乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-17: 细节已通知厂商并且等待厂商处理中 2015-12-17: 厂商已经确认,细节仅向厂商公开 2015-12-27: 细节向核心白帽子及相关领域专家公开 2016-01-06: 细节向普通白帽子公开 2016-01-16: 细节向实习白帽子公开 2016-01-28: 细节向公众公开
...
优分期jenkins存在java反序列化jenkins.ufenqi.com直接执行命令
反弹 收shell
uname -aLinux iZ25j1y0ldaZ 2.6.32-431.23.3.el6.x86_64 #1 SMP Thu Jul 31 17:20:51 UTC 2014 x86_64 x86_64 x86_64 GNU/Linuxwhoamijenkinsls -altotal 108dr-xr-xr-x. 23 root root 4096 Sep 28 12:13 .dr-xr-xr-x. 23 root root 4096 Sep 28 12:13 ..-rw-r--r-- 1 root root 0 Sep 28 12:13 .autofsck-rw-r--r-- 1 root root 0 Jan 30 2015 .autorelabeldr-xr-xr-x. 2 root root 4096 Sep 19 03:13 bindr-xr-xr-x. 4 root root 4096 Aug 14 2014 bootdrwxr-xr-x 4 root root 4096 Aug 22 14:14 datadrwxr-xr-x 16 root root 3360 Sep 28 12:13 devdrwxr-xr-x. 83 root root 4096 Dec 16 03:39 etcdrwxr-xr-x. 31 root root 4096 Dec 2 15:04 homedr-xr-xr-x. 11 root root 4096 May 26 2015 libdr-xr-xr-x. 9 root root 12288 Sep 19 03:13 lib64drwx------. 2 root root 16384 Aug 14 2014 lost+founddrwxr-xr-x. 2 root root 4096 Sep 23 2011 mediadrwxr-xr-x. 2 root root 4096 Sep 23 2011 mntdrwxr-xr-x. 4 root root 4096 Aug 22 14:14 optdr-xr-xr-x 134 root root 0 Sep 28 20:13 procdr-xr-x--x. 7 root root 4096 Nov 26 11:32 rootdr-xr-xr-x. 2 root root 12288 Sep 19 03:13 sbindrwxr-xr-x. 2 root root 4096 Aug 14 2014 selinuxdrwxr-xr-x. 2 root root 4096 Sep 23 2011 srvdrwxr-xr-x 13 root root 0 Sep 28 20:13 sysdrwxrwxrwt. 6 root root 4096 Dec 17 16:28 tmpdrwxr-xr-x. 13 root root 4096 Aug 14 2014 usrdrwxr-xr-x. 20 root root 4096 Aug 14 2014 var
cd /homels -altotal 124drwxr-xr-x. 31 root root 4096 Dec 2 15:04 .dr-xr-xr-x. 23 root root 4096 Sep 28 12:13 ..drwx------ 3 chenliuyi chenliuyi 4096 Jul 21 16:36 chenliuyidrwx------ 5 deploy deploy 4096 Sep 10 18:13 deploydrwx------ 3 derek derek 4096 Jul 21 16:14 derekdrwx------ 3 gaoying gaoying 4096 Sep 25 18:26 gaoyingdrwx------ 3 guomengfei guomengfei 4096 Nov 4 11:02 guomengfeidrwx------ 3 huming huming 4096 Nov 10 13:55 humingdrwx------ 9 jenkins jenkins 4096 Nov 24 09:42 jenkinsdrwx------ 7 jiaozhichao jiaozhichao 4096 Dec 16 15:55 jiaozhichaodrwx------ 3 kangruiwei kangruiwei 4096 Sep 25 11:18 kangruiweidrwx------ 3 liugang liugang 4096 Jul 21 16:13 liugangdrwx------ 3 liuwendong liuwendong 4096 Sep 10 11:49 liuwendongdrwx------ 3 liuyourun liuyourun 4096 Sep 24 10:19 liuyourundrwx------ 3 lixinpeng lixinpeng 4096 Oct 27 16:35 lixinpengdrwx------ 3 lixiuyu lixiuyu 4096 Dec 13 06:32 lixiuyudrwx------ 3 lixuehui lixuehui 4096 Oct 10 10:18 lixuehuidrwx------ 3 luojiaoxia luojiaoxia 4096 Jul 21 16:34 luojiaoxiadrwx------ 3 maijieyu maijieyu 4096 Sep 7 15:32 maijieyudrwx------ 3 muhua muhua 4096 Jul 21 16:46 muhuadrwx------ 3 ruanxiaozhen ruanxiaozhen 4096 Jul 21 16:23 ruanxiaozhendrwx------ 3 shaoyingnan shaoyingnan 4096 Nov 16 19:46 shaoyingnandrwx------ 3 tuwei tuwei 4096 Dec 16 16:59 tuweidrwx------ 3 wangsong wangsong 4096 Nov 22 19:47 wangsongdrwx------ 3 weilisong weilisong 4096 Nov 16 16:19 weilisongdrwx------ 3 xiejisheng xiejisheng 4096 Dec 2 15:07 xiejishengdrwx------ 3 xuheyang xuheyang 4096 Sep 28 10:19 xuheyangdrwx------ 4 xulifeng xulifeng 4096 Nov 27 16:18 xulifengdrwx------ 3 zhanghongwei zhanghongwei 4096 Jul 21 16:21 zhanghongweidrwx------ 7 zhangpengwei zhangpengwei 4096 Jul 8 14:21 zhangpengweidrwx------ 3 zhangzheng zhangzheng 4096 Jul 29 18:20 zhangzheng
cat /etc/hosts127.0.0.1 localhost::1 localhost localhost.localdomain localhost6 localhost6.localdomain610.171.16.185 iZ25j1y0ldaZiZ25tag7wftZ 10.170.233.17510.170.233.17 i5Z25tag7wftZ10.172.238.163 git.ufenqi.com
等...ok
···
改
危害等级:高
漏洞Rank:12
确认时间:2015-12-17 21:03
好问题
暂无