当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0167170

漏洞标题:某市城乡建设局全市建设行业信息化系统服务器存在多个漏洞,并getshell

相关厂商:cncert国家互联网应急中心

漏洞作者: 朱元璋

提交时间:2016-01-05 23:30

修复时间:2016-02-22 17:50

公开时间:2016-02-22 17:50

漏洞类型:系统/服务补丁不及时

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-05: 细节已通知厂商并且等待厂商处理中
2016-01-08: 厂商已经确认,细节仅向厂商公开
2016-01-18: 细节向核心白帽子及相关领域专家公开
2016-01-28: 细节向普通白帽子公开
2016-02-07: 细节向实习白帽子公开
2016-02-22: 细节向公众公开

简要描述:

RT

详细说明:

打开官网http://**.**.**.**/,图中链接存在多个漏洞

0.png


00.png


**.**.**.**:7001/存在“Java 反序列化”漏洞

01.png


**.**.**.**:7001/tendererSystem/tenderer/bid!wwZbGgList.action存在struts2 S2-019漏洞

02.png


直接上传木马到服务器中

03.png


insert into  aaa (Client_Name,Client_Id,Zb_Gc_Id) values 	('黑龙江八一农垦大学' , '44815FB006DB11E29FB0A3FB487E1972' , 'e65f71372a8745b2b20d8d4c86de5df9');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆市人民医院' , '2c9082e845885e3f0145968edfa65477' , 'b9dee33293ec4e2fab189ba3865b85ca');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆创业广场有限责任公司' , 'E340FFD0D4C111E1BFD0E4EE0AE2884A' , '753229aeaf864e4f84e13b2f86577b22');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新汽车工业园有限责任公司' , '2c9082384c357bc0014c36b5c6801162' , '215b98a59b45461e98ccdd9528fe1889');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新汽车工业园有限责任公司' , '2c9082384c357bc0014c36b5c6801162' , '3f36243c98064b00860617ed3e95c9f2');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新汽车工业园有限责任公司' , '2c9082384c357bc0014c36b5c6801162' , 'e0816c0de5034bda8e32b2f5a9d89c3a');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新技术产业开发区管理委员会规划建设局' , '162207C0AAF311E2A8F4A8367E6C2FA6' , 'db0756525f4d4acea40b01339b3c64db');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新区兴化园区管理委员会' , '4C8695B0CCBD11E295B0FA11FD10F2FF' , 'a73f33448c09472688150357e736931e');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆经济技术开发区管理委员会' , '786682B0FB7E11E082B0915FF809AA1A' , '00f4c2e08e66461fabdb5621d69165e0');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新技术产业开发区管理委员会城市管理局' , '82AA9820AAEF11E2A8F495C46E7AC945' , '517a0070fdda4335a1a241b7c81e5e77');
insert into aaa (Client_Name,Client_Id,Zb_Gc_Id) values ('大庆高新汽车工业园有限责任公司' , '2c9082384c357bc0014c36b5c6801162' , '84ca3e557c3a40b58f6834b5337cdba4');
insert into bbb (bd_id,time_limit) values ('30e7150882eb40379f0f893415de0ac0' , '2013-09-19 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('092bb9fe64034a4c9a2cbc42ca7b76fd' , '2013-08-20 至 2013-10-31');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e014152cec8ae0047' , '2013-10-14 至 2013-12-31');
insert into bbb (bd_id,time_limit) values ('b6bf9376900748719c2dc442036477f2' , '2013-10-22 至 2015-10-30');
insert into bbb (bd_id,time_limit) values ('15c84d5da4b34ad4beda79d93d809df7' , '2014-04-01 至 2015-06-20');
insert into bbb (bd_id,time_limit) values ('ebd54467fc1146da99137f58f8f9ba21' , '2014-05-14 至 2016-08-29');
insert into bbb (bd_id,time_limit) values ('0e419ecc95ae4c7da31762af36b576ba' , '2014-05-14 至 2016-08-29');
insert into bbb (bd_id,time_limit) values ('8a90ce44436638c601446ccceb4f0059' , '2014-05-24 至 2014-08-24');
insert into bbb (bd_id,time_limit) values ('604b6b0109644481a996f2db023b0ded' , '2014-05-24 至 2016-08-30');
insert into bbb (bd_id,time_limit) values ('2db73411a18e491e9c868eddf1969a77' , '2014-06-12 至 2015-03-30');
insert into bbb (bd_id,time_limit) values ('c3fc02652e0c443d81a9da216f793b16' , '2014-06-20 至 2015-08-25');
insert into bbb (bd_id,time_limit) values ('04b2c0c207b04cb0b646572799857647' , '2014-07-15 至 2015-10-31');
insert into bbb (bd_id,time_limit) values ('4c6f15bb648446c6ba8c7db4fb85b1c4' , '2014-07-15 至 2015-10-31');
insert into bbb (bd_id,time_limit) values ('69d43b30f2d84c0e90ac458077f72ece' , '2014-07-20 至 2014-11-15');
insert into bbb (bd_id,time_limit) values ('8a90ce4446d7031501471a212ac6008c' , '2014-07-22 至 2014-09-30');
insert into bbb (bd_id,time_limit) values ('8a90ce444780f9de01478a30d1b90015' , '2014-08-14 至 2014-09-05');
insert into bbb (bd_id,time_limit) values ('16bb71b0a3e74bc2a1b2a7cd7a4be2b9' , ' 至 中标结果公示期满后20日内完成');
insert into bbb (bd_id,time_limit) values ('8a90ce44483f2c54014868e173500054' , '2014-09-29 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('e3405a18ac584ec3927e4de3dcea66d6' , '2014-10-18 至 2015-10-30');
insert into bbb (bd_id,time_limit) values ('f3541c115bc644fb9cb7da11b8d473c9' , '2014-10-18 至 2014-11-15');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148ed8e40d4006d' , '2014-10-21 至 2014-11-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148baf95c5a004f' , '2014-10-21 至 2016-06-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148baf7ffdd004e' , '2014-10-21 至 2016-06-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148f7b680e0009c' , '2014-10-23 至 2014-11-15');
insert into bbb (bd_id,time_limit) values ('3191020f95fb4d88bdf429ed796049bc' , '2014-11-04 至 2015-08-01');
insert into bbb (bd_id,time_limit) values ('6fdcd92527554e149fc2ce8286dd0431' , '2015-04-15 至 2015-05-30');
insert into bbb (bd_id,time_limit) values ('f7794b2f25404f23a23825af339ca85a' , ' 60 ');
insert into bbb (bd_id,time_limit) values ('a8429c29b62a4a5fb066b838355361cd' , '2015-04-15 至 2015-05-30');
insert into bbb (bd_id,time_limit) values ('aef0338e672e478cbe68f77d4e6040e0' , '2013-07-30 至 2013-12-31');
insert into bbb (bd_id,time_limit) values ('e2620f2fc21d49b9a2997ef131685274' , '2013-07-30 至 2013-09-10');
insert into bbb (bd_id,time_limit) values ('a1336f2b14d24d62b4afeee2ea955378' , '2013-08-06 至 2013-09-30');
insert into bbb (bd_id,time_limit) values ('c8d7ccc935dd486e88e34621db75d1aa' , '2013-09-06 至 2013-12-25');
insert into bbb (bd_id,time_limit) values ('8a90ce44410fe72901411165042d0014' , '2013-09-26 至 2013-11-20');
insert into bbb (bd_id,time_limit) values ('8a90ce4440dd768401410b1bab2d006d' , '2013-09-25 至 2013-11-15');
