当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0130107

漏洞标题:超星某系统弱口令 可直接获取数千高校服务器权限

相关厂商:超星网

漏洞作者: 路人甲

提交时间:2015-07-29 11:18

修复时间:2015-08-03 11:20

公开时间:2015-08-03 11:20

漏洞类型:服务弱口令

危害等级:高

自评Rank:20

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-29: 细节已通知厂商并且等待厂商处理中
2015-08-03: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

超星某系统弱口令 可直接获取数千高校服务器权限

详细说明:

cx.16q.cn 管理员弱口令 wangkun wangkun
hejuan hejuan
zhanghengshuo zhanghengshuo
heyanbin heyanbin
大部分的管理员账号都是姓名的全拼
这些账号登陆进去就可以看到很多高校服务器的远程账号密码
问了下度娘找到 超星的邮箱用户列表
如下

mask 区域
*****m>;"ssp3"<[email protected]>;"ssp2"<[email protected]>;"ssp1"<[email protected]>;"周颖"<[email protected]>;"周聪"<[email protected]>;"岳慧"<[email protected]>;"yanfa"<[email protected]>;"肖佩"<[email protected]>;"马强"<[email protected]>;"李金晶"<[email protected]>;"张惠龙"<[email protected]>;"韩天奇"<[email protected]>;"甘永宏"<[email protected]>;"程灿"<[email protected]>;"周国庆"<[email protected]>;"张浩春"<[email protected]>;"黄祥龙"<[email protected]>;"汪伟"<[email protected]>;"王慧荣"<[email protected]>;"杨杰"<[email protected]>;"戚洋"<[email protected]>;"苏恩来"<[email protected]>;"李存"<[email protected]>;"杨奇"<[email protected]>;"陈文彬"<[email protected]>;"高云"<[email protected]>;"刘敏"<[email protected]>;"韩芳"<[email protected]>;"魏云霞"<[email protected]>;"任晨光"<[email protected]>;"孟书娟"<[email protected]>;"书目组资源安装提库用"<[email protected]>;"王进"<[email protected]>;"张彦华"<[email protected]>;"焦丽娟"<[email protected]>;"李继伟"<[email protected]>;"王芳/王红"<[email protected]>;"赵子丹"<[email protected]>;"田凤敏"<[email protected]>;"王维"<[email protected]>;"杨玉丽"<[email protected]>;"郭会玉"<[email protected]>;"姜冬梅"<[email protected]>;"毕婷婷"<[email protected]>;"赵雪"<[email protected]>;"Teaching"<[email protected]>;"ask"<[email protected]>;"赵旭娟"<[email protected]>;"赵培雷"<[email protected]>;"资源建设部A"<[email protected]>;"资源建设部B"<[email protected]>;"资源建设部C"<[email protected]>;"资源建设部H"<[email protected]>;"资源建设部I"<[email protected]>;"资源建设部K"<[email protected]>;"资源建设部LR"<[email protected]>;"资源建设部Q"<[email protected]>;"资源建设部R"<[email protected]>;"资源建设部S"<[email protected]>;"资源建设部T"<[email protected]>;"资源建设部U"<[email protected]>;"资源建设部V"<[email protected]>;"资源建设部W"<[email protected]>;"资源建设事业部"<[email protected]>;"资源建设部D"<[email protected]>;"shumuzu"<[email protected]>;"赵学凤"<[email protected]>;"王东媛"<[email protected]>;"zyjsbn"<[email protected]>;"史晓艳"<[email protected]>;"数据服务器专腥"<[email protected]>;"韩晓东"<[email protected]>;"李永东"<[email protected]>;"权巧"<[email protected]>;"徐贵水"<[email protected]>;"李敬"<[email protected]>;"李琳娟"<[email protected]>;"读秀客服"<[email protected]>;"郑晓磊"<[email protected]>;"读秀"<[email protected]>;"拷贝组用"<[email protected]>;"夏淑芳使用"<[email protected]>;"李娜"<[email protected]>;"servermonitor"<[email protected]>;"张德衡"<[email