当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0165739

漏洞标题:上海某IDC机房IBM刀片机弱口令/直接可遍历全网

相关厂商:cncert国家互联网应急中心

漏洞作者: 路人甲

提交时间:2016-01-01 16:52

修复时间:2016-02-20 15:48

公开时间:2016-02-20 15:48

漏洞类型:服务弱口令

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-01: 细节已通知厂商并且等待厂商处理中
2016-01-08: 厂商已经确认,细节仅向厂商公开
2016-01-18: 细节向核心白帽子及相关领域专家公开
2016-01-28: 细节向普通白帽子公开
2016-02-07: 细节向实习白帽子公开
2016-02-20: 细节向公众公开

简要描述:

RT

详细说明:

一次偶然的机会,发现一公网IP地址,存在ftp弱口令oracle/oracle,一测试,竟然也是系统的用户名密码,还是直接telnet登录,登录上去一瞧,惊呆了,IBM AIX 刀片机 ..数据库...IDC机房... 简直不忍直视....
漏洞地址:**.**.**.**
漏洞类型:弱口令 ftp:oracle/oracle telnet:oracle/oracle

idc.jpg

漏洞证明:

idc.jpg


blade3:/home/oracle$uname -a
AIX blade3 1 6 0001D64BD400
blade3:/home/oracle$ifconfig
usage: ifconfig -a [ -m ] [ -d ] [ -u ] [ af ]
ifconfig -l [ -d ] [ -u ]
ifconfig [ -m ] interface
[ af [ address [ dest_addr ] ] [ netmask mask ] [ broadcast addr ]
[ alias ] [ delete ] ]
[ up ] [ down ] [ detach ]
[ af first[alias] address [ ... ] ]
[ site6 site_number ]
[ metric n ]
[ mtu n ]
[ arp | -arp ]
[ link0 | -link0 ] [ link1 | -link1 ] [ link2 | -link2 ]
[ tcp_low_rto n | -tcp_low_rto ]
[ inet6 scope n zone n ]
blade3:/home/oracle$ifconfig -a
en0: flags=1e080863,c0<UP,BROADCAST,NOTRAILERS,RUNNING,SIMPLEX,MULTICAST,GROUPRT,64BIT,CHECKSUM_OFFLOAD(ACTIVE),LARGESEND,CHAIN>
inet **.**.**.** netmask 0xffffff00 broadcast **.**.**.**
tcp_sendspace 131072 tcp_recvspace 65536 rfc1323 0
en1: flags=1e080863,c0<UP,BROADCAST,NOTRAILERS,RUNNING,SIMPLEX,MULTICAST,GROUPRT,64BIT,CHECKSUM_OFFLOAD(ACTIVE),LARGESEND,CHAIN>
inet **.**.**.** netmask 0xffffff00 broadcast **.**.**.**
tcp_sendspace 131072 tcp_recvspace 65536 rfc1323 0
lo0: flags=e08084b,c0<UP,BROADCAST,LOOPBACK,RUNNING,SIMPLEX,MULTICAST,GROUPRT,64BIT,LARGESEND,CHAIN>
inet **.**.**.** netmask 0xff000000 broadcast **.**.**.**
inet6 ::1%1/0
tcp_sendspace 131072 tcp_recvspace 131072 rfc1323 1
blade3:/home/oracle$prtconf
System Model: IBM,8406-71Y
Machine Serial Number: 061D64B
Processor Type: PowerPC_POWER7
Processor Implementation Mode: POWER 7
Processor Version: PV_7_Compat
Number Of Processors: 8
Processor Clock Speed: 3000 MHz
CPU Type: 64-bit
Kernel Type: 64-bit
LPAR Info: 1 06-1D64B
Memory Size: 31616 MB
Good Memory Size: 31616 MB
Platform Firmware level: AA730_078
Firmware Version: IBM,AA730_078
Console Login: enable
Auto Restart: true
Full Core: false

Network Information
Host Name: blade3
IP Address: **.**.**.**
Sub Netmask: **.**.**.**
Gateway: **.**.**.**
Name Server:
Domain Name:

