VoIPmonitor GUI¿çÕ¾¾ç±¾·ì϶

°ä²¼¹¦·ò 2021-06-17

0x00 ·ì϶¸ÅÊö

CVE   ID


ʱ    ¼ä

2021-06-17

Àà    ÐÍ

XSS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ·ì϶ÏêÇé

image.png

 

SIP (Session Initiation Protocol   £¬¼´»á»°ÌáÒéºÍ̸)ÊÇÒ»¸öÀûÓòãµÄÐÅÁî½ÚÔìºÍ̸   £¬ÓÃÓÚ´´½¨¡¢Åú¸ÄºÍ¿ªÊÍÒ»¸ö»ò¶à¸ö²Î¼ÓÕߵĻỰ¡£SIPÊÇ¿ÉÓÃÓÚʵÏÖVoIPµÄ¶à¶àºÍ̸֮һ   £¬ÊÇ¿í·ºÊ¹ÓõÄÐÐÒµ³ß¶ÈºÍ̸¡£

VoIPmonitorÊÇ¿ªÔ´µÄÍøÂçÊý¾Ý°üÐá̽Æ÷Èí¼þ   £¬¿É×¥°ü·ÖÎöSIPºÍRTPµÈºÍ̸¡£

2021Äê06ÔÂ10ÈÕ   £¬Enable Security µÄ°²È«×êÑÐÔ± Juxhin Dyrmishi Brigjaj ¹«¿ªÅû¶ÁËVoIPmonitor GUIÖеÄÒ»¸ö¿çÕ¾µã¾ç±¾ (XSS) ·ì϶¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ SIP ÐÂÎÅÔÚÖ¸±êϵͳÉÏÖ´ÐжñÒâ´úÂë   £¬ÉõÖÁ»ñµÃ¶ÔÖ¸±êϵͳµÄÓÆ¾ÃºóÃŽӼû¡£

×êÑÐÈËԱͨ¹ý½«User-AgentÉèÖÃΪ<img src=x alert(1)>   £¬ÈôÊÇËüÔÚ DOM ÖгöÏÖ   £¬ä¯ÀÀÆ÷½«ÎÞ·¨»ñÈ¡ÏÂ/xµÄͼÏñ   £¬²¢ÔÚʧ°ÜʱִÐжñÒâ´úÂ룺

image.png

 

×êÑÐÈËÔ±ÀûÓô˷ì϶´´½¨ÁËÒ»¸öºóÃÅÖÎÀíÓû§   £¬½«Ò»Ê±È¨ÏÞÌáÉýΪÓÀÔ¶ÖÎÀíÔ±½Ó¼ûȨÏÞ£º

image.png

 

´Ë±í   £¬¹¥»÷Õß»¹¿ÉÄÜÌáÒéÒÔϹ¥»÷»î¶¯£º

l  Éø³öͨ¹ýºÏ·¨ VoIP ¿Í»§¶ËµÄÃô¸ÐÊý¾Ý¡£ÕâÔÚÏÖʵ»·¾³Öгö¸ñÓÐЧ   £¬VoIPmonitor GUI½«ÔÚÄÚ²¿ÔËÐÐ   £¬Äܹ»Í¨¹ý´ø±íDNS·þÎñÆ÷£¨»òÆäËü²½Ö裩ÇÔÈ¡Êý¾Ý £»

l  Óë´´½¨ÖÎÀíÔ±Óû§µÄ·½Ê½ÀàËÆ   £¬Ò²Äܹ»É¾³ý½Ó¼û½çÃæµÄÆäËûºÏ·¨ÖÎÀíÔ± £»

l  Äܹ»ÔڵǼÆÁÄ»ÉÏǶÈë¼üÅ̼ͼÆ÷×÷ΪºóÃÅ   £¬ÍøÂçÖÎÀíԱʹ´¦ £»

l  ÀûÓÃÄÚ²¿ Web ÀûÓ÷¨Ê½¡£

 

Ó°ÏìÁìÓò

VoIPmonitor GUI

 

0x02 ´ëÖý¨Òé

VoIPmonitor GUIÒѾ­°ä²¼ÁË´Ë·ì϶µÄ°²È«²¹¶¡   £¬½¨Ò龡¿ìÉý¼¶µ½×îа汾¡£

ÏÂÔØÁ´½Ó£º

http://www.voipmonitor.org/download?WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr

 

ͨÓð²È«½¨Òé

¶ÔÊäÈë»òÊä³ö½øÐбàÂë £»

½¨ÒéÔÚÀûÓ÷¨Ê½ÖÐʹÓõ¥Ò»±àÂëÕ½Êõ   £¬Ô¤·ÀË«³Á±àÂë»òË«³Á½âÂë·ÛËé½çÃæ»òµ¼ÖÂXSS¹¥»÷ £»

ÈôÊÇÓû§ÊäÈëÓµÓÐÔ¤ÆÚµÄÌåʽ¡¢½á¹¹ºÍ¿É½ÓÊܵÄÖµ   £¬ÇëÊ×ÏÈÑéÖ¤ÕâЩ²¢¹ýÂËÎÞЧÊäÈë¡£

Õë¶ÔDOM-XSSµÈ¿Í»§¶ËÊäÈë½øÐÐתÒåºÍ±àÂë¡£

 

 

0x03 ²Î¿¼Á´½Ó

https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/

http://www.voipmonitor.org/changelog-gui?major=5&WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr

https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/


0x04 ¹¦·òÏß

2021-06-10  ×êÑÐÈËÔ±¹«¿ªÅû¶·ì϶

2021-06-17  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png