":"测试通过终端数","en_US":"Devices that passed testing","ko_KR":"","ja_JP":""},
"ct_str_171":{"zh_CN":"其他","en_US":"Others","ko_KR":"","ja_JP":""},
"ct_str_172":{"zh_CN":"不兼容终端分布(屏幕尺寸)","en_US":"Distribution of incompatible devices (by screen size)","ko_KR":"","ja_JP":""},
"ct_str_173":{"zh_CN":"不兼容终端分布(系统版本)","en_US":"Distribution of incompatible devices (by system version)","ko_KR":"","ja_JP":""},
"ct_str_174":{"zh_CN":"不兼容终端分布(分辨率)","en_US":"Distribution of incompatible devices (by resolution)","ko_KR":"","ja_JP":""},
"ct_str_175":{"zh_CN":"不兼容终端分布(CPU)","en_US":"Distribution of incompatible devices (by CPU)","ko_KR":"","ja_JP":""},
"ct_str_176":{"zh_CN":"不兼容终端分布(内存)","en_US":"Distribution of incompatible devices (by internal storage)","ko_KR":"","ja_JP":""},
"ct_str_177":{"zh_CN":"业界均值","en_US":"Average in the industry","ko_KR":"","ja_JP":""},
"ct_str_178":{"zh_CN":"问题详细描述","en_US":"Descriptions of the issues","ko_KR":"","ja_JP":""},
"ct_str_179":{"zh_CN":"报告内容","en_US":"Report content","ko_KR":"","ja_JP":""},
"ct_str_180":{"zh_CN":"不兼容终端汇总?($num$)??","en_US":"Summary of incompatible devices","ko_KR":"","ja_JP":""},
"ct_str_181":{"zh_CN":"终端品牌","en_US":"Brand of devices","ko_KR":"","ja_JP":""},
"ct_str_182":{"zh_CN":"终端型号","en_US":"Model of devices","ko_KR":"","ja_JP":""},
"ct_str_183":{"zh_CN":"覆盖人群","en_US":"Crowd coverage","ko_KR":"","ja_JP":""},
"ct_str_184":{"zh_CN":"不兼容原因","en_US":"Reasons for incompatibility","ko_KR":"","ja_JP":""},
"ct_str_185":{"zh_CN":"内存","en_US":"Internal storage","ko_KR":"","ja_JP":""},
"ct_str_186":{"zh_CN":"屏幕尺寸","en_US":"Screen size","ko_KR":"","ja_JP":""},
"ct_str_187":{"zh_CN":"分辨率","en_US":"Resolution","ko_KR":"","ja_JP":""},
"ct_str_188":{"zh_CN":"系统版本","en_US":"System version","ko_KR":"","ja_JP":""},
"ct_str_189":{"zh_CN":"待优化项","en_US":"To be optimized","ko_KR":"","ja_JP":""},
"ct_str_190":{"zh_CN":"待优化终端汇总?","en_US":"Summary of devices in need of optimization","ko_KR":"","ja_JP":""},
"ct_str_191":{"zh_CN":"覆盖人群约$num$万","en_US":"Covering approximately $num$ users","ko_KR":"","ja_JP":""},
"ct_str_192":{"zh_CN":"通过终端汇总","en_US":"Summary of tested devices","ko_KR":"","ja_JP":""},
"ct_str_193":{"zh_CN":"点击查看问题定位","en_US":"Click to pinpoint issues","ko_KR":"","ja_JP":""},
"ct_str_194":{"zh_CN":"问题节点","en_US":"Issues occurrence","ko_KR":"","ja_JP":""},
"ct_str_195":{"zh_CN":"问题分类","en_US":"Issue category","ko_KR":"","ja_JP":""},
"ct_str_196":{"zh_CN":"问题描述","en_US":"Issue description","ko_KR":"","ja_JP":""},
"ct_str_197":{"zh_CN":"标记时间","en_US":"Marked time","ko_KR":"","ja_JP":""},
