ÊÓÆµ¼à¿ØÏµÍ³±£´æºóÃÅΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-06Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
https://github.com/tothi/pwn-hisilicon-dvr#summary
Îó²î¸ÅÊö
½üÆÚ£¬¶íÂÞ˹Ç徲ר¼ÒVladislav YarmakÐû²¼ÁËÔÚÊÓÆµ¼à¿ØÏµÍ³Ð¾Æ¬Öз¢Ã÷µÄºóÃŵÄʹÓÃÏêÇ飬ʹÓúóÃÅ¿ÉÒÔÈù¥»÷Õß»ñµÃÄ¿µÄ×°±¸ÖÐrootȨÏÞµÄshell£¬ÍêÈ«¿ØÖÆ×¡×°±¸¡£
×îеĹ̼þ°æ±¾ËäȻĬÈϽûÓÃÁËTelnet»á¼ûºÍµ÷ÊԶ˿ڣ¨9527/tcp£©£¬µ«·¿ªÁË9530/tcp¶Ë¿Ú£¬¿ÉÒÔͨ¹ýÏò°üÀ¨º£Ë¼Ð¾Æ¬×°±¸µÄ9530¶Ë¿Ú·¢ËÍһϵÁÐÌØÊâÏÂÁîÀ´Ê¹ÓúóÃÅ¡£ÕâЩÏÂÁî¿ÉÈù¥»÷ÕßÔÚÄ¿µÄ×°±¸ÉÏÆôÓÃTelnet·þÎñ£¬½ÓמͿÉÒÔʹÓÃÒÔÏÂÁù¸öĬÈÏTelnetƾ֤֮һ¾ÙÐеǼ£¬»ñµÃÒ»¸örootȨÏÞµÄshell¡£
ºóÃż¤»îÁ÷³ÌÈçÏ£º
1.¿Í»§¶ËÅþÁ¬Ä¿µÄ×°±¸µÄ9530¶Ë¿Ú£¬·¢ËÍ×Ö·û´®OpenTelnet:OpenOnce£¬¸Ã×Ö·û´®Ç°ÃæÒª¼ÓÉÏָʾÐÂÎų¤¶ÈµÄ×Ö½Ú¡£¸Ã°ì·¨¹ØÓÚÒÔǰ°æ±¾µÄºóÃÅʹÓÃÊÇ×îºóÒ»²½¡£ÈôÊǴ˰취ºóûÓÐÏìÓ¦£¬Ôòtelneted·þÎñ¿ÉÄÜÒѾÔËÐС£
2.·þÎñ¶Ë£¨Ö¸×°±¸£©»á»Ø¸´randNum:XXXXXXXX£¬ÆäÖÐXXXXXXXXÊÇ8Î»Ëæ»úÊý×Ö¡£
3.¿Í»§¶ËʹÓÃÔ¤¹²ÏíÃÜÔ¿×÷Ϊ¼ÓÃÜÃÜÔ¿£¬ÅäºÏËæ»úÊý¾ÙÐÐÒÔϰ취¡£
4.¿Í»§¶ËʹÓüÓÃÜÃÜÔ¿¼ÓÃÜËæ»úÊý×Ö£¬¸½¼ÓÔÚrandNum:Ö®ºó£¬ÔÙÔÚÍ·²¿Ìí¼Ó×ܳ¤¶ÈµÄ×Ö½Ú£¬È»ºó·¢Ë͸ø·þÎñ¶Ë¡£
5.·þÎñ¶Ë´Ó/mnt/custom/TelnetOEMPasswd¼ÓÔØÔ¤¹²ÏíÃÜÔ¿£¬»òÖ±½ÓʹÓÃĬÈÏÃÜÔ¿2wj9fsa2¡£
6.·þÎñ¶Ë¶ÔËæ»úÊý¾ÙÐмÓÃÜ£¬²¢Ñé֤Ч¹ûÊÇ·ñÓë¿Í»§¶Ë·¢Ë͹ýÀ´ÊÇ·ñÒ»Ñù¡£ÑéÖ¤Àֳɻظ´verify:OK£¬²»È»»Ø¸´verify:ERROR¡£
7.¿Í»§¶Ë¼ÓÃÜ×Ö·û´®Telnet:OpenOnce£¬Ç°Ãæ´øÉÏ×ܳ¤¶È×Ö½Ú£¬CMD:×Ö·û´®£¬È»ºó·¢Ë͸ø·þÎñ¶Ë¡£
8.·þÎñ¶Ë½âÃܳö½ÓÊܵ½µÄÏÂÁî¡£ÈôÊÇ»ñµÃµÄЧ¹û¼´ÊÇ×Ö·û´®Telnet:OpenOnce£¬¾Í»á»Ø¸´Open:OK£¬¿ªÆôµ÷ÊÔ¶Ë¿Ú9527£¬Æô¶¯telnet·þÎñ¡£
Îó²îÑéÖ¤
PoC£ºhttps://github.com/Snawoot/hisilicon-dvr-telnet¡£
Ó÷¨£º./hs-dvr-telnet HOST PSK
ÆäÖÐPSKĬÈÏÊÇ2wj9fsa2
ʾÀýÓ÷¨
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌ»¹Î´ÐÞ¸´Îó²î£¬¿É½ÓÄÉÔÝʱ·ÀÓù²½·¥£ºÓû§¿ÉÒÔÆ¾Ö¤ÐèÒªÏÞÖÆ¶ÔÊÜÓ°Ïì×°±¸µÄÍøÂç»á¼û£¬Ö»ÔÊÐíÊÜÐÅÍеÄÓû§¾ÙÐлá¼û¡£
²Î¿¼Á´½Ó
https://habr.com/en/post/486856/
https://www.huawei.com/cn/psirt/security-notices/huawei-sn-20200205-01-HiSilicon-cn?from=timeline


¾©¹«Íø°²±¸11010802024551ºÅ