漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-090759
漏洞标题:大众点评重要测试系统暴露导致高危注入
相关厂商:大众点评
漏洞作者: if、so
提交时间:2015-01-09 11:17
修复时间:2015-02-23 11:18
公开时间:2015-02-23 11:18
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:20
漏洞状态:厂商已经确认
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-01-09: 细节已通知厂商并且等待厂商处理中
2015-01-09: 厂商已经确认,细节仅向厂商公开
2015-01-19: 细节向核心白帽子及相关领域专家公开
2015-01-29: 细节向普通白帽子公开
2015-02-08: 细节向实习白帽子公开
2015-02-23: 细节向公众公开
简要描述:
大众点评重要测试系统暴露导致高危注入,海量数据库
详细说明:
如图,很重要的系统,让我想到了支付宝的那个可以更新余额的系统
查询处存在注入,mobileno
http://ceshi.51ping.com/getUserInfo?usernickname=iamp912&mobileno=xxxxx
海量数据,由于是mysql errorbased注入,数据简直和水一样来。。
databases
mysql用户账号密码!!
这些数据可能导致整个业务线数据泄露
库太多了,不好分辨,随便找了一个试试
看到forum库,尝试找dz论坛,找了好久,终于找到
bbs.51ping.com/bbs
成功进入后台
数据库权限很高,直接读文件
就不一一列举了,把数据对应上系统是个麻烦事
漏洞证明:
mysql用户账号密码!!
[*] 'analytic'@'10.1.%'
[*] 'analytic'@'10.101.%'
[*] 'analytic'@'10.128.%'
[*] 'analytic'@'10.2.%'
[*] 'analytic'@'192.168.%'
[*] 'analytic_r'@'10.1.%'
[*] 'analytic_r'@'10.101.%'
[*] 'analytic_r'@'10.128.%'
[*] 'analytic_r'@'10.2.%'
[*] 'analytic_r'@'192.168.%'
[*] 'aspnet_API'@'10.1.%'
[*] 'aspnet_API'@'10.128.%.%'
[*] 'aspnet_API'@'192.168.%'
[*] 'aspnet_dianping'@'10.1.%'
[*] 'aspnet_dianping'@'10.128.%'
[*] 'aspnet_dianping'@'10.254.25%'
[*] 'aspnet_dianping'@'192.168.%'
[*] 'aspnet_group'@'10.1.%'
[*] 'aspnet_group'@'10.128.%.%'
[*] 'aspnet_group'@'192.168.%'
[*] 'aspnet_sys'@'10.1.%'
[*] 'aspnet_sys'@'10.128.%.%'
[*] 'aspnet_sys'@'192.168.%'
[*] 'aspnet_user'@'10.1.%'
[*] 'aspnet_user'@'10.128.%.%'
[*] 'aspnet_user'@'192.168.%'
[*] 'bamenu'@'10.1.%'
[*] 'bamenu'@'10.101.%'
[*] 'bamenu'@'10.128.%'
[*] 'bamenu'@'10.2.%'
[*] 'bamenu'@'192.168.%'
[*] 'bamenu_r'@'10.1.%'
[*] 'bamenu_r'@'10.101.%'
[*] 'bamenu_r'@'10.128.%'
[*] 'bamenu_r'@'10.2.%'
[*] 'bamenu_r'@'192.168.%'
[*] 'beauty'@'10.1.%'
[*] 'beauty'@'10.101.%'
[*] 'beauty'@'10.128.%'
[*] 'beauty'@'10.2.%'
[*] 'beauty'@'192.168.%'
[*] 'beauty_r'@'10.1.%'
[*] 'beauty_r'@'10.101.%'
[*] 'beauty_r'@'10.128.%'
[*] 'beauty_r'@'10.2.%'
[*] 'beauty_r'@'192.168.%'
[*] 'binlog'@'10.1.%'
[*] 'binlog'@'10.128.%.%'
[*] 'binlog'@'192.168.%'
[*] 'bonus'@'10.1.%'
[*] 'bonus'@'10.101.%'
[*] 'bonus'@'10.128.%'
[*] 'bonus'@'10.2.%'
[*] 'bonus'@'192.168.%'
[*] 'bonus_r'@'10.1.%'
[*] 'bonus_r'@'10.101.%'
[*] 'bonus_r'@'10.128.%'
[*] 'bonus_r'@'10.2.%'
[*] 'bonus_r'@'192.168.%'
