The weak password Getshell exists in multiple core systems of Min 'an Property Insurance Co., Ltd.
1. Core Business System of Min 'an Property Insurance Co., Ltd.
Http: // 218.17.200.230: 9004/casserver/login? Service = http % 3A % 2F % 2F218. 17.200.230% 2Fj_acegi_security_check
Username weblogic, password weblogic123
Shell deployment test: http: // 218.17.200.230: 9001/job/2010.jsp
2. http://survey.minanins.com: 9001/console/login/LoginForm. jsp
Weblogic: weblogic123
3. http://extplat.minanins.com: 8011/console/login/LoginForm. jsp
Weblogic: weblogic123
4. http://simple.minanins.com: 8021/console/login/LoginForm. jsp
Weblogic: weblogic123
There are various insurance policies in the database.
5. http://mail.minanins.com: 9001/console/login/LoginForm. jsp
Weblogic: weblogic123
Change the password as soon as possible. It is useless to delete the shell.
Change the password as soon as possible. It is useless to delete the shell.
Solution:
Change the password and delete the suspicious webshell. Delete the shell to cure the problem...