insert into bbb (bd_id,time_limit) values ('8a90ce44410fe72901412aa9eebc00a5' , '2013-10-01 至 2013-10-30');
insert into bbb (bd_id,time_limit) values ('973e5342f1e94fd087da69afa8272a4e' , '2013-10-18 至 2013-11-30');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141b4a602760117' , '2013-10-26 至 2014-11-30');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141bef170a1014c' , '2013-10-29 至 2015-10-30');
insert into bbb (bd_id,time_limit) values ('785fb182098d432fae832faa3fdf2969' , '2013-12-11 至 2014-03-30');
insert into bbb (bd_id,time_limit) values ('492f661fd3d74179a25a781ab6352345' , '2013-12-20 至 2014-08-30');
insert into bbb (bd_id,time_limit) values ('0ddd9d6f937f4ac69a17933026334916' , '2014-02-08 至 2014-03-20');
insert into bbb (bd_id,time_limit) values ('3dd0ea929f3a40cd8f33763078b7d029' , '2014-03-01 至 2014-09-30');
insert into bbb (bd_id,time_limit) values ('09f2101d1155438bba8ef08748674bf6' , '2014-03-25 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('4ca3bfd06dc14f66825c7fabf5636e6c' , '2014-03-29 至 2014-12-31');
insert into bbb (bd_id,time_limit) values ('26624ce99e00481d90b77627cc79dab6' , '2014-05-06 至 2014-06-21');
insert into bbb (bd_id,time_limit) values ('5df13b34b972425bbc5bd60e73403662' , '2014-05-27 至 2014-08-30');
insert into bbb (bd_id,time_limit) values ('a22de579c47e455f9b84ac36eeda9b17' , '2014-06-04 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('87ab87d0a58146b5a866aca4a031c272' , '2014-06-04 至 2014-08-30');
insert into bbb (bd_id,time_limit) values ('528ca010a169499a9cbdcd590388f018' , '2014-06-05 至 2015-03-30');
insert into bbb (bd_id,time_limit) values ('da799b959c5b4d59ae7b0bf24b7d2791' , '2014-06-11 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('b184a201aef449bbbc65068a0d86f90e' , '2014-06-12 至 2015-03-30');
insert into bbb (bd_id,time_limit) values ('8a90ce44454a3f040145a6802670002c' , '2014-06-13 至 2014-08-13');
insert into bbb (bd_id,time_limit) values ('8a90ce44462d1c7401466b216c830073' , '2014-06-18 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('fe092faf58ca4088ad86d5c70f8a8162' , '中标结果公示期满后15日内完成');
insert into bbb (bd_id,time_limit) values ('30580b6893ab42b0a125683b086a3d5f' , '2014-07-30 至 2014-09-30');
insert into bbb (bd_id,time_limit) values ('f20372a0ba3f4d03a3df53cd633dcf00' , '2013-07-30 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('f561379b929f4d54a95a157a2162f10c' , '2013-07-30 至 2013-10-30');
insert into bbb (bd_id,time_limit) values ('acf770432d59436fbc986769840f47bf' , '2013-08-20 至 2013-11-02');
insert into bbb (bd_id,time_limit) values ('8a90ce444013c8c301405845577e0076' , '2013-08-21 至 2014-07-01');
insert into bbb (bd_id,time_limit) values ('498ab6d73c584d5ca5ffe813f1c12489' , '2013-09-10 至 2013-11-10');
insert into bbb (bd_id,time_limit) values ('df0f480393664d41a7744e70b028f242' , '2013-09-11 至 2013-10-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4440b085350140c7ce3fa8000c' , '2013-09-11 至 2013-11-30');
insert into bbb (bd_id,time_limit) values ('ed9d7f75f8904d2db2cef592c8df4420' , '2013-09-19 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4440dd76840140f0fd0cfd005a' , '2013-09-19 至 2013-11-15');
insert into bbb (bd_id,time_limit) values ('bdc9a9825bba4301a21cf25d8ae6dbb9' , '2013-09-19 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e014157e889dd0069' , '2013-10-15 至 2016-06-30');
insert into bbb (bd_id,time_limit) values ('ac95bdddfba64a15bc385b751c1095f1' , '2013-10-19 至 2015-07-31');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141dddf364e019f' , '2013-11-02 至 2015-07-31');
insert into bbb (bd_id,time_limit) values ('8a90ce4442da08800142df6b4ec90002' , '2014-04-15 至 2014-05-15');
insert into bbb (bd_id,time_limit) values ('0233c841998b46fea15b87a28907089f' , '2014-01-06 至 2015-07-30');
insert into bbb (bd_id,time_limit) values ('b4ab43652c784b9e99f260f37196e937' , '2014-04-01 至 2015-06-20');
insert into bbb (bd_id,time_limit) values ('8a90ce4443286c96014356bc1307002a' , '2014-03-11 至 2015-07-30');
insert into bbb (bd_id,time_limit) values ('3c0c1d1a6bdb4ea1a2bc5af01ae55680' , '2014-03-25 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('8a90ce44436638c60144f72cb8350141' , '2014-04-04 至 2014-12-31');
insert into bbb (bd_id,time_limit) values ('8a90ce44436638c60144d9700d9200f4' , '2014-04-04 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4444fd397d014517314c9b0064' , '2014-04-12 至 2014-07-15');
insert into bbb (bd_id,time_limit) values ('843d2ff27e0142eba2f49d1415e7f42d' , '2014-07-15 至 2015-10-31');
insert into bbb (bd_id,time_limit) values ('8e4fceb0a4884aed894acde4a36bc160' , '中标结果公示期满后15日内完成');
insert into bbb (bd_id,time_limit) values ('e3c9dde3e9be4c4380b2c876e9c192d4' , '2014-07-31 至 2014-09-25');
insert into bbb (bd_id,time_limit) values ('8a90ce44473e0a8e01475cdf68d50038' , '2014-08-02 至 2014-12-31');
insert into bbb (bd_id,time_limit) values ('dee1a2f5381840f99fc99a81eee75b8a' , '2014-08-10 至 2014-10-31');
insert into bbb (bd_id,time_limit) values ('e44df930ad0046ddac2403412f4fa5b1' , '2014-08-13 至 2015-01-30');
insert into bbb (bd_id,time_limit) values ('1e998095d24d41c3bf20b053878abe81' , '2013-08-14 至 2013-09-30');
insert into bbb (bd_id,time_limit) values ('d58e6d43270e4839baef87376c0e2f1d' , '2013-08-08 至 2013-09-30');
insert into bbb (bd_id,time_limit) values ('d1082dfd51ee4fb5aea85b3f95cc8b50' , '2013-10-19 至 2015-07-15');
insert into bbb (bd_id,time_limit) values ('c41adbe62732482e8cf37d756152aad0' , '2013-10-23 至 2013-11-15');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141a0013b9b0105' , '2013-10-26 至 2014-11-30');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141dde0500501a0' , '2013-11-02 至 2015-07-31');
insert into bbb (bd_id,time_limit) values ('8a90ce44420d9143014211bc001b0005' , '2013-11-14 至 2013-12-31');
insert into bbb (bd_id,time_limit) values ('8a90ce444212ae9801427e61855e006a' , '2013-12-05 至 2013-12-31');
