º£Ë¼Ð¾Æ¬±£´æºóÃÅΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


https://github.com/tothi/pwn-hisilicon-dvr#summary


Îó²î¸ÅÊö


º£Ë¼ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÉîÛÚµÄÖйú°ëµ¼Ì幫˾ £¬Á¥ÊôÓÚ»ªÎª £¬Ò²ÊÇÖйú×î´óµÄ¼¯³Éµç·Éè¼Æ¹«Ë¾ £¬ÆäоƬ±»È«ÇòÊýÒÔ°ÙÍò¼ÆµÄÎïÁªÍø×°±¸ËùʹÓà £¬°üÀ¨Çå¾²ÉãÏñÍ·¡¢DVRºÍNVR¡£


½üÆÚ £¬¶íÂÞ˹Ç徲ר¼ÒVladislav YarmakÐû²¼ÁËÔÚº£Ë¼Ð¾Æ¬Öз¢Ã÷µÄºóÃŵÄʹÓÃÏêÇé £¬Ê¹ÓúóÃÅ¿ÉÒÔÈù¥»÷Õß»ñµÃÄ¿µÄ×°±¸ÖÐrootȨÏÞµÄshell £¬ÍêÈ«¿ØÖÆ×¡×°±¸¡£


×îеĹ̼þ°æ±¾ËäȻĬÈϽûÓÃÁËTelnet»á¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£© £¬µ«·­¿ªÁË9530/tcp¶Ë¿Ú £¬¿ÉÒÔͨ¹ýÏò°üÀ¨º£Ë¼Ð¾Æ¬×°±¸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâÏÂÁîÀ´Ê¹ÓúóÃÅ¡£ÕâЩÏÂÁî¿ÉÈù¥»÷ÕßÔÚÄ¿µÄ×°±¸ÉÏÆôÓÃTelnet·þÎñ £¬½ÓמͿÉÒÔʹÓÃÒÔÏÂÁù¸öĬÈÏTelnetƾ֤֮һ¾ÙÐеǼ £¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


ºóÃż¤»îÁ÷³ÌÈçÏ£º


1.¿Í»§¶ËÅþÁ¬Ä¿µÄ×°±¸µÄ9530¶Ë¿Ú £¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce £¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏָʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¸Ã°ì·¨¹ØÓÚÒÔǰ°æ±¾µÄºóÃÅʹÓÃÊÇ×îºóÒ»²½¡£ÈôÊǴ˰취ºóûÓÐÏìÓ¦ £¬Ôòtelneted·þÎñ¿ÉÄÜÒѾ­ÔËÐС£


2.·þÎñ¶Ë£¨Ö¸×°±¸£©»á»Ø¸´randNum:XXXXXXXX £¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£


3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿ £¬ÅäºÏËæ»úÊý¾ÙÐÐÒÔϰ취¡£


4.¿Í»§¶ËʹÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö £¬¸½¼ÓÔÚrandNum:Ö®ºó £¬ÔÙÔÚÍ·²¿Ìí¼Ó×ܳ¤¶ÈµÄ×Ö½Ú £¬È»ºó·¢Ë͸ø·þÎñ¶Ë¡£


5.·þÎñ¶Ë´Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿ £¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£


6.·þÎñ¶Ë¶ÔËæ»úÊý¾ÙÐмÓÃÜ £¬²¢Ñé֤Ч¹ûÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£ÑéÖ¤Àֳɻظ´verify:OK £¬²»È»»Ø¸´verify:ERROR¡£


7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce £¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú £¬CMD:×Ö·û´® £¬È»ºó·¢Ë͸ø·þÎñ¶Ë¡£


8.·þÎñ¶Ë½âÃܳö½ÓÊܵ½µÄÏÂÁî¡£ÈôÊÇ»ñµÃµÄЧ¹û¼´ÊÇ×Ö·û´®Telnet:OpenOnce £¬¾Í»á»Ø¸´Open:OK £¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527 £¬Æô¶¯telnet·þÎñ¡£


Îó²îÑéÖ¤


PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£


Ó÷¨£º./hs-dvr-telnet HOST PSK


ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2


ʾÀýÓ÷¨


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£

ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌ»¹Î´ÐÞ¸´Îó²î £¬¿É½ÓÄÉÔÝʱ·ÀÓù²½·¥£ºÓû§¿ÉÒÔÆ¾Ö¤ÐèÒªÏÞÖÆ¶ÔÊÜÓ°Ïì×°±¸µÄÍøÂç»á¼û £¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§¾ÙÐлá¼û¡£


²Î¿¼Á´½Ó


https://habr.com/en/post/486856/