当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-085739

漏洞标题:福建网龙某后台弱口令可root

相关厂商:福建网龙

漏洞作者: 茜茜公主

提交时间:2014-12-03 18:34

修复时间:2015-01-17 18:36

公开时间:2015-01-17 18:36

漏洞类型:服务弱口令

危害等级:低

自评Rank:5

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-12-03: 细节已通知厂商并且等待厂商处理中
2014-12-03: 厂商已经确认,细节仅向厂商公开
2014-12-13: 细节向核心白帽子及相关领域专家公开
2014-12-23: 细节向普通白帽子公开
2015-01-02: 细节向实习白帽子公开
2015-01-17: 细节向公众公开

简要描述:

福建网龙某后台弱口令

详细说明:

后台地址:http://121.207.243.91:8001/web/login
帐号密码: admin/123456

ndabc.png

漏洞证明:

QQ截图20141203155422.jpg


ps root
root 1 0 0 Jul15 ? 00:08:16 /sbin/init
root 2 0 0 Jul15 ? 00:00:00 [kthreadd]
root 3 2 0 Jul15 ? 00:00:04 [migration/0]
root 4 2 0 Jul15 ? 00:06:04 [ksoftirqd/0]
root 5 2 0 Jul15 ? 00:00:00 [migration/0]
root 6 2 0 Jul15 ? 00:00:12 [watchdog/0]
root 7 2 0 Jul15 ? 00:00:05 [migration/1]
root 8 2 0 Jul15 ? 00:00:00 [migration/1]
root 9 2 0 Jul15 ? 00:04:00 [ksoftirqd/1]
root 10 2 0 Jul15 ? 00:00:12 [watchdog/1]
root 11 2 0 Jul15 ? 00:00:01 [migration/2]
root 12 2 0 Jul15 ? 00:00:00 [migration/2]
root 13 2 0 Jul15 ? 00:04:24 [ksoftirqd/2]
root 14 2 0 Jul15 ? 00:00:11 [watchdog/2]
root 15 2 0 Jul15 ? 00:00:01 [migration/3]
root 16 2 0 Jul15 ? 00:00:00 [migration/3]
root 17 2 0 Jul15 ? 00:04:19 [ksoftirqd/3]
root 18 2 0 Jul15 ? 00:00:11 [watchdog/3]
root 19 2 0 Jul15 ? 00:00:00 [migration/4]
root 20 2 0 Jul15 ? 00:00:00 [migration/4]
root 21 2 0 Jul15 ? 00:02:53 [ksoftirqd/4]
root 22 2 0 Jul15 ? 00:00:11 [watchdog/4]
root 23 2 0 Jul15 ? 00:00:00 [migration/5]
root 24 2 0 Jul15 ? 00:00:00 [migration/5]
root 25 2 0 Jul15 ? 00:02:47 [ksoftirqd/5]
root 26 2 0 Jul15 ? 00:00:12 [watchdog/5]
root 27 2 0 Jul15 ? 00:00:00 [migration/6]
root 28 2 0 Jul15 ? 00:00:00 [migration/6]
root 29 2 0 Jul15 ? 00:01:23 [ksoftirqd/6]
root 30 2 0 Jul15 ? 00:00:13 [watchdog/6]
root 31 2 0 Jul15 ? 00:00:00 [migration/7]
root 32 2 0 Jul15 ? 00:00:00 [migration/7]
root 33 2 0 Jul15 ? 00:01:27 [ksoftirqd/7]
root 34 2 0 Jul15 ? 00:00:11 [watchdog/7]
root 35 2 0 Jul15 ? 00:00:00 [migration/8]
root 36 2 0 Jul15 ? 00:00:00 [migration/8]
root 37 2 0 Jul15 ? 00:00:41 [ksoftirqd/8]
root 38 2 0 Jul15 ? 00:00:10 [watchdog/8]
root 39 2 0 Jul15 ? 00:00:00 [migration/9]
root 40 2 0 Jul15 ? 00:00:00 [migration/9]
root 41 2 0 Jul15 ? 00:00:47 [ksoftirqd/9]
root 42 2 0 Jul15 ? 00:00:11 [watchdog/9]
root 43 2 0 Jul15 ? 00:00:00 [migration/10]
root 44 2 0 Jul15 ? 00:00:00 [migration/10]
root 45 2 0 Jul15 ? 00:00:24 [ksoftirqd/10]
root 46 2 0 Jul15 ? 00:00:10 [watchdog/10]
root 47 2 0 Jul15 ? 00:00:00 [migration/11]
root 48 2 0 Jul15 ? 00:00:00 [migration/11]
root 49 2 0 Jul15 ? 00:00:26 [ksoftirqd/11]
root 50 2 0 Jul15 ? 00:00:11 [watchdog/11]
root 51 2 0 Jul15 ? 00:00:02 [migration/12]
root 52 2 0 Jul15 ? 00:00:00 [migration/12]
root 53 2 0 Jul15 ? 00:00:54 [ksoftirqd/12]
root 54 2 0 Jul15 ? 00:00:11 [watchdog/12]
root 55 2 0 Jul15 ? 00:00:03 [migration/13]
root 56 2 0 Jul15 ? 00:00:00 [migration/13]
root 57 2 0 Jul15 ? 00:01:01 [ksoftirqd/13]
root 58 2 0 Jul15 ? 00:00:11 [watchdog/13]
root 59 2 0 Jul15 ? 00:00:29 [migration/14]
root 60 2 0 Jul15 ? 00:00:00 [migration/14]
root 61 2 0 Jul15 ? 00:00:53 [ksoftirqd/14]
root 62 2 0 Jul15 ? 00:00:10 [watchdog/14]
root 63 2 0 Jul15 ? 00:00:29 [migration/15]
root 64 2 0 Jul15 ? 00:00:00 [migration/15]
root 65 2 0 Jul15 ? 00:00:53 [ksoftirqd/15]
root 66 2 0 Jul15 ? 00:00:11 [watchdog/15]
root 67 2 0 Jul15 ? 00:00:06 [migration/16]
root 68 2 0 Jul15 ? 00:00:00 [migration/16]
root 69 2 0 Jul15 ? 00:00:36 [ksoftirqd/16]
root 70 2 0 Jul15 ? 00:00:10 [watchdog/16]
root 71 2 0 Jul15 ? 00:00:05 [migration/17]
root 72 2 0 Jul15 ? 00:00:00 [migration/17]
