当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0106616

漏洞标题:某市农业委员会Getshell#第一弹

相关厂商:农业委员会

漏洞作者: 路人甲

提交时间:2015-04-10 15:23

修复时间:2015-05-29 18:14

公开时间:2015-05-29 18:14

漏洞类型:命令执行

危害等级:中

自评Rank:10

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-04-10: 细节已通知厂商并且等待厂商处理中
2015-04-14: 厂商已经确认,细节仅向厂商公开
2015-04-24: 细节向核心白帽子及相关领域专家公开
2015-05-04: 细节向普通白帽子公开
2015-05-14: 细节向实习白帽子公开
2015-05-29: 细节向公众公开

简要描述:

某市农业委员会Getshell#第一弹

详细说明:

0x01:getshell
网站:太仓市农业委员会
描述:站点存在Struts2命令执行
C:\Tomcat 6.0_Tomcat6tcny\webapps\ROOT\
nt authority\system
demo:http://58.210.170.254/1.jsp

1.png

漏洞证明:

活动连接
协议 本地地址 外部地址 状态
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:843 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2301 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2381 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:5374 0.0.0.0:0 LISTENING
TCP 0.0.0.0:9001 0.0.0.0:0 LISTENING
TCP 0.0.0.0:9009 0.0.0.0:0 LISTENING
TCP 0.0.0.0:12345 0.0.0.0:0 LISTENING
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49152 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49153 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49154 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49165 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49207 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49210 0.0.0.0:0 LISTENING
TCP 127.0.0.1:9005 0.0.0.0:0 LISTENING
TCP 127.0.0.1:49158 127.0.0.1:49159 ESTABLISHED
TCP 127.0.0.1:49159 127.0.0.1:49158 ESTABLISHED
TCP 192.168.1.100:80 66.249.64.67:45206 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.64.67:58247 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.67.155:37922 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:33465 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:38879 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:45166 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:50401 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:54363 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:56535 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:63374 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.107:65141 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.115:36474 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.115:47220 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.115:48258 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.123:36335 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.123:43348 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.123:45158 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.123:57319 CLOSE_WAIT
TCP 192.168.1.100:80 66.249.69.123:58852 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.203:11462 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.203:59926 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.229:10402 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.247:62895 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.248:27060 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.166.250:57393 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.207:59366 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.213:8526 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.218:53751 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.229:11203 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.233:8828 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.244:55366 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.167.248:28240 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.200:27919 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.205:46383 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.207:52706 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.212:34662 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.228:29538 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.234:9599 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.234:51792 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.168.246:10560 CLOSE_WAIT
TCP 192.168.1.100:80 101.226.169.216:29327 CLOSE_WAIT
TCP 192.168.1.100:80 111.20.19.36:37743 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37744 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37746 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37747 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37748 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37749 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37750 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37751 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37752 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37769 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37770 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37771 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37772 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37773 TIME_WAIT
TCP 192.168.1.100:80 111.20.19.36:37833 ESTABLISHED
TCP 192.168.1.100:80 180.76.6.134:24188 CLOSE_WAIT
TCP 192.168.1.100:80 180.76.6.155:36847 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.170:12147 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.202:10149 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.220:33036 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.221:8066 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.225:4862 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.227:59506 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.20.237:40975 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.21.203:10334 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.21.211:1586 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.21.249:30865 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.22.204:61877 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.22.214:26770 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.22.218:34126 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.22.233:55476 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.22.239:7864 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.25.210:49649 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.25.218:35606 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.25.221:18137 CLOSE_WAIT
TCP 192.168.1.100:80 182.118.25.245:52132 CLOSE_WAIT
TCP 192.168.1.100:80 188.165.15.23:34506 CLOSE_WAIT
TCP 192.168.1.100:80 188.165.15.23:38531 CLOSE_WAIT
TCP 192.168.1.100:80 188.165.15.55:37969 CLOSE_WAIT
TCP 192.168.1.100:80 188.165.15.55:52759 CLOSE_WAIT
TCP 192.168.1.100:80 188.165.15.188:53973 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.163:48176 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.163:49024 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.163:65194 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.165:37518 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.170:49238 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.172:63519 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.173:62505 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.174:41251 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.178:39724 CLOSE_WAIT
TCP 192.168.1.100:80 203.208.60.178:64134 CLOSE_WAIT
TCP 192.168.1.100:80 220.181.108.148:22259 TIME_WAIT
TCP 192.168.1.100:135 108.171.245.43:2449 ESTABLISHED
TCP 192.168.1.100:135 142.4.38.58:3317 ESTABLISHED
TCP 192.168.1.100:139 0.0.0.0:0 LISTENING
TCP 192.168.1.100:139 192.161.191.241:1056 TIME_WAIT
TCP 192.168.1.100:139 192.161.191.241:1080 TIME_WAIT
TCP 192.168.1.100:139 192.161.191.241:1150 TIME_WAIT
TCP 192.168.1.100:139 192.161.191.241:1262 TIME_WAIT

修复方案:

补丁

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:7

确认时间:2015-04-14 18:12

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给江苏分中心,由其后续协调网站管理单位处置。

最新状态:

暂无