º£Ë¼Ð¾Æ¬´æÔÚºóÃÅ·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-06·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
https://github.com/tothi/pwn-hisilicon-dvr#summary
·ì϶¸ÅÊö
º£Ë¼ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÉîÛÚµÄÖйú°ëµ¼Ì幫˾£¬´ÓÊôÓÚ»ªÎª£¬Ò²ÊÇÖйú×î´óµÄ¼¯³Éµç·Éè¼Æ¹«Ë¾£¬ÆäоƬ±»È«ÇòÊýÒÔ°ÙÍò¼ÆµÄÎïÁªÍøÉ豸ËùʹÓã¬Ô̺¬°²È«ÉãÏñÍ·¡¢DVRºÍNVR¡£
½üÆÚ£¬¶íÂÞ˹°²È«×¨¼ÒVladislav Yarmak°ä²¼ÁËÔÚº£Ë¼Ð¾Æ¬Öз¢ÏֵĺóÃŵÄÀûÓÃÏêÇ飬ÀûÓúóÃÅÄܹ»Èù¥»÷Õß»ñµÃÖ¸±êÉ豸ÖÐrootȨÏÞµÄshell£¬ÆëÈ«½ÚÔìסÉ豸¡£
×îеĹ̼þ°æ±¾¹ÌȻĬÈϽûÓÃÁËTelnet½Ó¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£©£¬µ«´ò¿ªÁË9530/tcp¶Ë¿Ú£¬Äܹ»Í¨¹ýÏòÔ̺¬º£Ë¼Ð¾Æ¬É豸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâºÅÁîÀ´ÀûÓúóÃÅ¡£ÕâЩºÅÁî¿ÉÈù¥»÷ÕßÔÚÖ¸±êÉ豸ÉÏÆôÓÃTelnet·þÎñ£¬½ÓמÍÄܹ»Ê¹ÓÃÒÔÏÂÁù¸öĬÈÏTelnetÍ´´¦Ö®Ò»½øÐеǼ£¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£
ºóÃż¤»îÁ÷³ÌÈçÏ£º
1.¿Í»§¶ËÏνÓÖ¸±êÉ豸µÄ9530¶Ë¿Ú£¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce£¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏÅúʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¸Ã²½Öè¶ÔÓÚÒÔǰ°æ±¾µÄºóÃÅÀûÓÃÊÇ×îºóÒ»²½¡£ÈôÊǴ˲½ÖèºóûÓÐÏìÓ¦£¬Ôòtelneted·þÎñ¿ÉÄÜÒѾÔËÐС£
2.·þÎñ¶Ë£¨Ö¸É豸£©»á»Ø¸´randNum:XXXXXXXX£¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£
3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿£¬¹²Í¬Ëæ»úÊý½øÐÐÒÔϲ½Öè¡£
4.¿Í»§¶ËÀûÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö£¬¸½¼ÓÔÚrandNum:Ö®ºó£¬ÔÙÔÚÍ·²¿Ôö³¤×ܳ¤¶ÈµÄ×Ö½Ú£¬¶øºó·¢Ë͸ø·þÎñ¶Ë¡£
5.·þÎñ¶Ë´Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿£¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£
6.·þÎñ¶Ë¶ÔËæ»úÊý½øÐмÓÃÜ£¬²¢ÑéÖ¤Á˾ÖÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£ÑéÖ¤³É¹¦»Ø¸´verify:OK£¬²»È»»Ø¸´verify:ERROR¡£
7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce£¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú£¬CMD:×Ö·û´®£¬¶øºó·¢Ë͸ø·þÎñ¶Ë¡£
8.·þÎñ¶Ë½âÃܳö½ÓÊܵ½µÄºÅÁî¡£ÈôÊǵõ½µÄÁ˾ֵÅ×Ú×Ö·û´®Telnet:OpenOnce£¬¾Í»á»Ø¸´Open:OK£¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527£¬Æô¶¯telnet·þÎñ¡£
·ì϶ÑéÖ¤
PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£
Ó÷¨£º./hs-dvr-telnet HOST PSK
ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2
ʾÀýÓ÷¨
½¨¸´½¨Òé
Ŀǰ³§ÉÌ»¹Î´½¨¸´·ì϶£¬¿É²Éȡһʱ·ÀÓù´ëÊ©£ºÓû§Äܹ»Æ¾¾Ý±ØÒªÏ޶ȶÔÊÜÓ°ÏìÉ豸µÄÍøÂç½Ó¼û£¬Ö»ÔÊÐíÊÜÐÅÀµµÄÓû§½øÐнӼû¡£
²Î¿¼Á´½Ó
https://habr.com/en/post/486856/


¾©¹«Íø°²±¸11010802024551ºÅ