[*] 'CMAdmin'@'10.128.%.%'
[*] 'CMAdmin'@'192.168.%'
[*] 'dbi_user'@'10.128.%.%'
[*] 'dbi_user'@'192.168.%'
[*] 'dianping.qa'@'10.1.77.%'
[*] 'dianping.qa'@'10.128.%'
[*] 'dianping.qa'@'192.168.%'
[*] 'dong.wang'@'10.1.1.62'
[*] 'dp_monitor'@'10.1.1.111'
[*] 'dp_monitor'@'localhost'
[*] 'dpbackup'@'localhost'
[*] 'dpbase_auth'@'10.1.2.119'
[*] 'dpbase_auth'@'10.1.2.139'
[*] 'dpbase_auth'@'10.1.77.211'
[*] 'dpclose'@'localhost'
[*] 'dpcom_adpt'@'10.1.%'
[*] 'dpcom_adpt'@'10.101.%'
[*] 'dpcom_adpt'@'10.128.%'
[*] 'dpcom_adpt'@'10.2.%'
[*] 'dpcom_adpt'@'192.168.%'
[*] 'dpcom_adpt_r'@'10.1.%'
[*] 'dpcom_adpt_r'@'10.101.%'
[*] 'dpcom_adpt_r'@'10.128.%'
[*] 'dpcom_adpt_r'@'10.2.%'
[*] 'dpcom_adpt_r'@'192.168.%'
[*] 'dpcom_cas'@'10.1.%'
[*] 'dpcom_cas'@'10.128.%'
[*] 'dpcom_cas'@'192.168.%'
[*] 'dpcom_cas_r'@'10.1.%'
[*] 'dpcom_cas_r'@'10.128.%'
[*] 'dpcom_cas_r'@'192.168.%'
[*] 'dpcom_crm'@'10.1.%'
[*] 'dpcom_crm'@'10.101.%'
[*] 'dpcom_crm'@'10.128.%'
[*] 'dpcom_crm'@'10.2.%'
[*] 'dpcom_crm'@'192.168.%'
[*] 'dpcom_crm_r'@'10.1.%'
[*] 'dpcom_crm_r'@'10.101.%'
[*] 'dpcom_crm_r'@'10.128.%'
[*] 'dpcom_crm_r'@'10.2.%'
[*] 'dpcom_crm_r'@'192.168.%'
[*] 'dpcom_dp_r'@'10.128.%.%'
[*] 'dpcom_dp_r'@'192.168.%'
[*] 'dpcom_emd'@'10.1.%'
[*] 'dpcom_emd'@'10.101.%'
[*] 'dpcom_emd'@'10.128.%'
[*] 'dpcom_emd'@'10.2.%'
[*] 'dpcom_emd'@'192.168.%'
[*] 'dpcom_emd_r'@'10.1.%'
[*] 'dpcom_emd_r'@'10.101.%'
[*] 'dpcom_emd_r'@'10.128.%'
[*] 'dpcom_emd_r'@'10.2.%'
[*] 'dpcom_emd_r'@'192.168.%'
[*] 'dpcom_fcr'@'10.1.%'
[*] 'dpcom_fcr'@'10.128.%'
[*] 'dpcom_fcr'@'192.168.%'
[*] 'dpcom_fcr_r'@'10.1.%'
[*] 'dpcom_fcr_r'@'10.128.%'
[*] 'dpcom_fcr_r'@'192.168.%'
[*] 'dpcom_job_r'@'10.1.%'
[*] 'dpcom_job_r'@'10.128.%.%'
[*] 'dpcom_job_r'@'192.168.%'
[*] 'dpcom_operation'@'10.1.%'
[*] 'dpcom_operation'@'10.101.%'
[*] 'dpcom_operation'@'10.128.%'
[*] 'dpcom_operation'@'10.2.%'
[*] 'dpcom_operation'@'192.168.%'
[*] 'dpcom_rtxum'@'10.1.%'
[*] 'dpcom_rtxum'@'10.128.%'
[*] 'dpcom_rtxum'@'192.168.%'
[*] 'dpcom_rtxum_r'@'10.1.%'
[*] 'dpcom_rtxum_r'@'10.128.%'
[*] 'dpcom_rtxum_r'@'192.168.%'
[*] 'dpcom_sys_r'@'192.168.%'
[*] 'dpcomm'@'10.1.%'
[*] 'dpcomm'@'10.128.%'
[*] 'DPK2Server'@'10.1.%'
[*] 'DPK2Server'@'10.101.%'
[*] 'DPK2Server'@'10.128.%'
[*] 'DPK2Server'@'10.2.%'
[*] 'DPK2Server'@'192.168.%'
[*] 'DPK2Server_r'@'10.1.%'
[*] 'DPK2Server_r'@'10.101.%'
[*] 'DPK2Server_r'@'10.128.%'
