Multiple security vulnerabilities in beinmei can cause the fall of the Intranet
Let's see how I penetrated beinmei's intranet.
Proof of vulnerability:
After looking for a long time, I finally found a breakthrough in Bein's internal network. This vulnerability allowed me to access the Bein's internal network: www.baby558.com.
This site does not seem to have any complaints, but the vulnerability is not identified. I am looking for an injection point, and so on. The vulnerability Apache java allows me to access the website. I tested it first. He has a background/manager/html. I directly use software for brute force attacks.
I believe you should understand that the background of beinmei has re-discovered the weak vulnerability password.
Someone said they got the Shell and I uploaded my pony. Why do you think of Huang jiaju?
Through a series of commands, port opening, permission escalation, and ing, I logged on to the remote terminal 3389
At this time, you must ask, isn't it necessary to penetrate the Intranet? Yes. This time, I will completely penetrate the entire site intranet of beinmei.
We can query the IP address 10.100.108.14 of the server Intranet. The other servers are also under this IP address segment. I scanned 10.100.108.0-10.100.108.255 FOR THE vro Authentication System and order system.
Let's take 10.100.108.17 as an example. Open the Order System webpage and I can see. action. In my mind, if there is a st vulnerability, I will test it with K8 software.
I have been familiar with opening his remote port and successfully created a user to log on.
Envy, jealousy, GB memory, G port, 24 Cores
I will not test other servers and databases one by one.
The username and password used to crack encryption are basically the same
Okay.
Solution:
I have modified the/manager/html password in admin/shenlan.
Your company is so rich to ask for gifts. Basically, all servers with 24 or more cores, www.baby558.com servers, are very 48 cores. I was shocked by my friends and I.
Www.baby558.com also has the ST2 vulnerability.