insert into bbb (bd_id,time_limit) values ('26a598af409a45feac4c876bae674528' , '2013-12-11 至 2014-03-30');
insert into bbb (bd_id,time_limit) values ('284f1ae4ee054a25851d1ffbbdc535cd' , '2013-12-13 至 2014-05-13');
insert into bbb (bd_id,time_limit) values ('db8b6bebb811402e8d7a3fb50a3e68d5' , '2014-06-05 至 2015-03-30');
insert into bbb (bd_id,time_limit) values ('71814eaf809b4a45b1ac159727885024' , '2014-06-13 至 2014-08-13');
insert into bbb (bd_id,time_limit) values ('9c8c981789a442cb9415ea432b6dcaf4' , '2014-06-20 至 2014-08-31');
insert into bbb (bd_id,time_limit) values ('f8383b78c0a24d89a5bc18274b7ef6fb' , '2014-08-06 至 2014-09-26');
insert into bbb (bd_id,time_limit) values ('c7d1fb5c9c0c40a78d97f6ef89a29026' , '2014-08-10 至 2014-10-31');
insert into bbb (bd_id,time_limit) values ('b2b6f53a62224894a65ea879bef1d207' , '2014-08-13 至 2015-01-30');
insert into bbb (bd_id,time_limit) values ('c9df70432df143b09160899251ee778d' , '2014-08-12 至 2015-08-01');
insert into bbb (bd_id,time_limit) values ('8a90ce444780f9de01478b2da60e0024' , '2014-08-13 至 2014-09-30');
insert into bbb (bd_id,time_limit) values ('4dc1fd255dc94445933785fc4d532081' , '2014-08-18 至 2016-10-30');
insert into bbb (bd_id,time_limit) values ('7ad322e0045640959903e2d44a420e1e' , ' 2014年8月20至2014年9月20日 ');
insert into bbb (bd_id,time_limit) values ('8a90ce4447a03e520147a3d298210019' , '2014-08-19 至 2014-09-03');
insert into bbb (bd_id,time_limit) values ('f4de6980d1474613bb240e3402d74690' , '2014-08-21 至 2015-07-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4447aef19f0147c2be78d4003b' , '2014-08-23 至 2014-10-15');
insert into bbb (bd_id,time_limit) values ('8a90ce4447aef19f0147c82de2c6005c' , '2014-08-26 至 2016-10-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4447aef19f0147d8487b3900d2' , '2014-08-28 至 2015-07-30');
insert into bbb (bd_id,time_limit) values ('a1f96e6d12d443e99703b3d0959f6a5a' , '2014-09-11 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('0475d0d247444ea8aa9df886404b59de' , '2014-09-16 至 2014-10-10');
insert into bbb (bd_id,time_limit) values ('dbf4f4f740334f81a7374f20fd5da943' , '2013-09-19 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('0b153d39c3334d529a87527d9cfbe29c' , '2013-09-17 至 2013-11-15');
insert into bbb (bd_id,time_limit) values ('bd803070ca154fc690701a4a9d691133' , '2013-09-19 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('a6cb0eaeeac348d4ada00700f604a23d' , '2013-09-24 至 2013-11-15');
insert into bbb (bd_id,time_limit) values ('8a90ce444143291e0141678bd07c0075' , '2013-10-15 至 2013-11-30');
insert into bbb (bd_id,time_limit) values ('b844f96e90d24a809d1b37313a3a53f1' , '2013-11-20 至 2014-06-30');
insert into bbb (bd_id,time_limit) values ('2b262ca2447543ce9e6cbce663737e65' , '2013-12-20 至 2014-08-30');
insert into bbb (bd_id,time_limit) values ('10239deab2cb4c56836f9207606788fa' , '2013-12-20 至 2015-07-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4442a243280142c6d726ab0058' , '2013-12-19 至 2014-05-30');
insert into bbb (bd_id,time_limit) values ('fa2acd4206ab4d9db78d02dfc1631874' , '2014-04-11 至 2014-07-15');
insert into bbb (bd_id,time_limit) values ('d1e8d6fb7416475da9f8ece3b2c983be' , '2014-05-17 至 2014-12-30');
insert into bbb (bd_id,time_limit) values ('05fcae49053345eb9d5b568b32cf07a2' , '2014-05-24 至 2016-08-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4445f857410145f86cb9060002' , '2014-05-27 至 2014-07-15');
insert into bbb (bd_id,time_limit) values ('8a90ce44468a3e3e0146a2baad610053' , '2014-06-27 至 2015-08-25');
insert into bbb (bd_id,time_limit) values ('8a90ce44468a3e3e0146b2072ef1008c' , '2014-07-02 至 2014-08-20');
insert into bbb (bd_id,time_limit) values ('8a90ce4446d703150147139d5c670053' , '2014-07-26 至 2014-12-31');
insert into bbb (bd_id,time_limit) values ('8a90ce444780f9de014790e3607b0052' , '2014-08-14 至 2014-10-30');
insert into bbb (bd_id,time_limit) values ('7cf7920b29d3465f8668fa0a75d233a8' , '2014-08-16 至 2014-10-15');
insert into bbb (bd_id,time_limit) values ('2fec93785c0646d1afcaf156e3042343' , '2014-08-16 至 2014-09-30');
insert into bbb (bd_id,time_limit) values ('8a90ce44483f2c540148625bfe77002b' , '2014-09-24 至 2014-10-25');
insert into bbb (bd_id,time_limit) values ('18fe7be7a34142d69d192ceab74873cc' , '2014-10-08 至 2014-11-20');
insert into bbb (bd_id,time_limit) values ('8a90ce44486c7181014886edbed8001c' , '2014-09-30 至 2014-10-31');
insert into bbb (bd_id,time_limit) values ('8a90ce44486c718101488799facc0029' , '2014-09-30 至 2014-10-31');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148aaac25c70005' , '2014-10-13 至 2015-08-30');
insert into bbb (bd_id,time_limit) values ('8a90ce4448a742fe0148aaab40f00003' , '2014-10-13 至 2015-08-30');
insert into bbb (bd_id,time_limit) values ('8a90ce44486c71810148a55ef6760074' , '2014-10-15 至 2014-11-15');
insert into bbb (bd_id,time_limit) values ('1f87aed2b51e4b29a189627f3eb86535' , '2015-05-30 至 2015-09-30');
insert into bbb (bd_id,time_limit) values ('a84735349207493cb8325470920a35c7' , '2015-06-15 至 2015-11-30');
insert into bbb (bd_id,time_limit) values ('f1db6b8491f148aabcfd2149bccc5749' , '自中标结果公示期满起30天内完成方案设计、初步设计和施工图设计。');
insert into bbb (bd_id,time_limit) values ('8a90ce444cd5bbfc014cdedb7ce3000a' , '2015-06-10 至 2015-08-10');
insert into bbb (bd_id,time_limit) values ('6dc86261d4544da3b1ea7e3a17ea20c0' , '2015-06-10 至 2015-07-20');
insert into bbb (bd_id,time_limit) values ('78cb1606eb794a8a9868f2020aff464b' , '2015-06-10 至 2015-09-30');
insert into bbb (bd_id,time_limit) values ('7ccf10b1710c4a389ba13c84ba2d2c7e' , '2015-05-09 至 2015-12-31');
insert into bbb (bd_id,time_limit) values ('6e3dd6a3e42c43c08f3d86e06f0ec87e' , '2015-06-20 至 2015-08-30');
insert into bbb (bd_id,time_limit) values ('d66dc6d395a24e92bcca95dc9321ee57' , '2015-05-21 至 2015-10-30');