root 73 2 0 Jul15 ? 00:00:35 [ksoftirqd/17]
root 74 2 0 Jul15 ? 00:00:11 [watchdog/17]
root 75 2 0 Jul15 ? 00:00:01 [migration/18]
root 76 2 0 Jul15 ? 00:00:00 [migration/18]
root 77 2 0 Jul15 ? 00:00:24 [ksoftirqd/18]
root 78 2 0 Jul15 ? 00:00:11 [watchdog/18]
root 79 2 0 Jul15 ? 00:00:04 [migration/19]
root 80 2 0 Jul15 ? 00:00:00 [migration/19]
root 81 2 0 Jul15 ? 00:00:22 [ksoftirqd/19]
root 82 2 0 Jul15 ? 00:00:11 [watchdog/19]
root 83 2 0 Jul15 ? 00:00:00 [migration/20]
root 84 2 0 Jul15 ? 00:00:00 [migration/20]
root 85 2 0 Jul15 ? 00:00:15 [ksoftirqd/20]
root 86 2 0 Jul15 ? 00:00:11 [watchdog/20]
root 87 2 0 Jul15 ? 00:00:00 [migration/21]
root 88 2 0 Jul15 ? 00:00:00 [migration/21]
root 89 2 0 Jul15 ? 00:00:16 [ksoftirqd/21]
root 90 2 0 Jul15 ? 00:00:11 [watchdog/21]
root 91 2 0 Jul15 ? 00:00:00 [migration/22]
root 92 2 0 Jul15 ? 00:00:00 [migration/22]
root 93 2 0 Jul15 ? 00:00:22 [ksoftirqd/22]
root 94 2 0 Jul15 ? 00:00:10 [watchdog/22]
root 95 2 0 Jul15 ? 00:00:00 [migration/23]
root 96 2 0 Jul15 ? 00:00:00 [migration/23]
root 97 2 0 Jul15 ? 00:00:14 [ksoftirqd/23]
root 98 2 0 Jul15 ? 00:00:11 [watchdog/23]
root 99 2 0 Jul15 ? 00:39:37 [events/0]
root 100 2 0 Jul15 ? 00:06:01 [events/1]
root 101 2 0 Jul15 ? 00:05:39 [events/2]
root 102 2 0 Jul15 ? 00:05:39 [events/3]
root 103 2 0 Jul15 ? 00:05:22 [events/4]
root 104 2 0 Jul15 ? 00:05:22 [events/5]
root 105 2 0 Jul15 ? 00:05:27 [events/6]
root 106 2 0 Jul15 ? 00:05:27 [events/7]
root 107 2 0 Jul15 ? 00:05:03 [events/8]
root 108 2 0 Jul15 ? 00:05:02 [events/9]
root 109 2 0 Jul15 ? 00:05:14 [events/10]
root 110 2 0 Jul15 ? 00:05:17 [events/11]
root 111 2 0 Jul15 ? 00:06:39 [events/12]
root 112 2 0 Jul15 ? 00:05:25 [events/13]
root 113 2 0 Jul15 ? 00:05:55 [events/14]
root 114 2 0 Jul15 ? 00:05:53 [events/15]
root 115 2 0 Jul15 ? 00:05:21 [events/16]
root 116 2 0 Jul15 ? 00:05:17 [events/17]
root 117 2 0 Jul15 ? 00:05:16 [events/18]
root 118 2 0 Jul15 ? 00:05:22 [events/19]
root 119 2 0 Jul15 ? 00:05:02 [events/20]
root 120 2 0 Jul15 ? 00:05:07 [events/21]
root 121 2 0 Jul15 ? 00:05:54 [events/22]
root 122 2 0 Jul15 ? 00:06:31 [events/23]
root 123 2 0 Jul15 ? 00:00:00 [cgroup]
root 124 2 0 Jul15 ? 00:00:00 [khelper]
root 125 2 0 Jul15 ? 00:00:00 [netns]
root 126 2 0 Jul15 ? 00:00:00 [async/mgr]
root 127 2 0 Jul15 ? 00:00:00 [pm]
root 128 2 0 Jul15 ? 00:00:41 [sync_supers]
root 129 2 0 Jul15 ? 00:00:51 [bdi-default]
root 130 2 0 Jul15 ? 00:00:00 [kintegrityd/0]
root 131 2 0 Jul15 ? 00:00:00 [kintegrityd/1]
root 132 2 0 Jul15 ? 00:00:00 [kintegrityd/2]
root 133 2 0 Jul15 ? 00:00:00 [kintegrityd/3]
root 134 2 0 Jul15 ? 00:00:00 [kintegrityd/4]
root 135 2 0 Jul15 ? 00:00:00 [kintegrityd/5]
root 136 2 0 Jul15 ? 00:00:00 [kintegrityd/6]
root 137 2 0 Jul15 ? 00:00:00 [kintegrityd/7]
root 138 2 0 Jul15 ? 00:00:00 [kintegrityd/8]
root 139 2 0 Jul15 ? 00:00:00 [kintegrityd/9]
root 140 2 0 Jul15 ? 00:00:00 [kintegrityd/10]
root 141 2 0 Jul15 ? 00:00:00 [kintegrityd/11]
root 142 2 0 Jul15 ? 00:00:00 [kintegrityd/12]
root 143 2 0 Jul15 ? 00:00:00 [kintegrityd/13]
root 144 2 0 Jul15 ? 00:00:00 [kintegrityd/14]
root 145 2 0 Jul15 ? 00:00:00 [kintegrityd/15]
root 146 2 0 Jul15 ? 00:00:00 [kintegrityd/16]
root 147 2 0 Jul15 ? 00:00:00 [kintegrityd/17]
root 148 2 0 Jul15 ? 00:00:00 [kintegrityd/18]
root 149 2 0 Jul15 ? 00:00:00 [kintegrityd/19]
root 150 2 0 Jul15 ? 00:00:00 [kintegrityd/20]
root 151 2 0 Jul15 ? 00:00:00 [kintegrityd/21]
root 152 2 0 Jul15 ? 00:00:00 [kintegrityd/22]
root 153 2 0 Jul15 ? 00:00:00 [kintegrityd/23]
root 154 2 0 Jul15 ? 00:02:23 [kblockd/0]
root 155 2 0 Jul15 ? 00:02:58 [kblockd/1]
