当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0134086

漏洞标题:汽车点评网DNS域传输信息泄漏

相关厂商:xgo.com.cn

漏洞作者: 路人甲

提交时间:2015-08-14 13:03

修复时间:2015-09-28 15:22

公开时间:2015-09-28 15:22

漏洞类型:应用配置错误

危害等级:低

自评Rank:1

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-08-14: 细节已通知厂商并且等待厂商处理中
2015-08-14: 厂商已经确认,细节仅向厂商公开
2015-08-24: 细节向核心白帽子及相关领域专家公开
2015-09-03: 细节向普通白帽子公开
2015-09-13: 细节向实习白帽子公开
2015-09-28: 细节向公众公开

简要描述:

DNS域传输导致任何匿名用户都可以获取DNS服务器某一域的所有记录,将整个企业的基础业务以及网络架构对外暴露从而造成严重的信息泄露,甚至导致企业网络被渗透。

详细说明:

1.管理打打马赛克?

root@localhost:~# dig axfr @ns1.zol.com xgo.com.cn
; <<>> DiG 9.8.4-rpz2+rl005.12-P1 <<>> axfr @ns1.zol.com xgo.com.cn
; (1 server found)
;; global options: +cmd
xgo.com.cn. 300 IN SOA ns.xgo.com.cn. admin.xgo.com.cn. 2014041001 10800 1800 604800 86400
xgo.com.cn. 300 IN NS ns.zol.com.
xgo.com.cn. 300 IN NS ns1.zol.com.
xgo.com.cn. 300 IN A 114.112.87.88
xgo.com.cn. 300 IN MX 10 mail.xgo.com.cn.
xgo.com.cn. 300 IN TXT "v=spf1 ip4:123.103.72.0/24 ip4:117.79.92.96/27 ~all"
2010.xgo.com.cn. 300 IN A 114.112.87.88
360.xgo.com.cn. 300 IN A 114.112.87.80
z201403._domainkey.xgo.com.cn. 300 IN TXT "k=rsa\; p=MEwwDQYJKoZIhvcNAQEBBQADOwAwOAIxALThe9a6AukDA/OJA0fkeFCBU1VmajzLW4EoIJ2J6XLMBl/zma6nIn6ENn7rS93TlQIDAQAB"
active.xgo.com.cn. 300 IN A 114.112.87.80
admin.xgo.com.cn. 300 IN A 117.79.92.107
akesu.xgo.com.cn. 300 IN A 114.112.87.80
anqing.xgo.com.cn. 300 IN A 114.112.87.80
api.xgo.com.cn. 300 IN A 114.112.87.80
appweb.xgo.com.cn. 300 IN A 114.112.87.80
as.xgo.com.cn. 300 IN A 114.112.87.80
bao.xgo.com.cn. 300 IN A 117.79.92.109
baoyang.xgo.com.cn. 300 IN A 114.112.87.77
bb.xgo.com.cn. 300 IN A 114.112.87.80
bbs.xgo.com.cn. 300 IN A 114.112.87.80
bd.xgo.com.cn. 300 IN A 114.112.87.80
*.bdcoop.xgo.com.cn. 300 IN A 122.115.59.78
*.bdcrop.xgo.com.cn. 300 IN A 122.115.59.78
bj.xgo.com.cn. 300 IN A 114.112.87.80
www.bk.xgo.com.cn. 300 IN A 122.115.59.78
bms.xgo.com.cn. 300 IN A 123.103.57.172
bt.xgo.com.cn. 300 IN A 114.112.87.80
buy.xgo.com.cn. 300 IN A 114.112.87.77
bz.xgo.com.cn. 300 IN A 114.112.87.80
car.xgo.com.cn. 300 IN A 114.112.87.80
cc.xgo.com.cn. 300 IN A 114.112.87.80
cd.xgo.com.cn. 300 IN A 114.112.87.80
cf.xgo.com.cn. 300 IN A 114.112.87.80
changzhi.xgo.com.cn. 300 IN A 114.112.87.80
changzhou.xgo.com.cn. 300 IN A 114.112.87.80
chedai.xgo.com.cn. 300 IN A 114.112.87.80
chenzhou.xgo.com.cn. 300 IN A 114.112.87.80
chezhan.xgo.com.cn. 300 IN A 114.112.87.80
city.xgo.com.cn. 300 IN A 114.112.87.80
comments.xgo.com.cn. 300 IN A 117.79.92.111
count.xgo.com.cn. 300 IN A 114.112.87.69
cq.xgo.com.cn. 300 IN A 114.112.87.80
cs.xgo.com.cn. 300 IN A 114.112.87.80
cz.xgo.com.cn. 300 IN A 114.112.87.80
dealer.xgo.com.cn. 300 IN A 114.112.87.80
dealerii.xgo.com.cn. 300 IN A 124.254.2.226
