Ìá½»ÐèÇó
    *
    *

    *
    *
    *
    Á¢¼´Ìá½»
    µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

    logo

      ²úÆ·Óë·þÎñ
      ½â¾ö·½°¸
      ¼¼ÊõÖ§³Ö
      ºÏ×÷·¢Õ¹
      ¹ØÓڻƽð³Ç

      ÉêÇëÊÔÓÃ
        CVE-2020-24581 D-Link DSL-2888A Ô¶³ÌÃüÁîÖ´ÐЩ¶´¸´ÏÖÓë·ÖÎö
        ·¢²¼Ê±¼ä£º2023-03-24 ÔĶÁ´ÎÊý£º 1392 ´Î
        ©¶´¼ò½é

        D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾´æÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿Éͨ¹ý·ÃÎÊ/cgi-bin/execute_cmd.cgi´¥·¢ÃüÁîÖ´ÐЩ¶´¡£





         Ó°Ï췶Χ

        D-Link DSL-2888A AU_2.31_V1.1.47ae55֮ǰµÄ°æ±¾





         Â©¶´¸´ÏÖ
        Ê×ÏÈÔÚ¹ÜÀíÔ±ÃÜÂëÀ¸´¦ÊäÈëÈÎÒâÃÜÂë
        ͼƬ
        µã»÷µÇ¼ºó·ÃÎÊ/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=id¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´
        ͼƬ




         Â©¶´·ÖÎö

        Ö´ÐÐÃüÁîbinwal -Me ../IOT_BUG/CVE-2020-24581/DSL-2888A_AU_2.12_V1.1.47Z1-Image-all.bin --run-as=root½«¹Ì¼þÎļþϵͳÌáÈ¡£¬ÌáÈ¡ºóµÄĿ¼½á¹¹ÈçͼËùʾ

        ͼƬ

        Ö´ÐÐÃüÁî

        cd jffs2-root

        ½øÈëÎļþϵͳ£¬Îļþϵͳ½á¹¹ÈçͼËùʾ

        ͼƬ

        ¸Ã©¶´ÎªwebÓ¦Óé¶´£¬¸Ã¹Ì¼þÖÐweb×é¼þΪdhttpd£¬Ö´ÐÐÃüÁîfind . -name ¡°dhttpd¡±ËÑË÷web×é¼þλÖã¬ËÑË÷½á¹ûÈçͼËùʾ

        ͼƬ

        ÈçͼËùʾ£¬Í¨¹ýIDA´ò¿ªdhttpd

        ͼƬ

        ¸ÃÔ¶³ÌÃüÁîÖ´ÐнӿÚΪ/cgi-bin/execute_cmd.cgi£¬ÈçͼËùʾ£¬ÔÚº¯Êýsub_9C4CÖУ¬Èç¹û·ÃÎÊ·¾¶ÖдæÔÚ/cgi-bin£¬Ôòµ÷ÓÃsub_BEA0º¯Êý½øÐд¦Àí

        ͼƬ

        ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ52Ðн«cgiÎļþÓëcgi-binĿ¼½øÐÐÆ´½Ó£¬ÔÚµÚ53ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚ£¬ÔÚµÚ63ÐÐÅжÏcgiÎļþÊÇ·ñ´æÔÚÖ´ÐÐȨÏÞ

        ͼƬ

        ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄµÚ70Ðн«»ñÈ¡µ±Ç°Îļþ·¾¶£¬ÔÚ71ÐÐÔÚfile²éÕÒ¡±/¡±×îºóÒ»´ÎµÄλÖã¬Èç¹û¸ÃλÖôæÔÚ£¬ÔòÔÚµÚ76ÐнøÈëfileĿ¼

        ͼƬ

        ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ105-108Ðн«½øÐÐcgiÎļþÖ´Ðл·¾³±äÁ¿ÅäÖÃ

        ͼƬ

        ¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬ÔÚsub_BEA0º¯ÊýµÄ111-143Ðн«½øÐÐÉí·ÝУÑé

        ͼƬ

        ¼ÌÐø¸ú½øsub_BEA0º¯Êý£¬ÈçͼËùʾ£¬Í¨¹ýÉí·ÝУÑéºó£¬ÔÚµÚ149Ðе÷ÓÃsub_BB5Cº¯Êý¶ÔcgiÎļþ½øÐд¦Àí

        ͼƬ

        ¸ú½øsub_BB5Cº¯Êý£¬ÔÚsub_BB5Cº¯ÊýµÄµÚ40Ðе÷ÓÃexecveº¯ÊýÖ´ÐÐcgiÎļþ

        ͼƬ
        ²éÕÒ´æÔÚ©¶´µÄexecute_cmd.cgiÎļþ£¬execute_cmd.cgiÎļþλÓÚÎļþϵͳϵÄwww/cgi-binĿ¼
        ͼƬ

        ²é¿´execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝ£¬execute_cmd.cgiÎļþ¾ßÌåÄÚÈÝÈçͼËùʾ£¬execute_cmd.cgiÎļþÄÚÈÝΪ»ñÈ¡QUERY_STRINGÖеڶþ¸ö²ÎÊýµÄÖµ£¬²¢Í¨¹ý·´ÒýºÅ``ÒÔÖ´ÐÐÃüÁʽִÐиÃÖµ

        ͼƬ

        ÔÚIDAÖÐËÑË÷QUERY_STRING£¬ËÑË÷½á¹ûÈçͼËùʾ

        ͼƬ

        ÔÚjsÎļþĿ¼²éÕÒQueryString£¬²éÕÒ½á¹ûÈçͼËùʾ

        ͼƬ

        ·ÃÎÊ´æÔÚQueryString×Ö·ûµÄajax.jsÎļþ£¬ajax.jsÎļþÄÚÈÝÈçͼËùʾ

        ͼƬ

        ¹Êµ±Í¨¹ýÉí·ÝУÑéʱ£¬¹¹Ôìuri£º/cgi-bin/execute_cmd.cgi?timestamp=1&cmd=cmd¿ÉÖ´ÐÐÈÎÒâÃüÁÓÉÓڸð汾·ÓÉÆ÷ÔÚÃÜÂëÀ¸ÊäÈëÈÎÒâÃÜÂëºó¼´¿ÉÈÆ¹ýÉí·ÝУÑ飬ËùÒÔ²»ÐèÖªµÀÉ豸ÃÜÂë¼´¿É´¥·¢ÃüÁîÖ´ÐЩ¶´

        ͼƬ


        Ãâ·ÑÊÔÓÃ
        ·þÎñÈÈÏß

        ÂíÉÏ×Éѯ

        400-811-3777

        »Øµ½¶¥²¿
        ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