漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2016-0196967
漏洞标题:山东省某市人社局GetShell影响千万敏感数据
相关厂商:山东省某市人社局
漏洞作者: 路人甲
提交时间:2016-04-18 11:50
修复时间:2016-06-06 11:50
公开时间:2016-06-06 11:50
漏洞类型:系统/服务补丁不及时
危害等级:高
自评Rank:12
漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2016-04-18: 细节已通知厂商并且等待厂商处理中
2016-04-22: 厂商已经确认,细节仅向厂商公开
2016-05-02: 细节向核心白帽子及相关领域专家公开
2016-05-12: 细节向普通白帽子公开
2016-05-22: 细节向实习白帽子公开
2016-06-06: 细节向公众公开
简要描述:
...
详细说明:
反序列getshell,发现了已有shell,直接引用
**.**.**.**:8002/bea_wls_internal/test.jsp
pwd:
*****11*****
<url>jdbc:oracle:thin:@**.**.**.**:1521:jnwsfwdb1</url>
<driver-name>oracle.jdbc.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>isso</value>
</property>
</properties>
<password-encrypted>{AES}jLCNt4LqaH4FXPOXIardbPeQlqvm51YyRcaZGOaXSzo=</password-encrypted>
SI EMP_PLAN 710845465
SI MEDI_ACCOUNT 206113580
SIBK AGED_ACCOUNT 162101411
SI HARM_ACCOUNT 150955241
MD CARD_INCOME 146944271
MD CARD_PAYOUT 139296091
SI LOST_ACCOUNT 137231734
SI BIRTH_ACCOUNT 129290852
DE JOB_DATA 76295521
DE EMP_PLAN_BAK_2014 70936969
DE EMP_PLAN 70343287
SIBK AGED_ACCOUNT_HIS 48325928
SI EMP_PAY_HIS 42943980
SI BILL_DETL 25348181
SI ORGN_DUE_PAY_GENL 23845243
SI BILL_PART 23541691
SI EMP_ADD 22267670
SI AGED_ACCOUNT 21791494
SI AGED_ACCOUNT_SUM 17387020
SISO ORGN_DUE_PAY_GENL 15052854
SI EMP_CMPL 12587398
MD CARD_ACCOUNT 9460737
MD EMP_NATL 8392716
SI PER_REG 7714891
SI BILL_GENL 6197620
SISO BIZ_LOG_INFO160303 5347232
CSI EMP_NATL 5214840
SI CSI_EMP_NATL 5192421
AGED EMP_GIV_STD 4716356
SISO EMP_NATL 4695524
DE DECLARE_NATL 4241822
SI ORGN_RATE 4161692
DE DECLARE_NATL_BAK_2014 4025052
SI EMP_NATL 3639073
SYS WRM$_SNAPSHOT_DETAILS 3452909
DE DECLARE_NATL_20150706 3268305
DE DECLARE_NATL_BF 3244266
DE ORGN_PLAN 3136815
SI SI_DWS_USER_20151029 2421023
SIBK EMP_PAY_HIS 2174245
DE EMP_ADD_GRBH 2118020
MD PATIENT_INFO 2071436
SI LOGINRECORD 2007114
DE DECLARE_NATL_20150116_2_2 1664522
LOST EMP_GIV_HIS 1503376
SYS WRI$_OPTSTAT_HISTGRM_HISTORY 1265269
MD PATIENT_HOSP_SICK 1138878
SISO BA02 760478
SYS WRH$_EVENT_HISTOGRAM 737243
HSP SEND_MESSAGE 675045
SI ORGN_CMPL 664958
DE EMP_ADD 571087
SI ORGN_JOIN 502611
漏洞证明:
SI EMP_PLAN 710845465
SI MEDI_ACCOUNT 206113580
SIBK AGED_ACCOUNT 162101411
SI HARM_ACCOUNT 150955241
MD CARD_INCOME 146944271
MD CARD_PAYOUT 139296091
SI LOST_ACCOUNT 137231734
SI BIRTH_ACCOUNT 129290852
DE JOB_DATA 76295521
DE EMP_PLAN_BAK_2014 70936969
DE EMP_PLAN 70343287
SIBK AGED_ACCOUNT_HIS 48325928
SI EMP_PAY_HIS 42943980
SI BILL_DETL 25348181
SI ORGN_DUE_PAY_GENL 23845243
SI BILL_PART 23541691
SI EMP_ADD 22267670
SI AGED_ACCOUNT 21791494
SI AGED_ACCOUNT_SUM 17387020
SISO ORGN_DUE_PAY_GENL 15052854
SI EMP_CMPL 12587398
MD CARD_ACCOUNT 9460737
MD EMP_NATL 8392716
SI PER_REG 7714891
SI BILL_GENL 6197620
SISO BIZ_LOG_INFO160303 5347232
CSI EMP_NATL 5214840
SI CSI_EMP_NATL 5192421
AGED EMP_GIV_STD 4716356
SISO EMP_NATL 4695524
DE DECLARE_NATL 4241822
SI ORGN_RATE 4161692
DE DECLARE_NATL_BAK_2014 4025052
SI EMP_NATL 3639073
SYS WRM$_SNAPSHOT_DETAILS 3452909
DE DECLARE_NATL_20150706 3268305
DE DECLARE_NATL_BF 3244266
DE ORGN_PLAN 3136815
SI SI_DWS_USER_20151029 2421023
SIBK EMP_PAY_HIS 2174245
DE EMP_ADD_GRBH 2118020
MD PATIENT_INFO 2071436
SI LOGINRECORD 2007114
DE DECLARE_NATL_20150116_2_2 1664522
LOST EMP_GIV_HIS 1503376
SYS WRI$_OPTSTAT_HISTGRM_HISTORY 1265269
MD PATIENT_HOSP_SICK 1138878
SISO BA02 760478
SYS WRH$_EVENT_HISTOGRAM 737243
HSP SEND_MESSAGE 675045
SI ORGN_CMPL 664958
DE EMP_ADD 571087
SI ORGN_JOIN 502611
修复方案:
更新补丁
版权声明:转载请注明来源 路人甲@乌云
漏洞回应
厂商回应:
危害等级:高
漏洞Rank:11
确认时间:2016-04-22 11:42
厂商回复:
CNVD确认并复现所述情况,已经转由CNCERT下发给山东分中心,由其后续协调网站管理单位处置.
最新状态:
暂无