root 156 2 0 Jul15 ? 00:00:02 [kblockd/2]
root 157 2 0 Jul15 ? 00:00:02 [kblockd/3]
root 158 2 0 Jul15 ? 00:00:01 [kblockd/4]
root 159 2 0 Jul15 ? 00:00:01 [kblockd/5]
root 160 2 0 Jul15 ? 00:00:00 [kblockd/6]
root 161 2 0 Jul15 ? 00:00:00 [kblockd/7]
root 162 2 0 Jul15 ? 00:00:00 [kblockd/8]
root 163 2 0 Jul15 ? 00:00:00 [kblockd/9]
root 164 2 0 Jul15 ? 00:00:00 [kblockd/10]
root 165 2 0 Jul15 ? 00:00:00 [kblockd/11]
root 166 2 0 Jul15 ? 00:00:05 [kblockd/12]
root 167 2 0 Jul15 ? 00:00:05 [kblockd/13]
root 168 2 0 Jul15 ? 00:00:00 [kblockd/14]
root 169 2 0 Jul15 ? 00:00:01 [kblockd/15]
root 170 2 0 Jul15 ? 00:00:00 [kblockd/16]
root 171 2 0 Jul15 ? 00:00:00 [kblockd/17]
root 172 2 0 Jul15 ? 00:00:00 [kblockd/18]
root 173 2 0 Jul15 ? 00:00:00 [kblockd/19]
root 174 2 0 Jul15 ? 00:00:00 [kblockd/20]
root 175 2 0 Jul15 ? 00:00:00 [kblockd/21]
root 176 2 0 Jul15 ? 00:00:00 [kblockd/22]
root 177 2 0 Jul15 ? 00:00:00 [kblockd/23]
root 178 2 0 Jul15 ? 00:00:00 [kacpid]
root 179 2 0 Jul15 ? 00:00:00 [kacpi_notify]
root 180 2 0 Jul15 ? 00:00:00 [kacpi_hotplug]
root 181 2 0 Jul15 ? 00:00:00 [ata_aux]
root 182 2 0 Jul15 ? 00:00:00 [ata_sff/0]
root 183 2 0 Jul15 ? 00:00:00 [ata_sff/1]
root 184 2 0 Jul15 ? 00:00:00 [ata_sff/2]
root 185 2 0 Jul15 ? 00:00:00 [ata_sff/3]
root 186 2 0 Jul15 ? 00:00:00 [ata_sff/4]
root 187 2 0 Jul15 ? 00:00:00 [ata_sff/5]
root 188 2 0 Jul15 ? 00:00:00 [ata_sff/6]
root 189 2 0 Jul15 ? 00:00:00 [ata_sff/7]
root 190 2 0 Jul15 ? 00:00:00 [ata_sff/8]
root 191 2 0 Jul15 ? 00:00:00 [ata_sff/9]
root 192 2 0 Jul15 ? 00:00:00 [ata_sff/10]
root 193 2 0 Jul15 ? 00:00:00 [ata_sff/11]
root 194 2 0 Jul15 ? 00:00:00 [ata_sff/12]
root 195 2 0 Jul15 ? 00:00:00 [ata_sff/13]
root 196 2 0 Jul15 ? 00:00:00 [ata_sff/14]
root 197 2 0 Jul15 ? 00:00:00 [ata_sff/15]
root 198 2 0 Jul15 ? 00:00:00 [ata_sff/16]
root 199 2 0 Jul15 ? 00:00:00 [ata_sff/17]
root 200 2 0 Jul15 ? 00:00:00 [ata_sff/18]
root 201 2 0 Jul15 ? 00:00:00 [ata_sff/19]
root 202 2 0 Jul15 ? 00:00:00 [ata_sff/20]
root 203 2 0 Jul15 ? 00:00:00 [ata_sff/21]
root 204 2 0 Jul15 ? 00:00:00 [ata_sff/22]
root 205 2 0 Jul15 ? 00:00:00 [ata_sff/23]
root 206 2 0 Jul15 ? 00:00:00 [ksuspend_usbd]
root 207 2 0 Jul15 ? 00:00:00 [khubd]
root 208 2 0 Jul15 ? 00:00:00 [kseriod]
root 209 2 0 Jul15 ? 00:00:00 [md/0]
root 210 2 0 Jul15 ? 00:00:00 [md/1]
root 211 2 0 Jul15 ? 00:00:00 [md/2]
root 212 2 0 Jul15 ? 00:00:00 [md/3]
root 213 2 0 Jul15 ? 00:00:00 [md/4]
root 214 2 0 Jul15 ? 00:00:00 [md/5]
root 215 2 0 Jul15 ? 00:00:00 [md/6]
root 216 2 0 Jul15 ? 00:00:00 [md/7]
root 217 2 0 Jul15 ? 00:00:00 [md/8]
root 218 2 0 Jul15 ? 00:00:00 [md/9]
root 219 2 0 Jul15 ? 00:00:00 [md/10]
root 220 2 0 Jul15 ? 00:00:00 [md/11]
root 221 2 0 Jul15 ? 00:00:00 [md/12]
root 222 2 0 Jul15 ? 00:00:00 [md/13]
root 223 2 0 Jul15 ? 00:00:00 [md/14]
root 224 2 0 Jul15 ? 00:00:00 [md/15]
root 225 2 0 Jul15 ? 00:00:00 [md/16]
root 226 2 0 Jul15 ? 00:00:00 [md/17]
root 227 2 0 Jul15 ? 00:00:00 [md/18]
root 228 2 0 Jul15 ? 00:00:00 [md/19]
root 229 2 0 Jul15 ? 00:00:00 [md/20]
root 230 2 0 Jul15 ? 00:00:00 [md/21]
root 231 2 0 Jul15 ? 00:00:00 [md/22]
root 232 2 0 Jul15 ? 00:00:00 [md/23]
root 233 2 0 Jul15 ? 00:00:00 [md_misc/0]
root 234 2 0 Jul15 ? 00:00:00 [md_misc/1]
root 235 2 0 Jul15 ? 00:00:00 [md_misc/2]
root 236 2 0 Jul15 ? 00:00:00 [md_misc/3]
root 237 2 0 Jul15 ? 00:00:00 [md_misc/4]
root 238 2 0 Jul15 ? 00:00:00 [md_misc/5]
root 239 2 0 Jul15 ? 00:00:00 [md_misc/6]
root 240 2 0 Jul15 ? 00:00:00 [md_misc/7]
root 241 2 0 Jul15 ? 00:00:00 [md_misc/8]
root 242 2 0 Jul15 ? 00:00:00 [md_misc/9]
root 243 2 0 Jul15 ? 00:00:00 [md_misc/10]