[*] 'DPK2Server_r'@'10.2.%'
[*] 'DPK2Server_r'@'192.168.%'
[*] 'dpk2server'@'10.1.%'
[*] 'dpk2server'@'10.101.%'
[*] 'dpk2server'@'10.128.%'
[*] 'dpk2server'@'10.2.%'
[*] 'dpk2server'@'192.168.%'
[*] 'dpk2server_r'@'10.1.%'
[*] 'dpk2server_r'@'10.101.%'
[*] 'dpk2server_r'@'10.128.%'
[*] 'dpk2server_r'@'10.2.%'
[*] 'dpk2server_r'@'192.168.%'
[*] 'dploader'@'localhost'
[*] 'dpmasterdata'@'10.1.%'
[*] 'dpmasterdata'@'10.101.%'
[*] 'dpmasterdata'@'10.128.%'
[*] 'dpmasterdata'@'10.2.%'
[*] 'dpmasterdata'@'192.168.%'
[*] 'dpmasterdata_r'@'10.1.%'
[*] 'dpmasterdata_r'@'10.101.%'
[*] 'dpmasterdata_r'@'10.128.%'
[*] 'dpmasterdata_r'@'10.2.%'
[*] 'dpmasterdata_r'@'192.168.%'
[*] 'dpmobile'@'10.1.%'
[*] 'dpmobile'@'10.128.%'
[*] 'dpmobile'@'192.168.%'
[*] 'dpmobile_r'@'10.1.%'
[*] 'dpmobile_r'@'10.128.%'
[*] 'dpmobile_r'@'192.168.%'
[*] 'dpreview'@'10.1.%'
[*] 'dpreview'@'10.101.%'
[*] 'dpreview'@'10.128.%'
[*] 'dpreview'@'10.2.%'
[*] 'dpreview'@'192.168.%'
[*] 'dpreview_r'@'10.1.%'
[*] 'dpreview_r'@'10.101.%'
[*] 'dpreview_r'@'10.128.%'
[*] 'dpreview_r'@'10.2.%'
[*] 'dpreview_r'@'192.168.%'
[*] 'dpsf'@'10.1.%'
[*] 'dpsf'@'10.101.%'
[*] 'dpsf'@'10.128.%'
[*] 'dpsf'@'10.2.%'
[*] 'dpsf'@'192.168.%'
[*] 'dpsf_r'@'10.1.%'
[*] 'dpsf_r'@'10.101.%'
[*] 'dpsf_r'@'10.128.%'
[*] 'dpsf_r'@'10.2.%'
[*] 'dpsf_r'@'192.168.%'
[*] 'dpshop'@'10.1.%'
[*] 'dpshop'@'10.101.%'
[*] 'dpshop'@'10.128.%'
[*] 'dpshop'@'10.2.%'
[*] 'dpshop'@'192.168.%'
[*] 'dpshop_a'@'10.1.%'
[*] 'dpshop_a'@'10.101.%'
[*] 'dpshop_a'@'10.128.%'
[*] 'dpshop_a'@'10.2.%'
[*] 'dpshop_a'@'192.168.%'
[*] 'dpshop_a_r'@'10.1.%'
[*] 'dpshop_a_r'@'10.101.%'
[*] 'dpshop_a_r'@'10.128.%'
[*] 'dpshop_a_r'@'10.2.%'
[*] 'dpshop_a_r'@'192.168.%'
[*] 'dpshop_r'@'10.1.%'
[*] 'dpshop_r'@'10.101.%'
[*] 'dpshop_r'@'10.128.%'
[*] 'dpshop_r'@'10.2.%'
[*] 'dpshop_r'@'192.168.%'
[*] 'faping.miao'@'10.1.1.62'
[*] 'form'@'10.1.%'
[*] 'form'@'10.128.%'
[*] 'form'@'10.254.251.%'
[*] 'form'@'192.168.%'
[*] 'form_r'@'10.1.%'
[*] 'form_r'@'10.128.%'
[*] 'form_r'@'192.168.%'
[*] 'forum'@'10.1.%'
[*] 'forum'@'10.101.%'
[*] 'forum'@'10.128.%'
[*] 'forum'@'10.2.%'
[*] 'forum'@'192.168.%'
[*] 'forum_r'@'10.1.%'
[*] 'forum_r'@'10.101.%'
[*] 'forum_r'@'10.128.%'
[*] 'forum_r'@'10.2.%'
[*] 'forum_r'@'192.168.%'
[*] 'freshdp'@'10.128.%.%'
[*] 'freshdp'@'192.168.%'
[*] 'FSAccounting'@'10.1.%'