Paging Space Information
Total Paging Space: 24576MB
Percent Used: 1%

Volume Groups Information
==============================================================================
rootvg:
PV_NAME PV STATE TOTAL PPs FREE PPs FREE DISTRIBUTION
hdisk0 active 558 254 31..55..00..56..112
==============================================================================

arch1vg:
PV_NAME PV STATE TOTAL PPs FREE PPs FREE DISTRIBUTION
hdisk1 active 399 38 00..00..00..00..38
==============================================================================

datavg:
PV_NAME PV STATE TOTAL PPs FREE PPs FREE DISTRIBUTION
hdisk8 active 639 394 124..00..14..128..128
==============================================================================

oggvg:
PV_NAME PV STATE TOTAL PPs FREE PPs FREE DISTRIBUTION
hdisk7 active 599 198 00..00..00..78..120
==============================================================================

0516-010 : Volume group must be varied on; use varyonvg command.
==============================================================================

INSTALLED RESOURCE LIST
The following resources are installed on the machine.
+/- = Added or deleted from Resource List.
* = Diagnostic support not available.

Model Architecture: chrp
Model Implementation: Multiple Processor, PCI bus

+ sys0 System Object
+ sysplanar0 System Planar
* vio0 Virtual I/O Bus
* vsa0 U8406.71Y.061D64B-V1-C0 LPAR Virtual Serial Adapter
* vty0 U8406.71Y.061D64B-V1-C0-L0 Asynchronous Terminal
* pci2 U78A5.001.WIHDF42-P1 PCI Express Bus
+ fcs0 U78A5.001.WIHDF42-P1-C19-T1 8Gb PCIe FC Blade Expansion Card (7710322577107601)
+ fscsi0 U78A5.001.WIHDF42-P1-C19-T1 FC SCSI I/O Controller Protocol Device
* hdisk1 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L0 MPIO IBM 2076 FC Disk
* hdisk2 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L1000000000000 MPIO IBM 2076 FC Disk
* hdisk3 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L2000000000000 MPIO IBM 2076 FC Disk
* hdisk4 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L3000000000000 MPIO IBM 2076 FC Disk
* hdisk5 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L4000000000000 MPIO IBM 2076 FC Disk
* hdisk6 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L5000000000000 MPIO IBM 2076 FC Disk
* hdisk7 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L6000000000000 MPIO IBM 2076 FC Disk
* hdisk8 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L7000000000000 MPIO IBM 2076 FC Disk
* hdisk9 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L8000000000000 MPIO IBM 2076 FC Disk
* hdisk10 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L9000000000000 MPIO IBM 2076 FC Disk
* hdisk11 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-LA000000000000 MPIO IBM 2076 FC Disk