漏洞证明:

F:\weblogic server\tendererSystem\tendererSystem>whoami
============================================================================================================r
lenovo-kv9ta50h\administrator
F:\weblogic server\tendererSystem\tendererSystem>net user
============================================================================================================r
\\LENOVO-KV9TA50H µÄÓû§ÕÊ»§
-------------------------------------------------------------------------------
Administrator Guest guoyp
wangmy xuhy
ÃüÁî³É¹¦Íê³É¡£
F:\weblogic server\tendererSystem\tendererSystem>net view
============================================================================================================r
·þÎñÆ÷Ãû³Æ ×¢½â
-------------------------------------------------------------------------------
\\2011-20110929SA
\\2013-1115-1402
\\2015-0910-0938
\\LENOVO-2H3GC7C1
\\LENOVO-6HQI6JE0
\\LENOVO-FAD09C6D
\\LENOVO-KV9TA50H
\\LENOVO-XSU53O40
\\PC-201108251449
\\XL-20130618AMPU
\\XL-20130618HVUJ
\\XL-20130618VOLT
\\XL-20130618ZOGG
\\ÓÚÊÀÈý-PC
\\ÆÀ±êÊÒ7
ÃüÁî³É¹¦Íê³É¡£
F:\weblogic server\tendererSystem\tendererSystem>net share
============================================================================================================r
¹²ÏíÃû ×ÊÔ´ ×¢½â
-------------------------------------------------------------------------------
ADMIN$ C:\Windows Ô¶³Ì¹ÜÀí
C$ C:\ ĬÈϹ²Ïí
D$ D:\ ĬÈϹ²Ïí
IPC$ Ô¶³Ì IPC
E$ E:\ ĬÈϹ²Ïí
H$ H:\ ĬÈϹ²Ïí
F$ F:\ ĬÈϹ²Ïí
G$ G:\ ĬÈϹ²Ïí
E E:\
F F:\
soft F:\soft
tem D:\bid\tem
weblogic server
F:\weblogic server
ÅäÖÃÎļþ 127 D:\ÅäÖÃÎļþ 127
ÃüÁî³É¹¦Íê³É¡£
F:\weblogic server\tendererSystem\tendererSystem>net start
============================================================================================================r
ÒѾ­Æô¶¯ÒÔÏ Windows ·þÎñ:
Application Host Helper Service
Background Intelligent Transfer Service
Base Filtering Engine
Certificate Propagation
COM+ Event System
Cryptographic Services
DCOM Server Process Launcher
Desktop Window Manager Session Manager
DHCP Client
Diagnostic Policy Service
Distributed Link Tracking Client
Distributed Transaction Coordinator
DNS Client
Google ¸üзþÎñ (gupdate)
Group Policy Client
IIS Admin Service
IKE and AuthIP IPsec Keying Modules
IP Helper
IPsec Policy Agent
Microsoft Antimalware Service
Microsoft FTP Service
Microsoft iSCSI Initiator Service
Network Connections
Network List Service
Network Location Awareness
Network Store Interface Service
OracleOraDb11g_home1TNSListener
OracleServiceORCL
Plug and Play
Power
Print Spooler
QQPCMgr RTP Service
Remote Desktop Configuration
Remote Desktop Services
Remote Desktop Services UserMode Port Redirector
Remote Procedure Call (RPC)
Remote Registry
RPC Endpoint Mapper
Security Accounts Manager
Server
Shell Hardware Detection
Software Protection
System Event Notification Service
TAOFrame
Task Scheduler
TCP/IP NetBIOS Helper
TeamViewer 9
User Profile Service
Virtual Disk
Windows Event Log
Windows Firewall
Windows Font Cache Service
Windows Management Instrumentation
Windows Modules Installer
Windows Process Activation Service
Windows Remote Management (WS-Management)
Windows Time
Windows Update
WinHTTP Web Proxy Auto-Discovery Service
Workstation
World Wide Web Publishing Service
ÃüÁî³É¹¦Íê³É¡£
F:\weblogic server\tendererSystem\tendererSystem>netstat -ano
============================================================================================================r
»î¶¯Á¬½Ó
ЭÒé ±¾µØµØÖ· ÍⲿµØÖ· ״̬ PID
TCP **.**.**.**:80 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:135 **.**.**.**:0 LISTENING 868
TCP **.**.**.**:445 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:1521 **.**.**.**:0 LISTENING 10036
TCP **.**.**.**:3389 **.**.**.**:0 LISTENING 5944
TCP **.**.**.**:6666 **.**.**.**:0 LISTENING 3924
TCP **.**.**.**:8885 **.**.**.**:0 LISTENING 3924
TCP **.**.**.**:47001 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:49152 **.**.**.**:0 LISTENING 948
TCP **.**.**.**:49153 **.**.**.**:0 LISTENING 484
TCP **.**.**.**:49154 **.**.**.**:0 LISTENING 1304
TCP **.**.**.**:49157 **.**.**.**:0 LISTENING 1352
TCP **.**.**.**:49185 **.**.**.**:0 LISTENING 464
TCP **.**.**.**:49187 **.**.**.**:0 LISTENING 6076
TCP **.**.**.**:54167 **.**.**.**:0 LISTENING 9768
TCP **.**.**.**:139 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:7001 **.**.**.**:0 LISTENING 5032
TCP **.**.**.**:49407 **.**.**.**:3260 ESTABLISHED 4
TCP **.**.**.**:139 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:212 **.**.**.**:0 LISTENING 3924
TCP **.**.**.**:7001 **.**.**.**:0 LISTENING 5032
TCP **.**.**.**:7001 **.**.**.**:61815 FIN_WAIT_1 5032
TCP **.**.**.**:7001 **.**.**.**:61860 FIN_WAIT_1 5032
