漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-0107914
漏洞标题:泡椒网多站某服务未授权访问(疑似影响用户数据)
相关厂商:paojiao.com
漏洞作者: 管管侠
提交时间:2015-04-14 17:57
修复时间:2015-06-02 22:06
公开时间:2015-06-02 22:06
漏洞类型:未授权访问/权限绕过
危害等级:高
自评Rank:20
漏洞状态:厂商已经确认
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-04-14: 细节已通知厂商并且等待厂商处理中
2015-04-18: 厂商已经确认,细节仅向厂商公开
2015-04-28: 细节向核心白帽子及相关领域专家公开
2015-05-08: 细节向普通白帽子公开
2015-05-18: 细节向实习白帽子公开
2015-06-02: 细节向公众公开
简要描述:
详细说明:
Memcached配置不当导致未授权访问
1. 115.29.176.12:11211
STAT uptime 2535841
STAT time 1429004497
STAT version 1.4.20
STAT libevent 1.4.13-stable
STAT pointer_size 64
STAT rusage_user 282.219096
STAT rusage_system 1254.372306
STAT curr_connections 24
STAT total_connections 153
STAT connection_structures 32
STAT reserved_fds 20
STAT cmd_get 8306649
STAT cmd_set 738838
STAT cmd_flush 42
STAT cmd_touch 0
STAT get_hits 7321725
STAT get_misses 984924
STAT delete_misses 0
STAT delete_hits 0
STAT incr_misses 0
STAT incr_hits 0
STAT decr_misses 0
STAT decr_hits 0
STAT cas_misses 0
STAT cas_hits 0
STAT cas_badval 0
STAT touch_hits 0
STAT touch_misses 0
STAT auth_cmds 0
STAT auth_errors 0
STAT bytes_read 1111783459
STAT bytes_written 20152531445
STAT limit_maxbytes 3221225472
STAT accepting_conns 1
STAT listen_disabled_num 0
STAT threads 4
STAT conn_yields 0
STAT hash_power_level 16
STAT hash_bytes 524288
STAT hash_is_expanding 0
STAT malloc_fails 0
STAT bytes 13706057
STAT curr_items 10657
STAT total_items 738838
漏洞证明:
2. 58.215.179.85:11211
STAT uptime 17551330
STAT time 1429004533
STAT version 1.4.15
STAT libevent 1.4.13-stable
STAT pointer_size 64
STAT rusage_user 100.702690
STAT rusage_system 802.499001
STAT curr_connections 10
STAT total_connections 754
STAT connection_structures 55
STAT reserved_fds 20
STAT cmd_get 2352671
STAT cmd_set 0
STAT cmd_flush 0
STAT cmd_touch 0
STAT get_hits 0
STAT get_misses 2352671
STAT delete_misses 0
STAT delete_hits 0
STAT incr_misses 0
STAT incr_hits 0
STAT decr_misses 0
STAT decr_hits 0
STAT cas_misses 0
STAT cas_hits 0
STAT cas_badval 0
STAT touch_hits 0
STAT touch_misses 0
STAT auth_cmds 0
STAT auth_errors 0
STAT bytes_read 722888666
STAT bytes_written 825688287
STAT limit_maxbytes 5368709120
STAT accepting_conns 1
STAT listen_disabled_num 0
STAT threads 4
STAT conn_yields 1370
STAT hash_power_level 16
STAT hash_bytes 524288
STAT hash_is_expanding 0
STAT bytes 0
STAT curr_items 0
STAT total_items 0
STAT expired_unfetched 0
STAT evicted_unfetched 0
修复方案:
版权声明:转载请注明来源 管管侠@乌云
漏洞回应
厂商回应:
危害等级:中
漏洞Rank:10
确认时间:2015-04-18 22:05
厂商回复:
感谢
最新状态:
暂无