* rmt0 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L1000000000000 Other FC SCSI Tape Drive
* rmt1 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L2000000000000 Other FC SCSI Tape Drive
* rmt2 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L3000000000000 Other FC SCSI Tape Drive
* rmt3 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L4000000000000 Other FC SCSI Tape Drive
+ fcs1 U78A5.001.WIHDF42-P1-C19-T2 8Gb PCIe FC Blade Expansion Card (7710322577107601)
+ fscsi1 U78A5.001.WIHDF42-P1-C19-T2 FC SCSI I/O Controller Protocol Device
* pci1 U78A5.001.WIHDF42-P1 PCI Bus
+ usbhc0 U78A5.001.WIHDF42-P1 USB Host Controller (33103500)
+ usbhc1 U78A5.001.WIHDF42-P1 USB Host Controller (33103500)
+ usbhc2 U78A5.001.WIHDF42-P1 USB Enhanced Host Controller (3310e000)
* pci0 U78A5.001.WIHDF42-P1 PCI Bus
+ sissas0 U78A5.001.WIHDF42-P1-T3 PCI-X266 Planar 3Gb SAS Adapter
* sas0 U78A5.001.WIHDF42-P1-T3 Controller SAS Protocol
* sfwcomm0 SAS Storage Framework Comm
+ hdisk0 U78A5.001.WIHDF42-P1-D1 SAS Disk Drive (300000 MB)
+ ses0 U78A5.001.WIHDF42-P1-Y1 SAS Enclosure Services Device
* sata0 U78A5.001.WIHDF42-P1-T3 Controller SATA Protocol
* lhea0 U78A5.001.WIHDF42-P1 Logical Host Ethernet Adapter (l-hea)
+ ent1 U78A5.001.WIHDF42-P1-T5 Logical Host Ethernet Port (lp-hea)
+ ent0 U78A5.001.WIHDF42-P1-T4 Logical Host Ethernet Port (lp-hea)
+ L2cache0 L2 Cache
+ mem0 Memory
+ proc0 Processor
+ proc4 Processor
+ proc8 Processor
+ proc12 Processor
+ proc16 Processor
+ proc20 Processor
+ proc24 Processor
+ proc28 Processor
blade3:/home/oracle$ps -ef
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 Jun 06 - 23:26 /etc/init
root 3342568 4063482 0 Jun 06 - 0:10 /usr/sbin/portmap
root 3539136 1 0 Jun 06 - 359:05 /usr/sbin/syncd 60
root 3604688 1 0 Jun 06 - 0:22 /opt/ibm/director/cimom/b
root 4063482 1 0 Jun 06 - 0:00 /usr/sbin/srcmstr
root 4129002 1 0 Jun 06 - 0:00 /usr/ccs/bin/shlap64
root 4194538 1 0 Jun 06 - 0:00 /usr/lib/errdemon
root 4325624 4063482 0 Jun 06 - 0:00 /opt/freeware/cimom/pegas
root 4456640 4063482 0 Jun 06 - 17:12 /usr/sbin/syslogd
root 4587736 1 0 Jun 06 - 5:51 /usr/sbin/cron
root 4718778 1 0 Jun 06 - 31:33 /usr/bin/topasrec -L -s
root 4849898 4063482 0 Jun 06 - 40:21 /usr/sbin/clcomd -d
root 5439672 1 0 Jun 06 - 23:04 ./slp_srvreg -D
root 5570578 4063482 0 Jun 06 - 0:00 /bin/ksh /pconsole/lwi/bi
pconsole 5701870 5570578 0 Jun 06 - 0:00 /bin/ksh /pconsole/lwi/bi
root 5767348 1 0 Jun 06 - 0:00 /usr/sbin/uprintfd
oracle 5832846 1 0 Nov 03 - 3:15 ora_lgwr_ORCL
root 5898454 4063482 0 Jun 06 - 15:43 /usr/sbin/inetd
root 6029498 4063482 0 Jun 06 - 0:00 /opt/freeware/cimom/pegas
root 6094970 4063482 0 Jun 06 - 0:00 /usr/sbin/rsct/bin/IBM.Se
root 6160586 4063482 0 Jun 06 - 202:07 /usr/es/sbin/cluster/clco
