当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0165852

漏洞标题:神州数码交付宝Getshell泄露百万信息可探测内网89台主机

相关厂商:digitalchina.com

漏洞作者: 路人甲

提交时间:2015-12-29 21:29

修复时间:2015-12-31 11:20

公开时间:2015-12-31 11:20

漏洞类型:命令执行

危害等级:高

自评Rank:15

漏洞状态:厂商已经修复

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-29: 细节已通知厂商并且等待厂商处理中
2015-12-30: 厂商已经确认,细节仅向厂商公开
2015-12-31: 厂商已经修复漏洞并主动公开,细节向公众公开

简要描述:

RT

详细说明:

http://202.108.145.58/default/

52.png


存在JAVA反序列化命令执行漏洞

50.png


内网IP

51.png


直接写shell
http://202.108.145.58/sso-server/she11.jsp?o=vLogin

53.png


数据库配置

<jdbc-driver-params>
<url>jdbc:oracle:thin:@172.16.1.13:1521:ntoptest</url>
<driver-name>oracle.jdbc.driver.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>ntop</value>
</property>
</properties>
<password-encrypted>{AES}V4FhseVJGl6mXcSohg920/a0N8EwqY6vtwlLt0I/Ecc=</password-encrypted>
</jdbc-driver-params>


解密
ntop
ntop456
百万级数据库信息泄露

54.png


再扫下内网

http://172.16.1.12 >> >>Serv-U/11.2.0.0 >>Success
http://172.16.1.13 >> >>null >>Success
http://172.16.1.84 >> 智慧城市>>Apache-Coyote/1.1 >>Success
http://172.16.1.37 >> >>Serv-U/14.0.1.0 >>Success
http://172.16.1.94 >> >>Apache >>Success
http://172.16.1.66 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.16 >> Xampp Compatible 1.9.2phpinfo()>>Apache/2.4.10 (Win32) OpenSSL/0.9.8zc PHP/5.2.17 >>Success
http://172.16.1.52 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.51 >> >>Apache >>Success
http://172.16.1.110 >> >>Microsoft-IIS/7.0 >>Success
http://172.16.1.26 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.112 >> >>Apache/2.2.22 (Win32) mod_ssl/2.2.22 OpenSSL/0.9.8t >>Success
http://172.16.1.113 >> Apache Tomcat>>Apache-Coyote/1.1 >>Success
http://172.16.1.80 >> Sogoso.com ���Ϲ��� ��������� ������Ҫ��>>Microsoft-IIS/5.0 >>Success
http://172.16.1.85 >> >>Serv-U/11.2.0.0 >>Success
http://172.16.1.46 >> Apache Tomcat/7.0.47>>Apache-Coyote/1.1 >>Success
http://172.16.1.111 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.106 >> ����������>>Microsoft-IIS/6.0 >>Success
http://172.16.1.18 >> >>Microsoft-IIS/7.5 >>Success
http://172.16.1.34 >> ����ע���ѯ>>Microsoft-IIS/6.0 >>Success
http://172.16.1.109 >> 神州云科 >>Apache-Coyote/1.1 >>Success
http://172.16.1.123 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.119 >> Oracle HTTP Server Index>>Oracle HTTP Server Powered by Apache/1.3.22 (Win32) mod_plsql/3.0.9.8.3b mod_ssl/2.8.5 OpenSSL/0.9.6b mod_fastcgi/2.2.12 mod_oprocmgr/1.0 mod_perl/1.25 >>Success
http://172.16.1.5 >> >>Microsoft-IIS/7.5 >>Success
http://172.16.1.139 >> Adobe Flash Media Server>>Apache/2.2.21 (Win32) DAV/2 >>Success
http://172.16.1.141 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.137 >> >>HttpServer >>Success
http://172.16.1.138 >> >>Apache >>Success
http://172.16.1.40 >> >>nginx/1.2.5 >>Success
http://172.16.1.43 >> 金库运配系统2.0>>null >>Success
http://172.16.1.149 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.150 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.59 >> HW e-FA>>null >>Success
http://172.16.1.60 >> >>nginx/1.3.4 >>Success
http://172.16.1.67 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.54 >> Apache Tomcat/7.0.57>>Apache-Coyote/1.1 >>Success
http://172.16.1.64 >> Index of />>Apache/2.0.59 (Unix) >>Success