deyang.xgo.com.cn. 300 IN A 114.112.87.80
dg.xgo.com.cn. 300 IN A 114.112.87.80
dl.xgo.com.cn. 300 IN A 114.112.87.80
dlii.xgo.com.cn. 300 IN A 122.115.59.78
drive.xgo.com.cn. 300 IN A 114.112.87.88
dt.xgo.com.cn. 300 IN A 114.112.87.80
dy.xgo.com.cn. 300 IN A 114.112.87.80
dz.xgo.com.cn. 300 IN A 114.112.87.80
ershou.xgo.com.cn. 300 IN A 114.112.87.80
fs.xgo.com.cn. 300 IN A 114.112.87.80
fuyang.xgo.com.cn. 300 IN A 114.112.87.80
fuzhou.xgo.com.cn. 300 IN A 114.112.87.80
fz.xgo.com.cn. 300 IN A 114.112.87.80
ganzhou.xgo.com.cn. 300 IN A 114.112.87.80
gps.xgo.com.cn. 300 IN A 114.112.87.80
groupadmin.xgo.com.cn. 300 IN A 117.79.92.111
guide.xgo.com.cn. 300 IN A 114.112.87.80
guilin.xgo.com.cn. 300 IN A 114.112.87.80
guizhou.xgo.com.cn. 300 IN A 114.112.87.88
gy.xgo.com.cn. 300 IN A 114.112.87.80
gz.xgo.com.cn. 300 IN A 114.112.87.80
ha.xgo.com.cn. 300 IN A 114.112.87.88
hd.xgo.com.cn. 300 IN A 114.112.87.80
hengyang.xgo.com.cn. 300 IN A 114.112.87.80
heze.xgo.com.cn. 300 IN A 114.112.87.80
hezuo.xgo.com.cn. 300 IN A 114.112.87.80
hf.xgo.com.cn. 300 IN A 114.112.87.80
hh.xgo.com.cn. 300 IN A 114.112.87.80
history.xgo.com.cn. 300 IN A 114.112.87.88
hk.xgo.com.cn. 300 IN A 114.112.87.80
hld.xgo.com.cn. 300 IN A 114.112.87.80
hn.xgo.com.cn. 300 IN A 114.112.87.80
hrb.xgo.com.cn. 300 IN A 114.112.87.80
hs.xgo.com.cn. 300 IN A 114.112.87.80
huaihua.xgo.com.cn. 300 IN A 114.112.87.80
huangshan.xgo.com.cn. 300 IN A 114.112.87.80
huizhou.xgo.com.cn. 300 IN A 114.112.87.80
huzhou.xgo.com.cn. 300 IN A 114.112.87.80
hz.xgo.com.cn. 300 IN A 114.112.87.80
icon.xgo.com.cn. 300 IN CNAME img2.xgo.com.cn.
image.xgo.com.cn. 300 IN A 117.79.92.102
img.xgo.com.cn. 300 IN CNAME img2.xgo.com.cn.
img2.xgo.com.cn. 300 IN CNAME cxgoimg.zcdn.com.cn.
img3.xgo.com.cn. 300 IN CNAME img2.xgo.com.cn.
imgd.xgo.com.cn. 300 IN CNAME imgd.zol.com.cn.
imgf.xgo.com.cn. 300 IN CNAME imgf.zol.com.cn.
imgm.xgo.com.cn. 300 IN CNAME img2.xgo.com.cn.
imgr.xgo.com.cn. 300 IN A 114.112.87.88
imp.xgo.com.cn. 300 IN CNAME imp.zol.com.cn.
ja.xgo.com.cn. 300 IN A 114.112.87.80
jh.xgo.com.cn. 300 IN A 114.112.87.80
jilin.xgo.com.cn. 300 IN A 114.112.87.80
jining.xgo.com.cn. 300 IN A 114.112.87.80
jinnang.xgo.com.cn. 300 IN A 117.79.92.111
upload.jinnang.xgo.com.cn. 300 IN A 117.79.92.102
jinzhong.xgo.com.cn. 300 IN A 114.112.87.80
jinzhou.xgo.com.cn. 300 IN A 114.112.87.80
jiujiang.xgo.com.cn. 300 IN A 114.112.87.80
jm.xgo.com.cn. 300 IN A 114.112.87.80
jn.xgo.com.cn. 300 IN A 114.112.87.80
jnii.xgo.com.cn. 300 IN A 124.254.2.226
js.xgo.com.cn. 300 IN CNAME js.zol.com.cn.
jx.xgo.com.cn. 300 IN A 114.112.87.80
jy.xgo.com.cn. 300 IN A 114.112.87.80
jz.xgo.com.cn. 300 IN A 114.112.87.80
kelamayi.xgo.com.cn. 300 IN A 114.112.87.80