TCP **.**.**.**:61815 **.**.**.**:7001 ESTABLISHED 5032
TCP **.**.**.**:61860 **.**.**.**:7001 ESTABLISHED 5032
TCP **.**.**.**:62022 **.**.**.**:139 TIME_WAIT 0
TCP **.**.**.**:62030 **.**.**.**:7001 TIME_WAIT 0
TCP **.**.**.**:62034 **.**.**.**:443 SYN_SENT 5804
TCP **.**.**.**:62035 **.**.**.**:443 SYN_SENT 5804
TCP **.**.**.**:1521 **.**.**.**:51115 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:52034 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:52348 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:54213 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:54833 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:55642 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:58132 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:58316 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:58535 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:59043 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:59540 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:59542 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:60086 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:60576 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:61007 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:61352 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:62351 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:64386 ESTABLISHED 10036
TCP **.**.**.**:1521 **.**.**.**:64979 ESTABLISHED 10036
TCP **.**.**.**:5939 **.**.**.**:0 LISTENING 2684
TCP **.**.**.**:5939 **.**.**.**:49179 ESTABLISHED 2684
TCP **.**.**.**:7001 **.**.**.**:0 LISTENING 5032
TCP **.**.**.**:7085 **.**.**.**:0 LISTENING 3924
TCP **.**.**.**:49179 **.**.**.**:5939 ESTABLISHED 5252
TCP **.**.**.**:51115 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:52034 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:52348 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:54159 **.**.**.**:0 LISTENING 10036
TCP **.**.**.**:54213 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:54833 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:55642 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:58132 **.**.**.**:1521 ESTABLISHED 9276
TCP **.**.**.**:58316 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:58535 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:59043 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:59540 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:59542 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:60086 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:60576 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:61007 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:61352 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:61960 **.**.**.**:61961 ESTABLISHED 3924
TCP **.**.**.**:61961 **.**.**.**:61960 ESTABLISHED 3924
TCP **.**.**.**:61962 **.**.**.**:61963 ESTABLISHED 3924
TCP **.**.**.**:61963 **.**.**.**:61962 ESTABLISHED 3924
TCP **.**.**.**:61964 **.**.**.**:61965 ESTABLISHED 3924
TCP **.**.**.**:61965 **.**.**.**:61964 ESTABLISHED 3924
TCP **.**.**.**:61966 **.**.**.**:61967 ESTABLISHED 3924
TCP **.**.**.**:61967 **.**.**.**:61966 ESTABLISHED 3924
TCP **.**.**.**:61968 **.**.**.**:61969 ESTABLISHED 3924
TCP **.**.**.**:61969 **.**.**.**:61968 ESTABLISHED 3924
TCP **.**.**.**:61970 **.**.**.**:61971 ESTABLISHED 3924
TCP **.**.**.**:61971 **.**.**.**:61970 ESTABLISHED 3924
TCP **.**.**.**:61972 **.**.**.**:61973 ESTABLISHED 3924
TCP **.**.**.**:61973 **.**.**.**:61972 ESTABLISHED 3924
TCP **.**.**.**:61974 **.**.**.**:61975 ESTABLISHED 3924
TCP **.**.**.**:61975 **.**.**.**:61974 ESTABLISHED 3924
TCP **.**.**.**:61976 **.**.**.**:61977 ESTABLISHED 3924
TCP **.**.**.**:61977 **.**.**.**:61976 ESTABLISHED 3924
TCP **.**.**.**:61978 **.**.**.**:61979 ESTABLISHED 3924
TCP **.**.**.**:61979 **.**.**.**:61978 ESTABLISHED 3924
TCP **.**.**.**:61980 **.**.**.**:61981 ESTABLISHED 3924
TCP **.**.**.**:61981 **.**.**.**:61980 ESTABLISHED 3924
TCP **.**.**.**:61982 **.**.**.**:61983 ESTABLISHED 3924
TCP **.**.**.**:61983 **.**.**.**:61982 ESTABLISHED 3924
TCP **.**.**.**:61984 **.**.**.**:61985 ESTABLISHED 3924
TCP **.**.**.**:61985 **.**.**.**:61984 ESTABLISHED 3924
TCP **.**.**.**:61986 **.**.**.**:61987 ESTABLISHED 3924
TCP **.**.**.**:61987 **.**.**.**:61986 ESTABLISHED 3924
TCP **.**.**.**:61988 **.**.**.**:61989 ESTABLISHED 3924
TCP **.**.**.**:61989 **.**.**.**:61988 ESTABLISHED 3924
TCP **.**.**.**:61990 **.**.**.**:61991 ESTABLISHED 3924
TCP **.**.**.**:61991 **.**.**.**:61990 ESTABLISHED 3924
TCP **.**.**.**:61992 **.**.**.**:61993 ESTABLISHED 3924
TCP **.**.**.**:61993 **.**.**.**:61992 ESTABLISHED 3924