protected]>;"陈佳佳"<[email protected]>;"赵凡一"<[email protected]>;"张巧芬"<[email protected]>;"大雅客服"<[email protected]>;"王佳宁"<[email protected]>;"邹道亮"<[email protected]>;"安晓燕"<[email protected]>;"gongchangfzu"<[email protected]>;"陈银威"<[email protected]>;"徐莹娇"<[email protected]>;"郝晴"<[email protected]>;"牛建国"<[email protected]>;"赵丽丽"<[email protected]>;"果新"<[email protected]>;"焦馨蕊"<[email protected]>;"赵丽丽"<[email protected]>;"张晓蒙"<[email protected]>;"王涛"<[email protected]>;"马腾"<[email protected]>;"张美玲"<[email protected]>;"魏雅南"<[email protected]>;"马建新"<[email protected]>;"超星通行证"<[email protected]>;"fanya_service"<[email protected]>;"史超"<[email protected]>;"郭玉"<[email protected]>;"张姣姣"<[email protected]>;"张幸淑"<[email protected]>;"招聘"<[email protected]>;"李晓娟"<[email protected]>;"唐军"<[email protected]>;"史昊"<[email protected]>;"马航"<[email protected]>;"姜彬彬"<[email protected]>;"人力资源部共用"<[email protected]>;"王红梅"<[email protected]>;"常雯"<[email protected]>;"朱平"<[email protected]>;"吕彩红"<[email protected]>;"史强"<[email protected]>;"史松"<[email protected]>;"熊雪飞"<[email protected]>;"龚治晋"<[email protected]>;"姚兰"<[email protected]>;"阙超"<[email protected]>;"阙超"<[email protected]>;"招人"<[email protected]>;"合同"<[email protected]>;"保证金"<[email protected]>;"史强"<[email protected]>;"付玮娜"<[email protected]>;"李正义"<[email protected]>;"张秀美"<[email protected]>;"路志鹏"<[email protected]>;"林静"<[email protected]>;"采购"<[email protected]>;"郭红静"<[email protected]>;"吴晶晶"<[email protected]>;"许敏"<[email protected]>;"孟莉"<[email protected]>;"李君"<[email protected]>;"借款"<[email protected]>;"肖月"<[email protected]>;"scbf"<[email protected]>;"张蓉"<[email protected]>;"票据"<[email protected]>;"韩静"<[email protected]>;"张丽萍"<[email protected]>;"周淑敏"<[email protected]>;"杨淑慧"<[email protected]>;"满博"<[email protected]>;"刘强"<[email protected]>;"罗兰苹"<[email protected]>;"cw"<[email protected]>;"存档"<[email protected]>;"办公室"<[email protected]>;"蔡亚明"<[email protected]>;"可静"<[email protected]>;"版权"<[email protected]>;"赵琳"<[email protected]>;"张彬"<[email protected]>;"赵文生"<[email protected]>;"文娟"<[email protected]>;"罗丹"<[email protected]>;"马鸿玥"<[email protected]>;"苏海坡"<[email protected]>;"周成功"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"王维"<[email protected]>;"闫秀娟"<[email protected]>;"李华章"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"超星数字图书馆"<[email protected]>;"姜浩然"<[email protected]>;"史超"<[email protected]>;"任冉冉"<[email protected]>;"张旸"<[email protected]>;"张帅"<[email protected]>;"黄玉玺"<[email protected]>;"姚曦"<[email protected]>;"谢荣"<[email protected]>;"肖磊"<[email protected]>;"胡相艳"<[email protected]>;"王军"<[email protected]>;"王红"<[email protected]>;"童飞"<[email protected]>;"彭帆"<[email protected]>;"邓克毅"<[email protected]>;"杨继虎"<[email