A weak service password in a business management system of Guohua life insurance caused getshell to be accessible to the Intranet.
China Life Insurance Business Management System address: http: // 59.151.39.85/pre/
The system uses weblogic middleware and has a weak password weblogic/weblogic
Use weblogic getshell
One-sentence Trojan URL: http: // 59.151.39.85/chopper. jsp password: pandas
Note that you must manually enter the path/
Server
Space Used
Owner
10.32.48.32 (e-commerce)
Normal
Zhang Zhiyi, Fu Shiqi
10.32.76.85 (e-commerce)
Normal
Zhang Zhiyi, Fu Shiqi
10.32.76.83 (e-commerce)
Normal
Zhang Zhiyi, Fu Shiqi
10.56.96.22 (e-commerce)
Normal
Zhang Zhiyi, Fu Shiqi
10.56.48.31 (e-commerce)
Normal
Zhang Zhiyi, Fu Shiqi
10.32.75.101 (core database)
Normal
DBA
10.32.75.102 (yinbaotong database)
Normal
DBA
10.32.76.110 (Node B)
Normal
DBA
10.56.80.41 (node C)
94%
DBA
10.32.76.90 (CORE)
Normal
Zeng Zhichao
10.32.76.73 (CORE)
Normal
Zeng Zhichao
10.32.76.74 (CORE)
Normal
Zeng Zhichao
10.32.76.71 (CORE)
Normal
Zeng Zhichao
10.32.76.75 (CORE)
90%
Zeng Zhichao
10.32.76.76 (CORE)
Normal
Zeng Zhichao
10.32.76.121 (CORE) normal
Zeng Zhichao
10.56.80.176 (CORE)
Normal
Zeng Zhichao
10.56.80.177 (CORE)
Normal
Zeng Zhichao
10.32.76.72 (CORE)
Normal
Zeng Zhichao
10.32.48.37)
Normal
Zeng Zhichao
10.32.48.39)
Normal
Zeng Zhichao
10.32.48.40 (both business)
Normal
Zeng Zhichao
10.32.76.22 (Marketing report)
Normal
Zeng Zhichao
10.32.76.56 (Henan Rural Credit)
Normal
Zeng Zhichao
10.32.76.55)
Normal
Zeng Zhichao
10.32.76.11 (post-batch processing by ICBC)
Normal
Zeng Zhichao
10.32.76.12 (post-approval by ABC)
Normal
Zeng Zhichao
10.32.76.13 (post-approval of China Construction Bank)
Normal
Zeng Zhichao
10.32.76.14 (post-batch processing of the postal store)
Normal
Zeng Zhichao
10.32.76.15 (ICBC yundong core)
Normal
Zeng Zhichao
10.32.76.16 (ABC yundong core)
Normal
Zeng Zhichao
10.32.76.17)
Normal
Zeng Zhichao
10.32.76.18)
Normal
Zeng Zhichao
10.32.16.19 (front-end postal bank)
Normal
Zeng Zhichao
10.32.16.20 (front-end server of Hebei Construction Bank)
Normal
Zeng Zhichao
10.32.16.21 (frontend host of Hubei Construction Bank)
Normal
Zeng Zhichao
10.32.16.23 (front-end server of Tianjin Construction Bank)
Normal
Zeng Zhichao
10.32.76.77 (group insurance import server)
Normal
Cui lianxi
10.32.76.27 (third-party BPM server)
Normal
Zeng Zhichao
10.32.76.162 (after ABC)
Normal
Zeng Zhichao
10.32.76.161 (after ICBC)
Normal
Zeng Zhichao
10.32.76.155 (Bank of China Bank baotong core)
Normal
Zeng Zhichao
10.32.76.154 (after the Bank of China)
Normal
Zeng Zhichao
10.32.76.126 (post-storage)
Normal
Zeng Zhichao
10.32.76.125 (post Construction Bank)
Normal
Zeng Zhichao
10.32.76.122 (E-commerce (new electronic sales process) Front-end host)
Normal
Zeng Zhichao
10.32.48.70 (Chongqing Minya front-end)
Normal
Zeng Zhichao
10.32.48.69 (front of kaita, Liaoning)
Normal
Zeng Zhichao
10.32.48.67)
Normal
Zeng Zhichao
10.32.48.64)
Normal
Zeng Zhichao
10.32.48.63 (kinglun front-end)
Normal
Zeng Zhichao
10.32.48.61 (Hunan aviation insurance)
Normal
Zeng Zhichao
10.32.48.42)
Normal
Zeng Zhichao
10.32.48.41 (Ehome front-end server)
Normal
Zeng Zhichao
10.32.32.210 (Henan Rural Credit Cooperative front-end server)
Normal
Zeng Zhichao
10.32.16.86 (Bank of China frontend)
Normal
Zeng Zhichao
10.32.16.48 (Boc frontend host (New Process ))
Normal
Zeng Zhichao
10.32.16.47 (ABC frontend LifeKeeper backup (New Process ))
Normal
Zeng Zhichao
10.32.16.46 (row front-end machine LifeKeeper backup (New Process ))
Normal
Zeng Zhichao
10.32.16.18 (ICBC front-end server (new Shanghai ))
Normal
Zeng Zhichao
10.32.16.17 (ABC frontend server (new Shanghai ))
Normal
Zeng Zhichao
10.32.16.13 (Bank of China (new Shanghai ))
Normal
Zeng Zhichao
10.32.16.11 (front-end server of Hunan Construction Bank (new Shanghai ))
10.32.66.23 (Investment System) normal Zhao Feng
10.32.76.59 (Monitoring Server) normal Tian Wei
10.32.48.75 (e-commerce) is normal
10.32.76.106 (e-commerce) is normal
10.32.76.102 (e-commerce) 95% Zhang Zhiyi and Fu Shiqi
10.32.76.109 (e-commerce) 91% Zhang Zhiyi and Fu Shiqi
10.32.76.148 (CORE)
Normal
Zeng Zhichao
10.32.76.152 (CORE)
Normal
Zeng Zhichao
10.32.76.179 (CORE)
90%
Zeng Zhichao
10.32.48.47 (ERP)
Normal
Wang Lei
10.32.48.73 (ERP)
Normal
Wang Lei
10.32.48.29 (ERP)
Normal
Wang Lei
10.32.48.175 (ERP)
Normal
Wang Lei
10.32.48.111 (ERP)
Normal
Wang Lei,
10.32.48.132 (ERP)
Normal
Wang Lei
10.32.48.82 (online payment system) normal Zhao Feng Fu Shiqi
10.32.76.169 (online payment system) normal Zhao Feng Fu Shiqi
10.32.48.83 (online payment system) normal Zhao Feng Fu Shiqi
10.32.76.170 (online payment system) normal Zhao Feng Fu Shiqi
10.32.48.81 (e-commerce)
Normal
Zhang zhiyun
10.32.76.168 (e-commerce)
Normal
Zhang zhiyun
10.56.81.55 (node C)
95%
DBA
Vulnerability fix:
Changed to a complex strong password to solve the problem.