root 244 2 0 Jul15 ? 00:00:00 [md_misc/11]
root 245 2 0 Jul15 ? 00:00:00 [md_misc/12]
root 246 2 0 Jul15 ? 00:00:00 [md_misc/13]
root 247 2 0 Jul15 ? 00:00:00 [md_misc/14]
root 248 2 0 Jul15 ? 00:00:00 [md_misc/15]
root 249 2 0 Jul15 ? 00:00:00 [md_misc/16]
root 250 2 0 Jul15 ? 00:00:00 [md_misc/17]
root 251 2 0 Jul15 ? 00:00:00 [md_misc/18]
root 252 2 0 Jul15 ? 00:00:00 [md_misc/19]
root 253 2 0 Jul15 ? 00:00:00 [md_misc/20]
root 254 2 0 Jul15 ? 00:00:00 [md_misc/21]
root 255 2 0 Jul15 ? 00:00:00 [md_misc/22]
root 256 2 0 Jul15 ? 00:00:00 [md_misc/23]
root 257 2 0 Jul15 ? 00:00:00 [linkwatch]
root 274 2 0 Jul15 ? 00:00:12 [khungtaskd]
root 275 2 0 Jul15 ? 00:00:01 [kswapd0]
root 276 2 0 Jul15 ? 00:00:01 [kswapd1]
root 277 2 0 Jul15 ? 00:00:00 [ksmd]
root 278 2 0 Jul15 ? 00:01:06 [khugepaged]
root 279 2 0 Jul15 ? 00:00:00 [aio/0]
root 280 2 0 Jul15 ? 00:00:00 [aio/1]
root 281 2 0 Jul15 ? 00:00:00 [aio/2]
root 282 2 0 Jul15 ? 00:00:00 [aio/3]
root 283 2 0 Jul15 ? 00:00:00 [aio/4]
root 284 2 0 Jul15 ? 00:00:00 [aio/5]
root 285 2 0 Jul15 ? 00:00:00 [aio/6]
root 286 2 0 Jul15 ? 00:00:00 [aio/7]
root 287 2 0 Jul15 ? 00:00:00 [aio/8]
root 288 2 0 Jul15 ? 00:00:00 [aio/9]
root 289 2 0 Jul15 ? 00:00:00 [aio/10]
root 290 2 0 Jul15 ? 00:00:00 [aio/11]
root 291 2 0 Jul15 ? 00:00:00 [aio/12]
root 292 2 0 Jul15 ? 00:00:00 [aio/13]
root 293 2 0 Jul15 ? 00:00:00 [aio/14]
root 294 2 0 Jul15 ? 00:00:00 [aio/15]
root 295 2 0 Jul15 ? 00:00:00 [aio/16]
root 296 2 0 Jul15 ? 00:00:00 [aio/17]
root 297 2 0 Jul15 ? 00:00:00 [aio/18]
root 298 2 0 Jul15 ? 00:00:00 [aio/19]
root 299 2 0 Jul15 ? 00:00:00 [aio/20]
root 300 2 0 Jul15 ? 00:00:00 [aio/21]
root 301 2 0 Jul15 ? 00:00:00 [aio/22]
root 302 2 0 Jul15 ? 00:00:00 [aio/23]
root 303 2 0 Jul15 ? 00:00:00 [crypto/0]
root 304 2 0 Jul15 ? 00:00:00 [crypto/1]
root 305 2 0 Jul15 ? 00:00:00 [crypto/2]
root 306 2 0 Jul15 ? 00:00:00 [crypto/3]
root 307 2 0 Jul15 ? 00:00:00 [crypto/4]
root 308 2 0 Jul15 ? 00:00:00 [crypto/5]
root 309 2 0 Jul15 ? 00:00:00 [crypto/6]
root 310 2 0 Jul15 ? 00:00:00 [crypto/7]
root 311 2 0 Jul15 ? 00:00:00 [crypto/8]
root 312 2 0 Jul15 ? 00:00:00 [crypto/9]
root 313 2 0 Jul15 ? 00:00:00 [crypto/10]
root 314 2 0 Jul15 ? 00:00:00 [crypto/11]
root 315 2 0 Jul15 ? 00:00:00 [crypto/12]
root 316 2 0 Jul15 ? 00:00:00 [crypto/13]
root 317 2 0 Jul15 ? 00:00:00 [crypto/14]
root 318 2 0 Jul15 ? 00:00:00 [crypto/15]
root 319 2 0 Jul15 ? 00:00:00 [crypto/16]
root 320 2 0 Jul15 ? 00:00:00 [crypto/17]
root 321 2 0 Jul15 ? 00:00:00 [crypto/18]
root 322 2 0 Jul15 ? 00:00:00 [crypto/19]
root 323 2 0 Jul15 ? 00:00:00 [crypto/20]
root 324 2 0 Jul15 ? 00:00:00 [crypto/21]
root 325 2 0 Jul15 ? 00:00:00 [crypto/22]
root 326 2 0 Jul15 ? 00:00:00 [crypto/23]
root 331 2 0 Jul15 ? 00:00:00 [kthrotld/0]
root 332 2 0 Jul15 ? 00:00:00 [kthrotld/1]
root 333 2 0 Jul15 ? 00:00:00 [kthrotld/2]
root 334 2 0 Jul15 ? 00:00:00 [kthrotld/3]
root 335 2 0 Jul15 ? 00:00:00 [kthrotld/4]
root 336 2 0 Jul15 ? 00:00:00 [kthrotld/5]
root 337 2 0 Jul15 ? 00:00:00 [kthrotld/6]
root 338 2 0 Jul15 ? 00:00:00 [kthrotld/7]
root 339 2 0 Jul15 ? 00:00:00 [kthrotld/8]
root 340 2 0 Jul15 ? 00:00:00 [kthrotld/9]
root 341 2 0 Jul15 ? 00:00:00 [kthrotld/10]
root 342 2 0 Jul15 ? 00:00:00 [kthrotld/11]
root 343 2 0 Jul15 ? 00:00:00 [kthrotld/12]
root 344 2 0 Jul15 ? 00:00:00 [kthrotld/13]
root 345 2 0 Jul15 ? 00:00:00 [kthrotld/14]
root 346 2 0 Jul15 ? 00:00:00 [kthrotld/15]
root 347 2 0 Jul15 ? 00:00:00 [kthrotld/16]
root 348 2 0 Jul15 ? 00:00:00 [kthrotld/17]
root 349 2 0 Jul15 ? 00:00:00 [kthrotld/18]
root 350 2 0 Jul15 ? 00:00:00 [kthrotld/19]
root 351 2 0 Jul15 ? 00:00:00 [kthrotld/20]