protected]>;"黄梦娇"<[email protected]>;"何佳"<[email protected]>;"韩潇"<[email protected]>;"高亚菲"<[email protected]>;"王凤超"<[email protected]>;"方晔"<[email protected]>;"杨丹凤"<[email protected]>;"赵斌凯"<[email protected]>;"张辉"<[email protected]>;"马欢"<[email protected]>;"eryaweixin"<[email protected]>;"范永宏"<[email protected]>;"郝俊蕾"<[email protected]>;"史彦军"<[email protected]>;"尚景伟"<[email protected]>;"韩莹"<[email protected]>;"赵云飞"<[email protected]>;"赵平"<[email protected]>;"魏晓静"<[email protected]>;"教图视频产品"<[email protected]>;"位均地"<[email protected]>;"邓博"<[email protected]>;"濮东升"<[email protected]>;"李伊伶"<[email protected]>;"陈国际"<[email protected]>;"李阳"<[email protected]>;"甄琪"<[email protected]>;"胡正凯"<[email protected]>;"高明阳"<[email protected]>;"潘耀祖"<[email protected]>;"冯时"<[email protected]>;"卜霞"<[email protected]>;"覃宇星"<[email protected]>;"朱菲"<[email protected]>;"申大建"<[email protected]>;"蒋雪娇"<[email protected]>;"周雅斌"<[email protected]>;"王燕"<[email protected]>;"卢欣欣"<[email protected]>;"档案部"<[email protected]>;"赵悦"<[email protected]>;"路华伟"<[email protected]>;"田晋治"<[email protected]>;"刘大龙"<[email protected]>;"李文志"<[email protected]>;"侯京波"<[email protected]>;"刘伟"<[email protected]>;"赵芳"<[email protected]>;"陈智斌"<[email protected]>;"肇裔"<[email protected]>;"吴雅莹"<[email protected]>;"刘亚奇"<[email protected]>;"赵阳旭"<[email protected]>;"张学文"<[email protected]>;"祁小杰"<[email protected]>;"郭文娟"<[email protected]>;"王军"<[email protected]>;"丛素伟"<[email protected]>;"孙赫"<[email protected]>;"李思超"<[email protected]>;"聂进"<[email protected]>;"梁燕"<[email protected]>;"高婷婷"<[email protected]>;"高峰"<[email protected]>;"崔月"<[email protected]>;"唐锋"<[email protected]>;"张然"<[email protected]>;"刘雪芳"<[email protected]>;"王陆"<[email protected]>;"张金豹"<[email protected]>;"孙杰"<[email protected]>;"丁晓春"<[email protected]>;"成万里"<[email protected]>;"张恒雨"<[email protected]>;"王萌"<[email protected]>;"王敏"<[email protected]>;"唐吉斯"<[email protected]>;"卢元龙"<[email protected]>;"朱红"<[email protected]>;"王玉奎"<[email protected]>;"杨成"<[email protected]>;"孟琪"<[email protected]>;"李梦琪"<[email protected]>;"李海"<[email protected]>;"潘守东"<[email protected]>;"罗彬"<[email protected]>;"王晓英"<[email protected]>;"张雷"<[email protected]>;"舒展"<[email protected]>;"杨杰山"<[email protected]>;"王允亚"<[email protected]>;"程京雷"<[email protected]>;"刘麒"<[email protected]>;"浦佳"<[email protected]>;"张瑞华"<[email protected]>;"杨晓东"<[email protected]>;"刘嘉玲"<[email protected]>;"罗奇"<[email protected]>;"康军建"<[email protected]>;"贾继坤"<jiajikun*****


这是一部分还有的我就不贴出来了
通过这个列表可以使用Burp Suite爆破 然后你懂的

漏洞证明:

1wy.png


2wy.png


3wy.png


4wy.png


5wy.png


6wy.png


7wy.png


8wy.png

修复方案:

~~~

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-08-03 11:20

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无