[*] 'FSAccounting'@'10.101.%'
[*] 'FSAccounting'@'10.128.%'
[*] 'FSAccounting'@'10.2.%'
[*] 'FSAccounting'@'192.168.%'
[*] 'FSAccounting_r'@'10.1.%'
[*] 'FSAccounting_r'@'10.101.%'
[*] 'FSAccounting_r'@'10.128.%'
[*] 'FSAccounting_r'@'10.2.%'
[*] 'FSAccounting_r'@'192.168.%'
[*] 'fsexpense'@'10.1.%'
[*] 'fsexpense'@'10.101.%'
[*] 'fsexpense'@'10.128.%'
[*] 'fsexpense'@'10.2.%'
[*] 'fsexpense'@'192.168.%'
[*] 'fsexpense_r'@'10.1.%'
[*] 'fsexpense_r'@'10.101.%'
[*] 'fsexpense_r'@'10.128.%'
[*] 'fsexpense_r'@'10.2.%'
[*] 'fsexpense_r'@'192.168.%'
[*] 'FSReport'@'10.1.%'
[*] 'FSReport'@'10.101.%'
[*] 'FSReport'@'10.128.%'
[*] 'FSReport'@'10.2.%'
[*] 'FSReport'@'192.168.%'
[*] 'FSReport_r'@'10.1.%'
[*] 'FSReport_r'@'10.101.%'
[*] 'FSReport_r'@'10.128.%'
[*] 'FSReport_r'@'10.2.%'
[*] 'FSReport_r'@'192.168.%'
[*] 'fsworkflow'@'10.1.%'
[*] 'fsworkflow'@'10.101.%'
[*] 'fsworkflow'@'10.128.%'
[*] 'fsworkflow'@'10.2.%'
[*] 'fsworkflow'@'192.168.%'
[*] 'fsworkflow_r'@'10.1.%'
[*] 'fsworkflow_r'@'10.101.%'
[*] 'fsworkflow_r'@'10.128.%'
[*] 'fsworkflow_r'@'10.2.%'
[*] 'fsworkflow_r'@'192.168.%'
[*] 'gpadmin'@'10.1.1.239'
[*] 'haproxy'@'192.168.%'
[*] 'hong.wang'@'10.128.%.%'
[*] 'hong.wang'@'192.168.%'
[*] 'hrservice'@'10.1.%'
[*] 'hrservice'@'10.101.%'
[*] 'hrservice'@'10.128.%'
[*] 'hrservice'@'10.2.%'
[*] 'hrservice'@'192.168.%'
[*] 'hrservice_r'@'10.1.%'
[*] 'hrservice_r'@'10.101.%'
[*] 'hrservice_r'@'10.128.%'
[*] 'hrservice_r'@'10.2.%'
[*] 'hrservice_r'@'192.168.%'
[*] 'imageflow'@'10.1.%'
[*] 'imageflow'@'10.101.%'
[*] 'imageflow'@'10.128.%'
[*] 'imageflow'@'10.2.%'
[*] 'imageflow'@'192.168.%'
[*] 'imageflow_r'@'10.1.%'
[*] 'imageflow_r'@'10.101.%'
[*] 'imageflow_r'@'10.128.%'
[*] 'imageflow_r'@'10.2.%'
[*] 'imageflow_r'@'192.168.%'
[*] 'jin.huang'@'10.128.%.%'
[*] 'jin.huang'@'192.168.%'
[*] 'junyi.lu'@'10.1.1.%'
[*] 'mail_mirror'@'10.1.%'
[*] 'mmm_agent'@'10.1.77.%'
[*] 'mmm_monitor'@'10.1.77.%'
[*] 'motion'@'10.1.%'
[*] 'motion'@'10.101.%'
[*] 'motion'@'10.128.%'
[*] 'motion'@'10.2.%'
[*] 'motion'@'192.168.%'
[*] 'motion_r'@'10.1.%'
[*] 'motion_r'@'10.101.%'
[*] 'motion_r'@'10.128.%'
[*] 'motion_r'@'10.2.%'
[*] 'motion_r'@'192.168.%'
[*] 'myadmin'@'10.1.%'
[*] 'myadmin'@'10.1.1.186'
[*] 'myadmin'@'10.1.1.231'
[*] 'myadmin'@'10.1.1.62'
[*] 'myadmin'@'192.168.%'
[*] 'myadmin'@'localhost'
[*] 'overseas'@'10.1.%'
[*] 'overseas'@'10.101.%'
