Multiple security vulnerabilities in beinmei can cause the fall of the Intranet

Source: Internet
Author: User

Multiple security vulnerabilities in beinmei can cause the fall of the Intranet
Let's see how I penetrated beinmei's intranet.
Proof of vulnerability:

After looking for a long time, I finally found a breakthrough in Bein's internal network. This vulnerability allowed me to access the Bein's internal network: www.baby558.com.
 



This site does not seem to have any complaints, but the vulnerability is not identified. I am looking for an injection point, and so on. The vulnerability Apache java allows me to access the website. I tested it first. He has a background/manager/html. I directly use software for brute force attacks.


 



I believe you should understand that the background of beinmei has re-discovered the weak vulnerability password.
 



Someone said they got the Shell and I uploaded my pony. Why do you think of Huang jiaju?
 


 



Through a series of commands, port opening, permission escalation, and ing, I logged on to the remote terminal 3389

At this time, you must ask, isn't it necessary to penetrate the Intranet? Yes. This time, I will completely penetrate the entire site intranet of beinmei.
 



We can query the IP address 10.100.108.14 of the server Intranet. The other servers are also under this IP address segment. I scanned 10.100.108.0-10.100.108.255 FOR THE vro Authentication System and order system.
 



Let's take 10.100.108.17 as an example. Open the Order System webpage and I can see. action. In my mind, if there is a st vulnerability, I will test it with K8 software.
 



I have been familiar with opening his remote port and successfully created a user to log on.
 



Envy, jealousy, GB memory, G port, 24 Cores

I will not test other servers and databases one by one.

The username and password used to crack encryption are basically the same

Okay.

Solution:

I have modified the/manager/html password in admin/shenlan.



Your company is so rich to ask for gifts. Basically, all servers with 24 or more cores, www.baby558.com servers, are very 48 cores. I was shocked by my friends and I.



Www.baby558.com also has the ST2 vulnerability.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.