root 352 2 0 Jul15 ? 00:00:00 [kthrotld/21]
root 353 2 0 Jul15 ? 00:00:00 [kthrotld/22]
root 354 2 0 Jul15 ? 00:00:00 [kthrotld/23]
root 373 2 0 Jul15 ? 00:00:00 [kpsmoused]
root 374 2 0 Jul15 ? 00:00:00 [usbhid_resumer]
root 404 2 0 Jul15 ? 00:00:00 [kstriped]
root 529 2 0 Jul15 ? 00:00:00 [scsi_eh_0]
root 565 2 0 Jul15 ? 00:00:00 [scsi_eh_1]
root 566 2 0 Jul15 ? 00:00:00 [scsi_eh_2]
root 567 2 0 Jul15 ? 00:00:00 [scsi_eh_3]
root 568 2 0 Jul15 ? 00:00:00 [scsi_eh_4]
root 569 2 0 Jul15 ? 00:00:00 [scsi_eh_5]
root 570 2 0 Jul15 ? 00:00:00 [scsi_eh_6]
root 684 1 0 Nov14 ? 00:00:00 /usr/sbin/sshd
root 752 2 0 Jul15 ? 00:07:24 [jbd2/sda7-8]
root 753 2 0 Jul15 ? 00:00:00 [ext4-dio-unwrit]
root 1354 2 0 Jul15 ? 00:05:59 [edac-poller]
root 2239 2 0 Jul15 ? 00:00:00 [jbd2/sda1-8]
root 2240 2 0 Jul15 ? 00:00:00 [ext4-dio-unwrit]
root 2241 2 0 Jul15 ? 00:00:00 [jbd2/sda5-8]
root 2242 2 0 Jul15 ? 00:00:00 [ext4-dio-unwrit]
root 2243 2 0 Jul15 ? 00:06:26 [jbd2/sda2-8]
root 2244 2 0 Jul15 ? 00:00:00 [ext4-dio-unwrit]
root 2245 2 0 Jul15 ? 00:00:10 [jbd2/sda3-8]
root 2246 2 0 Jul15 ? 00:00:00 [ext4-dio-unwrit]
root 2278 2 0 Jul15 ? 00:00:00 [kauditd]
root 2590 1 0 Jul15 ? 00:01:02 crond
root 2882 1 0 Jul15 ? 01:29:27 /opt/dell/srvadmin/sbin/dsm_sa_datamgrd
root 2962 2882 0 Jul15 ? 00:00:00 /opt/dell/srvadmin/sbin/dsm_sa_datamgrd
root 3018 1 0 Jul15 ? 00:03:10 /opt/dell/srvadmin/sbin/dsm_sa_eventmgrd
root 3077 1 0 Jul15 ? 00:51:29 /opt/dell/srvadmin/sbin/dsm_sa_snmpd
root 3152 1 0 Jul15 ? 00:00:03 /opt/dell/srvadmin/sbin/dsm_om_shrsvcd
root 3175 1 0 Jul15 ? 04:34:58 /usr/local/HropAgent/HropAgent
root 3208 1 0 Jul15 tty1 00:00:00 /sbin/mingetty /dev/tty1
root 3210 1 0 Jul15 tty2 00:00:00 /sbin/mingetty /dev/tty2
root 3212 1 0 Jul15 tty3 00:00:00 /sbin/mingetty /dev/tty3
root 3214 1 0 Jul15 tty4 00:00:00 /sbin/mingetty /dev/tty4
root 3218 1 0 Jul15 tty5 00:00:00 /sbin/mingetty /dev/tty5
root 3220 1 0 Jul15 tty6 00:00:00 /sbin/mingetty /dev/tty6
root 5474 1 65 15:47 ? 00:00:01 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/director/director/ebin -pa /usr/local/online/deps/baleen/ebin /usr/local/online/deps/bson/ebin /usr/local/online/deps/cowboy/ebin /usr/local/online/deps/cowlib/ebin /usr/local/online/deps/emysql/ebin /usr/local/online/deps/erldis/ebin /usr/local/online/deps/goldrush/ebin /usr/local/online/deps/lager/ebin /usr/local/online/deps/mimetypes/ebin /usr/local/online/deps/mochiweb/ebin /usr/local/online/deps/mongodb/ebin /usr/local/online/deps/ndc/ebin /usr/local/online/deps/nitrogen_core/ebin /usr/local/online/deps/nprocreg/ebin /usr/local/online/deps/pmod_transform/ebin /usr/local/online/deps/ranch/ebin /usr/local/online/deps/simple_bridge/ebin /usr/local/online/deps/sync/ebin /usr/local/online/deps/thrift/ebin -sname director -setcookie island -hidden -pa deps/ndc/ebin -eval ndc:ensure_start(director). -s code_reloader -config /usr/local/online/sys.config -noshell -noshell -noinput -noshell -noinput
root 5515 5474 0 15:47 ? 00:00:00 inet_gethost 4
root 5516 5515 0 15:47 ? 00:00:00 inet_gethost 4
root 5517 22857 1 15:47 ? 00:00:00 /bin/sh -s unix:cmd
root 5518 5517 0 15:47 ? 00:00:00 /bin/sh -s unix:cmd
root 5519 5518 3 15:47 ? 00:00:00 ps -ef
root 5520 5518 0 15:47 ? 00:00:00 grep root
root 8668 1 0 Sep28 ? 07:10:18 /usr/local/mongodb/bin/mongod --config /data/mongodb/etc/mongodb.conf