root 6291670 1 0 Jun 06 - 0:28 /usr/dt/bin/dtlogin -daem
root 6357192 1 0 Jun 06 - 0:30 /usr/bin/cimlistener
root 6422556 4063482 0 Jun 06 - 0:00 /usr/sbin/rsct/bin/IBM.DR
oracle 6488158 1 0 Nov 03 - 3:00 ora_dbw3_ORCL
root 6684676 1 0 Jun 06 - 5:30 [cimserve]
root 6750454 4063482 0 Jun 06 - 2:16 /usr/sbin/rsct/bin/rmcd -
root 6815954 4063482 0 Jun 06 - 57:12 /usr/sbin/snmpd
pconsole 6881288 5701870 0 Jun 06 - 59:58 /usr/java5/bin/java -Xmx5
root 6946856 1 0 Jun 06 - 2:17 bin/nonstop_aix @config/n
root 7012588 6946856 0 Jun 06 - 154:38 /var/opt/tivoli/ep/_jvm/j
root 7143486 1 0 Dec 09 vty0 0:00 /usr/sbin/getty /dev/cons
root 7208986 4063482 0 Jun 06 - 148:35 /usr/es/sbin/cluster/clst
root 7274590 4063482 0 Jun 06 - 0:00 /usr/sbin/rsct/bin/vac8/I
root 7340262 1 0 Jun 06 - 1:40 /opt/ibm/icc/cimom/bin/di
oracle 7405794 1 0 Nov 03 - 3:02 ora_dbw2_ORCL
root 7471346 1 0 Jun 06 - 0:00 /opt/freeware/cimom/pegas
oracle 8388632 1 0 Nov 03 - 3:00 ora_dbw1_ORCL
oracle 8454230 1 0 Nov 03 - 3:05 ora_dbw0_ORCL
oracle 8585258 1 0 Nov 03 - 1:45 ora_mman_ORCL
oracle 8847602 1 0 Nov 03 - 131:17 ora_dia0_ORCL
root 8913030 5898454 0 Jun 06 - 0:00 rpc.ttdbserver 100083 1
oracle 9044222 1 0 Nov 03 - 1:47 ora_dbrm_ORCL
oracle 9306332 1 0 Nov 03 - 11:20 ora_ckpt_ORCL
oracle 9699438 1 0 Nov 03 - 3:55 ora_psp0_ORCL
oracle 9764874 1 0 Nov 03 - 0:15 ora_qmnc_ORCL
oracle 9830476 1 0 Nov 03 - 0:45 ora_gen0_ORCL
oracle 9896126 1 0 Nov 03 - 28:56 ora_mmnl_ORCL
oracle 10420418 1 0 Nov 03 - 5:12 ora_smon_ORCL
oracle 10551346 1 0 Nov 03 - 21:22 ora_vktm_ORCL
ogg 12976174 38535210 0 Dec 24 - 27:36 oracleORCL (DESCRIPTION=(
oracle 21758094 1 0 Nov 03 - 0:53 ora_smco_ORCL
oracle 24248546 1 0 Nov 03 - 6:53 ora_pmon_ORCL
oracle 24510606 1 0 10:24:07 - 0:00 ora_w000_ORCL
oracle 32112752 1 0 Nov 03 - 0:10 ora_q000_ORCL
ogg 34537590 53870748 0 Dec 21 - 3:33 ./server -w 300 -p 7819-1
oracle 36045024 1 0 Nov 03 - 0:46 oracleORCL (LOCAL=NO)
oracle 36110346 1 0 Nov 03 - 11:20 ora_mmon_ORCL
root 36765756 5898454 0 10:24:04 - 0:00 telnetd -a
ogg 38535210 53870748 0 Dec 24 - 22:19 /ogg/replicat PARAMFILE /
oracle 42729504 1 0 Nov 03 - 0:32 ora_q002_ORCL
oracle 43188338 1 0 Nov 03 - 0:11 ora_reco_ORCL
root 52166842 5898454 0 Aug 10 - 0:00 cmsd 100068 2-5
ogg 53870748 1 0 Jun 06 - 64:11 ./mgr PARAMFILE /ogg/dirp
oracle 54001812 66781186 2 10:32:17 pts/1 0:00 ps -ef
oracle 55836790 1 0 Nov 03 - 0:46 oracleORCL (LOCAL=NO)
root 56557616 5898454 0 10:29:19 - 0:00 telnetd -a
oracle 66781186 56557616 0 10:29:19 pts/1 0:00 -ksh
oracle 5374400 1 0 Nov 03 - 0:41 ora_diag_ORCL
oracle 7143814 36765756 0 10:24:05 pts/0 0:00 -ksh
blade3:/home/oracle$lscfg -vp
INSTALLED RESOURCE LIST WITH VPD
The following resources are installed on your machine.