TCP **.**.**.**:61994 **.**.**.**:61995 ESTABLISHED 3924
TCP **.**.**.**:61995 **.**.**.**:61994 ESTABLISHED 3924
TCP **.**.**.**:61996 **.**.**.**:61997 ESTABLISHED 3924
TCP **.**.**.**:61997 **.**.**.**:61996 ESTABLISHED 3924
TCP **.**.**.**:61998 **.**.**.**:61999 ESTABLISHED 3924
TCP **.**.**.**:61999 **.**.**.**:61998 ESTABLISHED 3924
TCP **.**.**.**:62000 **.**.**.**:62001 ESTABLISHED 3924
TCP **.**.**.**:62001 **.**.**.**:62000 ESTABLISHED 3924
TCP **.**.**.**:62002 **.**.**.**:62003 ESTABLISHED 3924
TCP **.**.**.**:62003 **.**.**.**:62002 ESTABLISHED 3924
TCP **.**.**.**:62004 **.**.**.**:62005 ESTABLISHED 3924
TCP **.**.**.**:62005 **.**.**.**:62004 ESTABLISHED 3924
TCP **.**.**.**:62006 **.**.**.**:62007 ESTABLISHED 3924
TCP **.**.**.**:62007 **.**.**.**:62006 ESTABLISHED 3924
TCP **.**.**.**:62008 **.**.**.**:62009 ESTABLISHED 3924
TCP **.**.**.**:62009 **.**.**.**:62008 ESTABLISHED 3924
TCP **.**.**.**:62010 **.**.**.**:62011 ESTABLISHED 3924
TCP **.**.**.**:62011 **.**.**.**:62010 ESTABLISHED 3924
TCP **.**.**.**:62012 **.**.**.**:62013 ESTABLISHED 3924
TCP **.**.**.**:62013 **.**.**.**:62012 ESTABLISHED 3924
TCP **.**.**.**:62014 **.**.**.**:62015 ESTABLISHED 3924
TCP **.**.**.**:62015 **.**.**.**:62014 ESTABLISHED 3924
TCP **.**.**.**:62016 **.**.**.**:62017 ESTABLISHED 3924
TCP **.**.**.**:62017 **.**.**.**:62016 ESTABLISHED 3924
TCP **.**.**.**:62018 **.**.**.**:62019 ESTABLISHED 3924
TCP **.**.**.**:62019 **.**.**.**:62018 ESTABLISHED 3924
TCP **.**.**.**:62020 **.**.**.**:62021 ESTABLISHED 3924
TCP **.**.**.**:62021 **.**.**.**:62020 ESTABLISHED 3924
TCP **.**.**.**:62022 **.**.**.**:62023 ESTABLISHED 3924
TCP **.**.**.**:62023 **.**.**.**:62022 ESTABLISHED 3924
TCP **.**.**.**:62024 **.**.**.**:62025 ESTABLISHED 3924
TCP **.**.**.**:62025 **.**.**.**:62024 ESTABLISHED 3924
TCP **.**.**.**:62351 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:64386 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:64979 **.**.**.**:1521 ESTABLISHED 5032
TCP **.**.**.**:139 **.**.**.**:0 LISTENING 4
TCP **.**.**.**:7001 **.**.**.**:0 LISTENING 5032
TCP **.**.**.**:7001 **.**.**.**:1478 FIN_WAIT_2 5032
TCP **.**.**.**:7001 **.**.**.**:50281 TIME_WAIT 0
TCP **.**.**.**:7001 **.**.**.**:35971 TIME_WAIT 0
TCP **.**.**.**:7001 **.**.**.**:35978 ESTABLISHED 5032
TCP **.**.**.**:61633 **.**.**.**:5938 ESTABLISHED 2684
TCP **.**.**.**:62024 **.**.**.**:139 TIME_WAIT 0
TCP **.**.**.**:62026 **.**.**.**:139 TIME_WAIT 0
TCP **.**.**.**:62027 **.**.**.**:139 TIME_WAIT 0
TCP **.**.**.**:62036 **.**.**.**:443 SYN_SENT 7164
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 868
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:1521 [::]:0 LISTENING 10036
TCP [::]:3389 [::]:0 LISTENING 5944
TCP [::]:6666 [::]:0 LISTENING 3924
TCP [::]:8885 [::]:0 LISTENING 3924
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49152 [::]:0 LISTENING 948
TCP [::]:49153 [::]:0 LISTENING 484
TCP [::]:49154 [::]:0 LISTENING 1304
TCP [::]:49157 [::]:0 LISTENING 1352
TCP [::]:49185 [::]:0 LISTENING 464
TCP [::]:49187 [::]:0 LISTENING 6076
TCP [::]:54167 [::]:0 LISTENING 9768
TCP [::1]:7001 [::]:0 LISTENING 5032
TCP [fe80::100:7f:fffe%19]:7001 [::]:0 LISTENING 5032
TCP [fe80::5efe:**.**.**.**%16]:7001 [::]:0 LISTENING 5032
TCP [fe80::5efe:**.**.**.**%18]:7001 [::]:0 LISTENING 5032
TCP [fe80::5efe:**.**.**.**%17]:7001 [::]:0 LISTENING 5032
TCP [fe80::419:d90f:3764:d508%11]:7001 [::]:0 LISTENING 5032
TCP [fe80::8c78:9b97:2833:37ba%12]:1521 [fe80::8c78:9b97:2833:37ba%12]:54165 ESTABLISHED 10036
TCP [fe80::8c78:9b97:2833:37ba%12]:7001 [::]:0 LISTENING 5032
TCP [fe80::8c78:9b97:2833:37ba%12]:54165 [fe80::8c78:9b97:2833:37ba%12]:1521 ESTABLISHED 9768
TCP [fe80::d557:5ed5:abe5:8fd4%13]:7001 [::]:0 LISTENING 5032
TCP [fe80::f185:5f4a:dbf:3f63%14]:7001 [::]:0 LISTENING 5032
UDP **.**.**.**:123 *:* 1468
UDP **.**.**.**:500 *:* 1352
UDP **.**.**.**:4500 *:* 1352
UDP **.**.**.**:5355 *:* 1600
UDP **.**.**.**:49152 *:* 848
UDP **.**.**.**:137 *:* 4
UDP **.**.**.**:138 *:* 4
UDP **.**.**.**:137 *:* 4
UDP **.**.**.**:138 *:* 4
UDP **.**.**.**:65267 *:* 9276
UDP **.**.**.**:137 *:* 4
UDP **.**.**.**:138 *:* 4
UDP [::]:123 *:* 1468
UDP [::]:500 *:* 1352
UDP [::]:4500 *:* 1352
UDP [::]:5355 *:* 1600
UDP [fe80::d557:5ed5:abe5:8fd4%13]:546 *:* 1304
F:\weblogic server\tendererSystem\tendererSystem>tasklist /svc
============================================================================================================r
Ó³ÏñÃû³Æ PID ·þÎñ
========================= ======== ============================================
System Idle Process 0 ÔÝȱ
System 4 ÔÝȱ
smss.exe 808 ÔÝȱ
csrss.exe 896 ÔÝȱ
wininit.exe 948 ÔÝȱ
csrss.exe 956 ÔÝȱ
winlogon.exe 988 ÔÝȱ
