Coda video surveillance system mysql database weak password (involving all devices of China People's property insurance Suzhou Branch)
China People's Property Insurance Limited by share Ltd Suzhou Branch-Corda video surveillance system mysql database weak password, the management account involves PICC Suzhou Branch, Kunshan branch, Taicang branch, Changshu branch, Zhangjiagang branch, and Wujiang branch.
As a result, the data structure, equipment information and other sensitive information in the internal database of CoDA are leaked. The equipment information is the same as that in the http://www.wooyun.org/bugs/wooyun-2010-0114839,
1. Connect to the database
MYSQL**.**.**.**rootkdc
2. KDM3ADB, uas internal database
3. Information of more than 200 monitoring devices in Suzhou
Other regions
4. usernames and passwords of administrators in different regions
5. The database has the root permission, but does not have the write shell Permission.
6. log on with an account. The monitoring video cannot be viewed without the cu client.
[email protected]/88888
Solution:
Change the default password.