Model Architecture: chrp
Model Implementation: Multiple Processor, PCI bus
sys0 System Object
sysplanar0 System Planar
vio0 Virtual I/O Bus
vsa0 U8406.71Y.061D64B-V1-C0 LPAR Virtual Serial Adapter
Hardware Location Code......U8406.71Y.061D64B-V1-C0
vty0 U8406.71Y.061D64B-V1-C0-L0 Asynchronous Terminal
pci2 U78A5.001.WIHDF42-P1 PCI Express Bus
Hardware Location Code......U78A5.001.WIHDF42-P1
fcs0 U78A5.001.WIHDF42-P1-C19-T1 8Gb PCIe FC Blade Expansion Card (7710322577107601)
Network Address.............21000024FF439E56
ROS Level and ID............030E050309
Device Specific.(Z0)........00050309
Device Specific.(Z1)........030E0095
Device Specific.(Z2)........49535020
Device Specific.(Z3)........00002532
Device Specific.(Z4)........000E0002
Device Specific.(Z5)........0001000A
Device Specific.(Z6)........00010001
Device Specific.(Z7)........00000000
Device Specific.(Z8)........21000024FF439E56
Device Specific.(Z9)........ISP
Hardware Location Code......U78A5.001.WIHDF42-P1-C19-T1
fscsi0 U78A5.001.WIHDF42-P1-C19-T1 FC SCSI I/O Controller Protocol Device
hdisk1 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L0 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk2 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L1000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk3 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L2000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk4 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L3000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk5 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L4000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk6 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L5000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk7 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L6000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk8 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L7000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk9 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L8000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk10 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-L9000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
hdisk11 U78A5.001.WIHDF42-P1-C19-T1-W500507680210A98A-LA000000000000 MPIO IBM 2076 FC Disk
Manufacturer................IBM
Machine Type and Model......2145
ROS Level and ID............30303030
Serial Number...............2076
Device Specific.(Z0)........0000063268181002
Device Specific.(Z1)........
Device Specific.(Z2)........
Device Specific.(Z3)........
rmt0 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L1000000000000 Other FC SCSI Tape Drive
Manufacturer................IBM
Machine Type and Model......ULT3580-TD3
Serial Number...............
Device Specific.(Z3)........0000
rmt1 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L2000000000000 Other FC SCSI Tape Drive
Manufacturer................IBM
Machine Type and Model......ULT3580-TD3
Serial Number...............
Device Specific.(Z3)........0000
rmt2 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L3000000000000 Other FC SCSI Tape Drive
Manufacturer................IBM
Machine Type and Model......ULT3580-TD3
Serial Number...............
Device Specific.(Z3)........0000
rmt3 U78A5.001.WIHDF42-P1-C19-T1-W21000024FF371E37-L4000000000000 Other FC SCSI Tape Drive
Manufacturer................IBM
Machine Type and Model......ULT3580-TD3
Serial Number...............
Device Specific.(Z3)........0000
fcs1 U78A5.001.WIHDF42-P1-C19-T2 8Gb PCIe FC Blade Expansion Card (7710322577107601)
Network Address.............21000024FF439E57
ROS Level and ID............030E050309
Device Specific.(Z0)........00050309
Device Specific.(Z1)........030E0095
Device Specific.(Z2)........49535020