http://172.16.1.69 >> >>nginx/1.4.4 >>Success
http://172.16.1.70 >> Welcome to nginx!>>nginx/1.8.0 >>Success
http://172.16.1.42 >> Apache Tomcat/7.0.55 - Error report>>Apache-Coyote/1.1 >>Success
http://172.16.1.28 >> IBM HTTP Server>>IBM_HTTP_Server >>Success
http://172.16.1.88 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.91 >> >>nginx/1.0.11 >>Success
http://172.16.1.79 >> 神州数码DMT集团商用显示事业部CRM系统>>Apache/2.0.63 (Win32) PHP/5.2.14 >>Success
http://172.16.1.117 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.118 >> ITL微信平台>>null >>Success
http://172.16.1.176 >> >>Microsoft-IIS/7.5 >>Success
http://172.16.1.128 >> >>Apache >>Success
http://172.16.1.86 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.132 >> HW e-FA>>null >>Success
http://172.16.1.98 >> >>nginx/1.4.4 >>Success
http://172.16.1.185 >> >>Microsoft-IIS/7.5 >>Success
http://172.16.1.184 >> 产品登录界面>>Apache-Coyote/1.1 >>Success
http://172.16.1.171 >> index>>Microsoft-IIS/6.0 >>Success
http://172.16.1.187 >> >>Microsoft-IIS/6.0 >>Success
http://172.16.1.194 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.180 >> VisualSVN Server>>Apache >>Success
http://172.16.1.189 >> >>Microsoft-IIS/7.5 >>Success
http://172.16.1.153 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.62 >> Shop UED>>Apache/2.2.15 (Red Hat) >>Success
http://172.16.1.156 >> >>nginx/1.2.5 >>Success
http://172.16.1.159 >> Index of />>Apache/2.4.12 (Unix) PHP/5.5.23 >>Success
http://172.16.1.166 >> >>nginx/1.1.19 >>Success
http://172.16.1.148 >> >>Lotus-Domino >>Success
http://172.16.1.168 >> Welcome to nginx!>>nginx/1.3.0 >>Success
http://172.16.1.205 >> My JSP 'index.jsp' starting page>>null >>Success
http://172.16.1.224 >> IIS7>>Microsoft-IIS/7.5 >>Success
http://172.16.1.230 >> 首页 - 北京神州云科数据技术有限公司>>Apache-Coyote/1.1 >>Success
http://172.16.1.73 >> ��������-ͶӰ������>>Apache/2.2.8 (Unix) PHP/5.2.10 >>Success
http://172.16.1.219 >> CASE系统>>Apache-Coyote/1.1 >>Success
http://172.16.1.204 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.236 >> >>Apache/2.2.25 (Win32) >>Success
http://172.16.1.225 >> ����ƽ̨-----��ҳ>>Apache-Coyote/1.1 >>Success
http://172.16.1.195 >> >>nginx/1.8.0 >>Success
http://172.16.1.172 >> Server Login>>Lotus-Domino >>Success
http://172.16.1.211 >> 移动终端应用服务>>WebSEAL/6.1.0.4 (Build 090910) >>Success
http://172.16.1.212 >> >>nginx/1.4.4 >>Success
http://172.16.1.210 >> ��������IT���ͳһ��֤ƽ̨>>WebSEAL/6.1.0.4 (Build 090910) >>Success
http://172.16.1.213 >> ������������������޹�˾>>Apache-Coyote/1.1 >>Success
http://172.16.1.239 >> >>Apache/2.2.22 (Win32) >>Success
http://172.16.1.227 >> >>nginx >>Success
http://172.16.1.244 >> >>Apache-Coyote/1.1 >>Success
http://172.16.1.250 >> 移动终端应用服务>>WebSEAL/6.1.0.4 (Build 090910) >>Success
http://172.16.1.248 >> 金库运配系统2.0>>null >>Success
http://172.16.1.209 >> 同仁堂健康ITSM:Login>>Apache-Coyote/1.1 >>Success
http://172.16.1.221 >> Sametime>>IBM_HTTP_Server >>Success
http://172.16.1.235 >> Sametime会议中心>>IBM_HTTP_Server >>Success
http://172.16.1.234 >> Server Login>>Lotus-Domino >>Success
http://172.16.1.240 >> 神州数码>>IBM_HTTP_Server >>Success


内网89台主机可漫游!!!

漏洞证明:

修复方案:

20rank还是值得!

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2015-12-30 09:34

厂商回复:

马上处理

最新状态:

2015-12-31:已打补丁