services.exe 464 ÔÝȱ
lsass.exe 484 SamSs
lsm.exe 496 ÔÝȱ
svchost.exe 592 DcomLaunch, PlugPlay, Power
QQPCRTP.exe 848 QQPCRTP
svchost.exe 868 RpcEptMapper, RpcSs
svchost.exe 1304 Dhcp, eventlog, lmhosts
svchost.exe 1352 AeLookupSvc, BITS, CertPropSvc, gpsvc,
IKEEXT, iphlpsvc, LanmanServer, MSiSCSI,
ProfSvc, Schedule, SENS, SessionEnv,
ShellHWDetection, Winmgmt, wuauserv
svchost.exe 1468 EventSystem, netprofm, nsi, W32Time,
WinHttpAutoProxySvc
svchost.exe 1544 Netman, TrkWks, UmRdpService, UxSms
svchost.exe 1600 CryptSvc, Dnscache, LanmanWorkstation,
NlaSvc, WinRM
svchost.exe 1856 BFE, DPS, MpsSvc
spoolsv.exe 912 Spooler
svchost.exe 1568 AppHostSvc
svchost.exe 1792 ftpsvc
inetinfo.exe 1820 IISADMIN
svchost.exe 2596 RemoteRegistry
TeamViewer_Service.exe 2684 TeamViewer9
svchost.exe 2716 W3SVC, WAS
taskhost.exe 3476 ÔÝȱ
dwm.exe 3696 ÔÝȱ
explorer.exe 3788 ÔÝȱ
msseces.exe 4548 ÔÝȱ
TeamViewer.exe 5252 ÔÝȱ
tv_w32.exe 5436 ÔÝȱ
tv_x64.exe 5444 ÔÝȱ
svchost.exe 5944 TermService
svchost.exe 6076 PolicyAgent
TAOFrame.exe 6480 TAOFrame
msdtc.exe 6668 MSDTC
svchost.exe 5144 FontCache
mmc.exe 6620 ÔÝȱ
MsMpEng.exe 6176 MsMpSvc
csrss.exe 2308 ÔÝȱ
winlogon.exe 2704 ÔÝȱ
LogonUI.exe 6704 ÔÝȱ
rdpclip.exe 6096 ÔÝȱ
mmc.exe 7404 ÔÝȱ
vds.exe 7280 vds
TrustedInstaller.exe 7692 TrustedInstaller
sppsvc.exe 1008 sppsvc
java.exe 3924 ÔÝȱ
conhost.exe 2292 ÔÝȱ
QQPYLiveup.exe 1288 ÔÝȱ
chrome.exe 5804 ÔÝȱ
chrome.exe 2548 ÔÝȱ
taskeng.exe 7488 ÔÝȱ
GoogleUpdate.exe 7872 ÔÝȱ
chrome.exe 2096 ÔÝȱ
chrome.exe 6888 ÔÝȱ
TNSLSNR.EXE 10036 OracleOraDb11g_home1TNSListener
oracle.exe 9768 OracleServiceORCL
cmd.exe 9980 ÔÝȱ
conhost.exe 6860 ÔÝȱ
java.exe 5032 ÔÝȱ
plsqldev.exe 9276 ÔÝȱ
splwow64.exe 9772 ÔÝȱ
w3wp.exe 9316 ÔÝȱ
GoogleUpdate.exe 9484 ÔÝȱ
GoogleUpdate.exe 7164 gupdate
tasklist.exe 10144 ÔÝȱ
conhost.exe 8864 ÔÝȱ
WmiPrvSE.exe 6976 ÔÝȱ
F:\weblogic server\tendererSystem\tendererSystem>ipconfig /all
============================================================================================================r
Windows IP ÅäÖÃ
Ö÷»úÃû . . . . . . . . . . . . . : Lenovo-KV9TA50H
Ö÷ DNS ºó׺ . . . . . . . . . . . :
½ÚµãÀàÐÍ . . . . . . . . . . . . : »ìºÏ
IP ·ÓÉÒÑÆôÓà . . . . . . . . . . : ·ñ
WINS ´úÀíÒÑÆôÓÃ . . . . . . . . . : ·ñ
ÒÔÌ«ÍøÊÊÅäÆ÷ ±¾µØÁ¬½Ó 4:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Intel(R) 82576NS Gigabit Ethernet Controller #4
ÎïÀíµØÖ·. . . . . . . . . . . . . : 08-9E-01-8B-00-8F
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ÊÇ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
ÒÔÌ«ÍøÊÊÅäÆ÷ ±¾µØÁ¬½Ó 3:
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Intel(R) 82576NS Gigabit Ethernet Controller #3
ÎïÀíµØÖ·. . . . . . . . . . . . . : 08-9E-01-8B-00-8E
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
±¾µØÁ´½Ó IPv6 µØÖ·. . . . . . . . : fe80::d557:5ed5:abe5:8fd4%13(Ê×Ñ¡)
IPv4 µØÖ· . . . . . . . . . . . . : **.**.**.**(Ê×Ñ¡)
×ÓÍøÑÚÂë . . . . . . . . . . . . : **.**.**.**
ĬÈÏÍø¹Ø. . . . . . . . . . . . . : **.**.**.**
DHCPv6 IAID . . . . . . . . . . . : 369663489
DHCPv6 ¿Í»§¶Ë DUID . . . . . . . : 00-01-00-01-19-44-38-23-08-9E-01-8B-00-90
DNS ·þÎñÆ÷ . . . . . . . . . . . : **.**.**.**
**.**.**.**
TCPIP É쵀 NetBIOS . . . . . . . : ÒÑÆôÓÃ
ÒÔÌ«ÍøÊÊÅäÆ÷ ±¾µØÁ¬½Ó 2:
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Intel(R) 82576NS Gigabit Ethernet Controller #2
ÎïÀíµØÖ·. . . . . . . . . . . . . : 08-9E-01-8B-00-91
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
±¾µØÁ´½Ó IPv6 µØÖ·. . . . . . . . : fe80::8c78:9b97:2833:37ba%12(Ê×Ñ¡)
IPv4 µØÖ· . . . . . . . . . . . . : **.**.**.**(Ê×Ñ¡)
×ÓÍøÑÚÂë . . . . . . . . . . . . : **.**.**.**
ĬÈÏÍø¹Ø. . . . . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 302554625
DHCPv6 ¿Í»§¶Ë DUID . . . . . . . : 00-01-00-01-19-44-38-23-08-9E-01-8B-00-90
DNS ·þÎñÆ÷ . . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
TCPIP É쵀 NetBIOS . . . . . . . : ÒÑÆôÓÃ
ÒÔÌ«ÍøÊÊÅäÆ÷ ±¾µØÁ¬½Ó:
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Intel(R) 82576NS Gigabit Ethernet Controller
ÎïÀíµØÖ·. . . . . . . . . . . . . : 08-9E-01-8B-00-90
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
±¾µØÁ´½Ó IPv6 µØÖ·. . . . . . . . : fe80::419:d90f:3764:d508%11(Ê×Ñ¡)
IPv4 µØÖ· . . . . . . . . . . . . : **.**.**.**(Ê×Ñ¡)
×ÓÍøÑÚÂë . . . . . . . . . . . . : **.**.**.**
ĬÈÏÍø¹Ø. . . . . . . . . . . . . : **.**.**.**
DHCPv6 IAID . . . . . . . . . . . : 235445761
DHCPv6 ¿Í»§¶Ë DUID . . . . . . . : 00-01-00-01-19-44-38-23-08-9E-01-8B-00-90
DNS ·þÎñÆ÷ . . . . . . . . . . . : **.**.**.**
TCPIP É쵀 NetBIOS . . . . . . . : ÒÑÆôÓÃ
ËíµÀÊÊÅäÆ÷ isatap.{F1FB4472-B2AF-45ED-B0E5-5248EE55C0F2}:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Microsoft ISATAP Adapter