Device Specific.(Z3)........00002532
Device Specific.(Z4)........000E0002
Device Specific.(Z5)........0001000A
Device Specific.(Z6)........00010001
Device Specific.(Z7)........00000001
Device Specific.(Z8)........21000024FF439E57
Device Specific.(Z9)........ISP
Hardware Location Code......U78A5.001.WIHDF42-P1-C19-T2
fscsi1 U78A5.001.WIHDF42-P1-C19-T2 FC SCSI I/O Controller Protocol Device
pci1 U78A5.001.WIHDF42-P1 PCI Bus
Hardware Location Code......U78A5.001.WIHDF42-P1
usbhc0 U78A5.001.WIHDF42-P1 USB Host Controller (33103500)
Hardware Location Code......U78A5.001.WIHDF42-P1
usbhc1 U78A5.001.WIHDF42-P1 USB Host Controller (33103500)
Hardware Location Code......U78A5.001.WIHDF42-P1
usbhc2 U78A5.001.WIHDF42-P1 USB Enhanced Host Controller (3310e000)
Hardware Location Code......U78A5.001.WIHDF42-P1
pci0 U78A5.001.WIHDF42-P1 PCI Bus
Hardware Location Code......U78A5.001.WIHDF42-P1
sissas0 U78A5.001.WIHDF42-P1-T3 PCI-X266 Planar 3Gb SAS Adapter
ROM Level.(alterable).......04200033
Customer Card ID Number.....57D0
Hardware Location Code......U78A5.001.WIHDF42-P1-T3
sas0 U78A5.001.WIHDF42-P1-T3 Controller SAS Protocol
sfwcomm0 SAS Storage Framework Comm
hdisk0 U78A5.001.WIHDF42-P1-D1 SAS Disk Drive (300000 MB)
Manufacturer................IBM-ESXS
Machine Type and Model......HUC106030CSS60
FRU Number..................42D0628
ROS Level and ID............44333930
Serial Number...............PQHJZLGB
EC Level....................L81062
Part Number.................42D0631
Device Specific.(Z0)........000006329F011002
Device Specific.(Z1)........CDXSA390
Device Specific.(Z2)........00SS
Device Specific.(Z3)........12073
Device Specific.(Z4)........0001
Device Specific.(Z5)........22
Device Specific.(Z6)........L81062
Hardware Location Code......U78A5.001.WIHDF42-P1-D1
ses0 U78A5.001.WIHDF42-P1-Y1 SAS Enclosure Services Device
ROM Level.(alterable)....... 01
Hardware Location Code......U78A5.001.WIHDF42-P1-Y1
sata0 U78A5.001.WIHDF42-P1-T3 Controller SATA Protocol
lhea0 U78A5.001.WIHDF42-P1 Logical Host Ethernet Adapter (l-hea)
Hardware Location Code......U78A5.001.WIHDF42-P1
ent1 U78A5.001.WIHDF42-P1-T5 Logical Host Ethernet Port (lp-hea)
IBM Host Ethernet Adapter:
Network Address.............5CF3FC9F95EB
ent0 U78A5.001.WIHDF42-P1-T4 Logical Host Ethernet Port (lp-hea)
IBM Host Ethernet Adapter:
Network Address.............5CF3FC9F95EA
L2cache0 L2 Cache
mem0 Memory
proc0 Processor
proc4 Processor
proc8 Processor
proc12 Processor
proc16 Processor
proc20 Processor
proc24 Processor
proc28 Processor
PLATFORM SPECIFIC
Name: IBM,8406-71Y
Model: IBM,8406-71Y
Node: /
Device Type: chrp
System VPD:
Record Name.................VSYS
Flag Field..................XXSV
Brand.......................B0
Hardware Location Code......U8406.71Y.061D64B
Machine/Cabinet Serial No...061D64B
Machine Type and Model......8406-71Y
Product Specific.(SG).......FFFFFFF
Product Specific.(TN).......FFFFFFFF
Manufacture ID..............FFFFFFF
Storage Fclty System ID.....FF
System Unique ID (SUID).....0004AC180A5B
World Wide Node Name........FFFFFFFFFFFFFFFF
World Wide Port Name........C050760547D5
Version.....................ipzSeries
Physical Location: U8406.71Y.061D64B
CEC:
Record Name.................VCEN
Flag Field..................XXEV
Brand.......................B0
Hardware Location Code......U78A5.001.WIHDF42
Machine/Cabinet Serial No...WIHDF42
Machine Type and Model......78A5-001
Controlling CEC ID..........8406-71Y 061D64B
Rack Serial Number..........0000000000000000
Feature Code/Marketing ID...78A5-001
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42
SYS BP & 8W PROC:
Record Name.................VINI
Flag Field..................XXBP
Hardware Location Code......U78A5.001.WIHDF42-P1
Customer Card ID Number.....531B
Serial Number...............YL12W2053055