root 10255 1 3 Oct29 ? 1-01:13:27 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 1048576 -zdbbl 524288 -A 32 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/homer/homer/ebin -pa /usr/local/online/homer/deps/cowboy/ebin /usr/local/online/homer/deps/cowlib/ebin /usr/local/online/homer/deps/erldis/ebin /usr/local/online/homer/deps/goldrush/ebin /usr/local/online/homer/deps/lager/ebin /usr/local/online/homer/deps/ndc/ebin /usr/local/online/homer/deps/ranch/ebin -sname homer -setcookie island -hidden -pa deps/ndc/ebin -eval ndc:ensure_start(homer). -s code_reloader -config /usr/local/online/homer/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 10319 10255 0 Oct29 ? 00:00:00 inet_gethost 4
root 10320 10319 0 Oct29 ? 00:00:00 inet_gethost 4
root 15215 1 0 Jul18 ? 00:06:40 /usr/local/erlang/lib/erlang/erts-5.8.4/bin/epmd -daemon
root 15217 1 1 Jul18 ? 1-15:51:07 /usr/local/erlang/lib/erlang/erts-5.8.4/bin/beam.smp -- -root /usr/local/erlang/lib/erlang -progname erl -- -home /root -- -noshell -noinput -pa ebin edit deps/mochiweb/ebin -boot start_sasl -sname hfs_dev -s hfs -s reloader
root 15515 22893 0 Nov02 ? 00:01:24 inet_gethost 4
root 15697 1 1 12:19 ? 00:03:06 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/ndhub/ndhub/ebin -pa /usr/local/online/deps/baleen/ebin /usr/local/online/deps/bson/ebin /usr/local/online/deps/cowboy/ebin /usr/local/online/deps/cowlib/ebin /usr/local/online/deps/emysql/ebin /usr/local/online/deps/erldis/ebin /usr/local/online/deps/goldrush/ebin /usr/local/online/deps/lager/ebin /usr/local/online/deps/mimetypes/ebin /usr/local/online/deps/mochiweb/ebin /usr/local/online/deps/mongodb/ebin /usr/local/online/deps/ndc/ebin /usr/local/online/deps/nitrogen_core/ebin /usr/local/online/deps/nprocreg/ebin /usr/local/online/deps/pmod_transform/ebin /usr/local/online/deps/ranch/ebin /usr/local/online/deps/simple_bridge/ebin /usr/local/online/deps/sync/ebin /usr/local/online/deps/thrift/ebin -sname ndhub -setcookie island -hidden -eval ndc:ensure_start(ndhub). -s code_reloader -config /usr/local/online/sys.config -noshell -noshell -noinput -noshell -noinput
root 15738 15697 0 12:19 ? 00:00:00 inet_gethost 4
root 15740 15738 0 12:19 ? 00:00:00 inet_gethost 4
root 16891 1 0 Nov15 ? 00:11:55 /usr/bin/python /usr/bin/salt-minion -d
root 18927 1 1 Oct24 ? 18:44:27 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -noshell -noinput -pa ebin edit deps/mochiweb/ebin -boot start_sasl -name http_dev3@127.0.0.1 -setcookie ndcserver_flower3 -s http -s reloader
root 18937 1 1 Oct24 ? 14:40:54 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -noshell -noinput -pa ebin edit deps/mochiweb/ebin -boot start_sasl -name hfs_dev3@127.0.0.1 -setcookie ndcserver_flower3 -s hfs -s reloader
root 18959 1 0 Oct24 ? 00:13:27 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -noshell -noinput -name ndc_manager3@127.0.0.1 -setcookie ndcserver_flower3 -config ./conf/run -boot ndcmgr
root 19066 18959 0 Oct24 ? 00:00:00 inet_gethost 4
root 19067 19066 0 Oct24 ? 00:00:00 inet_gethost 4
root 19077 1 0 Oct24 ? 00:07:56 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -K true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -noshell -noinput -cfgevn 2014 ndc_manager3@127.0.0.1 "ndc flowerpot" bs_flowerpot -name ndc_flower3@127.0.0.1 -setcookie ndcserver_flower3 -config ./conf/run -pz ./ -boot ndc_service
root 19118 19077 0 Oct24 ? 00:00:04 inet_gethost 4
root 19119 19118 0 Oct24 ? 00:00:02 inet_gethost 4
root 19136 18927 0 Oct24 ? 00:00:00 inet_gethost 4
root 19137 19136 0 Oct24 ? 00:00:00 inet_gethost 4
root 20278 1 0 Oct31 ? 00:00:00 /sbin/udevd -d
root 20477 2 0 Sep24 ? 00:03:08 [flush-8:0]
root 20958 1 0 Oct31 ? 00:22:57 /usr/sbin/snmpd -LS0-6d -Lf /dev/null -p /var/run/snmpd.pid
root 21019 1 0 Oct31 ? 00:00:02 /sbin/rsyslogd -i /var/run/syslogd.pid -c 5