"ct_str_198":{"zh_CN":"共$num$条信息","en_US":"$num$ notifications","ko_KR":"","ja_JP":""},
"ct_str_199":{"zh_CN":"测试开始","en_US":"Start testing","ko_KR":"","ja_JP":""},
"ct_str_200":{"zh_CN":"时间轴","en_US":"Time axis","ko_KR":"","ja_JP":""},
"ct_str_201":{"zh_CN":"相关日志","en_US":"Related logs","ko_KR":"","ja_JP":""},
"ct_str_202":{"zh_CN":"点击下载全部日志","en_US":"Click to download all logs","ko_KR":"","ja_JP":""},
"ct_str_203":{"zh_CN":"共$num$张截图","en_US":"$num$ screenshots in total","ko_KR":"","ja_JP":""},
"ct_str_204":{"zh_CN":"性能视图[注:点击图例可过滤显示对应的性能视图;拖动性能视图可放大数据节点,点击Reset zoom 重置","en_US":"Performance chart (note: click on the line-chart to highlight each individual line of performance. Drag performance line to enlarge data display and click ‘reset’ to zoom back to the original picture.)","ko_KR":"","ja_JP":""},
"ct_str_205":{"zh_CN":"没有数据","en_US":"No data","ko_KR":"","ja_JP":""},
"ct_str_206":{"zh_CN":"没有相关性能或截图数据","en_US":"No performance or screenshots","ko_KR":"","ja_JP":""},
"ct_str_207":{"zh_CN":"点击下载全部日志","en_US":"Click to download all logs","ko_KR":"","ja_JP":""},
"ct_str_208":{"zh_CN":"上传文件","en_US":"Upload file","ko_KR":"","ja_JP":""},
"ct_str_209":{"zh_CN":"点击上传文件","en_US":"Click to upload file","ko_KR":"","ja_JP":""},
"ct_str_210":{"zh_CN":"取消上传","en_US":"Cancel uploading","ko_KR":"","ja_JP":""},
"ct_str_211":{"zh_CN":"或将文件拖拽至此区域","en_US":"or drag file to this area","ko_KR":"","ja_JP":""},
"ct_str_212":{"zh_CN":"文件上传暂不支持IE7及以下版本","en_US":"Internet Explorer version 7 and below are not supported","ko_KR":"","ja_JP":""},
"ct_str_213":{"zh_CN":"只能上传","en_US":"Upload only","ko_KR":"","ja_JP":""},
"ct_str_214":{"zh_CN":"类型的文件","en_US":"File type","ko_KR":"","ja_JP":""},
"ct_str_215":{"zh_CN":"文件名长度超过80位","en_US":"File name has exceeded 80 characters","ko_KR":"","ja_JP":""},
"ct_str_216":{"zh_CN":"上传终止","en_US":"Cancel uploading","ko_KR":"","ja_JP":""},
"ct_str_217":{"zh_CN":"云端上传失败,请稍后再试","en_US":"Cloud uploading failed, please try again later","ko_KR":"","ja_JP":""},
"ct_str_218":{"zh_CN":"正在验证文件","en_US":"Verifying files","ko_KR":"","ja_JP":""},
"ct_str_219":{"zh_CN":"处理失败","en_US":"Unable to process","ko_KR":"","ja_JP":""},
"ct_str_220":{"zh_CN":"用户验证失败","en_US":"User verification failed","ko_KR":"","ja_JP":""},
"ct_str_221":{"zh_CN":"上传成功","en_US":"Upload completed","ko_KR":"","ja_JP":""},
"ct_str_222":{"zh_CN":"上传失败,链接中断","en_US":"Unable to upload due to connection failure","ko_KR":"","ja_JP":""}
}

修复方案:

这个公司听朋友提起过、还挺关注的!希望贵公司重视安全,在移动app开发以及互联网方面做的更好!
#$奖励有木有?
#小礼物有木有?

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2015-03-17 11:08

厂商回复:

确认漏洞,非常感谢

最新状态:

暂无