CCIN Extender...............1
Product Specific.(VZ).......01
FRU Number..................46K6798
Part Number.................74Y2720
Power.......................3400800111010000
Product Specific.(HE).......0001
Product Specific.(CT).......40F30001
Product Specific.(HW).......0002
Product Specific.(B3).......000000000001
Product Specific.(B4).......00
Product Specific.(B5).......
Product Specific.(B6).......
Product Specific.(B7).......000000000000000000000000
Product Specific.(B1).......5CF3FC9F95EA0010
Product Specific.(BS).........
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1
Memory DIMM:
Record Name.................VINI
Flag Field..................XXMS
Hardware Location Code......U78A5.001.WIHDF42-P1-C1
Customer Card ID Number.....322C
Serial Number...............YLD000F4C763
CCIN Extender...............1
Product Specific.(VZ).......03
FRU Number..................77P8692
Part Number.................77P8692
Power.......................4800000000010000
Size........................8192
Product Specific.(HE).......0001
Product Specific.(CT).......10210004
Product Specific.(HW).......0001
Product Specific.(B3).......030000000001
Product Specific.(B4).......00
Product Specific.(B7).......000000000000000000000000
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1-C1
Memory DIMM:
Record Name.................VINI
Flag Field..................XXMS
Hardware Location Code......U78A5.001.WIHDF42-P1-C3
Customer Card ID Number.....322C
Serial Number...............YLD001F4C762
CCIN Extender...............1
Product Specific.(VZ).......03
FRU Number..................77P8692
Part Number.................77P8692
Power.......................4800000000010000
Size........................8192
Product Specific.(HE).......0001
Product Specific.(CT).......10210004
Product Specific.(HW).......0001
Product Specific.(B3).......030000000001
Product Specific.(B4).......00
Product Specific.(B7).......000000000000000000000000
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1-C3
Memory DIMM:
Record Name.................VINI
Flag Field..................XXMS
Hardware Location Code......U78A5.001.WIHDF42-P1-C14
Customer Card ID Number.....322C
Serial Number...............YLD002F4C703
CCIN Extender...............1
Product Specific.(VZ).......03
FRU Number..................77P8692
Part Number.................77P8692
Power.......................4800000000010000
Size........................8192
Product Specific.(HE).......0001
Product Specific.(CT).......10210004
Product Specific.(HW).......0001
Product Specific.(B3).......030000000001
Product Specific.(B4).......00
Product Specific.(B7).......000000000000000000000000
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1-C14
Memory DIMM:
Record Name.................VINI
Flag Field..................XXMS
Hardware Location Code......U78A5.001.WIHDF42-P1-C16
Customer Card ID Number.....322C
Serial Number...............YLD003F4C701
CCIN Extender...............1
Product Specific.(VZ).......03
FRU Number..................77P8692
Part Number.................77P8692
Power.......................4800000000010000
Size........................8192
Product Specific.(HE).......0001
Product Specific.(CT).......10210004
Product Specific.(HW).......0001
Product Specific.(B3).......030000000001
Product Specific.(B4).......00
Product Specific.(B7).......000000000000000000000000
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1-C16
ANCHOR / RISER :
Record Name.................VINI
Flag Field..................XXAV
Hardware Location Code......U78A5.001.WIHDF42-P1-C17
Customer Card ID Number.....52C2
Serial Number...............YL10WC249003
CCIN Extender...............1
Product Specific.(VZ).......01
FRU Number..................46K7374
Part Number.................74Y2102
Power.......................8100008000000000
