VoIPmonitor GUI¿çÕ¾¾ç±¾·ì϶
°ä²¼¹¦·ò 2021-06-170x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-17 | |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

SIP (Session Initiation Protocol£¬¼´»á»°ÌáÒéºÍ̸)ÊÇÒ»¸öÀûÓòãµÄÐÅÁî½ÚÔìºÍ̸£¬ÓÃÓÚ´´½¨¡¢Åú¸ÄºÍ¿ªÊÍÒ»¸ö»ò¶à¸ö²Î¼ÓÕߵĻỰ¡£SIPÊÇ¿ÉÓÃÓÚʵÏÖVoIPµÄ¶à¶àºÍ̸֮һ£¬ÊÇ¿í·ºÊ¹ÓõÄÐÐÒµ³ß¶ÈºÍ̸¡£
VoIPmonitorÊÇ¿ªÔ´µÄÍøÂçÊý¾Ý°üÐá̽Æ÷Èí¼þ£¬¿É×¥°ü·ÖÎöSIPºÍRTPµÈºÍ̸¡£
2021Äê06ÔÂ10ÈÕ£¬Enable Security µÄ°²È«×êÑÐÔ± Juxhin Dyrmishi Brigjaj ¹«¿ªÅû¶ÁËVoIPmonitor GUIÖеÄÒ»¸ö¿çÕ¾µã¾ç±¾ (XSS) ·ì϶¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ SIP ÐÂÎÅÔÚÖ¸±êϵͳÉÏÖ´ÐжñÒâ´úÂ룬ÉõÖÁ»ñµÃ¶ÔÖ¸±êϵͳµÄÓÆ¾ÃºóÃŽӼû¡£
×êÑÐÈËԱͨ¹ý½«User-AgentÉèÖÃΪ<img src=x alert(1)>£¬ÈôÊÇËüÔÚ DOM ÖгöÏÖ£¬ä¯ÀÀÆ÷½«ÎÞ·¨»ñÈ¡ÏÂ/xµÄͼÏñ£¬²¢ÔÚʧ°ÜʱִÐжñÒâ´úÂ룺

×êÑÐÈËÔ±ÀûÓô˷ì϶´´½¨ÁËÒ»¸öºóÃÅÖÎÀíÓû§£¬½«Ò»Ê±È¨ÏÞÌáÉýΪÓÀÔ¶ÖÎÀíÔ±½Ó¼ûȨÏÞ£º

´Ë±í£¬¹¥»÷Õß»¹¿ÉÄÜÌáÒéÒÔϹ¥»÷»î¶¯£º
l Éø³öͨ¹ýºÏ·¨ VoIP ¿Í»§¶ËµÄÃô¸ÐÊý¾Ý¡£ÕâÔÚÏÖʵ»·¾³Öгö¸ñÓÐЧ£¬VoIPmonitor GUI½«ÔÚÄÚ²¿ÔËÐУ¬Äܹ»Í¨¹ý´ø±íDNS·þÎñÆ÷£¨»òÆäËü²½Ö裩ÇÔÈ¡Êý¾Ý£»
l Óë´´½¨ÖÎÀíÔ±Óû§µÄ·½Ê½ÀàËÆ£¬Ò²Äܹ»É¾³ý½Ó¼û½çÃæµÄÆäËûºÏ·¨ÖÎÀíÔ±£»
l Äܹ»ÔڵǼÆÁÄ»ÉÏǶÈë¼üÅ̼ͼÆ÷×÷ΪºóÃÅ£¬ÍøÂçÖÎÀíԱʹ´¦£»
l ÀûÓÃÄÚ²¿ Web ÀûÓ÷¨Ê½¡£
Ó°ÏìÁìÓò
VoIPmonitor GUI
0x02 ´ëÖý¨Òé
VoIPmonitor GUIÒѾ°ä²¼ÁË´Ë·ì϶µÄ°²È«²¹¶¡£¬½¨Ò龡¿ìÉý¼¶µ½×îа汾¡£
ÏÂÔØÁ´½Ó£º
http://www.voipmonitor.org/download?WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
ͨÓð²È«½¨Òé
¶ÔÊäÈë»òÊä³ö½øÐбàÂ룻
½¨ÒéÔÚÀûÓ÷¨Ê½ÖÐʹÓõ¥Ò»±àÂëÕ½Êõ£¬Ô¤·ÀË«³Á±àÂë»òË«³Á½âÂë·ÛËé½çÃæ»òµ¼ÖÂXSS¹¥»÷£»
ÈôÊÇÓû§ÊäÈëÓµÓÐÔ¤ÆÚµÄÌåʽ¡¢½á¹¹ºÍ¿É½ÓÊܵÄÖµ£¬ÇëÊ×ÏÈÑéÖ¤ÕâЩ²¢¹ýÂËÎÞЧÊäÈë¡£
Õë¶ÔDOM-XSSµÈ¿Í»§¶ËÊäÈë½øÐÐתÒåºÍ±àÂë¡£
0x03 ²Î¿¼Á´½Ó
https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
http://www.voipmonitor.org/changelog-gui?major=5&WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/
0x04 ¹¦·òÏß
2021-06-10 ×êÑÐÈËÔ±¹«¿ªÅû¶·ì϶
2021-06-17 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