km.xgo.com.cn. 300 IN A 114.112.87.80
ks.xgo.com.cn. 300 IN A 114.112.87.80
kuerle.xgo.com.cn. 300 IN A 114.112.87.80
la.xgo.com.cn. 300 IN A 114.112.87.80
labs.xgo.com.cn. 300 IN A 114.112.87.80
langfang.xgo.com.cn. 300 IN A 114.112.87.80
lc.xgo.com.cn. 300 IN A 114.112.87.80
lf.xgo.com.cn. 300 IN A 114.112.87.80
life.xgo.com.cn. 300 IN A 114.112.87.80
liuzhou.xgo.com.cn. 300 IN A 114.112.87.80
ls.xgo.com.cn. 300 IN A 114.112.87.80
luoyang.xgo.com.cn. 300 IN A 114.112.87.80
luzhou.xgo.com.cn. 300 IN A 114.112.87.80
ly.xgo.com.cn. 300 IN A 114.112.87.80
lyg.xgo.com.cn. 300 IN A 114.112.87.88
lz.xgo.com.cn. 300 IN A 114.112.87.80
m.xgo.com.cn. 300 IN A 114.112.87.80
app.m.xgo.com.cn. 300 IN A 114.112.87.80
mail.xgo.com.cn. 300 IN A 123.103.72.60
mall.xgo.com.cn. 300 IN A 114.112.87.77
mianyang.xgo.com.cn. 300 IN A 114.112.87.80
mz.xgo.com.cn. 300 IN A 114.112.87.80
nanchong.xgo.com.cn. 300 IN A 114.112.87.80
nb.xgo.com.cn. 300 IN A 114.112.87.80
nc.xgo.com.cn. 300 IN A 114.112.87.80
newdealer.xgo.com.cn. 300 IN A 114.112.87.88
news.xgo.com.cn. 300 IN A 114.112.87.80
nj.xgo.com.cn. 300 IN A 114.112.87.80
nn.xgo.com.cn. 300 IN A 114.112.87.80
nt.xgo.com.cn. 300 IN A 114.112.87.80
ny.xgo.com.cn. 300 IN A 114.112.87.80
ordos.xgo.com.cn. 300 IN A 114.112.87.88
photo.xgo.com.cn. 300 IN CNAME csimg.zcdn.com.cn.
pic.xgo.com.cn. 300 IN CNAME pic.zol.com.cn.
price.xgo.com.cn. 300 IN A 114.112.87.80
product.xgo.com.cn. 300 IN A 114.112.87.80
putian.xgo.com.cn. 300 IN A 114.112.87.88
px.xgo.com.cn. 300 IN A 114.112.87.80
qd.xgo.com.cn. 300 IN A 114.112.87.80
qhd.xgo.com.cn. 300 IN A 114.112.87.80
qujing.xgo.com.cn. 300 IN A 114.112.87.80
qz.xgo.com.cn. 300 IN A 114.112.87.80
reviews.xgo.com.cn. 300 IN A 114.112.87.80
rz.xgo.com.cn. 300 IN A 114.112.87.80
sanming.xgo.com.cn. 300 IN A 114.112.87.80
search.xgo.com.cn. 300 IN A 114.112.87.80
service.xgo.com.cn. 300 IN A 114.112.87.77
sh.xgo.com.cn. 300 IN A 114.112.87.80
shangrao.xgo.com.cn. 300 IN A 114.112.87.80
shaoyang.xgo.com.cn. 300 IN A 114.112.87.80
shii.xgo.com.cn. 300 IN A 124.254.2.226
shiyan.xgo.com.cn. 300 IN A 114.112.87.80
sjz.xgo.com.cn. 300 IN A 114.112.87.80
sjzii.xgo.com.cn. 300 IN A 124.254.2.226
sq.xgo.com.cn. 300 IN A 114.112.87.88
st.xgo.com.cn. 300 IN A 114.112.87.80
stat.xgo.com.cn. 300 IN CNAME stat.zol.com.cn.
subadmin.xgo.com.cn. 300 IN A 117.79.92.107
suining.xgo.com.cn. 300 IN A 114.112.87.80
suzhou.xgo.com.cn. 300 IN A 114.112.87.80
sx.xgo.com.cn. 300 IN A 114.112.87.80
sy.xgo.com.cn. 300 IN A 114.112.87.80
syii.xgo.com.cn. 300 IN A 124.254.2.226
sz.xgo.com.cn. 300 IN A 114.112.87.80
t.xgo.com.cn. 300 IN A 114.112.87.88
ta.xgo.com.cn. 300 IN A 114.112.87.80
taizhou.xgo.com.cn. 300 IN A 114.112.87.80