Product Specific.(HE).......0010
Product Specific.(CT).......40B40001
Product Specific.(HW).......0001
Product Specific.(B3).......000000000001
Product Specific.(B4).......00
Product Specific.(B7).......000000000000000000000000
Product Specific.(B9).......435321000035040A39825350FCAFD6CB55FC0CB24D
31AE1B7B1E764250154D328EC4BB27AA96107C4D33
D81BCF1F2D6899944D345CFAD780AE21561E
Version.....................ipzSeries
Physical Location: U78A5.001.WIHDF42-P1-C17
Fibre Channel Expansion Card :
Record Name.................VINI
Flag Field..................XXDT
Hardware Location Code......U78A5.001.WIHDF42-P1-C19
FRU Number..................44X1948
Part Number.................44X1947
Serial Number...............YK5022231Z06
Product Specific.(VZ).........
Product Specific.(HW).......01
Product Specific.(B1).......000000000000000000000000000000000000000000
000000000000000000000000000000000000000000
000000000000
Version.....................xSeries
Physical Location: U78A5.001.WIHDF42-P1-C19
System Firmware:
Code Level, LID Keyword.....Phyp_1 10102012030680A00701
Code Level, LID Keyword.....PFW 16442012022981CF0681
Code Level, LID Keyword.....FSP_Ker 09222012030781E00100
Code Level, LID Keyword.....FSP_Fil 09222012030781E00109
Code Level, LID Keyword.....FipS_BU 09232012030781E00208
Code Level, LID Keyword.....Phyp_2 10102012030685A00702
Microcode Image.............AA730_078 AA730_078 AA730_078
Hardware Location Code......U8406.71Y.061D64B-Y1
Physical Location: U8406.71Y.061D64B-Y1
Name: openprom
Model: IBM,AA730_078
Node: openprom
Name: interrupt-controller
Model: IBM, Logical PowerPC-PIC, 00
Node: interrupt-controller@0
Device Type: PowerPC-External-Interrupt-Presentation
Name: interrupt-controller
Model: IBM,Logical PHB
Node: interrupt-controller@800000025000208
Device Type: PowerPC-LSI-Source
Physical Location: U78A5.001.WIHDF42-P1
Name: interrupt-controller
Model: IBM,Logical PHB
Node: interrupt-controller@800000025000209
Device Type: PowerPC-LSI-Source
Physical Location: U78A5.001.WIHDF42-P1
Name: interrupt-controller
Model: IBM,Logical PHB
Node: interrupt-controller@80000002500020e
Device Type: PowerPC-LSI-Source
Physical Location: U78A5.001.WIHDF42-P1
Name: lhea
Node: lhea@200000001000000
Physical Location: U78A5.001.WIHDF42-P1
Name: pci
Model: IBM,Logical_PHB
Node: pci@800000020000208
Physical Location: U78A5.001.WIHDF42-P1
Name: pci
Model: IBM,Logical_PHB
Node: pci@800000020000209
Physical Location: U78A5.001.WIHDF42-P1
Name: pci
Model: IBM,Logical_PHB
Node: pci@80000002000020e
Device Type: pciex
Physical Location: U78A5.001.WIHDF42-P1
Name: vty
Node: vty@30000000
Device Type: serial
Physical Location: U8406.71Y.061D64B-V1-C0
Name: ethernet
Node: ethernet@200000001000001
Device Type: network
Physical Location: U78A5.001.WIHDF42-P1-T4
Name: ethernet
Node: ethernet@200000001000002
Device Type: network
Physical Location: U78A5.001.WIHDF42-P1-T5
Name: pci1014,02BD
Node: pci1014,02BD@1
Physical Location: U78A5.001.WIHDF42-P1-T3
Name: usb
Node: usb@1
Physical Location: U78A5.001.WIHDF42-P1
Name: usb
Node: usb@1,1
Physical Location: U78A5.001.WIHDF42-P1
Name: usb
Node: usb@1,2
Physical Location: U78A5.001.WIHDF42-P1
Name: fibre-channel
Model: QMI2582
Node: fibre-channel@0
Device Type: fcp
Physical Location: U78A5.001.WIHDF42-P1-C19-T1
Name: fibre-channel
Model: QMI2582
Node: fibre-channel@0,1
Device Type: fcp
Physical Location: U78A5.001.WIHDF42-P1-C19-T2
Name: hub
Node: hub@1
Physical Location: U78A5.001.WIHDF42-P1
Name: hub
Node: hub@1
Physical Location:
Name: hub
Node: hub@1
Physical Location: U78A5.001.WIHDF42-P1

修复方案:

1.修改弱口令;
2.安全基线配置加固;
3.对相关人员进行安全意识培训;
4.IDC,你比我懂。。。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:8

确认时间:2016-01-08 15:48

厂商回复:

CNVD确认并复现所述漏洞情况,已经转由CNCERT下发给上海分中心,由上海分中心后续协调网站管理单位处置。

最新状态:

暂无