NVRMini2ÉãÏñÍ·ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-1149 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-1150 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3 £¬¹Ù·½Î´ÆÀ¶¨

Ó°Ïì°æ±¾


NUUO NVRMini2 3.8.0¼°ÒÔϰ汾


·ì϶¸ÅÊö


Tenable¹ÙÍøÉϹ«¿ªÁ˹ØÓÚÓÉNUUO¹«Ë¾¿ª·¢µÄÉãÏñͷϵͳNVRMini2´æÔÚÁ½¸öÑϳÁ·ì϶¡£
CVE-2018-1149£ºÎ´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ö¿â»º³åÇøÒç³ö
CVE-2018-1150£ººóÃÅ
NVRMini2µÄ½á¹¹¼òͼÈçÏÂ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


·ì϶ÑéÖ¤


CVE-2018-1149£º
NVRMini2ϵͳ¶Ô±©Â¶³öÁËÒ»¸öHTTP½Ó¼û½Ó¿Úhttp://<target>/cgi-bin/cgi_system £¬Í¨¹ýÕâ¸ö½Ó¿Ú £¬ÓµÓÐȨÏÞµÄÓû§Äܹ»½Ó¼ûµ½ÖÕ¶ËÉ豸¡£cgi_systemÎļþÖеÄÖ°ÄÜÖ»ÓÐÊÚȨÓû§Äܹ»½Ó¼û £¬ÈÏÖ¤µÄ²½ÖèΪ±ÈÁ¦Óû§½Ó¼ûÊý¾ÝCookie×Ö¶ÎÖеÄPHPSESSIDÖµºÍ´æ´¢/tmpĿ¼ÖеÄsessionÎļþÃû £¬¹¹½¨sessionÎļþÃûµÄ´úÂëÈçÏ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´Ósub_534a4·µ»ØµÄֵΪ»á»°±êʶ×Ö·û´®¡£·¨Ê½¶Ô¸Ã×Ö·û´®³¤¶ÈûÓÐ×÷ÈκÎÏÞ¶È¡£µ±×Ö·û´®´«µÝµ½sprintfÒÔ¹¹½¨tmpÎļþÃûʱ²¢Ã»ÓÐÌìǵ²é³­¡£Òò¶ø £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½«³¬³¤µÄPHPSESSIDÖµÔ¶³Ì´«µÝ¸øsprintfµ¼Ö»º³åÇøÒç³ö £¬´Ó¶øÔ¶³ÌÖ´ÐдúÂë¡£
²âÊÔ´úÂëÈçÏ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


²âÊÔ´úÂë»áµ¼ÖÂNVRϵͳ»á²úÉú±ÀÀ£¾°Ïó £¬¾­¹ýÉî¿Ì·ÖÎö £¬Ò²Äܹ»Ô¶³ÌÖ´ÐдúÂë £¬¹¥»÷Õß²»½ö¿ÉÄܽÚÔìNVR £¬»¹Äܹ»½Ó¼ûºÍÅú¸ÄNVRÖÐËùÓеÄÓû§Æ¾Ö¤Êý¾Ý £¬Ó°ÏìÑϳÁ¡£


CVE-2018-1150£º
NVRMini2µÄPHP´úÂëÖг£¼ûµÄϰ¹ßΪ£º
²é³­µ±Ç°PHP»á»°ÊÇ·ñÓÐЧ¡£
ÑéÖ¤»á»°ÊÇ·ñÓµÓÐÔÚ½Ó¼ûµÄÒ³ÃæµÄÊʵ±È¨ÏÞ£¨¼´admin £¬poweruser £¬user £¬root £¬guest£©¡£
µ«ÊÇ £¬check_session_is_valid£¨£©º¯ÊýÖÐÈ´´æÔÚºóÃŵĴúÂë £¬º¯ÊýÈçÏ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÆäÖбêʶΪ¡°back door¡±µÄ×ÖÑùΪÆäÔ´ÂëÖоʹæÔڵġ£constant(¡°MOSES_FILE¡±) Ö¸ÏòµÄõ辶Ϊ/tmp/moses¡£ÈôÊÇ/tmp/moses/´æÔÚ £¬ÔòδÊÚȨµÄ¹¥»÷ÕßÄܹ»Ô¶³ÌÁгöËùÓзÇadminµÄÓû§ £¬²¢Åú¸ÄËûÃǵÄÃÜÂë.

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹¥»÷ÑÝʾÊÓÆµÈçÏ£º

http://www.iqiyi.com/w_19s2b6hn11.html

½¨¸´½¨Òé


¹Ù·½ÁÙʱûÓÐÓйصĹ滮 £¬½¨Òé±£ÕÏÉ豸²»Â¶³öÔÚ»¥ÁªÍøÉÏ £¬²¢ÔÚ·À»ðǽÉ豸ÉϲÎÓë¶ÔÉãÏñÍ·HTTP·þÎñµÄ½Ó¼û½ÚÔìÕ½Êõ¡£


²Î¿¼Á´½Ó


https://www.tenable.com/security/research/tra-2018-25