ÈýÁâsmartRTU²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-20

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14931 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


¡ñÓ°Ïì°æ±¾


²úÆ·: ÈýÁâµç»úsmartRTU ºÍINEA ME-RTU


¹Ì¼þ°æ±¾: ÈýÁâµç»ú2.02¼°Ö®Ç°°æ±¾/INEA 3.0¼°Ö®Ç°°æ±¾


¡ñÎó²î¸ÅÊö


ÈýÁâµç»úµÄsmartRTUºÍINEA ME-RTUÖб£´æÎ´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£


¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚÏà¹ØRTUÉÏÔ¶³ÌÖ´ÐÐí§Òâ²Ù×÷ϵͳÏÂÁî £¬ÓÉÓÚRTU»ùÓÚwebµÄÔ¶³ÌÉèÖÃÓ¦ÓöÔÓû§ÊäÈëÊý¾Ý²»×öÈκιýÂË¡£ÔÚ¡°mobile.php¡±Ò³ÃæÌṩµÄ¡°Mobile Connection Test¡±¹¦Ð§ÖÐ £¬ÔÊÐíÓû§pingí§ÒâÍøÖ·»òÕßIPµØµã£»ºÚ¿Í¿ÉÒÔÔÚÊäÈëIPµØµã»òÕßÍøÖ·µÄβ²¿Ìí¼ÓshellÏÂÁîÍÑÀë·û£¨£»£© £¬Ö®ºó½Ó×ÅÊäÈëËùÐèÒªÖ´ÐеIJÙ×÷ϵͳָÁî¡£


µ±¡°Mobile Connection Test¡±¹¦Ð§±»Ö´ÐеÄʱ¼ä £¬RTU»áŲÓá°action.php¡± £¬¸Ã¾ç±¾µÄÄÚÈÝÈçÏ£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ÓÉÓÚȱ·¦¶ÔÓû§ÊäÈëÊý¾ÝµÄ¹ýÂË £¬ºÚ¿Í¿ÉÒÔÔÚ$command±äÁ¿ºóÃæ¼Ó¹ÒÐèÒªÖ´ÐеIJÙ×÷ϵͳÏÂÁî¡£ÀýÈç £¬host±äÁ¿¿ÉÒÔÊÇ×Ö·û´®£º¡°www.inea.si;ping 127.0.0.1¡± £¬ÄÇôϵͳÊ×ÏÈ»áÖ´ÐÐÕýµ±µÄpingÏÂÁîÀ´²âÊÔwww.inea.siµÄÁ¬Í¨ÐÔ £¬È»ºóÔÙÖ´Ðв»·¨pingÏÂÁîÀ´²âÊÔµ±ÌïÖ÷»úµÄÁ¬Í¨ÐÔ¡£


ͨ¹ýÉèÖÃÎļþ¿ÉÒÔ·¢Ã÷ £¬Óû§¡°www-data¡±¿ÉÒÔͨ¹ýsudoersÖ´ÐÐÈô¸É¾ßÓÐrootȨÏÞµÄÖ¸Áî £¬¸ÃÉèÖÃÎļþµÄ´æ´¢µÄÎļþ·¾¶Îª/etc/sudoers.d/viswww¡£Ï±íËùʾΪÓû§¡°www-data¡±µÄËùÓÐȨÏÞ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ËäÈ»ÔÊÐíÒÔrootȨÏÞÖ´ÐеÄÏÂÁîºÜÊÇÓÐÏÞ £¬¿ÉÊÇÈÔÈ»¿ÉÒÔʹÓÃ/usr/sbin/serviceÏÂÁîÀ´ÈƹýÊÚȨÏÞÖÆ¡£Í¨¹ýʹÓá°service¡±ÏÂÁî £¬¿ÉÒÔÔÚRTUÉÏÆô¶¯netcat·þÎñ²¢½¨ÉèÒ»¸ö¾ßÓÐrootȨÏÞµÄshell¡£Ïêϸ²Ù×÷ÈçÏ£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ÏÂÃæ´úÂëËùʾΪÀÖ³ÉÔÚRTUÉÏÀÖ³ÉÒÔrootȨÏÞÔËÐÐshell£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ÓÉÓÚsession¼ì²éµÄȱʧ £¬Ê¹µÃºÚ¿Í¿ÉÒÔÖ±½Ó°Ñpayload·¢Ë͸ø¡°action.php¡±´Ó¶øÊµÏÖÉÏÊö¹¥»÷¡£ÏÂͼËùʾΪÔÚ¹¥»÷Ö÷»úÉÏÔ¶³ÌÖ´ÐÐcurlÏÂÁî¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



¡ñÎó²îÑéÖ¤


POC£ºhttps://cxsecurity.com/issue/WLB-2019080056¡£


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½Ã»Ðû²¼Ïà¹Ø²¹¶¡ £¬Çë¹Ø×¢¹ÙÍø£ºhttps://www.mitsubishielectric.com/¡£


¡ñ²Î¿¼Á´½Ó


https://www.mogozobo.com/?p=3593