ÊÓÆµ¼à¿ØÏµÍ³±£´æºóÃÅΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


https://github.com/tothi/pwn-hisilicon-dvr#summary


Îó²î¸ÅÊö


½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹Ç徲ר¼ÒVladislav YarmakÐû²¼ÁËÔÚÊÓÆµ¼à¿ØÏµÍ³Ð¾Æ¬Öз¢Ã÷µÄºóÃŵÄʹÓÃÏêÇ飬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓúóÃÅ¿ÉÒÔÈù¥»÷Õß»ñµÃÄ¿µÄ×°±¸ÖÐrootȨÏÞµÄshell£¬£¬£¬£¬£¬£¬£¬£¬ÍêÈ«¿ØÖÆ×¡×°±¸¡£¡£¡£¡£¡£¡£¡£¡£


×îеĹ̼þ°æ±¾ËäȻĬÈϽûÓÃÁËTelnet»á¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£©£¬£¬£¬£¬£¬£¬£¬£¬µ«·­¿ªÁË9530/tcp¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÏò°üÀ¨º£Ë¼Ð¾Æ¬×°±¸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâÏÂÁîÀ´Ê¹ÓúóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÏÂÁî¿ÉÈù¥»÷ÕßÔÚÄ¿µÄ×°±¸ÉÏÆôÓÃTelnetЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬½ÓמͿÉÒÔʹÓÃÒÔÏÂÁù¸öĬÈÏTelnetƾ֤֮һ¾ÙÐеǼ£¬£¬£¬£¬£¬£¬£¬£¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£¡£¡£¡£¡£¡£¡£¡£


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



ºóÃż¤»îÁ÷³ÌÈçÏ£º


1.¿Í»§¶ËÅþÁ¬Ä¿µÄ×°±¸µÄ9530¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏָʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã°ì·¨¹ØÓÚÒÔǰ°æ±¾µÄºóÃÅʹÓÃÊÇ×îºóÒ»²½¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊǴ˰취ºóûÓÐÏìÓ¦£¬£¬£¬£¬£¬£¬£¬£¬ÔòtelnetedЧÀÍ¿ÉÄÜÒѾ­ÔËÐС£¡£¡£¡£¡£¡£¡£¡£


2.ЧÀͶˣ¨Ö¸×°±¸£©»á»Ø¸´randNum:XXXXXXXX£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£¡£¡£¡£¡£¡£¡£¡£


3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬ÅäºÏËæ»úÊý¾ÙÐÐÒÔϰ취¡£¡£¡£¡£¡£¡£¡£¡£


4.¿Í»§¶ËʹÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö£¬£¬£¬£¬£¬£¬£¬£¬¸½¼ÓÔÚrandNum:Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬ÔÙÔÚÍ·²¿Ìí¼Ó×ܳ¤¶ÈµÄ×Ö½Ú£¬£¬£¬£¬£¬£¬£¬£¬È»ºó·¢Ë͸øÐ§ÀͶˡ£¡£¡£¡£¡£¡£¡£¡£


5.ЧÀͶ˴Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£¡£¡£¡£¡£¡£¡£¡£


6.ЧÀͶ˶ÔËæ»úÊý¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ñé֤Ч¹ûÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£¡£¡£¡£¡£¡£¡£¡£ÑéÖ¤Àֳɻظ´verify:OK£¬£¬£¬£¬£¬£¬£¬£¬²»È»»Ø¸´verify:ERROR¡£¡£¡£¡£¡£¡£¡£¡£


7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬£¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú£¬£¬£¬£¬£¬£¬£¬£¬CMD:×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬È»ºó·¢Ë͸øÐ§ÀͶˡ£¡£¡£¡£¡£¡£¡£¡£


8.ЧÀͶ˽âÃܳö½ÓÊܵ½µÄÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ»ñµÃµÄЧ¹û¼´ÊÇ×Ö·û´®Telnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬£¬¾Í»á»Ø¸´Open:OK£¬£¬£¬£¬£¬£¬£¬£¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527£¬£¬£¬£¬£¬£¬£¬£¬Æô¶¯telnetЧÀÍ¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£¡£¡£¡£¡£¡£¡£¡£


Ó÷¨£º./hs-dvr-telnet HOST PSK


ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2


ʾÀýÓ÷¨


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌ»¹Î´ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¿É½ÓÄÉÔÝʱ·ÀÓù²½·¥£ºÓû§¿ÉÒÔÆ¾Ö¤ÐèÒªÏÞÖÆ¶ÔÊÜÓ°Ïì×°±¸µÄÍøÂç»á¼û£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§¾ÙÐлá¼û¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://habr.com/en/post/486856/

https://www.huawei.com/cn/psirt/security-notices/huawei-sn-20200205-01-HiSilicon-cn?from=timeline