root 21347 1 0 Sep24 ? 00:00:00 nginx: master process /usr/local/nginx/bin/nginx -c /usr/local/nginx/conf/nginx.conf
root 21769 1 2 Oct27 ? 1-00:15:04 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 1572864 -zdbbl 524288 -A 32 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/banyan/banyan/ebin -pa /usr/local/online/banyan/deps/erldis/ebin /usr/local/online/banyan/deps/goldrush/ebin /usr/local/online/banyan/deps/lager/ebin /usr/local/online/banyan/deps/ndc/ebin -sname banyan -setcookie island -hidden -pa banyan/ebin -pa deps/ndc/ebin -eval ndc:ensure_start(banyan). -s code_reloader -config /usr/local/online/banyan/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 21813 1 2 Oct27 ? 18:25:03 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 1572864 -zdbbl 524288 -A 32 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/banyan_old/banyan/ebin -pa /usr/local/online/banyan_old/deps/emysql/ebin /usr/local/online/banyan_old/deps/goldrush/ebin /usr/local/online/banyan_old/deps/lager/ebin /usr/local/online/banyan_old/deps/ndc/ebin -sname banyan_old -setcookie island -hidden -pa banyan_old/ebin -eval ndc:ensure_start(banyan). -s code_reloader -config /usr/local/online/banyan_old/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 21824 1 2 Oct27 ? 23:05:59 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 1572864 -zdbbl 524288 -A 32 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/ndpush/ndpush/ebin -pa /usr/local/online/ndpush/deps/bson/ebin /usr/local/online/ndpush/deps/cowboy/ebin /usr/local/online/ndpush/deps/cowlib/ebin /usr/local/online/ndpush/deps/emysql/ebin /usr/local/online/ndpush/deps/erldis/ebin /usr/local/online/ndpush/deps/goldrush/ebin /usr/local/online/ndpush/deps/lager/ebin /usr/local/online/ndpush/deps/mongodb/ebin /usr/local/online/ndpush/deps/ndc/ebin /usr/local/online/ndpush/deps/ranch/ebin -sname ndpush -setcookie island -hidden -pa ndpush/ebin -pa deps/ndc/ebin -eval ndc:ensure_start(ndpush). -s code_reloader -config /usr/local/online/ndpush/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 22260 21769 0 Oct27 ? 00:00:00 inet_gethost 4
root 22262 22260 0 Oct27 ? 00:00:00 inet_gethost 4
root 22264 21813 0 Oct27 ? 00:00:00 inet_gethost 4
root 22265 22264 0 Oct27 ? 00:00:00 inet_gethost 4
root 22274 21824 0 Oct27 ? 00:00:00 inet_gethost 4
root 22286 22274 0 Oct27 ? 00:00:00 inet_gethost 4
root 22294 1 0 Sep26 ? 01:27:54 /usr/local/redis/bin/redis-server *:6379
root 22857 1 8 Oct27 ? 2-23:19:29 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 102400 -zdbbl 131072 -A 4 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/island/island/ebin -pa /usr/local/online/island/deps/emysql/ebin /usr/local/online/island/deps/goldrush/ebin /usr/local/online/island/deps/lager/ebin /usr/local/online/island/deps/mimetypes/ebin /usr/local/online/island/deps/mochiweb/ebin /usr/local/online/island/deps/ndc/ebin /usr/local/online/island/deps/nitrogen_core/ebin /usr/local/online/island/deps/nprocreg/ebin /usr/local/online/island/deps/pmod_transform/ebin /usr/local/online/island/deps/simple_bridge/ebin /usr/local/online/island/deps/sync/ebin -sname island -setcookie island -hidden -pa deps/ndc/ebin -eval ndc:ensure_start(island). -s code_reloader -config /usr/local/online/island/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 22893 22857 0 Oct27 ? 00:01:37 inet_gethost 4
root 22894 22893 0 Oct27 ? 00:02:28 inet_gethost 4