ÎïÀíµØÖ·. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
ËíµÀÊÊÅäÆ÷ isatap.{240B87D4-81A4-4B19-8C42-3B5D6CFF0481}:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Microsoft ISATAP Adapter #2
ÎïÀíµØÖ·. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
ËíµÀÊÊÅäÆ÷ isatap.{336A448F-424A-4484-9468-BFC5EC1282EF}:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Microsoft ISATAP Adapter #3
ÎïÀíµØÖ·. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
ËíµÀÊÊÅäÆ÷ isatap.{67FC8BFC-535C-4551-9658-FEA9064FEAF6}:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Microsoft ISATAP Adapter #4
ÎïÀíµØÖ·. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
ËíµÀÊÊÅäÆ÷ Teredo Tunneling Pseudo-Interface:
ýÌå״̬ . . . . . . . . . . . . : ýÌåÒѶϿª
Á¬½ÓÌض¨µÄ DNS ºó׺ . . . . . . . :
ÃèÊö. . . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
ÎïÀíµØÖ·. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP ÒÑÆôÓÃ . . . . . . . . . . . : ·ñ
×Ô¶¯ÅäÖÃÒÑÆôÓÃ. . . . . . . . . . : ÊÇ
F:\weblogic server\tendererSystem\tendererSystem>systeminfo
============================================================================================================r
Ö÷»úÃû: LENOVO-KV9TA50H
OS Ãû³Æ: Microsoft Windows Server 2008 R2 Enterprise
OS °æ±¾: 6.1.7600 ÔÝȱ Build 7600
OS ÖÆÔìÉÌ: Microsoft Corporation
OS ÅäÖÃ: ¶ÀÁ¢·þÎñÆ÷
OS ¹¹¼þÀàÐÍ: Multiprocessor Free
×¢²áµÄËùÓÐÈË: lenovo
×¢²áµÄ×éÖ¯:
²úÆ· ID: 55041-507-4280034-84203
³õʼ°²×°ÈÕÆÚ: 2013/6/8, 9:01:44
ϵͳÆô¶¯Ê±¼ä: 2015/6/9, 14:57:05
ϵͳÖÆÔìÉÌ: LENOVO
ϵͳÐͺÅ: Lenovo WQ R680 G7
ϵͳÀàÐÍ: x64-based PC
´¦ÀíÆ÷: °²×°ÁË 4 ¸ö´¦ÀíÆ÷¡£
[01]: Intel64 Family 6 Model 47 Stepping 2 GenuineIntel ~1057 Mhz
[02]: Intel64 Family 6 Model 47 Stepping 2 GenuineIntel ~1057 Mhz
[03]: Intel64 Family 6 Model 47 Stepping 2 GenuineIntel ~1177 Mhz
[04]: Intel64 Family 6 Model 47 Stepping 2 GenuineIntel ~1057 Mhz
BIOS °æ±¾: Intel Corp. QSSC-S4R.QCI.01.00.X032.011820121606, 2012/1/18
Windows Ŀ¼: C:\Windows
ϵͳĿ¼: C:\Windows\system32
Æô¶¯É豸: \Device\HarddiskVolume1
ϵͳÇøÓòÉèÖÃ: zh-cn;ÖÐÎÄ(Öйú)
ÊäÈë·¨ÇøÓòÉèÖÃ: zh-cn;ÖÐÎÄ(Öйú)
ʱÇø: (UTC+08:00)±±¾©£¬ÖØÇ죬Ïã¸ÛÌرðÐÐÕþÇø£¬ÎÚ³ľÆë
ÎïÀíÄÚ´æ×ÜÁ¿: 32,619 MB
¿ÉÓõÄÎïÀíÄÚ´æ: 20,259 MB
ÐéÄâÄÚ´æ: ×î´óÖµ: 65,236 MB
ÐéÄâÄÚ´æ: ¿ÉÓÃ: 52,222 MB
ÐéÄâÄÚ´æ: ʹÓÃÖÐ: 13,014 MB
Ò³ÃæÎļþλÖÃ: D:\pagefile.sys
Óò: WORKGROUP
µÇ¼·þÎñÆ÷: \\LENOVO-KV9TA50H
ÐÞ²¹³ÌÐò: °²×°ÁË 99 ¸öÐÞ²¹³ÌÐò¡£
[01]: KB2032276
[02]: KB2124261
[03]: KB2271195
[04]: KB2296011
[05]: KB2305420
[06]: KB2345886
[07]: KB2347290
[08]: KB2387149
[09]: KB2393802
[10]: KB2419640
[11]: KB2423089
[12]: KB2425227
[13]: KB2442962
[14]: KB2483614
[15]: KB2506014
[16]: KB2506212
[17]: KB2509553
[18]: KB2511455
[19]: KB2533552
[20]: KB2535512
[21]: KB2536275
[22]: KB2536276
[23]: KB2544893
[24]: KB2552343
[25]: KB2560656
[26]: KB2564958
[27]: KB2570947
[28]: KB2584146
[29]: KB2585542
[30]: KB2604114
[31]: KB2618451
[32]: KB2620704
[33]: KB2621440
[34]: KB2631813
[35]: KB2643719
[36]: KB2644615
[37]: KB2645640
[38]: KB2653956
[39]: KB2654428
[40]: KB2655992
[41]: KB2656355
[42]: KB2656410
[43]: KB2658846
[44]: KB2659262
[45]: KB2661254
[46]: KB2667402
[47]: KB2676562
[48]: KB2685939
[49]: KB2690533
[50]: KB2691442
[51]: KB2698365
[52]: KB2705219
[53]: KB2706045
[54]: KB2712808
[55]: KB2716513
[56]: KB2718704
[57]: KB2719033
[58]: KB2729451
[59]: KB2736418
[60]: KB2742598
[61]: KB2743555
[62]: KB2748349
[63]: KB2749655
[64]: KB2753842
[65]: KB2756920
[66]: KB2757638
[67]: KB2758857
[68]: KB2765809
[69]: KB2769369
[70]: KB2770660
[71]: KB2779562
[72]: KB2785220
[73]: KB2789644
[74]: KB2790113
[75]: KB2790655
[76]: KB2807986
[77]: KB2808735
[78]: KB2813170
[79]: KB2813347
[80]: KB2840149
[81]: KB958488
[82]: KB972270
[83]: KB974431
[84]: KB974571
[85]: KB975467
[86]: KB975560
[87]: KB977074
[88]: KB978542
[89]: KB978601
[90]: KB979309
[91]: KB979482
[92]: KB979687
[93]: KB979688
[94]: KB979900
[95]: KB980408
[96]: KB981889
[97]: KB982132
[98]: KB982666
[99]: KB982799
Íø¿¨: °²×°ÁË 4 ¸ö NIC¡£
[01]: Intel(R) 82576NS Gigabit Ethernet Controller
Á¬½ÓÃû: ±¾µØÁ¬½Ó
ÆôÓÃ DHCP: ·ñ
IP µØÖ·
[01]: **.**.**.**
[02]: fe80::419:d90f:3764:d508
[02]: Intel(R) 82576NS Gigabit Ethernet Controller
Á¬½ÓÃû: ±¾µØÁ¬½Ó 2
ÆôÓÃ DHCP: ·ñ
IP µØÖ·
[01]: **.**.**.**
[02]: fe80::8c78:9b97:2833:37ba
[03]: Intel(R) 82576NS Gigabit Ethernet Controller
Á¬½ÓÃû: ±¾µØÁ¬½Ó 3
ÆôÓÃ DHCP: ·ñ
IP µØÖ·
[01]: **.**.**.**
[02]: fe80::d557:5ed5:abe5:8fd4
[04]: Intel(R) 82576NS Gigabit Ethernet Controller
Á¬½ÓÃû: ±¾µØÁ¬½Ó 4
״̬: ýÌåÁ¬½ÓÒÑÖжÏ
F:\weblogic server\tendererSystem\tendererSystem>

修复方案:

加强安全意识

版权声明:转载请注明来源 朱元璋@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:12

确认时间:2016-01-08 18:36

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给黑龙江分中心,由其后续协调网站管理单位处置.

最新状态:

暂无