乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-11-21: 细节已通知厂商并且等待厂商处理中 2015-11-24: 厂商已经主动忽略漏洞,细节向公众公开
RT
漏洞如图:https://aone.rajax.me
# Serverredis_version:3.0.4redis_git_sha1:00000000redis_git_dirty:0redis_build_id:5b63f0e22b69e668redis_mode:standaloneos:Linux 2.6.32-573.el6.x86_64 x86_64arch_bits:64multiplexing_api:epollgcc_version:4.4.7process_id:7278run_id:bdf5247648fae1c99903e9f331d9a6a8d986f1a2tcp_port:6379uptime_in_seconds:1574849uptime_in_days:18hz:10lru_clock:5275733config_file:/usr/local/redis-3.0.4/conf/redis.conf# Clientsconnected_clients:29client_longest_output_list:0client_biggest_input_buf:2blocked_clients:1# Memoryused_memory:1438264used_memory_human:1.37Mused_memory_rss:7290880used_memory_peak:433401320used_memory_peak_human:413.32Mused_memory_lua:36864mem_fragmentation_ratio:5.07mem_allocator:jemalloc-3.6.0# Persistenceloading:0rdb_changes_since_last_save:0rdb_bgsave_in_progress:0rdb_last_save_time:1448017092rdb_last_bgsave_status:okrdb_last_bgsave_time_sec:0rdb_current_bgsave_time_sec:-1aof_enabled:0aof_rewrite_in_progress:0aof_rewrite_scheduled:0aof_last_rewrite_time_sec:-1aof_current_rewrite_time_sec:-1aof_last_bgrewrite_status:okaof_last_write_status:ok# Statstotal_connections_received:78total_commands_processed:6974311instantaneous_ops_per_sec:0total_net_input_bytes:3397872660total_net_output_bytes:3192693929instantaneous_input_kbps:0.03instantaneous_output_kbps:0.00rejected_connections:0sync_full:0sync_partial_ok:0sync_partial_err:0expired_keys:0evicted_keys:0keyspace_hits:0keyspace_misses:0pubsub_channels:0pubsub_patterns:0latest_fork_usec:663migrate_cached_sockets:0# Replicationrole:masterconnected_slaves:0master_repl_offset:0repl_backlog_active:0repl_backlog_size:1048576repl_backlog_first_byte_offset:0repl_backlog_histlen:0# CPUused_cpu_sys:461.21used_cpu_user:314.08used_cpu_sys_children:13.10used_cpu_user_children:89.09# Clustercluster_enabled:0# Keyspacedb0:keys=1,expires=0,avg_ttl=0
和运维聊聊
危害等级:无影响厂商忽略
忽略时间:2015-11-24 11:23
该漏洞已于饿了么安全应急响应中心(ESRC)提交,属于重复上报,故做忽略处理。谢谢对饿了么的支持和关注!
暂无