[*] 'overseas'@'10.128.%'
[*] 'overseas'@'10.2.%'
[*] 'overseas'@'192.168.%'
[*] 'overseas_r'@'10.1.%'
[*] 'overseas_r'@'10.101.%'
[*] 'overseas_r'@'10.128.%'
[*] 'overseas_r'@'10.2.%'
[*] 'overseas_r'@'192.168.%'
[*] 'qunying.liu'@'10.1.%'
[*] 'repl'@'10.1.77.%'
[*] 'root'@'localhost'
[*] 'ryan.yu'@'10.128.%.%'
[*] 'ryan.yu'@'10.254.25%'
[*] 'ryan.yu'@'192.168.%'
[*] 'SearchKV'@'10.128.%.%'
[*] 'SearchKV'@'192.168.%'
[*] 'searchportal'@'10.1.%'
[*] 'searchportal'@'10.128.%'
[*] 'searchportal'@'192.168.%'
[*] 'searchportal_r'@'10.1.%'
[*] 'searchportal_r'@'10.128.%'
[*] 'searchportal_r'@'192.168.%'
[*] 'slb'@'10.1.%'
[*] 'slb'@'10.101.%'
[*] 'slb'@'10.128.%'
[*] 'slb'@'10.2.%'
[*] 'slb'@'192.168.%'
[*] 'slb_r'@'10.1.%'
[*] 'slb_r'@'10.101.%'
[*] 'slb_r'@'10.128.%'
[*] 'slb_r'@'10.2.%'
[*] 'slb_r'@'192.168.%'
[*] 'tempuser_L1U0'@'10.254.25%'
[*] 'tempuser_L1U0'@'192.168.%'
[*] 'tempuser_L2U0'@'10.254.25%'
[*] 'tempuser_L2U0'@'192.168.%'
[*] 'tempuser_L3U0'@'10.254.25%'
[*] 'tempuser_L3U0'@'192.168.%'
[*] 'tempuser_L3U1'@'10.254.25%'
[*] 'tempuser_L3U1'@'192.168.%'
[*] 'toplist'@'10.1.%'
[*] 'toplist'@'10.101.%'
[*] 'toplist'@'10.128.%'
[*] 'toplist'@'10.2.%'
[*] 'toplist'@'192.168.%'
[*] 'toplist_r'@'10.1.%'
[*] 'toplist_r'@'10.101.%'
[*] 'toplist_r'@'10.128.%'
[*] 'toplist_r'@'10.2.%'
[*] 'toplist_r'@'192.168.%'
[*] 'wechat'@'10.1.%'
[*] 'wechat'@'10.101.%'
[*] 'wechat'@'10.128.%'
[*] 'wechat'@'10.2.%'
[*] 'wechat'@'192.168.%'
[*] 'wechat_r'@'10.1.%'
[*] 'wechat_r'@'10.101.%'
[*] 'wechat_r'@'10.128.%'
[*] 'wechat_r'@'10.2.%'
[*] 'wechat_r'@'192.168.%'
[*] 'welife'@'10.1.%'
[*] 'welife'@'10.101.%'
[*] 'welife'@'10.128.%'
[*] 'welife'@'10.2.%'
[*] 'welife'@'192.168.%'
[*] 'welife_r'@'10.1.%'
[*] 'welife_r'@'10.101.%'
[*] 'welife_r'@'10.128.%'
[*] 'welife_r'@'10.2.%'
[*] 'welife_r'@'192.168.%'
[*] 'wesms'@'10.1.%'
[*] 'wesms'@'10.101.%'
[*] 'wesms'@'10.128.%'
[*] 'wesms'@'10.2.%'
[*] 'wesms'@'192.168.%'
[*] 'wesms_r'@'10.1.%'
[*] 'wesms_r'@'10.101.%'
[*] 'wesms_r'@'10.128.%'
[*] 'wesms_r'@'10.2.%'
[*] 'wesms_r'@'192.168.%'
[*] 'zhiyuan.li'@'10.1.%'
[*] 'zhiyuan.li'@'10.128.%.%'
[*] 'zhiyuan.li'@'192.168.%'
</code>
这些数据可能导致整个业务线数据泄露
库太多了,不好分辨,随便找了一个试试
看到forum库,尝试找dz论坛,找了好久,终于找到
bbs.51ping.com/bbs
成功进入后台
数据库权限很高,直接读文件
修复方案:
版权声明:转载请注明来源 if、so@乌云
漏洞回应
厂商回应:
危害等级:高
漏洞Rank:15
确认时间:2015-01-09 15:22
厂商回复:
感谢,一次重大失误的配置造成的
最新状态:
暂无