NVRMini2ÉãÏñÍ·ÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-09-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-1149£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ10£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2018-1150£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.3£¬¹Ù·½Î´ÆÀ¶¨

Ó°Ïì°æ±¾


NUUO NVRMini2 3.8.0¼°ÒÔϰ汾


·ì϶¸ÅÊö


Tenable¹ÙÍøÉϹ«¿ªÁ˹ØÓÚÓÉNUUO¹«Ë¾¿ª·¢µÄÉãÏñͷϵͳNVRMini2´æÔÚÁ½¸öÑϳÁ·ì϶¡£
CVE-2018-1149£ºÎ´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ö¿â»º³åÇøÒç³ö
CVE-2018-1150£ººóÃÅ
NVRMini2µÄ½á¹¹¼òͼÈçÏÂ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ì϶ÑéÖ¤


CVE-2018-1149£º
NVRMini2ϵͳ¶Ô±©Â¶³öÁËÒ»¸öHTTP½Ó¼û½Ó¿Úhttp://<target>/cgi-bin/cgi_system£¬Í¨¹ýÕâ¸ö½Ó¿Ú£¬ÓµÓÐȨÏÞµÄÓû§Äܹ»½Ó¼ûµ½ÖÕ¶ËÉ豸¡£cgi_systemÎļþÖеÄÖ°ÄÜÖ»ÓÐÊÚȨÓû§Äܹ»½Ó¼û£¬ÈÏÖ¤µÄ²½ÖèΪ±ÈÁ¦Óû§½Ó¼ûÊý¾ÝCookie×Ö¶ÎÖеÄPHPSESSIDÖµºÍ´æ´¢/tmpĿ¼ÖеÄsessionÎļþÃû£¬¹¹½¨sessionÎļþÃûµÄ´úÂëÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ósub_534a4·µ»ØµÄֵΪ»á»°±êʶ×Ö·û´®¡£·¨Ê½¶Ô¸Ã×Ö·û´®³¤¶ÈûÓÐ×÷ÈκÎÏÞ¶È¡£µ±×Ö·û´®´«µÝµ½sprintfÒÔ¹¹½¨tmpÎļþÃûʱ²¢Ã»ÓÐÌìǵ²é³­¡£Òò¶ø£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½«³¬³¤µÄPHPSESSIDÖµÔ¶³Ì´«µÝ¸øsprintfµ¼Ö»º³åÇøÒç³ö£¬´Ó¶øÔ¶³ÌÖ´ÐдúÂë¡£
²âÊÔ´úÂëÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²âÊÔ´úÂë»áµ¼ÖÂNVRϵͳ»á²úÉú±ÀÀ£¾°Ï󣬾­¹ýÉî¿Ì·ÖÎö£¬Ò²Äܹ»Ô¶³ÌÖ´ÐдúÂ룬¹¥»÷Õß²»½ö¿ÉÄܽÚÔìNVR£¬»¹Äܹ»½Ó¼ûºÍÅú¸ÄNVRÖÐËùÓеÄÓû§Æ¾Ö¤Êý¾Ý£¬Ó°ÏìÑϳÁ¡£


CVE-2018-1150£º
NVRMini2µÄPHP´úÂëÖг£¼ûµÄϰ¹ßΪ£º
²é³­µ±Ç°PHP»á»°ÊÇ·ñÓÐЧ¡£
ÑéÖ¤»á»°ÊÇ·ñÓµÓÐÔÚ½Ó¼ûµÄÒ³ÃæµÄÊʵ±È¨ÏÞ£¨¼´admin£¬poweruser£¬user£¬root£¬guest£©¡£
µ«ÊÇ£¬check_session_is_valid£¨£©º¯ÊýÖÐÈ´´æÔÚºóÃŵĴúÂ룬º¯ÊýÈçÏ£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖбêʶΪ¡°back door¡±µÄ×ÖÑùΪÆäÔ´ÂëÖоʹæÔڵġ£constant(¡°MOSES_FILE¡±) Ö¸ÏòµÄõ辶Ϊ/tmp/moses¡£ÈôÊÇ/tmp/moses/´æÔÚ£¬ÔòδÊÚȨµÄ¹¥»÷ÕßÄܹ»Ô¶³ÌÁгöËùÓзÇadminµÄÓû§£¬²¢Åú¸ÄËûÃǵÄÃÜÂë.

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷ÑÝʾÊÓÆµÈçÏ£º

http://www.iqiyi.com/w_19s2b6hn11.html

½¨¸´½¨Òé


¹Ù·½ÁÙʱûÓÐÓйصĹ滮£¬½¨Òé±£ÕÏÉ豸²»Â¶³öÔÚ»¥ÁªÍøÉÏ£¬²¢ÔÚ·À»ðǽÉ豸ÉϲÎÓë¶ÔÉãÏñÍ·HTTP·þÎñµÄ½Ó¼û½ÚÔìÕ½Êõ¡£


²Î¿¼Á´½Ó


https://www.tenable.com/security/research/tra-2018-25