当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0107914

漏洞标题:泡椒网多站某服务未授权访问(疑似影响用户数据)

相关厂商:paojiao.com

漏洞作者: 管管侠

提交时间:2015-04-14 17:57

修复时间:2015-06-02 22:06

公开时间:2015-06-02 22:06

漏洞类型:未授权访问/权限绕过

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-04-14: 细节已通知厂商并且等待厂商处理中
2015-04-18: 厂商已经确认,细节仅向厂商公开
2015-04-28: 细节向核心白帽子及相关领域专家公开
2015-05-08: 细节向普通白帽子公开
2015-05-18: 细节向实习白帽子公开
2015-06-02: 细节向公众公开

简要描述:

详细说明:

2.png


Memcached配置不当导致未授权访问
1. 115.29.176.12:11211
STAT uptime 2535841
STAT time 1429004497
STAT version 1.4.20
STAT libevent 1.4.13-stable
STAT pointer_size 64
STAT rusage_user 282.219096
STAT rusage_system 1254.372306
STAT curr_connections 24
STAT total_connections 153
STAT connection_structures 32
STAT reserved_fds 20
STAT cmd_get 8306649
STAT cmd_set 738838
STAT cmd_flush 42
STAT cmd_touch 0
STAT get_hits 7321725
STAT get_misses 984924
STAT delete_misses 0
STAT delete_hits 0
STAT incr_misses 0
STAT incr_hits 0
STAT decr_misses 0
STAT decr_hits 0
STAT cas_misses 0
STAT cas_hits 0
STAT cas_badval 0
STAT touch_hits 0
STAT touch_misses 0
STAT auth_cmds 0
STAT auth_errors 0
STAT bytes_read 1111783459
STAT bytes_written 20152531445
STAT limit_maxbytes 3221225472
STAT accepting_conns 1
STAT listen_disabled_num 0
STAT threads 4
STAT conn_yields 0
STAT hash_power_level 16
STAT hash_bytes 524288
STAT hash_is_expanding 0
STAT malloc_fails 0
STAT bytes 13706057
STAT curr_items 10657
STAT total_items 738838

漏洞证明:

2. 58.215.179.85:11211
STAT uptime 17551330
STAT time 1429004533
STAT version 1.4.15
STAT libevent 1.4.13-stable
STAT pointer_size 64
STAT rusage_user 100.702690
STAT rusage_system 802.499001
STAT curr_connections 10
STAT total_connections 754
STAT connection_structures 55
STAT reserved_fds 20
STAT cmd_get 2352671
STAT cmd_set 0
STAT cmd_flush 0
STAT cmd_touch 0
STAT get_hits 0
STAT get_misses 2352671
STAT delete_misses 0
STAT delete_hits 0
STAT incr_misses 0
STAT incr_hits 0
STAT decr_misses 0
STAT decr_hits 0
STAT cas_misses 0
STAT cas_hits 0
STAT cas_badval 0
STAT touch_hits 0
STAT touch_misses 0
STAT auth_cmds 0
STAT auth_errors 0
STAT bytes_read 722888666
STAT bytes_written 825688287
STAT limit_maxbytes 5368709120
STAT accepting_conns 1
STAT listen_disabled_num 0
STAT threads 4
STAT conn_yields 1370
STAT hash_power_level 16
STAT hash_bytes 524288
STAT hash_is_expanding 0
STAT bytes 0
STAT curr_items 0
STAT total_items 0
STAT expired_unfetched 0
STAT evicted_unfetched 0

修复方案:

版权声明:转载请注明来源 管管侠@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2015-04-18 22:05

厂商回复:

感谢

最新状态:

暂无