NVRMini2ÉãÏñÍ·ÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-09-21

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-1149£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-1150£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3£¬£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

Ó°Ïì°æ±¾


NUUO NVRMini2 3.8.0¼°ÒÔϰ汾


Îó²î¸ÅÊö


Tenable¹ÙÍøÉϹûÕæÁ˹ØÓÚÓÉNUUO¹«Ë¾¿ª·¢µÄÉãÏñͷϵͳNVRMini2±£´æÁ½¸öÑÏÖØÎó²î¡£¡£¡£
CVE-2018-1149£ºÎ´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¿ÍÕ»»º³åÇøÒç³ö
CVE-2018-1150£ººóÃÅ
NVRMini2µÄ½á¹¹¼òͼÈçÏÂ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Îó²îÑéÖ¤


CVE-2018-1149£º
NVRMini2ϵͳ¶ÔÍâ̻¶ÁËÒ»¸öHTTP»á¼û½Ó¿Úhttp://<target>/cgi-bin/cgi_system£¬£¬£¬£¬ £¬£¬Í¨¹ýÕâ¸ö½Ó¿Ú£¬£¬£¬£¬ £¬£¬¾ßÓÐȨÏÞµÄÓû§¿ÉÒÔ»á¼ûµ½ÖÕ¶Ë×°±¸¡£¡£¡£cgi_systemÎļþÖеĹ¦Ð§Ö»ÓÐÊÚȨÓû§¿ÉÒÔ»á¼û£¬£¬£¬£¬ £¬£¬ÈÏÖ¤µÄÒªÁìΪ½ÏÁ¿Óû§»á¼ûÊý¾ÝCookie×Ö¶ÎÖеÄPHPSESSIDÖµºÍ´æ´¢/tmpĿ¼ÖеÄsessionÎļþÃû£¬£¬£¬£¬ £¬£¬¹¹½¨sessionÎļþÃûµÄ´úÂëÈçÏ£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


´Ósub_534a4·µ»ØµÄֵΪ»á»°±êʶ×Ö·û´®¡£¡£¡£³ÌÐò¶Ô¸Ã×Ö·û´®³¤¶ÈûÓÐ×÷ÈκÎÏÞÖÆ¡£¡£¡£µ±×Ö·û¹´×ª´ïµ½sprintfÒÔ¹¹½¨tmpÎļþÃûʱ²¢Ã»ÓнçÏß¼ì²é¡£¡£¡£Òò´Ë£¬£¬£¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«³¬³¤µÄPHPSESSIDÖµÔ¶³Ìת´ï¸øsprintfµ¼Ö»º³åÇøÒç³ö£¬£¬£¬£¬ £¬£¬´Ó¶øÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£
²âÊÔ´úÂëÈçÏ£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


²âÊÔ´úÂë»áµ¼ÖÂNVRϵͳ»á±¬·¢Íß½âÕ÷Ï󣬣¬£¬£¬ £¬£¬¾­ÓÉÉîÈëÆÊÎö£¬£¬£¬£¬ £¬£¬Ò²¿ÉÒÔÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬ £¬£¬¹¥»÷Õß²»µ«Äܹ»¿ØÖÆNVR£¬£¬£¬£¬ £¬£¬»¹¿ÉÒÔ»á¼ûºÍÐÞ¸ÄNVRÖÐËùÓеÄÓû§Æ¾Ö¤Êý¾Ý£¬£¬£¬£¬ £¬£¬Ó°ÏìÑÏÖØ¡£¡£¡£


CVE-2018-1150£º
NVRMini2µÄPHP´úÂëÖг£¼ûµÄϰ¹ßΪ£º
¼ì²éÄ¿½ñPHP»á»°ÊÇ·ñÓÐÓᣡ£¡£
ÑéÖ¤»á»°ÊÇ·ñ¾ßÓÐÕýÔÚ»á¼ûµÄÒ³ÃæµÄÊʵ±È¨ÏÞ£¨¼´admin£¬£¬£¬£¬ £¬£¬poweruser£¬£¬£¬£¬ £¬£¬user£¬£¬£¬£¬ £¬£¬root£¬£¬£¬£¬ £¬£¬guest£©¡£¡£¡£
¿ÉÊÇ£¬£¬£¬£¬ £¬£¬check_session_is_valid£¨£©º¯ÊýÖÐÈ´±£´æºóÃŵĴúÂ룬£¬£¬£¬ £¬£¬º¯ÊýÈçÏ£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÆäÖбêʶΪ¡°back door¡±µÄ×ÖÑùΪÆäÔ´ÂëÖоͱ£´æµÄ¡£¡£¡£constant(¡°MOSES_FILE¡±) Ö¸ÏòµÄ·¾¶Îª/tmp/moses¡£¡£¡£ÈôÊÇ/tmp/moses/±£´æ£¬£¬£¬£¬ £¬£¬ÔòδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÁгöËùÓзÇadminµÄÓû§£¬£¬£¬£¬ £¬£¬²¢ÐÞ¸ÄËûÃǵÄÃÜÂë.

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¹¥»÷ÑÝʾÊÓÆµÈçÏ£º

http://www.iqiyi.com/w_19s2b6hn11.html

ÐÞ¸´½¨Òé


¹Ù·½ÔÝʱûÓÐÏà¹ØµÄ¼Æ»®£¬£¬£¬£¬ £¬£¬½¨Òé°ü¹Ü×°±¸²»Ì»Â¶ÔÚ»¥ÁªÍøÉÏ£¬£¬£¬£¬ £¬£¬²¢ÔÚ·À»ðǽװ±¸ÉϼÓÈë¶ÔÉãÏñÍ·HTTPЧÀ͵Ļá¼û¿ØÖÆÕ½ÂÔ¡£¡£¡£


²Î¿¼Á´½Ó


https://www.tenable.com/security/research/tra-2018-25