dealer.test.xgo.com.cn. 300 IN A 117.79.92.112
m.test.xgo.com.cn. 300 IN A 117.79.92.112
service.test.xgo.com.cn. 300 IN A 117.79.92.112
tj.xgo.com.cn. 300 IN A 114.112.87.80
tjbh.xgo.com.cn. 300 IN A 114.112.87.80
ts.xgo.com.cn. 300 IN A 114.112.87.80
ty.xgo.com.cn. 300 IN A 114.112.87.80
tz.xgo.com.cn. 300 IN A 114.112.87.80
upimage.xgo.com.cn. 300 IN A 117.79.92.102
upimg.xgo.com.cn. 300 IN A 117.79.92.102
v.xgo.com.cn. 300 IN A 114.112.87.80
wanghai.xgo.com.cn. 300 IN A 114.112.87.88
wap.xgo.com.cn. 300 IN A 114.112.87.88
weihai.xgo.com.cn. 300 IN A 114.112.87.80
wf.xgo.com.cn. 300 IN A 114.112.87.80
wh.xgo.com.cn. 300 IN A 114.112.87.80
wuhu.xgo.com.cn. 300 IN A 114.112.87.80
www.xgo.com.cn. 300 IN A 114.112.87.80
wx.xgo.com.cn. 300 IN A 114.112.87.80
wz.xgo.com.cn. 300 IN A 114.112.87.80
xa.xgo.com.cn. 300 IN A 114.112.87.80
xg.xgo.com.cn. 300 IN A 114.112.87.80
xiangtan.xgo.com.cn. 300 IN A 114.112.87.80
xianning.xgo.com.cn. 300 IN A 114.112.87.80
xining.xgo.com.cn. 300 IN A 114.112.87.80
xinyu.xgo.com.cn. 300 IN A 114.112.87.80
xj.xgo.com.cn. 300 IN A 114.112.87.80
xm.xgo.com.cn. 300 IN A 114.112.87.80
xt.xgo.com.cn. 300 IN A 114.112.87.80
xtup.xgo.com.cn. 300 IN A 117.79.92.111
xx.xgo.com.cn. 300 IN A 114.112.87.80
xy.xgo.com.cn. 300 IN A 114.112.87.80
xz.xgo.com.cn. 300 IN A 114.112.87.88
yancheng.xgo.com.cn. 300 IN A 114.112.87.88
yangzhou.xgo.com.cn. 300 IN A 114.112.87.80
yc.xgo.com.cn. 300 IN A 114.112.87.80
yili.xgo.com.cn. 300 IN A 114.112.87.80
yinchuan.xgo.com.cn. 300 IN A 114.112.87.80
yk.xgo.com.cn. 300 IN A 114.112.87.80
yongpin.xgo.com.cn. 300 IN A 117.79.92.115
yt.xgo.com.cn. 300 IN A 114.112.87.80
yulin.xgo.com.cn. 300 IN A 114.112.87.80
yuncheng.xgo.com.cn. 300 IN A 114.112.87.80
yuxi.xgo.com.cn. 300 IN A 114.112.87.80
yw.xgo.com.cn. 300 IN A 114.112.87.80
yy.xgo.com.cn. 300 IN A 114.112.87.80
zb.xgo.com.cn. 300 IN A 114.112.87.80
zdc.xgo.com.cn. 300 IN A 114.112.87.80
zh.xgo.com.cn. 300 IN A 114.112.87.80
zhidao.xgo.com.cn. 300 IN CNAME open.zhidao.baidu.com.
zhuaqu.xgo.com.cn. 300 IN A 114.112.87.88
zhuzhou.xgo.com.cn. 300 IN A 114.112.87.80
zj.xgo.com.cn. 300 IN A 114.112.87.80
zjk.xgo.com.cn. 300 IN A 114.112.87.80
zs.xgo.com.cn. 300 IN A 114.112.87.80
zunyi.xgo.com.cn. 300 IN A 114.112.87.80
zz.xgo.com.cn. 300 IN A 114.112.87.80
xgo.com.cn. 300 IN SOA ns.xgo.com.cn. admin.xgo.com.cn. 2014041001 10800 1800 604800 86400
;; Query time: 58 msec
;; SERVER: 123.103.72.22#53(123.103.72.22)
;; WHEN: Fri Aug 14 12:38:16 2015
;; XFR size: 237 records (messages 1, bytes 5273)

漏洞证明:

修复方案:

限制IP、使用key认证.
毕竟这个暴露了你们的后台地址 = =。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:低

漏洞Rank:5

确认时间:2015-08-14 15:21

厂商回复:

感谢,已经处理完毕。

最新状态:

暂无


漏洞评价:

评论