º£Ë¼Ð¾Æ¬±£´æºóÃÅΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
https://github.com/tothi/pwn-hisilicon-dvr#summary
Îó²î¸ÅÊö
º£Ë¼ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÉîÛÚµÄÖйú°ëµ¼Ì幫˾£¬£¬£¬£¬£¬£¬£¬Á¥ÊôÓÚ»ªÎª£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇÖйú×î´óµÄ¼¯³Éµç·Éè¼Æ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÆäоƬ±»È«ÇòÊýÒÔ°ÙÍò¼ÆµÄÎïÁªÍø×°±¸ËùʹÓ㬣¬£¬£¬£¬£¬£¬°üÀ¨Çå¾²ÉãÏñÍ·¡¢DVRºÍNVR¡£¡£¡£¡£¡£
½üÆÚ£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹Ç徲ר¼ÒVladislav YarmakÐû²¼ÁËÔÚº£Ë¼Ð¾Æ¬Öз¢Ã÷µÄºóÃŵÄʹÓÃÏêÇ飬£¬£¬£¬£¬£¬£¬Ê¹ÓúóÃÅ¿ÉÒÔÈù¥»÷Õß»ñµÃÄ¿µÄ×°±¸ÖÐrootȨÏÞµÄshell£¬£¬£¬£¬£¬£¬£¬ÍêÈ«¿ØÖÆ×¡×°±¸¡£¡£¡£¡£¡£
×îеĹ̼þ°æ±¾ËäȻĬÈϽûÓÃÁËTelnet»á¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£©£¬£¬£¬£¬£¬£¬£¬µ«·¿ªÁË9530/tcp¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÏò°üÀ¨º£Ë¼Ð¾Æ¬×°±¸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâÏÂÁîÀ´Ê¹ÓúóÃÅ¡£¡£¡£¡£¡£ÕâЩÏÂÁî¿ÉÈù¥»÷ÕßÔÚÄ¿µÄ×°±¸ÉÏÆôÓÃTelnetЧÀÍ£¬£¬£¬£¬£¬£¬£¬½ÓמͿÉÒÔʹÓÃÒÔÏÂÁù¸öĬÈÏTelnetƾ֤֮һ¾ÙÐеǼ£¬£¬£¬£¬£¬£¬£¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£¡£¡£¡£¡£
ºóÃż¤»îÁ÷³ÌÈçÏ£º
1.¿Í»§¶ËÅþÁ¬Ä¿µÄ×°±¸µÄ9530¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏָʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¡£¡£¡£¡£¸Ã°ì·¨¹ØÓÚÒÔǰ°æ±¾µÄºóÃÅʹÓÃÊÇ×îºóÒ»²½¡£¡£¡£¡£¡£ÈôÊǴ˰취ºóûÓÐÏìÓ¦£¬£¬£¬£¬£¬£¬£¬ÔòtelnetedЧÀÍ¿ÉÄÜÒѾÔËÐС£¡£¡£¡£¡£
2.ЧÀͶˣ¨Ö¸×°±¸£©»á»Ø¸´randNum:XXXXXXXX£¬£¬£¬£¬£¬£¬£¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£¡£¡£¡£¡£
3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ÅäºÏËæ»úÊý¾ÙÐÐÒÔϰ취¡£¡£¡£¡£¡£
4.¿Í»§¶ËʹÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö£¬£¬£¬£¬£¬£¬£¬¸½¼ÓÔÚrandNum:Ö®ºó£¬£¬£¬£¬£¬£¬£¬ÔÙÔÚÍ·²¿Ìí¼Ó×ܳ¤¶ÈµÄ×Ö½Ú£¬£¬£¬£¬£¬£¬£¬È»ºó·¢Ë͸øÐ§ÀͶˡ£¡£¡£¡£¡£
5.ЧÀͶ˴Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£¡£¡£¡£¡£
6.ЧÀͶ˶ÔËæ»úÊý¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬²¢Ñé֤Ч¹ûÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£¡£¡£¡£¡£ÑéÖ¤Àֳɻظ´verify:OK£¬£¬£¬£¬£¬£¬£¬²»È»»Ø¸´verify:ERROR¡£¡£¡£¡£¡£
7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú£¬£¬£¬£¬£¬£¬£¬CMD:×Ö·û´®£¬£¬£¬£¬£¬£¬£¬È»ºó·¢Ë͸øÐ§ÀͶˡ£¡£¡£¡£¡£
8.ЧÀͶ˽âÃܳö½ÓÊܵ½µÄÏÂÁî¡£¡£¡£¡£¡£ÈôÊÇ»ñµÃµÄЧ¹û¼´ÊÇ×Ö·û´®Telnet:OpenOnce£¬£¬£¬£¬£¬£¬£¬¾Í»á»Ø¸´Open:OK£¬£¬£¬£¬£¬£¬£¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527£¬£¬£¬£¬£¬£¬£¬Æô¶¯telnetЧÀÍ¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£¡£¡£¡£¡£
Ó÷¨£º./hs-dvr-telnet HOST PSK
ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2
ʾÀýÓ÷¨
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌ»¹Î´ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬¿É½ÓÄÉÔÝʱ·ÀÓù²½·¥£ºÓû§¿ÉÒÔÆ¾Ö¤ÐèÒªÏÞÖÆ¶ÔÊÜÓ°Ïì×°±¸µÄÍøÂç»á¼û£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÊÜÐÅÈεÄÓû§¾ÙÐлá¼û¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://habr.com/en/post/486856/


¾©¹«Íø°²±¸11010802024551ºÅ