Shell can threaten the Intranet caused by improper configuration of a System in China Mobile
Improper configuration causes shell to threaten the Intranet
Detailed description:
**. **: 8000/MMSSender
What does the appearance look like?
Let's go to the system through **. **: 8000/jmx-console/getshell.
Pony **. **: 8000/wooyun/woo. jsp
One sentence
**. **: 8000/wooyun/woo2yun. jsp
Password pandas
DAMA **. **: 8000/wooyun/1. jspx xxxxxx
Threat Intranet
Proof of vulnerability:
It looks like a moving thing, but it cannot be proved.
I don't know why it seems to be related to telecom again.
D:/MMBP Source/MMSManagerWeb/xml/SelectConfigfo. xml
MMS business management platform?
Baidu: Beijing zhangshangtong Network Technology Co., Ltd.
Unreadable data
D:/MMSData/History/
Many files containing mobile phone numbers are generated daily under the folder.
D:/MMBP/MmbpSrv/user.confirm
D:/MMBP/MmbpSrv/SmbpSpApi Log/
Okay, that's it. If there is something wrong with the vendor, I beg for review and help me change it.
Solution:
Correctly configure jboss and delete shell.