1. some internal staff systems of the early domain name sandai.net used RTX for access control, leading to leakage of important internal O & M information due to improper access control measures. 2. ESXServer is used to deploy some application tests and servers, and ESXServer is not correctly set, resulting in access security for some secondary domain names that are in critical status. 3. weak password of the internal management system.
Description: #1. Entry: Xunlei coffee
Security risk information: due to the absence of strict configuration for RTX authentication, the public network can access the internal system.
Risk address: http://coffee.xunlei.com: 8000/viewthread. php? Tid = 791
Risk content:
Telecom testing environment
Use Remote Desktop to connect to any of the following
1) Direct Internet access with a public IP Address
Windows 20003
Vm1) domain name twin0550vm1.sandai.net account administrator password xunlei.com
Vm2) domain name twin0550vm2.sandai.net account administrator password xunlei.com
Vm3) domain name twin0550vm3.sandai.net account administrator password xunlei.com
Vm4) domain name twin0550vm4.sandai.net account administrator password xunlei.com
#2. Process: Enter the public network test Server
Application User Password: administrator: xunlei.com
Log on to the target server and find that one server has other weak passwords that have been controlled by the attacker HK.
Some server information is as follows:
Ethernet adapter local connection 2:
Connection-specific DNS Suffix .:
IP Address ......: 10.7.7.2
Subnet Mask ......: 255.255.255.0
Default Gateway .........:
Ethernet adapter local connection 3:
Connection-specific DNS Suffix .:
IP Address ......: 121.10.137.103
Subnet Mask ......
Default Gateway ......: 121.10.137.1
C: \ Documents ents and Settings \ Administrator> ping 192.168.14.10
Pinging 192.168.14.10 with 32 bytes of data:
Reply from 192.168.14.10: bytes = 32 time = 1 ms TTL = 254
Ping statistics for 192.168.14.10:
Packets: Sent = 1, stored ED = 1, Lost = 0 (0% loss ),
Approximate round trip times in milli-seconds:
Minimum = 1 ms, Maximum = 1 ms, Average = 1 ms
All Server IP addresses with weak passwords:
121.10.137.100 121.10.137.101 121.10.137.103 121.10.137.104 10.7.7.3 121.14.82.218
For example:
#3. Improper ESXServer configuration causes ARP attacks on front-end hosts of several Substations
Risky IP Address: 121.14.82.218
Risky load substation: kankan.xunlei.com; movie.xunlei.com
Attack effects such as (test for only one second ):
#4. SVN important information leakage:
Account:
New svn 192.168.13.252
Account Password (password includes [])
Wuwenhua [wwh121395]
Http: // 10.10.16.252/code_svn/
#5. weak passwords in the internal business system, which can be further penetrated:
Risk address: admin.sendfile.vip.xunlei.com
Risk Information: 1. Weak Password: test 2. You can obtain PHP WebShell by editing the configuration file in the background to further penetrate the Intranet.
Conclusion: The Point-to-end operation does not affect the normal operation of the thunder system. It is a pity that the domain is not seen.
Solution:
#1. Disable thunder coffee or block Internet access
#2. It is best to use uniform identity authentication on the test server to increase the complexity of the password.
#3. Thoroughly check all server Nic configurations related to the ESXServer virtualization server, and disable mixed mode on unwanted machines. (this option can be configured for both vSphere and vCenter)
#4. enhance employees' awareness of password protection
#5. Set a system forced Password Policy