root 24643 1 1 Oct27 ? 14:05:03 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/necktie/necktie/ebin -pa /usr/local/online/necktie/deps/baleen/ebin /usr/local/online/necktie/deps/bson/ebin /usr/local/online/necktie/deps/emysql/ebin /usr/local/online/necktie/deps/goldrush/ebin /usr/local/online/necktie/deps/lager/ebin /usr/local/online/necktie/deps/mongodb/ebin /usr/local/online/necktie/deps/ranch/ebin -sname necktie -setcookie island -hidden -pa ebin -eval application:start(syntax_tools). -eval application:start(compiler). -eval application:start(goldrush). -eval application:start(lager). -eval application:start(bson). -eval application:start(mongodb). -eval application:start(crypto). -eval application:start(emysql). -eval application:start(ranch). -eval application:start(necktie). -s code_reloader -config /usr/local/online/necktie/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 24684 24643 0 Oct27 ? 00:00:00 inet_gethost 4
root 24685 24684 0 Oct27 ? 00:00:00 inet_gethost 4
root 24937 1 1 Oct27 ? 15:37:11 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/bazaars/bazaars/ebin -pa /usr/local/online/bazaars/deps/baleen/ebin /usr/local/online/bazaars/deps/bson/ebin /usr/local/online/bazaars/deps/emysql/ebin /usr/local/online/bazaars/deps/goldrush/ebin /usr/local/online/bazaars/deps/lager/ebin /usr/local/online/bazaars/deps/mongodb/ebin -sname bazaars -setcookie island -hidden -pa bazaars/ebin -eval application:start(syntax_tools). -eval application:start(compiler). -eval application:start(goldrush). -eval application:start(lager). -eval application:start(bson). -eval application:start(mongodb). -eval application:start(inets). -eval application:start(crypto). -eval application:start(emysql). -eval application:start(bazaars). -eval application:start(inets). -eval application:start(crypto). -s code_reloader -config /usr/local/online/bazaars/etc/sys.config -noshell -noshell -noinput -noshell -noinput
root 24978 24937 0 Oct27 ? 00:00:00 inet_gethost 4
root 24979 24978 0 Oct27 ? 00:00:00 inet_gethost 4
root 27683 1 0 Oct22 ? 00:00:00 /bin/sh /usr/local/mysql-5.5.25/bin/mysqld_safe --defaults-file=/data/mysql_data/my.cnf --datadir=/data/mysql_data --pid-file=/data/mysql_data/ip-010031-243091.pid
root 30204 1 0 Jul21 ? 00:00:00 /usr/sbin/vsftpd /etc/vsftpd/vsftpd.conf
root 30852 1 3 Dec02 ? 00:52:46 /usr/local/lib/erlang/erts-6.1/bin/beam.smp -P 1048576 -zdbbl 524288 -A 64 -K true -sub true -- -root /usr/local/lib/erlang -progname erl -- -home /root -- -pa /usr/local/online/login/login/ebin -pa /usr/local/online/deps/baleen/ebin /usr/local/online/deps/bson/ebin /usr/local/online/deps/cowboy/ebin /usr/local/online/deps/cowlib/ebin /usr/local/online/deps/emysql/ebin /usr/local/online/deps/erldis/ebin /usr/local/online/deps/goldrush/ebin /usr/local/online/deps/lager/ebin /usr/local/online/deps/mimetypes/ebin /usr/local/online/deps/mochiweb/ebin /usr/local/online/deps/mongodb/ebin /usr/local/online/deps/ndc/ebin /usr/local/online/deps/nitrogen_core/ebin /usr/local/online/deps/nprocreg/ebin /usr/local/online/deps/pmod_transform/ebin /usr/local/online/deps/ranch/ebin /usr/local/online/deps/simple_bridge/ebin /usr/local/online/deps/sync/ebin /usr/local/online/deps/thrift/ebin -sname login -setcookie island -hidden -pa deps/ndc/ebin -eval ndc:ensure_start(login). -s code_reloader -config /usr/local/online/sys.config -noshell -noshell -noinput -noshell -noinput
root 30999 30852 0 Dec02 ? 00:00:00 inet_gethost 4
root 31000 30999 0 Dec02 ? 00:00:00 inet_gethost 4

修复方案:

加强管理,如果是废弃的后台就关闭掉

版权声明:转载请注明来源 茜茜公主@乌云


漏洞回应

厂商回应:

危害等级:低

漏洞Rank:5

确认时间:2014-12-03 18:39

厂商回复:

感谢 路人甲 提交的漏洞,已安排修复

最新状态:

暂无


漏洞评价:

评论

  1. 2014-12-24 15:05 | 宝宝 ( 普通白帽子 | Rank:125 漏洞数:33 | 我是好宝宝)

    和我之前找的如出一辙啊 WooYun: 福建网龙某后台弱口令

  2. 2014-12-24 16:02 | 茜茜公主 ( 普通白帽子 | Rank:2360 漏洞数:406 | 家里二宝出生,这几个月忙着把屎把尿...忒...)

    @宝宝 呵呵 是滴,扫你剩下的啊