ÊÓÆµ¼à¿ØÏµÍ³´æÔÚºóÃÅ·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


https://github.com/tothi/pwn-hisilicon-dvr#summary


·ì϶¸ÅÊö


½üÆÚ £¬¶íÂÞ˹°²È«×¨¼ÒVladislav Yarmak°ä²¼ÁËÔÚÊÓÆµ¼à¿ØÏµÍ³Ð¾Æ¬Öз¢ÏֵĺóÃŵÄÀûÓÃÏêÇé £¬ÀûÓúóÃÅÄܹ»Èù¥»÷Õß»ñµÃÖ¸±êÉ豸ÖÐrootȨÏÞµÄshell £¬ÆëÈ«½ÚÔìסÉ豸¡£


×îеĹ̼þ°æ±¾¹ÌȻĬÈϽûÓÃÁËTelnet½Ó¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£© £¬µ«´ò¿ªÁË9530/tcp¶Ë¿Ú £¬Äܹ»Í¨¹ýÏòÔ̺¬º£Ë¼Ð¾Æ¬É豸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâºÅÁîÀ´ÀûÓúóÃÅ¡£ÕâЩºÅÁî¿ÉÈù¥»÷ÕßÔÚÖ¸±êÉ豸ÉÏÆôÓÃTelnet·þÎñ £¬½ÓמÍÄܹ»Ê¹ÓÃÒÔÏÂÁù¸öĬÈÏTelnetÍ´´¦Ö®Ò»½øÐеǼ £¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ºóÃż¤»îÁ÷³ÌÈçÏ£º


1.¿Í»§¶ËÏνÓÖ¸±êÉ豸µÄ9530¶Ë¿Ú £¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce £¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏÅúʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¸Ã²½Öè¶ÔÓÚÒÔǰ°æ±¾µÄºóÃÅÀûÓÃÊÇ×îºóÒ»²½¡£ÈôÊǴ˲½ÖèºóûÓÐÏìÓ¦ £¬Ôòtelneted·þÎñ¿ÉÄÜÒѾ­ÔËÐС£


2.·þÎñ¶Ë£¨Ö¸É豸£©»á»Ø¸´randNum:XXXXXXXX £¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£


3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿ £¬¹²Í¬Ëæ»úÊý½øÐÐÒÔϲ½Öè¡£


4.¿Í»§¶ËÀûÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö £¬¸½¼ÓÔÚrandNum:Ö®ºó £¬ÔÙÔÚÍ·²¿Ôö³¤×ܳ¤¶ÈµÄ×Ö½Ú £¬¶øºó·¢Ë͸ø·þÎñ¶Ë¡£


5.·þÎñ¶Ë´Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿ £¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£


6.·þÎñ¶Ë¶ÔËæ»úÊý½øÐмÓÃÜ £¬²¢ÑéÖ¤Á˾ÖÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£ÑéÖ¤³É¹¦»Ø¸´verify:OK £¬²»È»»Ø¸´verify:ERROR¡£


7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce £¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú £¬CMD:×Ö·û´® £¬¶øºó·¢Ë͸ø·þÎñ¶Ë¡£


8.·þÎñ¶Ë½âÃܳö½ÓÊܵ½µÄºÅÁî¡£ÈôÊǵõ½µÄÁ˾ֵÅ×Ú×Ö·û´®Telnet:OpenOnce £¬¾Í»á»Ø¸´Open:OK £¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527 £¬Æô¶¯telnet·þÎñ¡£


·ì϶ÑéÖ¤


PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£


Ó÷¨£º./hs-dvr-telnet HOST PSK


ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2


ʾÀýÓ÷¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



½¨¸´½¨Òé


Ŀǰ³§ÉÌ»¹Î´½¨¸´·ì϶ £¬¿É²Éȡһʱ·ÀÓù´ëÊ©£ºÓû§Äܹ»Æ¾¾Ý±ØÒªÏ޶ȶÔÊÜÓ°ÏìÉ豸µÄÍøÂç½Ó¼û £¬Ö»ÔÊÐíÊÜÐÅÀµµÄÓû§½øÐнӼû¡£


²Î¿¼Á´½Ó


https://habr.com/en/post/486856/

https://www.huawei.com/cn/psirt/security-notices/huawei-sn-20200205-01-HiSilicon-cn?from=timeline