Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      CVE-2020-24581 D-Link DSL-2888A Ô¶³ÌÃüÁîÖ´ÐЩ¶´¸´ÏÖÓë·ÖÎö
      ·¢²¼Ê±¼ä£º2023-03-24 ÔĶÁ´ÎÊý£º 1391 ´Î
      ©¶´¼ò½é

      D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾´æÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿Éͨ¹ý·ÃÎÊ/cgi-bin/execute_cmd.cgi´¥·¢ÃüÁîÖ´ÐЩ¶´¡£





       Ó°Ï췶Χ

      D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾





       Â©¶´¸´ÏÖ
      Ê×ÏÈÔÚ¹ÜÀíÔ±ÃÜÂëÀ¸´¦ÊäÈëÈÎÒâÃÜÂë
      ͼƬ
      µã»÷µÇ¼ºó·ÃÎÊ/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=id¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´
      ͼƬ




       Â©¶´·ÖÎö

      Ö´ÐÐÃüÁîbinwal -Me ../IOT_BUG/CVE-2020-24581/DSL-2888A_AU_2.12_V1.1.47Z1-Image-all.bin --run-as=root½«¹Ì¼þÎļþϵͳÌáÈ¡£¬ÌáÈ¡ºóµÄĿ¼½á¹¹ÈçͼËùʾ

      ͼƬ

      Ö´ÐÐÃüÁî

      cd jffs2-root

      ½øÈëÎļþϵͳ£¬Îļþϵͳ½á¹¹ÈçͼËùʾ

      ͼƬ

      ¸Ã©¶´ÎªwebÓ¦Óé¶´£¬¸Ã¹Ì¼þÖÐweb×é¼þΪdhttpd£¬Ö´ÐÐÃüÁîfind . -name ¡°dhttpd¡±ËÑË÷web×é¼þλÖã¬ËÑË÷½á¹ûÈçͼËùʾ

      ͼƬ

      ÈçͼËùʾ£¬Í¨¹ýIDA´ò¿ªdhttpd

      ͼƬ

      ¸ÃÔ¶³ÌÃüÁîÖ´ÐнӿÚΪ/cgi-bin/execute_cmd.cgi£¬ÈçͼËùʾ£¬ÔÚº¯Êýsub_9C4CÖУ¬Èç¹û·ÃÎÊ·¾¶ÖдæÔÚ/cgi-bin£¬Ôòµ÷ÓÃsub_BEA0º¯Êý½øÐд¦Àí

      ͼƬ

      ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ52Ðн«cgiÎļþÓëcgi-binĿ¼½øÐÐÆ´½Ó£¬ÔÚµÚ53ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚ£¬ÔÚµÚ63ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚÖ´ÐÐȨÏÞ

      ͼƬ

      ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ70Ðн«»ñÈ¡µ±Ç°Îļþ·¾¶£¬ÔÚ71ÐÐÔÚfile²éÕÒ¡±/¡±×îºóÒ»´ÎµÄλÖã¬Èç¹û¸ÃλÖôæÔÚ£¬ÔòÔÚµÚ76ÐнøÈëfileĿ¼

      ͼƬ

      ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ105-108Ðн«½øÐÐcgiÎļþÖ´Ðл·¾³±äÁ¿ÅäÖÃ

      ͼƬ

      ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ111-143Ðн«½øÐÐÉí·ÝУÑé

      ͼƬ

      ¼ÌÐø¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬Í¨¹ýÉí·ÝУÑéºó£¬ÔÚµÚ149Ðе÷ÓÃsub_BB5Cº¯Êý¶ÔcgiÎļþ½øÐд¦Àí

      ͼƬ

      ¸ú½øsub_BB5Cº¯Êý£¬ÔÚsub_BB5Cº¯ÊýµÄµÚ40Ðе÷ÓÃexecveº¯ÊýÖ´ÐÐcgiÎļþ

      ͼƬ
      ²éÕÒ´æÔÚ©¶´µÄexecute_cmd.cgiÎļþ£¬execute_cmd.cgiÎļþλÓÚÎļþϵͳϵÄwww/cgi-binĿ¼
      ͼƬ

      ²é¿´execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝ£¬execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝÈçͼËùʾ£¬execute_cmd.cgiÎļþÄÚÈÝΪ»ñÈ¡QUERY_STRINGÖеڶþ¸ö²ÎÊýµÄÖµ£¬²¢Í¨¹ý·´ÒýºÅ``ÒÔÖ´ÐÐÃüÁʽִÐиÃÖµ

      ͼƬ

      ÔÚIDAÖÐËÑË÷QUERY_STRING£¬ËÑË÷½á¹ûÈçͼËùʾ

      ͼƬ

      ÔÚjsÎļþĿ¼²éÕÒQueryString£¬²éÕÒ½á¹ûÈçͼËùʾ

      ͼƬ

      ·ÃÎÊ´æÔÚQueryString×Ö·ûµÄajax.jsÎļþ£¬ajax.jsÎļþÄÚÈÝÈçͼËùʾ

      ͼƬ

      ¹Êµ±Í¨¹ýÉí·ÝУÑéʱ£¬¹¹Ôìuri£º/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=cmd¿ÉÖ´ÐÐÈÎÒâÃüÁÓÉÓڸð汾·ÓÉÆ÷ÔÚÃÜÂëÀ¸ÊäÈëÈÎÒâÃÜÂëºó¼´¿ÉÈÆ¹ýÉí·ÝУÑ飬ËùÒÔ²»ÐèÖªµÀÉ豸ÃÜÂë¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´

      ͼƬ


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