乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-11-04: 细节已通知厂商并且等待厂商处理中 2015-11-05: 厂商已经确认,细节仅向厂商公开 2015-11-15: 细节向核心白帽子及相关领域专家公开 2015-11-25: 细节向普通白帽子公开 2015-12-05: 细节向实习白帽子公开 2015-12-20: 细节向公众公开
若我也能成为CEO~那么~
redis数据库未授权访问IP:42.159.192.145
42.159.192.145:0>info# Serverredis_version:2.8.4redis_git_sha1:00000000redis_git_dirty:0redis_build_id:a44a05d76f06a5d9redis_mode:standaloneos:Linux 3.16.0-29-generic x86_64arch_bits:64multiplexing_api:epollgcc_version:4.8.2process_id:1702run_id:c75429374d58616ca6ffdf64e3db6b67d8217381tcp_port:6379uptime_in_seconds:3906678uptime_in_days:45hz:10lru_clock:2049429config_file:/etc/redis/redis.conf# Clientsconnected_clients:11client_longest_output_list:0client_biggest_input_buf:0blocked_clients:0# Memoryused_memory:9020896used_memory_human:8.60Mused_memory_rss:19374080used_memory_peak:9897136used_memory_peak_human:9.44Mused_memory_lua:33792mem_fragmentation_ratio:2.15mem_allocator:jemalloc-3.4.1# Persistenceloading:0rdb_changes_since_last_save:0rdb_bgsave_in_progress:0rdb_last_save_time:1446557612rdb_last_bgsave_status:okrdb_last_bgsave_time_sec:1rdb_current_bgsave_time_sec:-1aof_enabled:0aof_rewrite_in_progress:0aof_rewrite_scheduled:0aof_last_rewrite_time_sec:-1aof_current_rewrite_time_sec:-1aof_last_bgrewrite_status:ok# Statstotal_connections_received:365626total_commands_processed:746359instantaneous_ops_per_sec:0rejected_connections:0sync_full:0sync_partial_ok:0sync_partial_err:0expired_keys:96evicted_keys:0keyspace_hits:390548keyspace_misses:167495pubsub_channels:0pubsub_patterns:0latest_fork_usec:1877# Replicationrole:masterconnected_slaves:0master_repl_offset:0repl_backlog_active:0repl_backlog_size:1048576repl_backlog_first_byte_offset:0repl_backlog_histlen:0# CPUused_cpu_sys:1134.95used_cpu_user:1070.59used_cpu_sys_children:152.21used_cpu_user_children:560.07# Keyspacedb0:keys=10269,expires=32,avg_ttl=442061302
大量信息泄露
这里为什么会有12306和途牛我也是不懂哇看这里,账号密码泄露(看看我们的CEO和网管)
duang~
验证
危害等级:高
漏洞Rank:15
确认时间:2015-11-05 14:28
问题很严重,感谢提供信息,我们已经在着手修复。
暂无