乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-03-29: 细节已通知厂商并且等待厂商处理中 2016-04-01: 厂商已经确认,细节仅向厂商公开 2016-04-11: 细节向核心白帽子及相关领域专家公开 2016-04-21: 细节向普通白帽子公开 2016-05-01: 细节向实习白帽子公开 2016-05-16: 细节向公众公开
RT
微信平台
**.**.**.**/tecsun_wechat/suzhouweixin_icon.html
存在console控制台弱口令漏洞可直接部署war包得webshell (账号weblogic 密码 weblogic123)url
**.**.**.**/console/
数据库信息:
<bean id="dataSource_A" class="org.springframework.jdbc.datasource.DriverManagerDataSource"> <property name="driverClassName" value="oracle.jdbc.driver.OracleDriver" /> <!-- value="jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS =(PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(ADDRESS = (PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(LOAD_BALANCE = yes)(FAILOVER = yes)(CONNECT_DATA =(SERVER = DEDICATED)(SERVICE_NAME = orcl)(FAILOVER_MODE =(TYPE = SELECT)(METHOD = BASIC)(RETRIES = 80)(DELAY = 3))))" /> value="jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS =(PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(ADDRESS = (PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(LOAD_BALANCE = yes)(FAILOVER = yes)(CONNECT_DATA =(SERVER = DEDICATED)(SERVICE_NAME = orcl)(FAILOVER_MODE =(TYPE = SELECT)(METHOD = BASIC)(RETRIES = 80)(DELAY = 3))))" /> --> <property name="url" value="jdbc:oracle:thin:@**.**.**.**:1521:orcl"/> <property name="username" value="tecsun_weixin" /> <property name="password" value="tecsun_chat" /> </bean> <bean id="poolConfig_A" class="com.tecsun.framework.basic.springpool.Config"> <property name="poolName" value="A" /> <property name="maxConnNum" value="300" /> <property name="expire" value="5000" /> </bean> <bean id="pool_A" class="com.tecsun.framework.basic.springpool.ConnectionPool"> <property name="dataSource" ref="dataSource_A" /> <property name="config" ref="poolConfig_A" /> </bean> <!-- 杩炴帴姹燗缁撴潫 --> <!-- 杩炴帴姹燘寮� --> <bean id="dataSource_B" class="org.springframework.jdbc.datasource.DriverManagerDataSource"> <property name="driverClassName" value="oracle.jdbc.driver.OracleDriver" /> <property name="url" value="jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS =(PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(ADDRESS = (PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(LOAD_BALANCE = yes)(FAILOVER = yes)(CONNECT_DATA =(SERVER = DEDICATED)(SERVICE_NAME = orcl)(FAILOVER_MODE =(TYPE = SELECT)(METHOD = BASIC)(RETRIES = 80)(DELAY = 3))))" /> <property name="username" value="hncard" /> <property name="password" value="hncard" /> </bean> <bean id="poolConfig_B" class="com.tecsun.framework.basic.springpool.Config"> <property name="poolName" value="B" /> <property name="maxConnNum" value="300" /> <property name="expire" value="5000" /> </bean> <bean id="pool_B" class="com.tecsun.framework.basic.springpool.ConnectionPool"> <property name="dataSource" ref="dataSource_B" /> <property name="config" ref="poolConfig_B" /> </bean> <!-- 杩炴帴姹燘缁撴潫 --> <!-- 杩炴帴姹燙寮� --> <bean id="dataSource_C" class="org.springframework.jdbc.datasource.DriverManagerDataSource"> <property name="driverClassName" value="oracle.jdbc.driver.OracleDriver" /> <property name="url" value="jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS =(PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(ADDRESS = (PROTOCOL = TCP)(HOST = **.**.**.**)(PORT = 1521))(LOAD_BALANCE = yes)(FAILOVER = yes)(CONNECT_DATA =(SERVER = DEDICATED)(SERVICE_NAME = orcl)(FAILOVER_MODE =(TYPE = SELECT)(METHOD = BASIC)(RETRIES = 80)(DELAY = 3))))" /> <property name="username" value="wechat_bus" /> <property name="password" value="tecsun_bus" /> </bean> <bean id="poolConfig_C" class="com.tecsun.framework.basic.springpool.Config"> <property name="poolName" value="C" /> <property name="maxConnNum" value="300" /> <property name="expire" value="5000" /> </bean> <bean id="pool_C" class="com.tecsun.framework.basic.springpool.ConnectionPool"> <property name="dataSource" ref="dataSource_C" /> <property name="config" ref="poolConfig_C" /> </bean> <!-- 杩炴帴姹燘缁撴潫 --> <!-- pool List --> <bean id="poolList" class="java.util.ArrayList"> <constructor-arg> <list> <ref bean="pool_A" /> <ref bean="pool_B" /> <ref bean="pool_C" /> </list> </constructor-arg> </bean> <!-- 杩炴帴姹犵鐞�--> <bean id="connectionManager" class="com.tecsun.framework.basic.springpool.ConnectionManager"> <property name="poolList" ref="poolList" /> </bean> <!-- dao_A Bean --> <bean id="basicDao_A" class="com.tecsun.framework.basic.dao.BasicDao" singleton="false"> <property name="connManager" ref="connectionManager" /> <property name="poolName" value="A" /> </bean> <bean id="basicDao_B" class="com.tecsun.framework.basic.dao.BasicDao" singleton="false"> <property name="connManager" ref="connectionManager" /> <property name="poolName" value="B" /> </bean> <bean id="basicDao_C" class="com.tecsun.framework.basic.dao.BasicDao" singleton="false"> <property name="connManager" ref="connectionManager" /> <property name="poolName" value="C" /> </bean> <!-- 浜嬪姟澶勭悊--> <bean id="serviceInterceptor" class="com.tecsun.framework.basic.spring.ServiceInterceptor" abstract="false" singleton="true" lazy-init="default" autowire="default" dependency-check="default"> </bean></beans>
登录数据库
value="jdbc:oracle:thin:@**.**.**.**:1521:orcl"/> <property name="username" value="tecsun_weixin" /> <property name="password" value="tecsun_chat" />
数据库SZ002中1000w个人信息
社保记录 近500W
另一个库中敏感信息 500W 个人详细信息
修改弱口令
危害等级:高
漏洞Rank:10
确认时间:2016-04-01 15:04
CNVD确认所述情况,已经转由CNCERT下发给安徽分中心,由其后续协调网站管理单位处置。
暂无